If your business turns over $3 million or less, you've probably never had to think much about the Privacy Act. That changes on 10 December 2026. The small business exemption that's applied since 1988 is being removed, and roughly 2.5 million more Australian businesses will come under the Act's full 13 Australian Privacy Principles. The part most owners haven't clocked yet: if you use any AI tool that screens, scores, or prices something about a customer or a candidate, you'll likely need to explain how it works — in your privacy policy, in plain English.
Key Takeaways
- Australia's Privacy Act small business exemption (turnover under $3 million) ends on 10 December 2026, bringing an estimated 2.5 million more businesses into scope.
- A new Automated Decision-Making (ADM) transparency rule under Australian Privacy Principle 1 requires businesses to plainly disclose how AI tools make or influence decisions about people — hiring screens, dynamic pricing, credit scoring, and similar tools all qualify.
- Non-compliant privacy policies can attract penalties of up to $66,000; serious or repeated breaches can reach $50 million or 30% of adjusted turnover, whichever is greater.
- The OAIC's guidance on ADM disclosure is expected around September 2026, giving businesses a narrow window to prepare before the 10 December commencement date.
- The first practical step is a plain audit of every AI tool touching customer or staff data — you can start that this week.
What Is Changing Under the Privacy Act in December 2026?
The Privacy Act 1988 is removing the small business exemption for entities with annual turnover of $3 million or less, starting 10 December 2026. Privacy law analysts estimate around 2.5 million additional Australian businesses will come within the Act's scope once the exemption lifts, under the Privacy and Other Legislation Amendment Act 2024.
For decades, the exemption let smaller entities operate with reduced privacy obligations compared to larger corporations. From 10 December 2026, that assumption no longer holds. If your business exceeds the $3 million turnover threshold, you must adhere to the full suite of 13 APPs — data security, individual access rights, cross-border disclosure, all of it.
This isn't a form to file once and forget. It's a shift in how small businesses need to handle personal data day to day, and it touches marketing databases, customer service systems, and — increasingly — the AI tools many businesses have adopted for efficiency without a second thought about what those tools actually do with people's data.
We advise clients to treat this as an immediate internal-review trigger, not a distant deadline. If you're not sure where your business currently stands, our guide to auditing your business's AI readiness is a reasonable place to start that stocktake.
Why Does This Affect Businesses Already Using AI Tools?
Automated decision-making (ADM) covers any AI tool that makes or materially influences a decision about a person — hiring screens, dynamic pricing, credit or risk scoring, and chatbot-driven service decisions all qualify. Most small business owners don't realise their existing AI tools already trigger this disclosure obligation under Australian Privacy Principle 1.
Picture a local recruitment agency using an AI tool to rank or filter resumes — that's an automated decision, not a background convenience. Same for a retail business using AI to adjust prices for loyalty members based on purchase history. These are everyday operations that now carry a specific legal obligation, and the OAIC has signalled a broad reading of what counts.
"The Paper is consultative, but it telegraphs an expansive interpretive stance." — Bird & Bird, on the OAIC's ADM Issues Paper
Many SMBs adopt AI as a sorting mechanism, not a decision-maker — but if a human signs off on the final step, the underlying obligation still applies once the AI's output materially shapes that outcome. That includes hiring tools we've covered in our piece on responsible AI use in HR, where screening tools are one of the clearest ADM examples regulators point to.
Pro tip
Common mistake: Assuming a human "final approval" step means your AI tool isn't making an automated decision. If the AI's output materially shapes the outcome — a ranked shortlist, a risk score, a suggested price — the disclosure obligation still applies, regardless of who clicks "approve" at the end.
What Exactly Must You Disclose About Your AI Systems?
Your privacy policy must plainly describe what personal information feeds an automated decision, what kind of decision the system makes or influences, and how the process works in general terms. Vague lines like "we use technology to improve services" won't cut it — the disclosure needs to be specific enough that an average customer understands what's actually happening.
Here's how that looks in practice for two common small business scenarios:
| AI use case | What triggers ADM | What your policy should say |
|---|---|---|
| AI resume screening | Ranks or filters job applicants using skills/experience data | State the tool filters applications based on named criteria (e.g. years of experience, qualifications) and that candidates can request an explanation |
| Dynamic/AI-driven pricing | Adjusts a price or offer based on customer history or demand | Disclose that prices may vary by customer history or market conditions, and how a customer can query a specific price |
| AI credit or risk scoring | Assesses risk or creditworthiness from customer data | Explain which data points feed the score and confirm customers can request an explanation of a decision affecting them |
The OAIC ran a public consultation on ADM transparency guidance, with submissions closing in June 2026, and has indicated final guidance is expected around September 2026. That's the reference point worth watching — it will likely set the expected level of detail.
Pro tip
Pro tip: When in doubt, disclose more rather than less. A privacy policy that over-explains an AI tool's logic is far cheaper to write than the cost of a follow-up OAIC inquiry after under-disclosing it.
What Happens If You Don't Comply?
Non-compliance carries two penalty tiers: up to $66,000 for a non-compliant privacy policy, and up to $50 million or 30% of adjusted turnover — whichever is greater — for serious or repeated privacy breaches. These apply to newly-in-scope small businesses the same as anyone else from 10 December 2026.
