Deadline

The 10 December 2026 deadline

The date the Privacy Act's new automated decision-making transparency provisions commence. Here's what you need to have done and how Aicura helps.

The date

The Privacy Act's new automated decision-making transparency provisions (APP 1.7, 1.8 and 1.9) commence on 10 December 2026. From that day, every APP entity's privacy policy needs to meet the new disclosure requirements. This is not an aspirational target. It's the date the law changes.

Privacy Act ADM deadline:—

What you need to have done by then

  • A complete AI Register. You can't disclose what decisions are being made by computer programs if you don't know what computer programs are making decisions. Cataloguing the systems is the first piece of work.
  • An understanding of which systems affect individuals. The disclosure requirement only applies to decisions that "could reasonably be expected to significantly affect" individual rights or interests. You need to know which of your systems meet that threshold.
  • An updated privacy policy. The actual compliance artefact. It needs to disclose the kinds of personal information used in automated decisions and the kinds of decisions being made, for both fully automated and substantially assisted decisions.
  • Internal sign-off on all of the above. Your privacy officer, your legal counsel, and likely your board need to agree on what's being disclosed and how. The sign-off process is often the slowest part.

What Aicura helps with

The four bullet points above map directly onto Aicura's product surface:

  • The AI Register handles cataloguing and captures the "affects individuals" metadata as a structured field.
  • The Privacy Policies module reviews your current privacy policy against the ADM requirements using your register as context, and generates a draft transparency statement.
  • The dashboard surfaces the deadline countdown and shows you which of your policies still have outstanding recommendations.

What Aicura doesn't help with is the sign-off step, which is your people's work. The product just gets them to the point where they have something to work from.

What happens if you're not ready

The OAIC has said it's preparing a proactive compliance scan of privacy policies against the ADM requirements. Penalties for non-compliant privacy policies can reach approximately A$330,000 per contravention by way of infringement notice, with civil penalties up to A$3.3 million for mid-tier offences and the greater of A$50 million / 3x benefit / 30% of turnover for the most serious. But the first-year enforcement is likely to focus on the largest and most visible organisations, and on ones where the non-compliance is obvious. A privacy policy that doesn't mention automated decision-making at all is the easiest kind of obvious.

Why it matters beyond the deadline

Getting the ADM disclosures right is a one-off project. Keeping them right is ongoing work. Your AI systems change, new ones are added, old ones are retired, the data they use changes, the decisions they produce change. A privacy policy that's accurate on 10 December 2026 will drift out of accuracy over the following year unless something keeps pulling it back into alignment with reality. That's the real reason Aicura is a subscription product and not a one-off tool. The deadline is a starting line, not a finish line.


A note on this page

This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.

For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.

Get started with Aicura.

Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.