The privacy deadline hiding in your marketing stack
From 10 December, software that makes decisions about people must be declared. Some of yours might.
Posted on
Filed under
Business

29/7
Most of the compliance conversation in Australian marketing over the past two years has been about cookies, consent banners and the slow death of third-party tracking. Meanwhile, a quieter change has been sitting in the legislation with a fixed date attached to it, and it lands on 10 December 2026.
From that date, if your business has arranged for software to make decisions about people, and those decisions could significantly affect their rights or interests, you have to disclose it in your privacy policy.
That is roughly four months away. We think a fair number of businesses will discover in November that the answer to "do we do that?" is yes, and that nobody could say exactly which system was doing it.
What the obligation actually says
The change comes from the Privacy and Other Legislation Amendment Act 2024 (Cth), which inserted new subclauses 1.7, 1.8 and 1.9 into Australian Privacy Principle 1. The OAIC has confirmed these commence on 10 December 2026.
The obligation is triggered where all three of the following are true:
Your organisation has arranged for a computer program to make a decision, or to do something substantially and directly related to making a decision
That decision could reasonably be expected to significantly affect the rights or interests of an individual
Personal information about that individual is used in the operation of the program
Where that applies, your privacy policy must set out the kinds of personal information used in those programs, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to making the decision.
Two details are easy to miss. First, "making a decision" includes refusing or failing to make one. Second, the obligation applies whether the outcome is good or bad for the person. A system that automatically approves someone is caught on the same terms as one that automatically declines them.
The rules also apply to decisions made from 10 December 2026 regardless of when you set the system up. There is no grandfathering for tools you already have running.
What it is not
It is worth being precise here, because a lot of the commentary around this has been louder than the law.
This is a transparency measure. Unlike the equivalent provisions in the European GDPR, it does not give individuals a right to contest an automated decision, a right to request human review, or a right to an explanation of a specific outcome. It does not require you to notify people directly. It requires you to describe, in your privacy policy, the kinds of automated decisions you make and the kinds of information you use to make them.
That is a lower bar than many people assume. It is also not optional. A privacy policy that fails to meet APP 1 requirements can attract a compliance notice, an infringement notice, or civil penalty proceedings, and the OAIC's enforcement posture has visibly hardened.
In the first week of January 2026 the regulator began its first ever compliance sweep, reviewing the privacy policies of approximately 60 entities against APP 1.4. The six sectors selected were rental and property, chemists and pharmacists, licensed venues, car rental companies, car dealerships, and pawnbrokers and second-hand dealers, chosen because they commonly collect personal information in person. Entities found to have non-compliant policies may face compliance and infringement notices with penalties of up to $66,000.
First question: does the Privacy Act even apply to you?
For a lot of Australian SMEs, the honest answer used to be no. The small business exemption covers organisations with annual turnover of $3 million or less, and that has historically captured the majority of Australian businesses.
That exemption has not been repealed. Removing it is a stated government commitment expected in the second tranche of Privacy Act reforms, but as at mid-2026 no second-tranche bill has been introduced and no commencement date has been set. Anyone telling you the exemption is already gone is ahead of the facts.
What has changed is that the exemption is being cut away at the edges, and one of those cuts landed this month.
From 1 July 2026, tranche 2 of the AML/CTF reforms brought real estate professionals, dealers in precious stones, metals and products, and professional service providers such as lawyers, conveyancers, accountants and trust and company service providers into the reporting entity regime. Under section 6E(1A) of the Privacy Act, those businesses must now comply with the Privacy Act in relation to personal information handled for the purposes of, or in connection with, their AML/CTF obligations, regardless of turnover. The OAIC has published dedicated guidance and a template collection notice for them.
One limitation matters here, and most of the commentary skips it. If you are otherwise exempt and are covered only because you are now a reporting entity, the OAIC has confirmed your privacy policy need only address your personal information handling for AML/CTF purposes. You are not required to document your other business activities. So the automated decision-making obligation, when it arrives in December, would only reach automated decisions connected to that AML/CTF handling, such as automated customer due diligence or risk assessment. It does not pull your whole marketing stack into scope.
Separately, some small businesses were already covered regardless of turnover for other reasons. The OAIC's examples include health service providers, businesses trading in personal information, and operators of residential tenancy databases. That list is not exhaustive, so it is worth checking your own position rather than assuming.
