Five Questions Before Anything Else
Before reading anything about what the obligation requires, answer these. They take about ten minutes and they determine whether the rest of this page is urgent, relevant or neither.
- Are we actually covered by the Privacy Act? Turnover above $3 million is the usual trigger, but a business of any size is covered if it provides a health service and holds health information, trades in personal information, is related to a larger covered entity, or is a contracted service provider under a Commonwealth contract. Do not answer this from memory — it is the question most often answered wrongly.
- Does anything in our business decide something about a person without a human involved? Not “do we use AI”. Any computer program counts, including rules written years ago.
- Does that decision use information about an identifiable person? A phone number tied to a customer record does. A count of calls per hour does not.
- Could the outcome matter to that person? Access to a service, money, a benefit, a legal position, an employment outcome. Not mere inconvenience.
- When did anyone last read our privacy policy? If the answer is a year or more, the December update is going to surface other things that have drifted out of date.
If you answered no to question 1
You have nothing to do for December — but check the answer properly rather than assuming. The single most common mistake in this area is a business under the turnover threshold concluding it is exempt without noticing that it holds health information, or that it is part of a group. And note that several 2026 articles claim the small business exemption has already been abolished. Primary sources do not support that: it was left out of the 2024 tranche and deferred, not repealed. Do not plan around it vanishing, and do not plan around it lasting forever either.
What Actually Changes on the Day
The Privacy and Other Legislation Amendment Act 2024 added new subclauses to APP 1. They commence on 10 December 2026. In substance: where a computer program makes, or does something substantially and directly related to making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual, and personal information is used, your privacy policy must set out the kinds of personal information used and the kinds of decisions made.
That is the whole thing. It is worth being precise about what it is not, because there is a lot of advisory content in circulation that describes something bigger.
| What it is | What it is not |
|---|---|
| A disclosure in your privacy policy | A prohibition on automated decisions |
| Described in kinds — categories of information, categories of decision | A technical explanation of how your systems work |
| Policy-level and public | A right for an individual to demand reasons for a specific decision |
| Applicable to any computer program | Limited to artificial intelligence |
| Triggered by programs that contribute to a decision | Limited to programs that make the final call |
The last two rows are the ones that catch phone systems. A phone platform almost never makes a final decision about anyone — it classifies, verifies, prioritises and routes, and a human further down the line decides. That pattern sits squarely inside “substantially and directly related to making a decision”. And the fact that half of it is deterministic routing written in 2019 rather than a model bought in 2026 makes no difference at all.
“We don't use AI to make decisions about customers” is true in most businesses and irrelevant in nearly all of them. The question is whether a program does — and one has been doing it since the day the phone system was installed.
On timing: the regulator consulted on guidance through an issues paper in the first half of 2026 and has signalled it intends to publish before commencement. Commentary on that consultation has consistently read the position as leaning broad rather than narrow. Either way, the planning conclusion is the same — if you begin when the guidance lands, you begin too late. Build the inventory now; the guidance then adjusts a position you already hold.
The Decision Tree for Your Phone System
Take your call flows and run each automated step through three gates in order. Anything that fails a gate stops there.
Gate 1 · Does it use who they are?
Does the branch depend on the identity of the caller, or only on what they pressed and what time it is? Time-of-day rules, menu selections and volume thresholds use no personal information and stop here. Most of a typical IVR stops at gate 1.
Gate 2 · Does anything different happen to them?
Different queue, different wait, different treatment, different outcome. If the identity lookup only puts a name on a screen for the human to read, it stops here. Screen pop alone is not a decision.
Gate 3 · Would a reasonable person care?
Applied to the standing rule, not the single call. One slightly longer wait is nothing. A rule that systematically gives one class of customer slower access to a service they pay for, every time, for a year, is something. Anything through gate 3 goes in your disclosure.
