from 10 December 2026, if a computer program uses personal information to make decisions that could reasonably be expected to significantly affect someone's rights or interests, your privacy policy has to say so. Not your terms. Not a clause buried in an MSA. Your public privacy policy, in language a person can read.
Most mid-market businesses have somewhere between six and forty automations running in their CRM right now, and no idea which ones are in scope.
Some of them are. Lead scoring is the one that surprises people.
What changes on 10 December 2026?
New obligations land in Australian Privacy Principle 1, the one about open and transparent management of personal information. From that date, if you use personal information in automated decision making of the relevant kind, your privacy policy must set out two things:
- the kinds of personal information used in those decisions, and
- the kinds of decisions being made that way.
The OAIC's APP 1 guidelines are the source, and the regulator is running a consultation on guidance for transparency in automated decision making ahead of commencement, with guidance intended by September 2026.
Two things to notice about how the obligation is written, because both are wider than the conversation most businesses are having.
It says "a computer program", not "AI". A logistic regression, a machine learning model and a plain if-then rule are all computer programs. There is no cleverness threshold to duck under.
It says "could reasonably be expected to significantly affect", not "does affect". You do not get to wait for someone to be harmed. The test is about the nature of the decision, not the outcome in a particular case.
Examples the OAIC's material points to include decisions affecting a person's rights under a contract or agreement, and decisions affecting their access to a significant service or support.
Why this is landing now
Because adoption got ahead of governance, and the numbers are not subtle.
The ABS found that 12% of Australian businesses used AI in 2024 to 25, up from 1% in 2021 to 22. Twelvefold in three years. Adoption ran higher among innovation-active businesses at 20%. Separately, business investment in AI research and development more than doubled, from $276.3 million to $668.3 million.
So a transparency obligation is arriving at precisely the moment most Australian businesses have something to be transparent about. That is not a coincidence, and it is a reasonable thing for a regulator to do.
Does a HubSpot workflow count as automated decision making?
Sometimes. This is the question that actually matters, and the one no vendor will answer for you, so here is how we reason about it.
The test is not how sophisticated the automation is. The test is what the decision does to a person.
Where we would look hard
- Automated eligibility or qualification that determines whether someone gets access to a service, a product, finance, or support.
- Lead scoring that gates human contact. If a score below a threshold means nobody ever calls that person back, then a decision about that person's access to your service has been made by a program.
- Routing that silently deprioritises. The same logic one step further along, and usually invisible to everyone including the business running it.
- Automated pricing, discounting or tiering applied to an individual.
- Automated support triage that decides who gets a human and who gets a knowledge base article.
- Anything touching a contract the person already has with you.
Where we would not lose sleep
- Internal reporting and dashboards.
- Deduplication, formatting and list hygiene.
- Sending someone a newsletter they asked for.
- Assigning an internal task to a staff member.
The uncomfortable middle is lead scoring, because almost every business we work with has it and almost nobody has thought of it as a decision about a person. It usually is one. Whether it clears the "significantly affect" bar depends entirely on what the score is wired to, which is exactly why you need the inventory before you need the legal opinion.
If routing is the automation you are now worried about, the mechanics of the thing we are discussing are here: how to set up lead routing in HubSpot. Read it again with this obligation in mind and the question stops being abstract.
What has to go in the privacy policy?
Two lists, in plain language: the kinds of personal information involved, and the kinds of decisions made. The OAIC guidance will firm up how much detail is expected, which is a good argument for drafting now and finalising after September rather than waiting and doing it in a panic in November.
A worked shape, to show what "kinds of" looks like in practice:
| Kinds of personal information used | Kinds of decisions made |
|---|---|
|
Contact details, employer and role, website and email engagement history, enquiry content, location at state level |
Whether an enquiry is prioritised for contact by a member of our team, and how quickly |
|
Service history, support ticket history, account status |
Whether a support request is routed to a specialist or handled through self-service |
Notice it does not require you to publish your scoring model, your thresholds, or your source code. It requires you to tell people, honestly and legibly, what you are doing. That is a much lower bar than most people fear and a much higher bar than most privacy policies currently clear.
The five step fix
What we would do this quarter, in order. The first two steps are free and everything else depends on them.
- Inventory every automation that touches personal information. Export your workflows. Include the ones nobody owns any more. In most portals this is an afternoon and it produces at least one genuine surprise.
- For each one, write down what decision it makes about a person. If the answer is "none", say so and move on. If the answer takes a paragraph, flag it.
- Sort the flagged ones into in scope, arguable, and out. Do not try to be clever with the arguable pile. That is what the legal read is for, and giving your lawyer a sorted list rather than a portal is how you keep that invoice small.
- Draft the two lists. Kinds of information, kinds of decisions.
