Does Your Business Use Automated Decision-Making? New Privacy Rules Start In December 2026

You may already be using automated decision-making in your business without calling it that.

Perhaps your recruitment platform ranks applicants before you review them. Maybe your payment provider flags certain customers as high risk, or an online system helps decide whether someone qualifies for your service.

These tools can save you time, but they can also influence decisions that have a real impact on people. From 10 December 2026, some Australian businesses will need to be more transparent about how these systems use personal information.

The change does not ban automated decision-making, and it does not only apply to sophisticated artificial intelligence. Instead, if your business is covered by the Privacy Act 1988, you may need to explain certain automated decision-making practices in your Privacy Policy.

That might sound like a simple document update. In reality, the first step is working out what your software is actually doing.

Key Date: 10 December 2026
If your business is covered by the Privacy Act, you should check whether any software uses personal information to make, or substantially influence, important decisions about people. Your
Privacy Policy may then need to be updated.

What Is Changing On 10 December 2026?

From 10 December 2026, new transparency requirements will apply to businesses and organisations covered by the Australian Privacy Principles.

You may need to update your Privacy Policy if your business has arranged for a computer program to use someone’s personal information to make - or do something substantially and directly related to making - a decision that could significantly affect that person’s rights or interests.

Personal information is broader than names and contact details. It can include application information, transaction history, account activity, identity documents and online identifiers, depending on whether the information can be connected to an identifiable person.

Where the rules apply, your Privacy Policy will need to explain the kinds of personal information being used, the kinds of decisions made entirely by computer programs and the kinds of decisions where software plays a substantial and direct role.

In practical terms, if software uses information about a customer, applicant or another individual to help make an important decision about them, you may need to be more open about that process.

The rules apply to relevant decisions made from 10 December 2026. This means an older system is not automatically exempt just because you introduced it, or collected the relevant information, before that date.

This Is Not Just About AI

When you hear “automated decision-making”, you might picture an advanced AI system making decisions without any human involvement.

The rules are broader than that.

The software could use machine learning or artificial intelligence, but it could also be a fairly ordinary system operating according to set rules, formulas or scoring criteria.

For example, imagine your online platform automatically rejects an application when certain conditions are not met. The technology may be simple, but it is still using personal information to make a decision.

The rules may also apply even where someone in your business gives the final approval.

Suppose your recruitment software scores hundreds of applications and gives you a shortlist. You may still decide who moves forward, but the system has already had a significant influence over who you consider.

Having a person approve the final result does not automatically take the process outside the rules. The important question is whether the software did something substantially and directly related to making the decision.

Recruitment is a useful example, although privacy obligations can change once a private-sector employment relationship begins because some employee records are exempt from the Privacy Act. If you use recruitment software, you may need to consider how information is handled at each stage of the hiring process.

Which Decisions Should You Be Looking For?

You do not need to include every automated process used by your business in your Privacy Policy.

The rules are concerned with decisions that could reasonably be expected to significantly affect someone’s rights or interests.

This generally means decisions that can have a meaningful effect on a person’s finances, opportunities, legal position or access to an important product, service or benefit.

An automated email confirming that an order has been shipped is unlikely to be the type of decision the new rules are targeting.

On the other hand, you should take a closer look if software can:

  • suspend or restrict a customer’s account;
  • reject an application or claim;
  • affect whether someone receives a financial product;
  • influence access to healthcare, housing or insurance;
  • rank someone for an employment opportunity; or
  • determine whether a person can access a significant service.

A decision can be covered whether it helps or disadvantages the person. A refusal or failure to make a decision may also be relevant.

The line will not always be obvious. A decision that seems minor in one business could have a much greater effect in another, particularly where the person is vulnerable or relies heavily on the service.

That is why it is worth looking at both the technology and the real-world outcome. The question is not simply “Are we using AI?” It is “What decision is this system influencing, and what does that mean for the person affected?”

