Back to ArticlesCompliance

Australia's New Privacy Act Reforms: What Every Business Using AI Needs to Know

Amulet Team

Amulet AI

30 March 20267 min read

Australia's privacy law just changed in ways that will affect almost every business that touches personal data — and if you're using AI tools in your operations, the new rules have a direct bearing on how you build, deploy, and disclose those systems.

The Privacy and Other Legislation Amendment Act 2024 (Cth) passed Parliament in late 2024 and has been rolling out in stages since. Two changes in particular should be on every Australian business leader's radar: the removal of the small business turnover exemption, and new mandatory transparency requirements for automated decision-making (ADM) that come into force on 10 December 2026.

This is not abstract policy. These are legal obligations with civil penalties up to $50 million or 30 per cent of annual turnover — whichever is greater.


The End of the $3 Million Exemption

For over two decades, businesses with annual turnover below $3 million were largely exempt from the Privacy Act 1988 (Cth). That era is over.

The Privacy and Other Legislation Amendment Act 2024 removes this exemption, meaning that almost every Australian business — regardless of size — is now covered by the Australian Privacy Principles (APPs). This change brings more than 100,000 additional small businesses under the Privacy Act's coverage.

What this means in practice:
  • You must have a compliant, publicly available privacy policy
  • You must collect only the personal information you reasonably need
  • You must give individuals the right to access and correct their data
  • You must notify the OAIC in the event of an eligible data breach
  • You face direct civil liability if individuals suffer a serious invasion of privacy

For small businesses that were previously flying under the radar — collecting customer emails, running CRM systems, using analytics tools — this is a significant shift. The OAIC now has sharper enforcement powers, and individuals have new rights to seek damages for emotional harm from privacy breaches.

What Is Automated Decision-Making Transparency (APP 1.8)?

The more significant change for AI-forward businesses is the introduction of automated decision-making (ADM) transparency obligations under subclauses 1.7, 1.8, and 1.9 of Schedule 1 to the amended Privacy Act.

From 10 December 2026, APP entities must disclose in their privacy policy:

  1. Whether they use personal information in automated decision-making that significantly affects individuals
  2. What kinds of personal information are involved in those decisions
  3. What kinds of decisions are made using that process

The Office of the Australian Information Commissioner (OAIC) has confirmed it will be updating guidance on APP 1 to address these new obligations. Law firm Jackson McDonald described the scope this way: entities must disclose systems that do "something substantially and directly related to the decision" — meaning it's not limited to fully automated decisions. If AI assists a human in making a decision about an individual, and personal information is used in that process, disclosure may be required.

What Counts as an "Automated Decision"?

Under the reforms, an automated decision-making system includes any process that uses personal information as a substantial or direct input into a decision with significant effects on an individual. This can include:

  • AI-generated credit or risk assessments
  • Automated screening of job applicants
  • AI-assisted triage in healthcare or insurance
  • Personalised pricing or access decisions driven by user data
  • Document or communication generation that uses personal profile data

If your business uses AI tools that ingest customer or employee data to make or influence decisions, you will need to audit those systems before December 2026.

Who Is an APP Entity?

Under the amended Act, an "APP entity" includes:

  • All Australian Government agencies
  • All organisations with annual turnover above the threshold
  • Small businesses previously exempt but now brought under coverage
  • Health service providers (regardless of size — always covered)
  • Businesses that trade in personal information
  • Businesses that provide services to the Commonwealth

The practical effect is that the vast majority of businesses operating in Australia — including startups, SaaS providers, consultants, and professional services firms — are now within scope.

Five Steps to Prepare Before December 2026

1. Audit your AI tools

List every software tool in your stack that uses personal information as an input. This includes your CRM, email platform, accounting software with AI features, any custom integrations, and dedicated AI tools. For each, determine whether it makes or assists in making decisions about individuals.

2. Review your privacy policy

Your privacy policy likely needs a significant update. It must now describe your use of automated decision-making, the types of personal information involved, and the categories of decisions affected. Vague boilerplate will not be enough — the OAIC is expected to issue specific guidance on what adequate disclosure looks like.

3. Assess your data flows

Map where personal information enters your AI systems, how it is processed, and what decisions or outputs result. This data flow mapping is a prerequisite for meaningful disclosure and for building internal accountability.

4. Choose privacy-compliant AI tools

Not all AI tools handle data the same way. Some popular consumer AI products send data to overseas servers for training, with limited controls on retention or use. Australian businesses should prioritise tools that offer:

  • Australian data residency (or at minimum, contractual data localisation)
  • Clear data processing agreements (DPAs)
  • No use of customer data for model training without explicit consent
  • Audit logs and access controls

Tools built with Australian compliance in mind — like Amulet, which processes data within Australian infrastructure and gives businesses full visibility over how AI handles their information — are worth evaluating against your December 2026 obligations.

5. Train your team

Your staff need to understand what personal information is, what your systems do with it, and how to handle data access or correction requests. The reforms create individual rights that must be actable — if someone asks what data you hold about them and how AI uses it, you need to be able to answer.


Penalties: The Stakes Are Real

Under the amended Privacy Act, serious or repeated privacy breaches can attract civil penalties of up to:

  • $50 million for large organisations
  • The greater of $2.5 million or three times the value of the benefit obtained for smaller entities
  • 30 per cent of adjusted turnover in the relevant period

Beyond financial penalties, individuals now have a direct right of action for serious invasions of privacy — creating reputational and litigation risk that sits outside the OAIC's enforcement processes entirely.

Key Dates to Lock In

| Date | Obligation |
|------|-----------|
| Now | Small business exemption removed — Privacy Act applies to most businesses |
| 10 December 2026 | ADM transparency obligations commence (APP 1.7, 1.8, 1.9) |
| Ongoing | Eligible data breach notification obligations apply |


The Bottom Line

Australia's privacy law is no longer just for big business. If you run a small or medium enterprise that uses AI tools — and the data suggests most Australian SMBs now do — you need to be thinking seriously about what personal information those tools use, what decisions they influence, and whether your privacy policy and operational practices are ready for December 2026.

The good news is that compliance is achievable with the right tools and the right approach. Start the audit now, update your privacy policy before mid-2026, and build AI procurement decisions around data sovereignty and transparency. Businesses that get ahead of these changes will be better placed to earn — and keep — the trust of their customers.


The information in this article is general in nature and does not constitute legal advice. For advice specific to your business, consult a privacy lawyer or compliance professional. Further reading:

Ready to explore enterprise AI?

Learn how Amulet can deploy AI within your infrastructure with complete data sovereignty.

Explore Enterprise Consulting