Run through the nine automated steps a modern contact platform typically performs, that produces a fairly consistent result:
| Automated step | Stops at | Note |
|---|---|---|
| Menu selection routing (“press 1 for accounts”) | Gate 1 | No personal information used at all |
| Business hours and holiday routing | Gate 1 | Time, not identity |
| Overflow to voicemail after N calls waiting | Gate 1 | Volume, not identity |
| Screen pop of the customer record to the agent | Gate 2 | Informs a human; changes nothing for the caller |
| Routing to the owner of the account | Gate 2 or 3 | Usually convenience. Assess it if “their” person is often unavailable and others are not offered |
| Priority queueing by customer tier | Gate 3 | Differential access to a paid service, applied by rule. Assess properly |
| AI classification of why they rang | Gate 3, if it decides more than routing | If the classification determines whether they get an appointment, a hardship path or an escalation, it is in |
| Automated identity verification | Through gate 3 | Pass or fail decides whether a person can access their own account. Clearly significant |
| Automatic blocking or diversion of a number | Through gate 3 | A program deciding a person cannot reach your business. The clearest example on the list |
The typical result
Six or seven of nine stop at gate 1 or 2. Two or three go through — usually automated verification, automatic blocking, and, separately, anything automatically assessing your own staff. That is a paragraph in a privacy policy, not a project. The businesses that turn this into a project are the ones that skip the inventory and disclose everything defensively, which produces a statement so broad it tells a reader nothing.
If you want the wider picture of what a current platform does by default before you audit yours, our guide to AI business phone systems covers the capability set and which calls to automate covers where teams usually draw the operational line — which sits in a different place to the legal one.
A Worked Example: Twelve People, One Phone Number
An Australian services business. Twelve staff, one main number, a CRM, and a phone system somebody configured properly four years ago and nobody has opened since. Turnover is above the threshold, so it is an APP entity. Here is what the audit found.
| Found in the call flow | Assessment |
|---|---|
| A three-option menu, then routing by which option was pressed | Out at gate 1. No personal information |
| CRM lookup on the incoming number, popping the record to whoever answers | Out at gate 2. Informs a human, changes nothing about the call's handling |
| A rule sending callers whose record shows an overdue invoice to a separate queue answered only by accounts | In. Identity-driven, materially different treatment, and it uses financial standing to change who a person can reach. Nobody in the business remembered this rule existed |
| Two mobile numbers hard-blocked at the carrier level after an abusive caller incident in 2024 | In. A program preventing identified individuals from contacting the business |
| Automated verification of date of birth and account number before the account team discusses a file | In. Pass or fail determines access to a person's own information |
| An AI summary written to the CRM after each call | Out. Records what happened; it does not decide anything |
| Automatic quality scoring of every call, feeding a monthly team leaderboard | In, and it is about staff. See the next section |
Four in-scope items, three of which nobody in the business could have named before the audit, and one — the overdue-invoice routing rule — that they decided to change on the spot for reasons that had nothing to do with privacy law. It had been quietly sending good customers with a disputed invoice into a debt-collection queue for four years.
The by-product is the point
The paragraph in the privacy policy took twenty minutes to write. The audit that produced it took two hours and found a routing rule actively damaging customer relationships. Most businesses will find at least one of these. Rules outlive the people who wrote them and the reasons they were written, and nothing else in the calendar ever prompts anyone to go and read them.
The Awkward One: Scoring Your Own Team
Automated call scoring assesses an identified employee, using personal information, and produces an output that feeds coaching, ranking, review, rosters or pay. On a plain reading that affects their interests more than most of the customer-facing items above.
There is a genuine complication and it should be said out loud rather than glossed. The Privacy Act contains an employee records exemption for private sector employers, covering acts and practices directly related to a current or former employment relationship and an employee record. How far it reaches automated assessment of employees is not settled. It has been on the reform agenda for years and was not resolved in the 2024 tranche.
Do not build a position that depends on an unsettled exemption
Disclosing that you use automated call scoring costs approximately nothing. Not disclosing it costs something if the exemption is read narrowly — and costs something else entirely if your team finds out from a customer, a job ad or a leaver. Tell people what is scored, how, and what happens to the score. That answer is safe under every reading, it is what a decent employer would do regardless, and it is the version that still works if the law moves.
Two things get conflated here and shouldn't be. Whether you may record a call is a state and territory surveillance devices question. Whether you may automatically assess a person using that recording is this question. Plenty of businesses are entirely correct on the first and have never considered the second. The operational side of scoring — what it changes in a team, and why concealing it backfires — is covered in AI call scoring and quality assurance.
The Paragraph You Have to Write
The obligation asks for kinds. Not a schema, not a model card, not a flowchart. Here is the structure that satisfies it, written as an illustration rather than wording to lift unreviewed.