You May Be Responsible For Third-Party Software Too

You do not need to have built the technology yourself for these rules to matter.

Like many businesses, you may rely on external platforms to process payments, screen applicants, verify identities, detect fraud, manage customer accounts or assess risk.

If you have arranged for one of these systems to use personal information as part of an important decision, the fact that another company owns the software may not remove your obligations.

This is where you may need to do some digging.

You might know that a provider has labelled a customer “high risk”, for example, without knowing what information led to that result or how much influence the score has over the final outcome.

If you then automatically restrict the customer’s account, you may need enough information from the provider to understand and accurately explain the process.

Reviewing the system may also uncover other privacy issues. The provider might store information overseas, use the data for its own purposes or combine it with information from other sources.

These issues are not part of the new automated decision-making test itself, but they may raise separate obligations under the Australian Privacy Principles.

The broader lesson is simple: you should know what your software does with personal information before you rely on its results or describe the process in your Privacy Policy.

Does This Apply To Your Small Business?

Not automatically.

The new requirement applies to APP entities, which means businesses and organisations covered by the Australian Privacy Principles.

The Privacy Act generally applies to organisations with annual turnover above $3 million. However, some businesses below that threshold are also covered.

This can include certain health service providers, businesses that trade in personal information, Commonwealth contracted service providers, credit reporting bodies and businesses that have voluntarily opted into the Privacy Act.

So, even if your turnover is below $3 million, you should not assume that the Privacy Act does not apply to you.

If your business is outside the Privacy Act, the specific December 2026 Privacy Policy obligation may not apply. However, that does not mean your automated systems are legally risk-free.

Recruitment software could create discrimination risks. A chatbot or automated sales tool could give customers misleading information. A system could rely on inaccurate data, disclose confidential material or produce outcomes that conflict with your contracts.

You may also find that larger clients, government customers, investors or business partners want to know how you use personal information and automated systems.

If you expect your business to grow, it may be easier to establish sensible privacy practices now than to rebuild everything later.

Is Updating Your Privacy Policy Enough?

For the new federal obligation, your Privacy Policy is the legally required place for the disclosure.

However, that does not always mean it is the best - or only - place to explain what is happening.

Most people do not read a Privacy Policy every time they submit an application, create an account or use a service.

If software is about to assess a job application, restrict an account or influence another important decision, a short explanation at that point may be more useful.

For example, you might tell applicants that software will analyse and rank information in their applications before they submit them. You could then link to a fuller explanation in your Privacy Policy.

If a customer’s account is restricted, you might explain that an automated risk assessment contributed to the decision and give them a way to raise a concern if the information used was incorrect.

These extra notices, explanations and review processes are not all expressly required by the new automated decision-making provisions. The new rules are mainly transparency obligations centred on your Privacy Policy, rather than a general right to human review or an obligation to notify every person individually.

Even so, clearer explanations can help avoid confusion and make complaints easier to resolve.

Your Privacy Policy itself should also be easy to find, clearly written and tailored to what your business actually does.

A broad sentence saying that you “may use AI to improve services” is unlikely to tell people very much. It does not explain what information you use, which decisions are involved or how the technology may affect them.

What Should You Do Before December?

The best place to start is not your Privacy Policy. It is your technology.

Look across your business and identify systems that use information about customers, applicants, workers or other individuals.

This may include recruitment platforms, fraud-detection tools, identity checks, account moderation systems, application software and tools that recommend prices, eligibility or access to services.

For each system, work out what information goes in, what result comes out and what happens next.

Does the system make the decision by itself? Does it produce a score or recommendation that your team normally follows? Could the result significantly affect someone? Is there a way to check the information or reconsider the outcome if something goes wrong?

This does not need to become a complicated technical audit.

The goal is to build a clear picture of where personal information and automated decisions meet inside your business.

Once you understand that, you can decide whether your Privacy Policy needs to be updated. You may also need to review your collection notices, internal procedures and contracts with software providers.

