RatedWithAI

RatedWithAI

Accessibility scanner

International ComplianceAugust 28, 2026

Australia Made Your Privacy Policy Name Every Automated Decision You Make

Australia did not pass an AI act. It amended its privacy statute so that, from December 2026, your privacy policy has to state which decisions a computer program makes about people and what personal information it uses to make them. The drafting takes a day. The list it depends on is the thing nobody has.

Why a disclosure duty is harder than a rights duty. A right to human review can be satisfied reactively, when someone asks. A publication requirement is unconditional, public, permanent and machine-readable by anyone who wants to compare what you published against what your product does. It converts an internal classification exercise into a document a plaintiff, a competitor and a regulator can all read on the same day — and there is no version of it that is accurate without an inventory.

Four Ways an Offshore Vendor Lands in Scope

Each is independent of the others, and none of them requires an Australian entity.

You carry on business in Australia

The Privacy Act reaches organisations that carry on business in Australia, and the earlier requirement that the information also be collected in Australia was removed by the 2022 amendments. Carrying on business is judged by conduct: Australian customers billed in Australian dollars, local pricing, a local reseller, targeted marketing or an Australian support presence each support it. There is no need for an entity, an office or staff in the country.

You are above the small-business threshold — or acting for someone who is

The small-business exemption remains for now, but it is narrower than its reputation and it is under active reform pressure. Trading in personal information, providing a health service, or being a contracted service provider under a Commonwealth contract each remove it regardless of turnover. A vendor selling into Australian enterprises or government is almost never relying on it in practice, because the customer's contract imposes the obligations anyway.

Your product makes decisions that significantly affect people

The transparency requirement attaches to decisions made using personal information that could reasonably be expected to significantly affect the rights or interests of an individual, where a computer program does the deciding substantially. Credit and eligibility are the obvious cases; account suspensions, pricing, ranking that determines livelihood, and risk scores that drive a human's foregone conclusion are the ones teams fail to classify.

You send Australian data to a model provider overseas

Cross-border disclosure carries an accountability rule with real bite: unless an exception applies, you remain liable for the overseas recipient's acts and practices as if they were your own. Routing prompts containing Australian personal information to a US model API is a disclosure, and the vendor's misuse becomes your interference with privacy.

The Transparency Requirement, Decomposed

For each element: what the amendment asks for, and the work that has to happen before a sentence can be written.

Name the decisions in the privacy policy

What the law asks
The privacy policy must state the kinds of personal information used in computer programs that make, or do a thing substantially relevant to making, decisions that significantly affect an individual's rights or interests — and the kinds of decisions themselves.
What you have to build
A decision inventory that is accurate enough to publish. This is a disclosure obligation whose input is an engineering fact, which is why it is harder than it reads: the policy is written by legal from a list nobody maintains, and the first person to notice the omission is a competitor or a journalist reading a public document.

The 'substantially relevant' reach

What the law asks
The wording captures programs that do something substantially relevant to the decision, not only programs that issue the final answer. A model that produces the score a human then rubber-stamps is in scope.
What you have to build
Classify by influence rather than by architecture. If removing the model would change outcomes at scale, it is substantially relevant however the org chart describes the human in the loop. Document the reasoning for each system you exclude — the excluded list is the one that gets challenged.

A commencement date that is not a soft launch

What the law asks
The requirement commences in December 2026, two years after the amending Act received assent, and the transition period was given precisely so that policies could be rewritten from a real inventory rather than from guesswork.
What you have to build
Work backwards: inventory, then classification decisions with reasons, then the policy language, then the internal process that keeps the list current as features ship. Teams that start with the policy language produce a document that is wrong within a quarter.

Transparency is the floor, not the whole regime

What the law asks
This provision requires disclosure rather than a right to human review, which makes it lighter than comparable European or Quebec obligations — but the surrounding Australian Privacy Principles on collection, use, quality, security and access continue to apply to every one of those systems.
What you have to build
Do not build only the disclosure. The same inventory feeds APP access and correction requests, which reach the personal information inside an automated decision and are enforceable today, without waiting for December.

What Else Is Now Pointed at the Same Product

The transparency provision is the deadline. These are the instruments that make the disclosure consequential rather than administrative.

