10 December 2026 · Australian Privacy Principle changes

Are you ready for the 10 December Australian Privacy Principle changes?

From 10 December, your privacy policy has to name every system that makes or shapes a decision about a client. This brochure explains what changes, what has to be done, and what it takes to have it done for you.

The Privacy and Other Legislation Amendment Act 2024 added three new requirements to Australian Privacy Principle 1. From 10 December 2026, if your organisation uses a computer program to make a decision that could significantly affect a person, or to substantially shape one, your privacy policy must say what personal information the program uses, which decisions it makes on its own, and which it substantially contributes to.

That covers intake and eligibility tools, rostering, incident triage, recruitment screening, AI note-takers and any spreadsheet with a formula that decides who gets what. A provider that thinks it has ten such systems usually has 25 or 30. A privacy policy that does not comply is a breach the OAIC can act on without going to court.

What's in the brochure

  • What the change means, in plain English, for a CEO or Board
  • The two tests that tell you whether you are covered
  • The seven kinds of system most providers overlook
  • What the 10 December Privacy Changes AI Systems Audit delivers, with the fixed price
Paul Berryman is Principal Consultant at Governance Works. CPAIG, Senior Lead Implementer ISO 42001, and 30 years in IT, 16 of them as a CIO or director, mostly in not-for-profit disability, aged care, health and community organisations.

Send me the brochure

Two pages, written for a CEO or Board. Emailed straight away.

We'll email the PDF straight away. Tick the second box if you'd also like The Guardrail, our short weekly note on AI regulation; it's optional, and every issue has an unsubscribe link. No phone calls unless you ask for one.