Your team should understand that a result is not automatically correct just because it came from software. Where a system contributes to an important decision, someone in the business should know who is responsible for checking the result and answering questions.

For higher-risk systems, a Privacy Impact Assessment may also help you identify issues before they turn into complaints or compliance problems.

Your Privacy Policy is an important part of privacy compliance, but it cannot replace a proper understanding of how your business handles personal information.

Is This Part Of A Wider Privacy Law Overhaul?

Yes. The automated decision-making rules are one part of Australia’s broader privacy reform program.

They were introduced through the first tranche of privacy reforms passed in 2024. That package also included stronger enforcement options, a statutory tort for serious invasions of privacy and work towards a Children’s Online Privacy Code.

Further reforms are also being considered. These could eventually affect areas such as the small-business exemption, individual privacy rights, direct marketing, data retention and the wider requirement to handle personal information fairly and reasonably.

Those proposals are not all current law, and further legislation would be needed before they become binding.

For now, the automated decision-making obligation is one of the next confirmed privacy changes with a clear commencement date.

What Happens If You Get It Wrong?

Failing to comply with the Australian Privacy Principles can lead to complaints and investigation by the Office of the Australian Information Commissioner.

That does not mean every incomplete Privacy Policy will automatically result in a large fine. The regulator has a range of investigation and enforcement options, and the outcome will depend on the circumstances.

However, formal enforcement is not the only risk.

If you do not understand how your own system works, you may struggle to answer customer questions, manage complaints or explain why a decision was made.

Problems can become more serious where information is inaccurate, the technology produces unfair outcomes or your Privacy Policy does not match what happens in practice.

The practical goal is to understand the system before you make promises about it.

Getting Ready For The New Rules

At first glance, the December 2026 change may look like another Privacy Policy update.

For some businesses, that may ultimately be all that is needed.

For others, reviewing the policy may reveal a bigger issue: no one is entirely sure what a third-party platform does, what information it relies on or how much influence it has over customers and applicants.

That is why it makes sense to start with your technology, not the legal wording.

Once you understand where personal information is being used, which decisions are being influenced and who is responsible for the final outcome, it becomes much easier to prepare an accurate Privacy Policy.

If you are unsure whether the new rules apply to your business, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

AI Governance Policies for Australian Businesses: What to Include

AI Governance Policies for Australian Businesses: What to Include

Using AI without clear internal rules can expose your business to privacy, contract, consumer law and confidentiality risks. Here is what an AI governance

4 Aug 2026
Read more
Workplace Surveillance Policy Template: What To Include In Australia

Workplace Surveillance Policy Template: What To Include In Australia

If you run a small business, it’s completely normal to want clarity over what’s happening in your workplace. Maybe you’ve had stock go missing, customer complaints about service, or safety concerns after...

4 Aug 2026
Read more
Employee Monitoring Notices in Australia: Employer Obligations and Privacy Risks

Employee Monitoring Notices in Australia: Employer Obligations and Privacy Risks

Employee monitoring can help protect your business, but poor notice, overly broad surveillance and weak privacy controls can create serious legal risk

3 Aug 2026
Read more
Privacy Agreement Essentials For Startups And Small Businesses In Australia

Privacy Agreement Essentials For Startups And Small Businesses In Australia

If you run a small business or startup, there’s a good chance you collect personal information every day - even if you don’t think of yourself as a “data business”. Maybe you...

3 Aug 2026
Read more
Reviewing Privacy Consent Wording for Australian Businesses

Reviewing Privacy Consent Wording for Australian Businesses

A privacy consent wording review helps Australian businesses check whether their forms, opt-ins and privacy notices are clear, accurate and aligned with

1 Aug 2026
Read more
Website Terms and Privacy for Digital Product Studios in Australia

Website Terms and Privacy for Digital Product Studios in Australia

Digital product studios often need more than a generic website disclaimer. Learn how website terms and privacy policies should work for Australian studios

1 Aug 2026
Read more
Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.