InstrumentWhat it means for a vendor
The statutory tort of serious invasion of privacyA cause of action for serious invasions of privacy — by intrusion upon seclusion or by misuse of information — is in force, with defences and a public-interest balancing test. It is significant for AI products because it is available to individuals directly, does not depend on the regulator taking an interest, and reaches conduct such as surveillance-adjacent features and inference about private matters that a privacy-principles analysis can leave looking technical.
Civil penalties and a tiered enforcement ladderThe regulator has a graduated set of powers: a serious-interference penalty at the top, a mid-tier civil penalty for interferences, and infringement notices for administrative failures such as a deficient privacy policy. The lower tiers matter more to a mid-sized vendor, because they can be issued without the evidentiary burden of the headline provision.
OAIC guidance on commercial AI productsThe regulator has published guidance for organisations deploying commercial AI products and for developers training generative models, addressing purpose limitation for training, the treatment of scraped data, accuracy obligations for generated outputs, and the point that consent is not a cure-all. Guidance is not law, and it is the document an investigator measures your conduct against.
The Children's Online Privacy CodeA code covering online services likely to be accessed by children is being developed, with obligations expected to bind services well beyond those aimed at children. If your product has any under-18 population, this is the Australian instrument most likely to change your defaults, and it lands close behind the transparency requirement.

Five Ways Teams Get the Disclosure Wrong

Publishing a policy sentence with no inventory behind it

A generic 'we may use automated systems' line does not state the kinds of information or the kinds of decisions, which is what the provision asks for. It is also a public admission that automated decisions exist, made without knowing which ones — the worst of both positions.

Excluding the model because a human signs off

The 'substantially relevant' wording was chosen to capture exactly that arrangement. If your justification for exclusion is a human approval step, keep the approval rate and the override rate, because those two numbers are the argument and you will not be able to produce them retrospectively.

Treating a model provider as a vendor rather than an overseas recipient

Under the cross-border rule you can be liable for what the recipient does with the information. A provider that retains prompts for abuse monitoring, or trains on inputs by default, transfers that exposure onto you — and the default settings are where this is decided, not the master agreement.

Assuming the small-business exemption covers you

The exemption is lost on several grounds unrelated to size, contracts routinely impose the obligations anyway, and it is a standing candidate for repeal. Building a compliance position on an exemption under active review is a plan with an expiry date nobody controls.

Waiting for December to start

The disclosure is due in December; the inventory it depends on takes longer than the drafting and surfaces classification arguments that need a decision-maker. Teams that begin in the final quarter publish a list of the decisions they could remember.

The inventory drill

Open your product's admin surface and list every state a user's account can enter without a person choosing it: suspended, limited, flagged, downgraded, deprioritised, declined, repriced. For each, write the personal information that drove it and one sentence on how much it matters to that person.

That list is your December disclosure, your access-request scope, your tort exposure map and your cross-border review scope, in one artefact. It is also, reliably, longer than the list anyone would have produced from memory — which is the entire reason the transition period exists.

Frequently Asked Questions

Does the transparency requirement give Australians a right to human review of our decisions?

Not on its face, and that is the most commonly overstated point about this reform. The obligation is to disclose in the privacy policy which kinds of decisions are substantially automated and what kinds of personal information those programs use. There is no accompanying statutory right to contest a decision or to demand a human reviewer, which makes the Australian provision lighter than the European, Brazilian or Quebec equivalents. Two qualifications matter commercially. First, the surrounding privacy principles still apply to the same systems: an individual can seek access to their personal information and require correction of inaccurate information, and where an automated decision rests on incorrect data those rights reach it. Second, publishing the list creates a target. Once your policy names the decisions, a complaint about any one of them starts with an admission that the system exists and does what you said it does, and the regulator's next question is about accuracy and security rather than about whether the system is there. The disclosure is genuinely lighter than a review right and it makes the other obligations easier to enforce.

We use a US model provider. What does the cross-border rule actually require?

