Automated Decision-Making Disclosure: Why Every Business Should Audit Its Systems Before December 2026
In our last update on Privacy Act reform, we mentioned one change with a fixed deadline. From 10 December 2026, according to the Privacy and Other Legislation Amendment Act 2024 (Cth), privacy policies must disclose where a business uses personal information in automated decision-making that could significantly affect a person's rights or interests.
If you read that requirement and thought, "We don’t really use AI,” it’s important to recognise that this disclosure obligation can still apply to your business. Even if you don’t use any flashy AI tools, your business might be using everyday systems that quietly shape decisions about your clients, customers, patients or applicants. The only reliable way to know what you actually need to disclose is to audit the systems you’re already using.
Does the Privacy Act even apply to your business?
The Privacy Act applies to Australian government agencies and organisations with an annual turnover over $3 million. Regardless of turnover, it also covers health service providers, businesses that trade in personal information, credit reporting bodies, contracted service providers under Commonwealth contracts, residential tenancy database operators, and AML/CTF reporting entities. Small businesses can also opt in voluntarily. If you're not sure where you sit, that's the first question to resolve, since everything below only matters if the Act applies to you.
Here's how we'd suggest approaching that audit.
How can you identify if a tool uses automated decision-making?
Most businesses underestimate how much of their client or customer journey is already automated in some way. Before you can assess anything against the legal test, you need an honest inventory. We'd suggest working through five categories:
1. Programs and systems, including intake portals
What software touches a person's information from their very first interaction with you? Think online enquiry forms, client or patient intake portals, booking systems, and practice or case management software. Anything that captures information and feeds it into a workflow belongs on the list.
2. Registration, identity verification and service eligibility tools
Any system that verifies who someone is or determines whether they qualify for a service, a discount, a loan, a level of cover, or a type of appointment. This includes automated ID verification tools, eligibility questionnaires that auto-score responses, and any system that filters or ranks applicants before a human sees them.
3. Support tools
Chatbots, automated ticketing systems, triage tools, and anything that auto-categorises, auto-prioritises, or auto-responds to a customer query. Even a simple "smart" ticketing system that assigns urgency levels can be doing more decision-making than it looks like on the surface.
4. Quality assurance, peer review and incident monitoring platforms
These are easy to overlook because they feel like internal, back-office tools rather than customer-facing ones. But if a monitoring platform flags a staff member's file, a transaction, or a case for review based on automated scoring, and that flag genuinely affects an outcome for a client or an employee, it's worth considering.
5. Automated scheduling, routing and professional allocation workflows
Any system that decides which staff member, practitioner, or team a client is allocated to, or how a job is routed through your business, can constitute automated decision-making. This is particularly true if the allocation affects the level of service, cost, or expertise a client receives.
Once you've got the list, the next step is to apply the legal test to each one.
How do you know if an automated system needs to be disclosed in your privacy policy?
For each program, tool or workflow you've identified, work through these questions in order.
1. Does the system make a decision, or do something substantially and directly related to a decision?
This is deliberately broad. It's not limited to a system that produces a final, standalone decision. It also covers a system that heavily informs or shapes a decision a human later "makes", if that human review is largely rubber-stamping the automated output. A scoring tool that ranks applicants, even if a person technically signs off on the outcome, is likely to be substantially related to the decision.
2. Does the decision affect access to services, contractual rights, or other significant rights or interests?
Not every automated process is significant enough to trigger disclosure. Routing a general enquiry to the right inbox is unlikely to affect anyone's rights or interests in a meaningful way. Automatically declining a service application, adjusting pricing based on a risk score, or determining which practitioner (and therefore what level of expertise or fee) a client is allocated to, is a different matter. These go to real, substantive outcomes for the individual.
3. Does it use personal information?
The system needs to be operating on information about an identifiable individual for the disclosure obligation to be relevant at all. A tool that only processes aggregated or fully de-identified data generally won't be caught, though it's worth checking whether "de-identified" genuinely holds up in practice, particularly given regulators are increasingly scrutinising re-identification risk.
If a system meets all three (it makes or substantially informs a decision, that decision affects a significant right or interest, and it operates on personal information), it needs to be reflected in your privacy policy's automated decision-making disclosure.
What if an automated system doesn't need to be disclosed?
Not every tool on your list will meet the test, and that's a perfectly good outcome. But "we assessed it, and it's fine" isn't itself a defensible position if you're ever asked to show your work. For every system you rule out, record:
Which of the three questions did it fail, and why
Where relevant, who the human decision-maker is and what genuine judgement they exercise (as distinct from confirming an automated recommendation)
The date of the assessment, so it can be revisited if the tool is updated or reconfigured
This documentation does two things: it protects you if a regulator or a client ever queries your position, and it gives you an early warning system. The tools you use in 2026 won't stay the same in 2027. Most software gets constantly updated and integrated with "smart" features, and your privacy policy should also be reviewed alongside those updates.
How often should you audit the automated systems in your business?
Because this obligation attaches to how you actually operate, not to a fixed statement you write once, the audit works best as a living register. Keep one line per system, review it whenever a new tool is adopted or an existing one is materially changed, and nominate a person responsible for keeping it current.
If you'd like help running this audit, working through the three-question test against your specific systems, or drafting the disclosure clause itself, that's exactly where we can add value. You can contact our team directly before the December 2026 deadline creeps up on you.
This article is general information only and doesn't constitute legal advice. If you'd like advice tailored to your business, get in touch with our team.
About the Author: Erin Vassallo
Erin Vassallo is the Principal Solicitor and founder of Law Team, a values-led law firm with a strong reputation across New South Wales and Queensland. With over two decades of experience in commercial, construction, and property development law, Erin is a trusted advisor to developers, landowners, and business owners navigating complex projects and legal risk.
Her hands-on experience includes joint ventures, structuring development deals, contract negotiation, risk mitigation, and project governance across residential, commercial, and mixed-use developments. Erin holds qualifications in law, political science, mediation, and disruptive strategy (Harvard Business School) and is the founder of Certified BCorp Law Team, committed to ethical business practices and social impact.
Frequently Asked Questions
-
Government agencies and businesses turning over more than $3 million a year, plus a handful of business types regardless of size (health providers, credit reporting bodies, AML/CTF reporting entities, and a few others). You can also opt in voluntarily even if you're under the threshold.
-
It can be. Anything that scores, ranks, filters, or routes people using their personal information may qualify, not just obvious "AI" tools. Intake forms, eligibility questionnaires, and ticketing systems are common examples people overlook.
-
Not necessarily. If the human is mostly rubber-stamping what the system recommends, rather than exercising real judgement, it can still count as automated decision-making.
-
You don't need to disclose it, but it's worth recording which test it failed, why, and when you checked. That way you've got something to point to if the tool changes later or someone questions your call.
-
No. Treat it as an ongoing process. Revisit your list whenever you bring on a new tool or an existing one gets updated, and have someone responsible for keeping it current.