Insights

Australia's Privacy Act reforms: what changes for personalisation

If your organisation uses personal information to decide what a customer is offered, charged, approved for or steered towards, Australia’s Privacy Act reforms reach you on 10 December 2026. From that date, privacy policies must disclose automated decision-making: the kinds of personal information the programs use, and the kinds of decisions they make. Personalisation engines are squarely the sort of system the drafters had in mind.

The obligation comes from the Privacy and Other Legislation Amendment Act 2024, the first tranche of the broader reform programme. Two other pieces of that Act already bite: a statutory tort for serious invasions of privacy has been available since June 2025, and the Office of the Australian Information Commissioner (OAIC) has new civil penalty tiers to work with. The OAIC is also running a compliance sweep of privacy policies now, and has signalled it will read the new obligation broadly. Its final guidance is expected by September 2026, three months before commencement.

When does the transparency obligation apply?

Three conditions, all of which must be met. A computer program makes the decision, or does something substantially and directly related to making it. The decision could significantly affect the rights or interests of an individual. And personal information is used in the process.

When Australia's automated decision-making transparency obligation applies: a computer program makes or substantially contributes to a decision, the decision could significantly affect an individual's rights or interests, and personal information is used. If all three are met, the kinds of personal information and kinds of decisions must be disclosed in the privacy policy by 10 December 2026.

Note what is not in the test. There is no requirement that the decision be fully automated; “substantially and directly related” catches models that score, rank or recommend before a person clicks approve. There is no carve-out for marketing. And “significantly affect the rights or interests” is deliberately wider than legal rights: OAIC’s signalling to date suggests price, access to a product, and the terms someone is offered will all qualify.

Is personalisation in scope?

Usually, yes, and more often than teams expect. A next-best-offer engine that decides which customers see a hardship option and which see a credit limit increase is making decisions that affect interests. Dynamic pricing that uses personal information affects what someone pays. Propensity models that route a customer to a retention treatment, or away from one, affect the service they receive. Retention scoring, claims triage and eligibility pre-screening are all built from personal information and all shape outcomes for individuals.

The honest position for most organisations is that they have more automated decisions than anyone has written down, spread across marketing platforms, decision engines, CRM workflows and a few spreadsheets with macros. The obligation does not care where the decision lives.

What actually has to change?

The visible deliverable is a privacy policy that says what kinds of personal information feed automated decisions and what kinds of decisions result. That sounds like a drafting exercise. It is not, because the disclosure has to be true, and it has to stay true as models and campaigns change.

Behind a truthful disclosure sits an inventory: every automated decision, the personal information it consumes, and an assessment of whether it could significantly affect someone. Organisations that have just done this work for APRA’s CPS 230 critical operations mapping (we covered that in our CPS 230 piece) will recognise the exercise and should reuse it. Everyone else is starting a register they will maintain from now on.

Then the disclosure itself. Boilerplate will not survive a sweep. “We may use automated processing to improve your experience” tells a regulator nothing and a customer less. The standard being set is specific: the categories of information, the categories of decisions, in language a customer could act on.

What to do before December

  1. Inventory every automated or model-assisted decision that touches a customer, including the ones marketing runs outside IT. Record the personal information each one uses.
  2. Assess each against the three conditions, and document the reasoning, especially where you conclude a decision does not significantly affect anyone. That conclusion will be tested.
  3. Rewrite the privacy policy’s automated decision-making section from the inventory, not from a template, and build a change trigger so new models and campaigns update it.
  4. Check that your decision systems can actually report what information they used for a given decision. If they cannot, the disclosure is a guess, and the tort and penalty regime now make guesses expensive.

That last point is where architecture meets compliance. A decision engine that records, for every decision, which inputs were used and which policy applied makes the disclosure a query rather than an investigation, and makes the answer to a customer’s question “why did I get this?” a matter of record. That is how we built CxOS, and it is the standard worth holding any personalisation platform to, whether or not it is ours. For the wider picture on getting AI into production inside these constraints, see our CxOS product page.

Let's talk about what you're trying to change.

A 30 minute call. No deck, no discovery workshop. Just the problem and whether we can help.

Book a call