Before disclosing personal information overseas you must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and unless an exception applies you remain accountable for the recipient's acts and practices as though they were yours. In practice that means contractual commitments backed by configuration you have actually verified. The commitments to get: no training on your data, a defined and bounded retention period including abuse-monitoring logs, sub-processor disclosure with notice of changes, security representations, and an obligation to assist with access and correction requests. The configuration to verify: the retention setting as it applies to your account rather than as described in marketing, the region your inference runs in if you have selected one, and what happens to data when you use a feature outside the main API such as fine-tuning, batch processing or a hosted agent runtime. The accountability structure is what makes this different from ordinary vendor management — a provider's quiet default change becomes your interference with privacy, so the review has to be periodic rather than a procurement gate you pass once.

How is this different from the EU AI Act work we have already done?

Different instrument, different trigger, largely the same evidence — which is the useful part. The European regime classifies systems by risk and imposes obligations on providers and deployers of high-risk systems, with documentation, human oversight and conformity duties attached. The Australian requirement is a privacy-policy disclosure keyed to decisions that significantly affect rights or interests, with no risk tiering and no conformity assessment. What overlaps is the foundational artefact: a maintained inventory of automated decisions, what data each uses, how significant the effect is, and where a human genuinely intervenes. A team that built that inventory for the European work can produce the Australian disclosure in an afternoon. A team that outsourced the European work to a consultancy and received a report often cannot, because the deliverable was a document rather than a process, and the document was accurate on the day it was written. If you are choosing what to build once, build the inventory as a living system with an owner and a release-time update, and treat each jurisdiction's paperwork as a rendering of it.

Does the statutory privacy tort actually threaten a SaaS product, or is it for tabloids and stalkers?

It is broader than the intrusion cases that get reported, and the information-misuse limb is the one relevant to software. The action covers serious invasions by intrusion upon seclusion or by misuse of information, requires a reasonable expectation of privacy in the circumstances, requires seriousness, and is subject to a public-interest balancing and a set of defences. Product features that plausibly reach it: inferring sensitive attributes such as health, sexuality or financial distress from behavioural data and acting on the inference visibly; surveillance-style monitoring of employees or users beyond what was disclosed; exposing information to a party the individual would not expect through a sharing feature or a model that reproduces training content; and location tracking beyond the stated purpose. Two features make it commercially distinct from a privacy complaint. It is brought by the individual directly, so it does not depend on the regulator's priorities, and damages can include emotional distress without proven financial loss. That combination is what makes representative proceedings viable, and it is why the tort is worth a specific look at any feature that infers something a user did not tell you.

Which decisions count as 'significantly affecting rights or interests'?

The phrase is deliberately broad and the guidance points at consequential outcomes rather than at a fixed list, so the right approach is to reason from effect on the person. Clearly in: credit and lending, insurance eligibility and pricing, employment and promotion, access to housing, government benefits, and health-related determinations. Also in, and routinely missed: account suspension or termination where the account is how someone earns or communicates; content removal or demonetisation for a creator; identity or fraud scores that block a transaction; individualised pricing that materially changes what a person pays; and ranking or matching that determines who receives work on a platform. Not in: internal analytics that produce no individual outcome, spam filtering with a reachable appeal, cosmetic personalisation, and A/B tests that do not alter a person's entitlement. The safe method is to document the borderline calls with a stated reason at the time you make them, because the difficult conversation is never about the obvious cases — it is about the suspension flow that nobody classified as a decision until a customer's livelihood depended on it.

What should we build first if Australia is a small share of revenue?

Front-load the inventory, because it is the input to every other obligation and the only one with a lead time you cannot compress. First, list every output that changes an individual's outcome, with the personal information each uses and a one-line significance judgement — expect three to five items nobody had classified. Second, decide and record the borderline cases with reasons, since the reasoning is what you will be asked for, not the conclusion. Third, review the model-provider configuration against the cross-border accountability rule: retention, training, sub-processors, region. Fourth, draft the privacy policy language from the inventory, not from a template, and state the kinds of information alongside the kinds of decisions because the provision asks for both. Fifth, add an inventory-update step to your release process with a named owner, which is what keeps the published list true after the first quarter. Everything else — the tort exposure, the children's code, the access and correction workflow — is scoped by that same inventory, so the cost of doing it well is amortised across every obligation rather than spent on one.

Related Reading