Where marketing technology actually sits
Here is where we would rather be useful than alarming.
Most of what sits in a standard marketing stack is very unlikely to be caught. Lead scoring that ranks enquiries for a sales team to work through, email automation that decides who receives which nurture sequence, ad platform algorithms deciding who sees a campaign, chatbots that route an enquiry to the right inbox: none of these obviously make decisions that significantly affect a person's rights or interests. They affect who gets a phone call sooner.
The OAIC's own examples of significant decisions point somewhere quite different: decisions granting or refusing a statutory benefit, decisions affecting a person's rights under a contract such as a life insurance policy, and decisions affecting access to a significant service or support such as healthcare.
The line gets blurry in places our clients actually work:
Lending and financial services. Automated pre-qualification, serviceability screening or credit-adjacent assessment that determines whether an application proceeds is a long way from a nurture sequence.
Education and training. Automated eligibility screening, course admission or enrolment decisions, and automated funding eligibility assessment for government-subsidised training places.
Insurance and health-adjacent services. Automated eligibility or coverage decisions, and automated triage that determines whether someone gets access to a service.
Property. Automated tenant screening and application ranking. Residential tenancy database operators are already covered by the Privacy Act regardless of turnover, and rental applications sit close to a person's access to housing.
There is also a procurement dimension that is easy to overlook. The obligation is triggered by decisions your organisation has arranged for a computer program to make. That includes third-party products. If you have bought a screening, scoring or eligibility tool, the fact that a vendor built it does not move the disclosure obligation onto the vendor.
The Western Australian layer
Perth businesses have a second thing to track, and it is already in force.
The Privacy and Responsible Information Sharing Act 2024 (WA) commenced on 1 July 2026. It applies to the WA public sector, and this is the part people miss, it can also apply to private sector organisations in their capacity as contracted service providers to WA public entities.
The PRIS Act goes further than the Commonwealth provisions on automated decision-making. Section 16 defines an automated decision-making process to include decisions materially assisted by an automated system, not only decisions made without any human involvement. A decision is materially assisted where a person relies on a preliminary step made by an automated system, such as a recommendation, assessment, conclusion or inference, and that step has a material bearing on the decision. Attorney General Tony Buti has said the new laws position the state as a privacy leader in Australia, citing its protections around automated decision-making. The notifiable information breach scheme under the Act begins on 1 January 2027.
If you hold state services contracts, the Commonwealth transparency obligation is the floor, not the ceiling.
What to do between now and December
Inventory your systems. List every tool that uses personal information and produces an outcome about a person, including third-party platforms and anything sitting inside your CRM. Most organisations we work with cannot produce this list on request, and building it is the slow part. The OAIC recommends maintaining a central personal information inventory covering why information was collected, where it is stored, who can access it, how long it is kept and whether third parties are involved. A spreadsheet is a legitimate starting point.
Sort by consequence, not by technology. The test is not whether something is AI. It is whether the decision significantly affects someone's rights or interests. A simple rules-based script can be caught while a sophisticated model is not.
Look at what your vendors are doing. Ask suppliers directly what decisions their product makes or materially assists, and get it in writing. This is a procurement question now, not just an IT one.
Wait for the guidance before you draft. The OAIC published an issues paper on 18 May 2026, consultation closed on 15 June 2026, and the regulator has said it intends to publish guidance by September 2026. Do the inventory work now and the drafting after.
Read your existing privacy policy. Many were written years ago and describe a business that no longer exists. If it is already non-compliant with the basic APP 1.4 requirements, the December addition is the smaller of your problems.
One related date worth diarising: the Children's Online Privacy Code must be registered by 10 December 2026. It applies to social media services, relevant electronic services and designated internet services likely to be accessed by children. Its commencement date has not yet been confirmed. If you operate an online service that children use, that is a separate piece of work.
TLDR;
The obligation is narrower than the headlines suggest and more consequential than most marketers realise. The work that takes time is not writing the disclosure. It is knowing what your systems actually do, which is a question worth being able to answer regardless of what the legislation requires.
This article is general information, not legal advice. The application of these obligations depends on your specific circumstances, and you should seek advice from a qualified legal practitioner about your own position.
