Local & private AI · 14 min read

What actually starts on 10 December 2026, and what doesn't.

By James Durkin, JDCS Updated 3 August 2026

There is a real date, a real obligation attached to it, and a claim circulating in Australian IT commentary that is going to cause a lot of unnecessary panic and, in a few cases, unnecessary spending. Worth separating the three. What follows is general information rather than legal advice, and the specifics of your own position are a question for a lawyer, but you can get most of the way there by understanding what the obligation is actually about.

The short version: a new APP 1.7 commences on 10 December 2026. If you use personal information in automated decisions that could significantly affect someone, your privacy policy has to say what kinds of information you use and what kinds of decisions you make. That is the whole obligation. The small business exemption has not been removed, despite a lot of articles saying it goes on the same date. Removing it is a proposal, not law.

What APP 1.7 actually requires

The Privacy and Other Legislation Amendment Act 2024 inserted a new Australian Privacy Principle 1.7, and it commences on 10 December 2026. It applies to APP entities, so the threshold question of whether you are one comes first.

Where such an entity uses personal information in a computer program to make, or to do something substantial towards making, a decision that could significantly affect an individual's rights or interests, the entity's privacy policy has to disclose two things: the kinds of personal information used in that way, and the kinds of decisions made.

Read that carefully, because the shape of it gets misdescribed a lot. This is a transparency obligation and nothing more ambitious. Automated decisions are not banned. Nobody is asking you to publish your logic or to notify each affected person individually. What it asks is that you can describe, in a public document, what your systems do with people's information when the stakes are real. That is a lower bar than most of the commentary implies, and a higher one than most businesses can currently clear, because very few have an accurate list of where software shapes decisions about people.

The genuinely hard part is not drafting the paragraph. It is knowing what to put in it.

The OAIC is reading "computer program" broadly

If you pictured a credit scoring engine or a claims assessment algorithm, widen the frame. Analysis of the regulator's approach published by law firm Pinsent Masons on 5 June 2026 indicates the OAIC is taking a broad view of what a computer program is. The reading extends to commonly used software, apps, word-processing tools, AI systems, generative AI tools, chatbots and virtual assistants.

The second signal matters more. Systems that materially assist human decision-making may still be captured, so full automation is not the threshold. A person clicking the final button doesn't necessarily take you out of scope if the software did the substantive work. Anyone who has read our companion piece on the Privacy Act changes and your automations will recognise the theme: a rubber stamp is not oversight.

Put those two together and the practical reach is much wider than a compliance-department reading suggests. A hiring manager pasting a stack of CVs into a chatbot and asking it to rank them is using personal information in a program that materially assists a decision about employment. A lead-scoring rule that decides who gets called back and who doesn't may be in scope. So might a tool that sets an individual customer's price, or one that triages who gets an appointment.

None of that means those uses are prohibited. It means they may need to appear in your privacy policy, described in kind. Final OAIC guidance is expected around September 2026 and should tighten up the edges. Between now and then, list honestly and get advice on the borderline ones rather than quietly deciding they don't count.

The claim going around that isn't right

A number of Australian IT and managed service provider articles currently state that the small business exemption is removed from 10 December 2026, often with a headline figure for how many additional businesses are about to be captured. That isn't correct, and it's worth setting out plainly rather than letting it spread.

Removing the small business exemption is a tranche 2 reform proposal. The government has said it supports the change in principle. The OAIC supports it. No bill implementing it has passed, and no commencement date has been fixed. Nothing about the exemption changes on 10 December 2026 as a consequence of the reforms that do commence that day.

Two honest caveats sit either side of that. Tranche 2 is a live policy direction rather than a dead one, so a business under the turnover threshold is planning for a probable future, not an impossible one. And the exemption has never covered everyone under the threshold, so "we're a small business" is a question worth actually checking rather than assuming. If APP 1.7 turns out to apply to you already, December is a date with your name on it.

I'm not interested in naming anyone who has published the wrong version. Deadlines get misread, drafts get confused with legislation, and the reform program has been genuinely messy to follow. The reason to correct it is that the mistake has a cost: businesses buying compliance work they don't need in December, and businesses that dismiss the whole thing once they discover one claim was wrong.

The exemption you probably lost on 1 July 2026

Here is the part that matters more than the December date for a lot of the businesses reading this, and it has already happened.

The small business exemption has never been a blanket. Section 6D(4) of the Privacy Act pulls you in regardless of turnover if you provide a health service and hold health information, if you trade in personal information, or if you hold a Commonwealth contract. Every clinic, physio, psychologist and dental practice in the country is covered on the first of those, however small.

And since 1 July 2026, section 6E(1A) does something similar for anyone who became an AML/CTF reporting entity under the tranche 2 changes. That is real estate professionals, conveyancers, accountants, lawyers, dealers in precious metals and stones, and trust and company service providers. For the activities connected to their AML/CTF obligations, the Act applies to them as if they were an organisation, whatever their turnover.

