Get started

Privacy

From 10 December 2026 your privacy policy must disclose automated decisions

From 10 December 2026, entities covered by the Privacy Act that use personal information in automated decision-making affecting a person’s rights or interests must disclose that in their privacy policy. The OAIC’s guidance was still in draft when this was written, so the detail may move before the date.

What changes in December

10 DEC2026

From this date, a privacy policy has to say so where personal information is used in automated decision-making that could affect someone’s rights or interests. Not a new consent, and not a ban — a disclosure you either have in your policy or you do not.

It is a policy amendment with a deadline. The work is deciding whether anything in your practice meets the description, and writing two or three honest sentences if it does.

From 10 December 2026, entities covered by the Privacy Act that use personal information in automated decision-making which affects a person’s rights or interests must say so in their privacy policy. It is a transparency obligation, not a prohibition — nobody is telling you to stop.

Does it apply to your practice?

Two questions decide it. First, are you covered by the Privacy Act at all? The small business exemption still stands at $3 million annual turnover, with carve-outs that apply regardless of turnover. Many smaller practices fall outside the Act entirely — though that is worth confirming rather than assuming, because the carve-outs are broader than most people expect.

Second, does anything in your stack make or substantially inform a decision about a person, using their personal information, without a human weighing in? That is a narrower question than “do we use AI”, and for most practices the honest answer today is probably no. It is worth asking before December rather than after.

The guidance is still draft

The OAIC consulted on guidance for transparency in automated decision-making in May 2026, with submissions closing in June. At the time of writing that guidance had not been finalised, so the detail of what a compliant privacy policy disclosure looks like may still move. The date is fixed; the detail is not.

We will update this article when the final guidance lands.

What is worth doing now

  • Write down where personal information meets automation in your practice, even if you conclude nothing qualifies. The exercise is the evidence.
  • Check whether you are an APP entity before spending time on the rest.
  • If you do use automated decision-making, note now who can explain how it reaches a decision — that is what a client will ask for.
  • Keep the human in the loop. A decision a person actually makes, using a tool as input, is a different thing from an automated decision.

Separately and already in force: the OAIC has recommended that organisations do not enter personal information — particularly sensitive information — into publicly available generative AI tools. That guidance was published in October 2024 and updated in January 2025, and it applies today.

Keeping the record is the hard part.

DeskMate writes who ran a skill, what it touched and who approved it, every time — as a by-product of the work rather than a log someone has to remember.