Illustrative only — review against your own systems and your own advice
“Automated decisions. Some of our systems use personal information to make, or to help make, decisions about people. When you contact us this includes verifying your identity before we discuss your account, using your contact and account details; directing certain enquiries to a specialist team based on the status of your account; restricting contact from numbers we have identified as abusive or fraudulent, using call records and prior contact history; and assessing the quality and compliance of calls handled by our team members, using call recordings and transcripts together with employee information. If a decision affects you and you would like to discuss it, contact [privacy contact].”
Three properties make that work, and they are worth checking your own draft against.
Written for the reader
“Directing certain enquiries to a specialist team” is honest and comprehensible. “Segment-based ACD treatment” is neither.
Durable across vendor changes
Describe the information category, not the supplier. “Recordings and transcripts” survives a platform migration; naming a specific AI vendor does not.
Actionable
A contact point isn't required by these subclauses. It is what turns a legal statement into transparency, and it costs nothing to include.
The Countdown: August to December
Sequenced so that guidance, whenever it lands, adjusts an existing position instead of starting one.
| Window | Do this | Done when |
|---|---|---|
| August | Answer the five questions. Confirm APP entity status properly. Run the three-gate audit on call flows, then the same on CRM automations, web forms and any scoring or segmentation tool | You have a one-page table of automated steps with a date on it |
| September | Draft the disclosure from the table. Decide and record your position on employee scoring. Read the regulator's guidance if it has published and adjust | A draft paragraph exists and someone senior has read it |
| October | Tell your staff what is automatically assessed and why, before it appears on a public page. Fix anything the audit found that you would not want to explain | Nobody on the team will be surprised by the policy |
| November | Publish. Brief the people who answer the phone so a question about it gets an answer rather than a transfer | The live policy contains the paragraph |
| December | Commencement on the 10th. Add a review trigger to any material change in call flows or AI features | The review trigger is written down somewhere that outlives you |
The October row is the one that gets dropped when time gets tight, and it is the one most likely to cause an actual problem. A team that learns from a customer, or from a public web page, that a model has been grading their calls draws conclusions about what else has not been mentioned. That damage is much more expensive to repair than the conversation would have been.
10 Dec
2026 commencement
5
Questions to know if you're caught
3
Gates in the phone audit
~2–3
Items typically in scope
What Good Looks Like Afterwards
Compliance deadlines are usually treated as something to survive. This one is more useful than that, because the artefact it forces you to produce is genuinely worth having.
After December, a business that did this properly can answer three questions it could not answer before: what does our phone system decide about people, what information does it use to decide it, and who owns each of those rules. Very few organisations could answer any of the three in August. Most will find at least one rule doing something nobody currently intends, because rules outlive their authors and no other event in the business calendar ever prompts someone to open them.
The habit worth keeping
Re-run the three-gate audit whenever you change call flows materially, add an AI feature, or change platform. It takes twenty minutes once the first one exists. Businesses that treat the December work as a one-off will be back in exactly the same position in two years — with a privacy policy describing a system that has since changed underneath it, which is arguably worse than not having written it.
This is general information, not legal advice, and it does not account for your circumstances. If you are working through what to automate and what to leave alone in the first place, where a small business should start with AI and AI voice agents: cost and ROI are the practical companions to this page. If you hold health information, note that you are covered regardless of turnover — the clinic phone privacy guide covers what that means day to day.
Frequently Asked Questions
What is the 10 December 2026 privacy deadline?
On that date, new subclauses in Australian Privacy Principle 1 commence. They were inserted by the Privacy and Other Legislation Amendment Act 2024. In substance they require an APP entity to set out in its privacy policy the kinds of personal information used, and the kinds of decisions made, where a computer program makes — or does something substantially and directly related to making — a decision that could reasonably be expected to significantly affect the rights or interests of an individual. It is a disclosure obligation attached to your privacy policy. It does not prohibit automated decisions, it does not require a human to review them, and it does not give individuals a right to demand reasons for a particular decision. A good deal of the advisory content circulating in 2026 describes something considerably broader, closer to the European position, which is not what commences here. The regulator consulted on guidance through an issues paper in the first half of 2026 and has signalled it intends to publish before the commencement date.
How do I know whether my business is even covered?