References
Office of the Australian Information Commissioner, Chapter 1: APP 1 Open and transparent management of personal information (updated 3 October 2025). https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information
Privacy and Other Legislation Amendment Act 2024 (Cth), Part 15 (Automated decisions and privacy policies). https://www.legislation.gov.au/C2024A00128/asmade/text
Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision Making and Automated Decision-Making Issues Paper (18 May 2026). https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making
Allens, Automated decision-making transparency: what APP entities need to know about the APP 1 amendments (June 2026). https://www.allens.com.au/insights-news/insights/2026/06/automated-decision-making-transparency-what-app-entities-need-to-know-about-the-app-1-amendments/
MinterEllison, OAIC targets privacy policies in high risk sectors (February 2026). https://www.minterellison.com/articles/oaic-ramps-up-privacy-enforcement-are-you-ready
Office of the Australian Information Commissioner, Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act (February 2026). https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/privacy-guidance-for-reporting-entities-under-the-anti-money-laundering-and-counter-terrorism-financing-act
HWL Ebsworth, Small businesses, big change: privacy obligations under tranche 2 of the AML/CTF reforms. https://hwlebsworth.com.au/small-businesses-big-change-privacy-obligations-under-tranche-2-of-the-aml-ctf-reforms/
Privacy and Responsible Information Sharing Act 2024 (WA), s 16. https://www.legislation.wa.gov.au/legislation/prod/filestore.nsf/FileURL/mrdoc_47994.htm/$FILE/Privacy%20and%20Responsible%20Information%20Sharing%20Act%202024%20-%20%5B00-00-00%5D.html?OpenElement=
Government of Western Australia, Privacy and Responsible Information Sharing. https://www.wa.gov.au/government/privacy-and-responsible-information-sharing
HWL Ebsworth, ExPRIS delivery: timetable set for the commencement of WA's new privacy laws. https://hwlebsworth.com.au/expris-delivery-timetable-set-for-the-commencement-of-was-new-privacy-laws/
Office of the Australian Information Commissioner, Children's Online Privacy Code. https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code
Rules Mate, The second tranche of Privacy Act reforms: what's proposed and what's still uncertain (12 June 2026). https://rulesmate.com.au/insights/privacy-act-second-tranche-reforms-2026-outlook
Most of the compliance conversation in Australian marketing over the past two years has been about cookies, consent banners and the slow death of third-party tracking. Meanwhile, a quieter change has been sitting in the legislation with a fixed date attached to it, and it lands on 10 December 2026.
From that date, if your business has arranged for software to make decisions about people, and those decisions could significantly affect their rights or interests, you have to disclose it in your privacy policy.
That is roughly four months away. We think a fair number of businesses will discover in November that the answer to "do we do that?" is yes, and that nobody could say exactly which system was doing it.
What the obligation actually says
The change comes from the Privacy and Other Legislation Amendment Act 2024 (Cth), which inserted new subclauses 1.7, 1.8 and 1.9 into Australian Privacy Principle 1. The OAIC has confirmed these commence on 10 December 2026.
The obligation is triggered where all three of the following are true:
Your organisation has arranged for a computer program to make a decision, or to do something substantially and directly related to making a decision
That decision could reasonably be expected to significantly affect the rights or interests of an individual
Personal information about that individual is used in the operation of the program
Where that applies, your privacy policy must set out the kinds of personal information used in those programs, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to making the decision.
Two details are easy to miss. First, "making a decision" includes refusing or failing to make one. Second, the obligation applies whether the outcome is good or bad for the person. A system that automatically approves someone is caught on the same terms as one that automatically declines them.
The rules also apply to decisions made from 10 December 2026 regardless of when you set the system up. There is no grandfathering for tools you already have running.
What it is not
It is worth being precise here, because a lot of the commentary around this has been louder than the law.
This is a transparency measure. Unlike the equivalent provisions in the European GDPR, it does not give individuals a right to contest an automated decision, a right to request human review, or a right to an explanation of a specific outcome. It does not require you to notify people directly. It requires you to describe, in your privacy policy, the kinds of automated decisions you make and the kinds of information you use to make them.
That is a lower bar than many people assume. It is also not optional. A privacy policy that fails to meet APP 1 requirements can attract a compliance notice, an infringement notice, or civil penalty proceedings, and the OAIC's enforcement posture has visibly hardened.