Two points of precision, because this gets mangled in both directions. The coverage is scoped to the activity, not the whole entity, so a small conveyancer is bound by the Australian Privacy Principles for the identity and source-of-funds material they now collect, and remains exempt for the rest of the practice unless something else in 6D(4) catches them. In practice, though, that material sits in the same system as everything else, so most firms will end up working to the same standard across the board. That is a commercial reality rather than a legal requirement, and it is worth deciding deliberately instead of discovering later.

The upshot: if you are an accountant, lawyer, conveyancer or agent who read "the small business exemption has not been removed" and relaxed, read it again. It has not been removed. You may simply no longer be inside it.

What did already change, in June 2025

While attention has been on December, something else has been in force for over a year. The statutory tort of serious invasion of privacy commenced on 10 June 2025.

A tort is something you get sued over. That places it alongside the regulator rather than inside it, which is a different kind of exposure from an OAIC complaint. It means the consequences of mishandling personal information are no longer only a matter of regulatory attention.

How the tort applies to any particular situation is squarely a question for a lawyer, and I won't pretend otherwise. The reason to mention it here is that it changes the calculation on informal AI use. A staff member quietly running client or customer material through a personal chatbot account was already an obligations problem. Since June 2025 it sits in a slightly sharper legal landscape than the one most internal AI policies were written for.

A checklist for the next few months

You have until December, the OAIC guidance should land around September, and the work below is worth doing regardless of how the tranche 2 argument resolves. None of it needs a compliance department.

  1. List every place software touches a decision about a person. Include the informal ones, because they're the ones nobody writes down: the CVs pasted into a chatbot, the spreadsheet that scores leads, the booking rule that decides who gets the early slot.
  2. Mark the ones with real consequences. Employment, credit, tenancy, eligibility for a service, individual pricing, access to something a person needs. Those are the candidates for "significantly affect".
  3. For each candidate, write two lines. The kinds of personal information used, and the kind of decision made. That is the exact shape the disclosure takes, so producing it now makes the drafting trivial later.
  4. Test whether your human review is genuine. Can the reviewer actually change the outcome, do they have the information to judge it, and would the file show they considered the individual case? If the honest answer is no, either fix the review or accept the decision is automated.
  5. Check what the tools do with the data. A decision might be disclosed properly and still send client information somewhere it shouldn't go. Our guides on whether Copilot is safe for confidential information and what AI data settings actually do cover that side.
  6. Hand the list to someone qualified for the wording. A solicitor can draft an APP-compliant privacy policy quickly. What they cannot do is tell you what your systems do. That's your half, and it's the half that takes the time.
  7. Diarise the OAIC guidance. Expected around September 2026. Re-read the list against it rather than assuming your September answer holds.
  8. Keep the review dated. A short record of what you looked at and when is worth having if anyone ever asks. It also makes next year's version an update rather than a fresh start.

If you want a structured starting point, the free business assessment walks through where software already sits in your operations, and an AI consulting conversation is a fast way to work out which of your flows this even touches.

Bottom line: one obligation commences on 10 December 2026, and it's a privacy policy disclosure about automated decisions that could significantly affect people. Read broadly, it reaches everyday tools rather than just algorithms. The small business exemption is not being removed on that date, whatever you've read, but check whether you are still inside it, because the AML changes on 1 July 2026 quietly took a lot of accountants, lawyers, conveyancers and agents out. Spend the next few months mapping where software shapes decisions about people, because that list is the deliverable a lawyer needs and the thing almost nobody has. General information, not legal advice.

Not sure if December touches you?

The first conversation is free. You'll get a plain-English read on where software already shapes decisions about people in your business, and what you'd need to write down before December.

Start a conversation

December questions, answered.

What changes in the Privacy Act on 10 December 2026?
A new Australian Privacy Principle 1.7, introduced by the Privacy and Other Legislation Amendment Act 2024, commences on that date. Where an APP entity uses personal information in automated decisions that could significantly affect a person's rights or interests, the privacy policy has to set out the kinds of personal information used and the kinds of decisions made. It is a transparency obligation about what your systems do.
Has the small business exemption been removed?
No. Several Australian IT and MSP articles currently say it is going on 10 December 2026, and that is not correct. Removing the exemption is a tranche 2 proposal. The government supports it in principle and the OAIC supports it, but no bill has passed and no commencement date has been fixed. Plan for it as likely eventually, not as law in December.
Does using ChatGPT count as automated decision-making?
It can. Analysis of the OAIC's approach published by Pinsent Masons on 5 June 2026 indicates a broad reading of computer program, extending to commonly used software, apps, word-processing tools, AI systems, generative AI tools, chatbots and virtual assistants. Systems that materially assist a human decision may still be captured, so a fully automated pipeline is not the threshold.
What counts as a decision that significantly affects someone?
The statutory language is a decision that could significantly affect an individual's rights or interests. Final OAIC guidance is expected around September 2026 and should sharpen the edges. In the meantime the sensible approach is to list your decisions honestly, flag anything with real consequences for a person, and get advice on the ones you are unsure about.
Do I need a lawyer for this?
For the privacy policy wording, yes, or at least someone qualified to draft it. What a lawyer cannot do is tell you what your systems actually do, and that is the harder half of the job. Map the decisions and the data first, then hand a solicitor an accurate description to work from. This article is general information, not legal advice.