Privacy
From 10 December 2026 your privacy policy must disclose automated decisions
From 10 December 2026, entities covered by the Privacy Act that use personal information in automated decision-making affecting a person’s rights or interests must disclose that in their privacy policy. The OAIC’s guidance was still in draft when this was written, so the detail may move before the date.
What changes in December
From this date, a privacy policy has to say so where personal information is used in automated decision-making that could affect someone’s rights or interests. Not a new consent, and not a ban — a disclosure you either have in your policy or you do not.
From 10 December 2026, entities covered by the Privacy Act that use personal information in automated decision-making which affects a person’s rights or interests must say so in their privacy policy. It is a transparency obligation, not a prohibition — nobody is telling you to stop.
Does it apply to your practice?
Two questions decide it. First, are you covered by the Privacy Act at all? The small business exemption still stands at $3 million annual turnover, with carve-outs that apply regardless of turnover. Many smaller practices fall outside the Act entirely — though that is worth confirming rather than assuming, because the carve-outs are broader than most people expect.
Second, does anything in your stack make or substantially inform a decision about a person, using their personal information, without a human weighing in? That is a narrower question than “do we use AI”, and for most practices the honest answer today is probably no. It is worth asking before December rather than after.
The guidance is still draft
The OAIC consulted on guidance for transparency in automated decision-making in May 2026, with submissions closing in June. At the time of writing that guidance had not been finalised, so the detail of what a compliant privacy policy disclosure looks like may still move. The date is fixed; the detail is not.
We will update this article when the final guidance lands.
What is worth doing now
- Write down where personal information meets automation in your practice, even if you conclude nothing qualifies. The exercise is the evidence.
- Check whether you are an APP entity before spending time on the rest.
- If you do use automated decision-making, note now who can explain how it reaches a decision — that is what a client will ask for.
- Keep the human in the loop. A decision a person actually makes, using a tool as input, is a different thing from an automated decision.
Separately and already in force: the OAIC has recommended that organisations do not enter personal information — particularly sensitive information — into publicly available generative AI tools. That guidance was published in October 2024 and updated in January 2025, and it applies today.
Sources
- Consultation on guidance for transparency in automated decision-making, Office of the Australian Information Commissioner, published 18 May 2026
- Guidance on privacy and the use of commercially available AI products, OAIC, published 21 October 2024, updated 17 January 2025
- Australian Privacy Principles and the small business exemption, OAIC
Keeping the record is the hard part.
DeskMate writes who ran a skill, what it touched and who approved it, every time — as a by-product of the work rather than a log someone has to remember.