Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services AI and compliance graphic with neural network nodes and a tick

The Office of the Australian Information Commissioner (OAIC) is expected to release its guidance on automated decision-making (ADM) transparency in September 2026. That gives Australian businesses roughly four months to get their privacy policies updated before the 10 December 2026 deadline.

What’s Changing

Under amendments to the Privacy Act 1988, any APP entity that uses a computer program to make — or substantially contribute to making — a decision that could significantly affect someone’s rights or interests must disclose that in their privacy policy. The disclosure needs to cover what personal information feeds the system, what decisions it makes, and where human involvement sits in the process.

The definition is deliberately broad. It captures AI models, rule-based automation, scoring engines, and anything in between. As White & Case noted in June, the obligation applies to any decision made on or after 10 December regardless of when the underlying system was deployed.

Why Most SMBs Aren’t Ready

In our experience working across Australian small and mid-sized businesses, most owners don’t realise how many of their everyday tools involve automated decision-making. CRM lead scoring, automated credit checks, insurance eligibility screening, staff rostering algorithms, even spam filters that quarantine client emails — all of these potentially fall within scope if they process personal information and affect someone’s rights.

The gap we see most often isn’t malice or negligence. It’s that businesses adopted these tools for operational efficiency without mapping what they actually do with personal data under the hood. That mapping exercise is the critical first step, and it takes longer than people expect.

What to Do Now

Don’t wait for the OAIC guidance to land before starting. Audit every tool and platform in your stack that processes personal information. Flag anything that automates or substantially informs a decision about a person — eligibility, pricing, access, risk scoring. Then update your privacy policy to describe those systems in plain English.

When the OAIC guidance arrives in September, you’ll be refining your disclosures rather than scrambling from scratch with a December deadline three months away.

If you need help mapping your systems, our managed IT team works with businesses across Sydney, Central West NSW, Brisbane, and Melbourne to audit IT environments and identify compliance gaps before they become problems. Get in touch.

Posted in Strategic