What the Australian Privacy Principle changes on automated decision-making mean for disability, aged care and community services providers, and what to do in the ten weeks left.
On 10 December 2026 a change to the Privacy Act comes into force that most service organisations have not heard of, and that almost none are ready for. It is not a new AI law. It is three new paragraphs in Australian Privacy Principle 1, and they require your privacy policy to tell the public which of your systems make or shape decisions about people.
That sounds like a job for whoever last edited the privacy policy. It isn’t. The disclosure is short, but you cannot write it until you know which systems decide things, what data they use and which of those decisions count. In a mid-sized disability, aged care or community services provider, an executive who estimates ten such systems usually turns out to have 25 or 30 once the staff are interviewed, and in my experience nobody has the list.
What the law now says
The Privacy and Other Legislation Amendment Act 2024 inserted new paragraphs 1.7, 1.8 and 1.9 into APP 1. From 10 December 2026, if an organisation covered by the Privacy Act has arranged for a computer program to make a decision that could reasonably be expected to significantly affect the rights or interests of an individual, or to do a thing that is substantially and directly related to making such a decision, its privacy policy must set out three things: the kinds of personal information used by the program, the kinds of decisions made solely by the program, and the kinds of decisions in which the program does something substantially and directly related to the decision.
Three points matter for providers. First, it says computer program, not artificial intelligence. A rules-based eligibility tool or a spreadsheet macro is a computer program. Second, “substantially and directly related” catches the common case where a system recommends and a human signs off; if the human routinely accepts the recommendation, the program is shaping the decision. Third, “significantly affect” is measured from the individual’s side. Access to a service, a support level, a shift allocation, a job application or a complaint outcome all qualify.
Are you covered?
Two tests. If your annual turnover is over $3 million, you are an APP entity. If you provide a health service of any kind, you are an APP entity regardless of turnover, and most disability, aged care and community health providers do. If either applies, the new disclosure applies to you. Exemptions exist, so turnover alone is not conclusive, but for this sector the safe assumption is that you are in.
What it will cost to get wrong
The same amendment gave the Office of the Australian Information Commissioner a lower tier of enforcement for exactly this kind of breach. A non-compliant privacy policy is now something the OAIC can address with an infringement notice or a lower-tier civil penalty without going to court, and the regulator ran a sweep of around 60 privacy policies in high-risk sectors during 2026 to make the point. The direct penalty is modest next to the indirect cost: a funder, an auditor or a Board asking why the organisation did not know what its own systems were doing.
If you are wondering whether anyone is actually ready, the regulator has already answered. The OAIC reviewed 23 Australian Government agencies in January and found that only four of them, 17 percent, had disclosed their use of automated decision-making in their public reporting. If the agencies that wrote the rules were at 17 percent, the service providers they fund are unlikely to be further ahead.
The disclosure is one paragraph. Writing it takes a list nobody has.
The systems providers overlook
When I run this exercise the surprises are rarely the obvious AI tools. They are the intake form that scores urgency, the rostering system that decides who gets the shift, the incident register that triages by severity, the recruitment platform that filters applicants before a human sees them, the AI note-taker a coordinator started using in March, the vendor’s client management system with a “recommended” flag nobody can explain, and the spreadsheet in finance with a formula that decides who is eligible for a fee waiver. Every one of those is a computer program doing something substantially related to a decision about a person.
What has to happen before 10 December
Four steps, in order.
- Build the inventory: every system, automation, AI tool and spreadsheet
that influences a decision about a client, participant, resident, applicant
or staff member, with the data it uses and whether a human is genuinely in
the loop. - Rate the risk: which decisions are significant, which are sole, which are
substantially shaped, and what else is exposed, from data quality and
security to vendor terms and whether the decision can be explained to the
client. - Draft the disclosure: the three required statements, in plain English,
mapped to the inventory, ready for legal sign-off and for the OAIC’s final
guidance, which is expected before the deadline. - Brief the Board: a short paper that says what was found, what has been
fixed, and who owns the list from here.
The inventory takes three to four weeks for a mid-sized organisation. Counting back from 10 December, the last comfortable start is the middle of November, and the OAIC guidance will not change the inventory, only the wording.
“Our lawyers will write the policy”
They should, and they will do it well. But ask them what they need first and the answer is always the same: the list. A lawyer can draft the three disclosures in an afternoon once they know which systems make decisions, which decisions are made without a human, which are substantially shaped by a program, and what personal information each one uses.
What a lawyer cannot do is find that out. The systems live in intake, rostering, HR, finance and the coordinator’s laptop, and the only way to surface them is to sit down with the people who use them and ask. The audit produces the list and the draft wording; your lawyer confirms the wording and takes the credit. That is the right division of labour, and it is cheaper than paying legal rates for discovery.
What Governance Works does about it
I spent 30 years in IT, 16 of them as a CIO or Director, mostly in not-for-profit disability, aged care, health and community organisations, before setting up Governance Works, so I know where these systems hide and how to talk about them to a Board.
The 10 December Privacy Changes AI Systems Audit is a fixed-price engagement that does the four steps above: a day of interviews with up to eight key staff, a risk-rated list of every system that influences a client decision across 15 risk domains, a 30-minute CEO briefing, a Board summary, a three-hour working session with your compliance lead, and a full report. Three to four weeks.
The brochure for CEOs and Boards, with all the detail, is available from governanceworks.com.au/10-december Questions to hello@governanceworks.com.au.
This article is general information, not legal advice. Confirm your obligations against the Privacy Act 1988 (Cth) and the OAIC’s guidance, or with your lawyer. Governance Works · Liability limited by a scheme approved under Professional Standards Legislation.