In the first week of January 2026 the regulator began its first ever compliance sweep, reviewing the privacy policies of approximately 60 entities against APP 1.4. The six sectors selected were rental and property, chemists and pharmacists, licensed venues, car rental companies, car dealerships, and pawnbrokers and second-hand dealers, chosen because they commonly collect personal information in person. Entities found to have non-compliant policies may face compliance and infringement notices with penalties of up to $66,000.
First question: does the Privacy Act even apply to you?
For a lot of Australian SMEs, the honest answer used to be no. The small business exemption covers organisations with annual turnover of $3 million or less, and that has historically captured the majority of Australian businesses.
That exemption has not been repealed. Removing it is a stated government commitment expected in the second tranche of Privacy Act reforms, but as at mid-2026 no second-tranche bill has been introduced and no commencement date has been set. Anyone telling you the exemption is already gone is ahead of the facts.
What has changed is that the exemption is being cut away at the edges, and one of those cuts landed this month.
From 1 July 2026, tranche 2 of the AML/CTF reforms brought real estate professionals, dealers in precious stones, metals and products, and professional service providers such as lawyers, conveyancers, accountants and trust and company service providers into the reporting entity regime. Under section 6E(1A) of the Privacy Act, those businesses must now comply with the Privacy Act in relation to personal information handled for the purposes of, or in connection with, their AML/CTF obligations, regardless of turnover. The OAIC has published dedicated guidance and a template collection notice for them.
One limitation matters here, and most of the commentary skips it. If you are otherwise exempt and are covered only because you are now a reporting entity, the OAIC has confirmed your privacy policy need only address your personal information handling for AML/CTF purposes. You are not required to document your other business activities. So the automated decision-making obligation, when it arrives in December, would only reach automated decisions connected to that AML/CTF handling, such as automated customer due diligence or risk assessment. It does not pull your whole marketing stack into scope.
Separately, some small businesses were already covered regardless of turnover for other reasons. The OAIC's examples include health service providers, businesses trading in personal information, and operators of residential tenancy databases. That list is not exhaustive, so it is worth checking your own position rather than assuming.
Where marketing technology actually sits
Here is where we would rather be useful than alarming.
Most of what sits in a standard marketing stack is very unlikely to be caught. Lead scoring that ranks enquiries for a sales team to work through, email automation that decides who receives which nurture sequence, ad platform algorithms deciding who sees a campaign, chatbots that route an enquiry to the right inbox: none of these obviously make decisions that significantly affect a person's rights or interests. They affect who gets a phone call sooner.
The OAIC's own examples of significant decisions point somewhere quite different: decisions granting or refusing a statutory benefit, decisions affecting a person's rights under a contract such as a life insurance policy, and decisions affecting access to a significant service or support such as healthcare.
The line gets blurry in places our clients actually work:
Lending and financial services. Automated pre-qualification, serviceability screening or credit-adjacent assessment that determines whether an application proceeds is a long way from a nurture sequence.
Education and training. Automated eligibility screening, course admission or enrolment decisions, and automated funding eligibility assessment for government-subsidised training places.
Insurance and health-adjacent services. Automated eligibility or coverage decisions, and automated triage that determines whether someone gets access to a service.
Property. Automated tenant screening and application ranking. Residential tenancy database operators are already covered by the Privacy Act regardless of turnover, and rental applications sit close to a person's access to housing.
There is also a procurement dimension that is easy to overlook. The obligation is triggered by decisions your organisation has arranged for a computer program to make. That includes third-party products. If you have bought a screening, scoring or eligibility tool, the fact that a vendor built it does not move the disclosure obligation onto the vendor.
The Western Australian layer
Perth businesses have a second thing to track, and it is already in force.
The Privacy and Responsible Information Sharing Act 2024 (WA) commenced on 1 July 2026. It applies to the WA public sector, and this is the part people miss, it can also apply to private sector organisations in their capacity as contracted service providers to WA public entities.
The PRIS Act goes further than the Commonwealth provisions on automated decision-making. Section 16 defines an automated decision-making process to include decisions materially assisted by an automated system, not only decisions made without any human involvement. A decision is materially assisted where a person relies on a preliminary step made by an automated system, such as a recommendation, assessment, conclusion or inference, and that step has a material bearing on the decision. Attorney General Tony Buti has said the new laws position the state as a privacy leader in Australia, citing its protections around automated decision-making. The notifiable information breach scheme under the Act begins on 1 January 2027.
