A new Australian privacy obligation starts on 10 December 2026, and it lands on one specific page of your website.

What changed

Australia has added an automated decision-making (ADM) transparency obligation to the Privacy Act. It arrives through the Privacy and Other Legislation Amendment Act 2024, which amends Australian Privacy Principle 1 (APP 1), the principle that governs what your privacy policy must contain.

From commencement, organisations covered by the Privacy Act have to spell out, in their privacy policy, the kinds of personal information their automated systems use and the kinds of decisions those systems make. The obligation bites where an entity "has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect the rights or interests of an individual."

The Office of the Australian Information Commissioner (OAIC) is developing guidance on how to meet the obligation, and confirmed the timeline on its own site. It published an Issues Paper on the transparency obligation on 18 May 2026, ran a consultation that closed on 15 June 2026, and intends to release final guidance by September 2026. The obligation itself commences on 10 December 2026.

One point worth flagging: the law uses the words "computer program", and the OAIC reads that broadly in its Issues Paper. So this is not only about tools badged as AI. Ordinary business software that makes a qualifying decision can be caught too.

What it means for you

If your firm uses software or AI to make, or to materially assist, decisions about clients that could significantly affect their rights or interests, you will need to disclose that use in your public privacy policy from 10 December 2026. That is a concrete website task with a date on it, not a nice-to-have.

The calm read: this is a transparency rule, not a ban on automated decisions. Nothing about how you run those systems has to change. What has to change is what your privacy-policy page says. You also have runway. Final guidance is due by September 2026, well before the December start, so the sensible step now is to note the date, take stock of where automated decisions touch clients, and plan a privacy-policy review rather than rush a rewrite.

Because the disclosure lives on a public page, it is also part of how your firm presents itself to anyone who checks, including regulators, prospective clients, and the AI assistants that now read privacy policies. A clear, current policy is one more reason to be trusted when someone is deciding whether to enquire.

Frequently asked questions

Does this apply to my firm?

It applies to organisations covered by the Privacy Act that use personal information in automated decisions capable of significantly affecting a person's rights or interests. For most professional-services firms, that means if you use software or AI to make or materially assist decisions about clients, yes, it applies to you.

What do I actually have to do?

Update your public privacy policy. From 10 December 2026 it must state the kinds of personal information your automated systems use and the kinds of decisions they make. The requirement sits under Australian Privacy Principle 1 (APP 1).

When does it start?

The obligation commences on 10 December 2026. The OAIC intends to publish guidance by September 2026, ahead of that date, and the consultation that shapes the guidance closed on 15 June 2026.

Does this only cover AI?

No. The law uses the phrase "computer program", which the OAIC reads broadly in its Issues Paper. Ordinary business software that makes a qualifying decision can be caught, not just tools badged as AI.

Do I need to stop using automated decisions?

No. This is a transparency rule, not a ban. It asks you to disclose the use in your privacy policy, so the measured step is to review that page well before December.

Amina
Editorial Team