← Back to blog

The Privacy Act Reforms: What Australian SaaS Businesses Must Do Now (2026)

Australia’s privacy law has changed in ways that matter for every SaaS business — including a new right to sue for serious privacy invasions, and from 10 December…

Australia’s privacy law has changed in ways that matter for every SaaS business — including a new right to sue for serious privacy invasions, and from 10 December 2026, mandatory transparency about automated decisions. Here’s what to do about it. (This is general information, not legal advice — confirm specifics with your lawyer.)

What’s changed

The first tranche of reforms to the Privacy Act has passed, strengthening Australia’s privacy framework. Two changes have the biggest practical impact on SaaS and technology businesses:

  • A statutory tort for serious invasions of privacy. Individuals can now sue for serious invasions of privacy — intruding on their seclusion or misusing their information. Importantly, this can reach businesses that aren’t otherwise bound by the Act, including small businesses under the $3 million turnover threshold.
  • Automated decision-making transparency (from 10 December 2026). Where you use automated systems (including, but not limited to, AI) to make decisions that could significantly affect a person’s rights or interests, you must disclose in your privacy policy what kinds of decisions are automated and what personal information is used.

Why this matters for SaaS founders

If your platform handles personal information — and almost every SaaS does — these reforms raise the bar on how you collect, use, secure and explain your data practices. The automated-decision rules are particularly relevant if you’ve added AI features that score, rank, approve or flag users.

A practical readiness checklist

  • Map your personal data — what you collect, where it lives, who can access it, and why.
  • Inventory automated decisions — identify any system (AI or rules-based) that materially affects users, and document the personal information it uses.
  • Update your privacy policy ahead of 10 December 2026 to meet the automated-decision transparency requirements.
  • Tighten security & access controls — strong data protection is now both a compliance and a litigation-risk issue.
  • Review data retention — hold personal information only as long as you genuinely need it.
  • Brief your team — privacy is now a whole-of-business responsibility, not just legal’s.

Where technology and compliance meet

Much of privacy readiness is technical: knowing where data flows, controlling access, securing storage, and being able to explain what your automated systems do. This is exactly the ground an independent technical assessment covers — surfacing the data-handling and security gaps that now carry real legal risk.

Frequently asked questions

Does this apply to small businesses?
The new statutory tort can apply even to businesses under the $3M turnover threshold that were previously outside the Act. Don’t assume you’re exempt — get advice.

When do the automated-decision rules start?
From 10 December 2026, with disclosures required where automated decisions could significantly affect individuals’ rights or interests.

Is this legal advice?
No — this is general information. Confirm how the reforms apply to your business with a qualified privacy lawyer.

Want to know if your platform’s data handling and security are ready? Explore our technical assessment or get in touch.

KA
in Connect on LinkedIn
The CTO Brief

Get the next one in your inbox

One sharp idea on technology leadership, every fortnight. No spam.

Keep reading
Tech Strategy

Multi-Tenancy Done Right: Isolation, Security and Scale for SaaS

3 min read
Tech Strategy

ISO 27001 for Australian SaaS: Is It Worth It, and When?

2 min read
Tech Strategy

Key-Person Risk: Spotting and Removing Single Points of Failure in Your Tech

3 min read
Free 45-minute discovery call

Want this thinking applied to your business?

Book a free call with Ken and get a senior, honest read on your technology.

Sister brand: CISO Advisory Australia — independent cyber security & Virtual CISO services