Automated decision-making and the Privacy Act, what changes on 10 December

Blog

September 2026

A studio portrait of a woman with cropped silver hair against a warm light-grey backdrop

There is a date in December that will apply to most care providers in Australia, and almost nothing in the sector press has mentioned it.

From 10 December 2026, the Privacy Act requires an organisation to disclose in its privacy policy where it uses personal information in automated decision-making that affects an individual's rights or interests. The obligation sits in Australian Privacy Principle 1.7.

It is a transparency duty, not a ban. It does not care whether you call the system AI. It cares whether a computer took part in a decision about a person.

Why this lands on care providers specifically

Care operators run more automated decisioning than they think. The obligation is written around the decision, not the technology, so the question is not "do we use AI" but "does software take part in decisions about people".

  1. Rostering and allocation. If a system matches workers to participants using personal information, it is taking part in a decision that affects both of them.
  2. Eligibility and intake. Any scoring, screening or triage step that ranks or filters people is squarely in scope.
  3. Incident triage. Tools that classify severity or route escalations are making a decision about how a person's harm gets handled.
  4. Workforce screening and compliance flags. A system that flags a worker as non-compliant is making a decision affecting their interests.

Almost every provider running a modern case-management platform is doing at least one of these. The obligation does not require the decision to be fully automated, and it does not require the system to be sophisticated. A rules engine counts.

Looking straight up a concrete spiral stairwell to a circle of sky

The reading is broad, and enforcement is cheap

The OAIC opened its consultation on guidance for this obligation on 18 May 2026 and closed submissions on 15 June. Four independent legal analyses of that consultation reach the same conclusion: the regulator is reading the obligation broadly rather than narrowly.

That matters more than it sounds, because of how it gets enforced.

Most compliance risk needs something to go wrong first

A reportable incident happens. A complaint is made. An audit falls due. There is an event, and the event triggers scrutiny.

This one needs nothing to go wrong at all

A privacy policy is a public document. Checking whether it discloses automated decision-making costs the regulator nothing, scales perfectly, and requires no cooperation from you. The OAIC is already running a compliance sweep of privacy policies.

You do not need an AI incident to be found non-compliant. You need somebody to read your website.

What it does not do

It is worth being precise about the limits, because the surrounding commentary is not.

The obligation is disclosure. It does not require you to stop using automated decision-making, to obtain consent for it, or to offer human review of every decision. It does not import the EU's risk categories.

It is also not an Australian AI Act, because there isn't one. The ten mandatory guardrails proposed in September 2024 were shelved in the December 2025 National AI Plan in favour of existing technology-neutral law.

That absence is exactly why this date matters. Australian care providers have no AI-specific statute, so their obligations around automated systems arrive through privacy law, the aged care standards and the NDIS instruments instead. They are harder to see, they are spread across three regulators, and they are already here.

Macro detail of a pale gerbera petal edge
Two women sitting together on a cream sofa in warm light

The part your vendor will not do for you

The disclosure duty sits with the entity that holds the personal information. It does not transfer to the software vendor.

If your platform cannot tell you which of its features take part in decisions about people, you cannot write an accurate privacy policy, and the gap is yours rather than theirs. Very few vendor contracts say this out loud.

Ask, in writing, and keep the answer. Two questions do most of the work:

  • Which features use personal information in a decision that affects a participant or a worker?
  • For each, what can you tell me about how the decision was reached?

A vendor who cannot answer the second question has told you something useful about the first.

What to do before 10 December

  • Inventory the decisions, not the software. Rostering, intake, triage, screening, flagging. Walk the list of things your organisation decides about people, then ask which of them software touches.
  • Write one sentence each. What the system does, and what the person is affected by. Plain language, because the privacy policy is read by the person it affects.
  • Get those sentences into the privacy policy. That is the whole obligation.
  • Send the two questions to every vendor. Diarise the replies.

The OAIC's final guidance is expected around September. Waiting for it is defensible. Waiting for it and then starting in December is not.

Sources. OAIC, consultation on guidance for transparency in automated decision-making, opened 18 May 2026, submissions closed 15 June 2026 (`V`). Privacy Act, Australian Privacy Principle 1.7, commencing 10 December 2026 (`V`). Australia's National AI Plan, December 2025, shelving the proposed mandatory guardrails (`C`, corroborated across independent analyses). The breadth of the OAIC's reading is `C`: four independent law-firm analyses agree, and the regulator's final guidance is not published yet.

Otherblogs

We’ll show you a certification done in ten hours.

You decide whether it holds up.

Rise © 2026