A privacy policy that fails to disclose ADM practices is a direct breach of APP 1. The $66,000 figure may sound manageable, but the OAIC can also issue enforceable undertakings requiring specific corrective action — which tends to be more disruptive and costly than getting the disclosure right the first time.
The heavier tier exists for a reason: serious or repeated breaches are assessed on the nature and duration of the breach, the degree of detriment caused, and how cooperative the business was. There's no reduced scrutiny flagged for newly-regulated small entities — enforcement applies from day one of the commencement date.
The cost of non-compliance — legal fees, remediation, reputational damage — will almost always exceed the cost of getting your privacy policy and AI documentation right before the deadline.
How Should Small Businesses Prepare Before 10 December 2026?
Preparing for this deadline comes down to five concrete steps you can start this week: audit your AI tools, document how each one works, update your privacy policy, set a review date, and brief your staff.
- Audit every AI tool touching customer or staff data. List hiring tools, pricing algorithms, chatbots, and risk models, and flag which ones make or materially influence a decision about a person.
- Document each tool's logic in plain terms. No technical specs needed — just a clear, non-jargon explanation of what data goes in and what decision comes out.
- Draft or update your privacy policy's ADM disclosure. Use plain language, test it on a non-technical staff member or customer, and avoid legalistic phrasing.
- Set a review date before the OAIC's guidance lands (~September 2026). Build in time to adjust your disclosures once the final guidance is published.
- Brief customer-facing staff. Make sure the team fielding questions can explain, in simple terms, how your AI tools work and how customers can request more information.
If this checklist raises more questions than it answers about your current AI stack, that's precisely the kind of tool-by-tool audit and readiness review we run with clients at GrowthGear — see our AI Strategy & Implementation service, or start with the AI Implementation Playbook for the broader framework this checklist sits inside. For the governance side of this work, our piece on building AI governance for small business and AI Insights' governance framework guide both go deeper on documentation practices that make this kind of disclosure straightforward rather than a scramble.
Is This a Compliance Burden or a Trust Opportunity?
Handled well, this is a trust opportunity rather than a pure compliance burden — a chance to be transparent about AI use ahead of competitors who are still treating it as a box-tick. Customers are increasingly wary of algorithms shaping outcomes they don't understand, and a business that explains its AI use clearly stands out for exactly that reason.
Proactively disclosing how your AI tools work signals you have nothing to hide about the decisions affecting your customers or candidates. That's not a marketing angle — it's a genuine difference in how a business is perceived once regulators, and customers, start asking the questions this new rule invites. Our overview of AI data security practices covers the adjacent groundwork worth doing at the same time as your ADM disclosure review.
This kind of AI-tool audit and readiness assessment is exactly the work we do with clients at GrowthGear — not as a legal compliance exercise, but as part of making sure the AI you've adopted for growth doesn't quietly become a liability. Turning a regulatory deadline into a documented, explainable AI stack is a genuinely useful outcome regardless of what the OAIC's final guidance says in September.
Privacy Act 2026 at a glance
| What | Detail |
|---|---|
| Commencement date | 10 December 2026 |
| Who's newly covered | Businesses with turnover under $3 million (~2.5 million additional entities) |
| New AI-specific rule | Automated Decision-Making transparency under APP 1 |
| OAIC guidance expected | ~September 2026 |
| Minor breach penalty | Up to $66,000 |
| Serious/repeated breach penalty | Up to $50 million or 30% of adjusted turnover |
| First action step | Audit every AI tool touching customer or staff data |
Frequently Asked Questions
From 10 December 2026, Australia removes the Privacy Act's small business exemption for entities with turnover under $3 million, bringing an estimated 2.5 million more businesses under all 13 Australian Privacy Principles.
Yes — if your AI tool makes or materially influences a decision about a person (hiring, pricing, credit, service eligibility), APP 1's automated decision-making rule requires a plain-language description in your privacy policy from 10 December 2026.
It covers any system, including AI, that makes or materially shapes an outcome affecting a person's rights or interests — AI resume screening, dynamic pricing, credit scoring, and chatbot-driven service decisions are common examples.
A non-compliant privacy policy can attract penalties of up to $66,000, while serious or repeated privacy breaches can carry penalties of up to $50 million or 30% of adjusted turnover, whichever is greater.
The OAIC's consultation on automated decision-making transparency guidance closed in June 2026, with final guidance expected around September 2026 — before the 10 December commencement date.
Start by auditing every AI tool that touches customer or staff data to identify which ones make or influence decisions, then draft plain-language privacy policy disclosures for each before the December 2026 deadline.
Sources & References
- Norton Rose Fulbright — analysis of the OAIC's consultation on the automated decision-making transparency obligation and the small business exemption removal (2026)
- Bird & Bird — "The Paper is consultative, but it telegraphs an expansive interpretive stance," on the OAIC's ADM Issues Paper (2026)
- OAIC — public consultation on guidance for transparency in automated decision-making, submissions closed June 2026
- MinterEllison — overview of Privacy Act penalty tiers, including the up to $50 million or 30% of adjusted turnover maximum for serious breaches (2026)