If you hold state services contracts, the Commonwealth transparency obligation is the floor, not the ceiling.
What to do between now and December
Inventory your systems. List every tool that uses personal information and produces an outcome about a person, including third-party platforms and anything sitting inside your CRM. Most organisations we work with cannot produce this list on request, and building it is the slow part. The OAIC recommends maintaining a central personal information inventory covering why information was collected, where it is stored, who can access it, how long it is kept and whether third parties are involved. A spreadsheet is a legitimate starting point.
Sort by consequence, not by technology. The test is not whether something is AI. It is whether the decision significantly affects someone's rights or interests. A simple rules-based script can be caught while a sophisticated model is not.
Look at what your vendors are doing. Ask suppliers directly what decisions their product makes or materially assists, and get it in writing. This is a procurement question now, not just an IT one.
Wait for the guidance before you draft. The OAIC published an issues paper on 18 May 2026, consultation closed on 15 June 2026, and the regulator has said it intends to publish guidance by September 2026. Do the inventory work now and the drafting after.
Read your existing privacy policy. Many were written years ago and describe a business that no longer exists. If it is already non-compliant with the basic APP 1.4 requirements, the December addition is the smaller of your problems.
One related date worth diarising: the Children's Online Privacy Code must be registered by 10 December 2026. It applies to social media services, relevant electronic services and designated internet services likely to be accessed by children. Its commencement date has not yet been confirmed. If you operate an online service that children use, that is a separate piece of work.
TLDR;
The obligation is narrower than the headlines suggest and more consequential than most marketers realise. The work that takes time is not writing the disclosure. It is knowing what your systems actually do, which is a question worth being able to answer regardless of what the legislation requires.
This article is general information, not legal advice. The application of these obligations depends on your specific circumstances, and you should seek advice from a qualified legal practitioner about your own position.
References
Office of the Australian Information Commissioner, Chapter 1: APP 1 Open and transparent management of personal information (updated 3 October 2025). https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information
Privacy and Other Legislation Amendment Act 2024 (Cth), Part 15 (Automated decisions and privacy policies). https://www.legislation.gov.au/C2024A00128/asmade/text
Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision Making and Automated Decision-Making Issues Paper (18 May 2026). https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making
Allens, Automated decision-making transparency: what APP entities need to know about the APP 1 amendments (June 2026). https://www.allens.com.au/insights-news/insights/2026/06/automated-decision-making-transparency-what-app-entities-need-to-know-about-the-app-1-amendments/
MinterEllison, OAIC targets privacy policies in high risk sectors (February 2026). https://www.minterellison.com/articles/oaic-ramps-up-privacy-enforcement-are-you-ready
Office of the Australian Information Commissioner, Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act (February 2026). https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/privacy-guidance-for-reporting-entities-under-the-anti-money-laundering-and-counter-terrorism-financing-act
HWL Ebsworth, Small businesses, big change: privacy obligations under tranche 2 of the AML/CTF reforms. https://hwlebsworth.com.au/small-businesses-big-change-privacy-obligations-under-tranche-2-of-the-aml-ctf-reforms/
Privacy and Responsible Information Sharing Act 2024 (WA), s 16. https://www.legislation.wa.gov.au/legislation/prod/filestore.nsf/FileURL/mrdoc_47994.htm/$FILE/Privacy%20and%20Responsible%20Information%20Sharing%20Act%202024%20-%20%5B00-00-00%5D.html?OpenElement=
Government of Western Australia, Privacy and Responsible Information Sharing. https://www.wa.gov.au/government/privacy-and-responsible-information-sharing
HWL Ebsworth, ExPRIS delivery: timetable set for the commencement of WA's new privacy laws. https://hwlebsworth.com.au/expris-delivery-timetable-set-for-the-commencement-of-was-new-privacy-laws/
Office of the Australian Information Commissioner, Children's Online Privacy Code. https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code
Rules Mate, The second tranche of Privacy Act reforms: what's proposed and what's still uncertain (12 June 2026). https://rulesmate.com.au/insights/privacy-act-second-tranche-reforms-2026-outlook
Author

Steven Donald
Chief Strategist
With over 30 years of experience across all facets of digital marketing, Steven Donald brings this expertise to his role as Chief Strategist at Pure Agency. Having navigated every evolution from early digital transformation to today's AI-driven landscape, Steven possesses a unique perspective on what truly drives performance.