- Get it reviewed, then publish it as part of your privacy policy before 10 December.
Realistically: step one is an afternoon, step two is a day, step three is a week of elapsed time waiting on other people, step four is an hour, step five depends on your lawyer. Start in September and it is comfortable. Start in November and it is not.
Do not have an afternoon spare?
The automation inventory and the scope assessment are part of an AI audit. You get the list of every automated decision your business makes about a customer, which is useful well beyond December.
Which of our automations are in scope?
We cannot answer that from here, and anyone who tells you they can has not looked at your portal.
What we can tell you is the shape of the answer, because it repeats. There is a long tail of harmless automation, a handful of genuinely in-scope decisions, and one or two that nobody remembered existed. That last category is the reason to do this properly rather than from memory. When we ran it over our own systems we found automations still firing for a product we had stopped selling.
The part that is actually an opportunity
Every business we know is going to treat this as a compliance chore, do it in November, and get nothing out of it but a paragraph on a page nobody reads.
The inventory is the valuable bit.
You are about to build a complete list of every automated decision your business makes about a customer. Almost no organisation has that. Everybody assumes they do. It is the same document you need for an AI roadmap, for a data governance review, for onboarding a new RevOps hire, and for working out why your pipeline reporting disagrees with itself.
If you are going to be forced to look, look properly.
While you are in there, two adjacent obligations
Since you are about to have every automation in a spreadsheet, two things worth checking at the same time. Both are Australian, and both are commonly got wrong by teams working from American sources.
Consent, under the Spam Act rather than CAN-SPAM
Australian rules distinguish express consent from inferred consent, put the burden of proving consent on the sender, require an unsubscribe that does not make someone log in or hand over more information, and make clear you cannot outsource the obligation to a third party or a purchased list.
If an automation sends a commercial electronic message, this applies to it. Inferred consent depends on a real, provable, ongoing relationship, which is a higher bar than "they were on a list we bought".
Who owns the decision internally
An inventory with no owner decays back into the state you found it in within a year. We wrote about that specifically in who should own your CRM, and the answer is usually a named person in RevOps rather than a committee.
Where this is all heading
December is a transparency obligation. It is worth understanding it as the first visible step rather than the whole story.
The government's Voluntary AI Safety Standard, published by the National AI Centre in September 2024, sets out ten guardrails covering accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply chain transparency and record keeping. It is voluntary and creates no new legal duty, and it is closely aligned to the mandatory guardrails proposed for high-risk settings.
Read it as a preview of the questions you will eventually be asked. Contestability in particular, the ability for a person to challenge an automated decision, is not part of the December obligation and is very obviously on the horizon.
If you are APRA-regulated, CPS 230 has been in force since 1 July 2025 and brings material service provider obligations, which changes who else has to know about your automations.
Frequently asked
Does this apply if we are under the small business threshold?
The exemption is narrower than most people assume and it disappears as you grow or as you handle certain kinds of information. At 60 to 200 people, assume you are in.
Is a human in the loop enough to take us out of scope?
It depends whether the human is genuinely deciding or rubber-stamping a queue. Be honest with yourselves about which one it is, because the person reviewing 200 auto-scored leads a day is not making 200 decisions.
Do we have to let people appeal an automated decision?
Not under the December obligation, which is about what your privacy policy discloses. Contestability is a separate conversation and it is guardrail territory in the Voluntary AI Safety Standard.
Do we need to disclose our scoring model?
No. The obligation is about the kinds of information used and the kinds of decisions made, not the internals.
What if our automations are in a tool other than our CRM?
Same obligation. The inventory needs to cover your marketing platform, your support desk, your finance system and anything custom. The CRM is usually where most of it lives, not all of it.
Who signs this off?
Whoever owns privacy, on advice. But whoever owns RevOps has to produce the inventory, because they are the only person who knows what is actually running.
Where to go from here
If you want the wider context on what Australian mid-market businesses are actually doing with AI, we pulled those numbers apart in AI adoption in the Australian mid-market. Our own privacy, security and data position is published in the Trust Centre.
Want to know what is in scope in your portal?
Or talk to us about running the inventory with your team.
One question to take into your next leadership meeting. If a customer asked tomorrow which decisions about them your systems make without a human, could anyone in the business answer?
This describes a published obligation. It is not legal advice. Get your own before you rely on it.
Sources
-
-
- OAIC, consultation on guidance for transparency in automated decision making
- OAIC, APP 1 guidelines, open and transparent management of personal information
- ABS, business adoption of artificial intelligence accelerates in 2024 to 25
- ACMA, avoid sending spam
- ACMA, consent expectations for businesses using direct marketing
- Voluntary AI Safety Standard, National AI Centre
- APRA CPS 230, Operational Risk Management
-