Australia’s privacy law has changed in ways that matter for every SaaS business — including a new right to sue for serious privacy invasions, and from 10 December 2026, mandatory transparency about automated decisions. Here’s what to do about it. (This is general information, not legal advice — confirm specifics with your lawyer.)
What’s changed
The first tranche of reforms to the Privacy Act has passed, strengthening Australia’s privacy framework. Two changes have the biggest practical impact on SaaS and technology businesses:
- A statutory tort for serious invasions of privacy. Individuals can now sue for serious invasions of privacy — intruding on their seclusion or misusing their information. Importantly, this can reach businesses that aren’t otherwise bound by the Act, including small businesses under the $3 million turnover threshold.
- Automated decision-making transparency (from 10 December 2026). Where you use automated systems (including, but not limited to, AI) to make decisions that could significantly affect a person’s rights or interests, you must disclose in your privacy policy what kinds of decisions are automated and what personal information is used.
Why this matters for SaaS founders
If your platform handles personal information — and almost every SaaS does — these reforms raise the bar on how you collect, use, secure and explain your data practices. The automated-decision rules are particularly relevant if you’ve added AI features that score, rank, approve or flag users.
A practical readiness checklist
- Map your personal data — what you collect, where it lives, who can access it, and why.
- Inventory automated decisions — identify any system (AI or rules-based) that materially affects users, and document the personal information it uses.
- Update your privacy policy ahead of 10 December 2026 to meet the automated-decision transparency requirements.
- Tighten security & access controls — strong data protection is now both a compliance and a litigation-risk issue.
- Review data retention — hold personal information only as long as you genuinely need it.
- Brief your team — privacy is now a whole-of-business responsibility, not just legal’s.
Where technology and compliance meet
Much of privacy readiness is technical: knowing where data flows, controlling access, securing storage, and being able to explain what your automated systems do. This is exactly the ground an independent technical assessment covers — surfacing the data-handling and security gaps that now carry real legal risk.
Frequently asked questions
Does this apply to small businesses?
The new statutory tort can apply even to businesses under the $3M turnover threshold that were previously outside the Act. Don’t assume you’re exempt — get advice.
When do the automated-decision rules start?
From 10 December 2026, with disclosures required where automated decisions could significantly affect individuals’ rights or interests.
Is this legal advice?
No — this is general information. Confirm how the reforms apply to your business with a qualified privacy lawyer.
Want to know if your platform’s data handling and security are ready? Explore our technical assessment or get in touch.