Turnover above three million dollars is the usual trigger, but size alone does not settle it, and this is the question most often answered wrongly. A business of any size is covered if it provides a health service and holds health information, which captures every medical, dental, allied health, aged care and many disability providers no matter how small. It is also covered if it trades in personal information, if it is related to a larger covered entity, or if it is a contracted service provider under a Commonwealth contract. Check this properly rather than assuming, because everything else depends on it. Note also that several 2026 articles state that the small business exemption has already been removed. Primary sources do not support that — it was left out of the 2024 tranche and deferred rather than repealed. The sensible planning position is neither to assume it disappears nor to assume it survives indefinitely.
Does this really apply to a phone system?
It applies to any computer program that uses personal information to make or contribute to a significant decision, and a modern contact platform does exactly that in several places. Run each automated step through three gates. Gate one: does the branch depend on who the caller is, rather than what they pressed or what time it is? Menu routing, business hours rules and volume overflow all stop here because they use no personal information. Gate two: does anything actually different happen to that person? A screen pop that shows the agent a customer record informs a human but changes nothing about the call, so it stops here too. Gate three: applied to the standing rule rather than a single call, would a reasonable person care? Typically six or seven of nine automated steps stop at gate one or two, and two or three go through — most often automated identity verification, automatic blocking or diversion of particular numbers, and separately anything that automatically assesses your own staff.
What sort of thing does an audit actually find?
In a twelve-person services business the audit found seven automated steps and four that were in scope. The menu routing and the CRM screen pop were out. Three were in and nobody in the business could have named them beforehand: a rule sending callers whose record showed an overdue invoice into a separate queue answered only by the accounts team, two mobile numbers hard-blocked at carrier level after an incident in 2024, and automated verification of date of birth and account number before the account team would discuss a file. The fourth was automatic quality scoring of every call feeding a monthly leaderboard. The overdue-invoice rule was changed on the spot for reasons unconnected with privacy law — it had spent four years quietly diverting good customers with disputed invoices into a debt-collection queue. That pattern is common. Routing rules outlive the people who wrote them and the reasons they were written, and no other event in a business calendar ever prompts anyone to open them.
Does automated scoring of our own staff count?
It assesses an identified employee, automatically, using personal information, and produces an output that feeds coaching, ranking, review, rostering or pay — which on a plain reading affects their interests more than most customer-facing examples. There is a real complication: the Privacy Act contains an employee records exemption for private sector employers covering acts and practices directly related to a current or former employment relationship and an employee record, and how far it reaches automated assessment of employees is not settled. It has been on the reform agenda for years and was not resolved in the 2024 tranche. The practical advice is not to build a compliance position that only works if the exemption is read broadly and stays that way. Disclosing that you use automated call scoring costs almost nothing; not disclosing it costs something if the exemption is read narrowly, and costs something else entirely if the team finds out from a customer or a departing colleague. Tell people what is scored, how, and what happens to the score. Note that whether you may record a call is a separate question governed by state and territory surveillance devices law — being correct on recording says nothing about automated assessment.
What should the privacy policy paragraph say?
It should describe kinds — categories of personal information and categories of decisions — not how any system works. A workable version names the decisions in language a customer would recognise: verifying your identity before we discuss your account, directing certain enquiries to a specialist team based on account status, restricting contact from numbers identified as abusive or fraudulent, and assessing the quality and compliance of calls handled by team members. Each is paired with the kinds of information it uses, such as contact and account details, call records and prior contact history, or recordings and transcripts together with employee information. Add a contact point for someone who wants to discuss a decision that affects them. That is not required by these subclauses, but it is what converts a legal statement into actual transparency and it costs nothing. Two drafting habits matter: write it for a reader rather than in platform terminology, and describe the information category rather than the supplier, so the paragraph survives a change of vendor without needing a rewrite.
What is a realistic plan between now and December?
Four windows. In August, answer the threshold questions, confirm your APP entity status properly, and run the three-gate audit across call flows, CRM automations, web forms and any scoring or segmentation tool — you are finished when you have a one-page table with a date on it. In September, draft the disclosure from that table, decide and write down your position on employee scoring, and adjust if the regulator's guidance has published. In October, tell your staff what is automatically assessed and why, before it appears on a public page, and fix anything the audit surfaced that you would not want to explain. In November, publish and brief the people who answer the phone so a question about it gets an answer rather than a transfer. Commencement is 10 December. The October step is the one dropped under time pressure and the one most likely to cause a real problem, because a team that learns from a customer or a web page that a model has been grading their calls draws conclusions about what else has gone unmentioned. Afterwards, re-run the audit whenever call flows change materially or a new AI feature is switched on — it takes twenty minutes once the first version exists.