October 2026 is just around the corner, and while spring is giving its way to warmer weather and everyone’s calendars are filling up with end-of-year parties, Christmas prep, and the annual scramble to hit targets, there’s also a quieter deadline that’s circling around in the air like a hawk.
December is not just about mince pies and last-minute online shopping this year. This is also a month when Australia flicks the switch on some of the most important privacy reforms we’ve seen in decades.
Table of Contents
For many business owners, this might feel like just another bit of government red tape. But these changes are not about making life harder for businesses. Make no mistake, they are much more about shifting the way companies earn and keep trust. Customers are more savvy than ever about how their data is used and algorithms are making more and more calls that affect people’s money, jobs, and reputations.
December 2026 is the deadline for two very specific reforms: the Children’s Online Privacy Code (kicking in on 10 December) and new Automated Decision Making (ADM) transparency requirements (rolling out on 11 December).
The names sound dry, sure, but the impact will definitely be felt in everyday business operations, and that includes from online shops to game developers to accountants with AI-powered tools.
This article unpacks what’s changing, why it matters, and what Australian businesses like yours (big or small) can do to prepare. The aim here is not to drown in legal jargon, but rather to make sense of it like you would when explaining something to a mate over a beer!
What exactly is coming into force in December 2026
The Children’s Online Privacy Code
The first big change lands on 10 December. The Office of the Australian Information Commissioner (OAIC) has been tasked with delivering a legally binding Children’s Online Privacy Code, and by this date it will become fully enforceable.
This code applies to social media platforms, to messaging apps, to video-sharing platforms, to online games, and even to services like cloud storage or content sharing if kids are likely to use them.
If the service attracts under-18s (even just some of the time) then the rules can and will apply.
The goal is simple: keep children safe online, and stop companies from treating kids’ data like a goldmine.
That means the following:
- Default settings that will keep kids’ profiles private
- Significantly stricter rules about how and why businesses collect children’s data
- Consent processes that are written in both kid-friendly and parent-friendly language
- Less hoarding of data, and more responsible deletion
- No more sneaky “dark patterns” that can trick your kids into saying yes to data collection
Imagine it as the digital equivalent of installing child locks on cupboards full of cleaning products. Kids can still open the fridge and play in the lounge room and use their toys, but the most harmful stuff is out of reach, and that’s what matters, right?
Automated Decision Making Transparency
The second major change drops the very next day, on 11 December.
From then on, all entities that are covered by the Privacy Act need to update their privacy policies in order to be more upfront about when automated decision making will be in play.
Automated decision making (or ADM, for short), is when a system uses personal information to make a decision without a human giving it a proper look.
Some examples are:
- Credit checks that approve or deny a loan
- Bots that block suspicious payments
- Recruitment platforms that sort résumés before a human sees them
- Algorithms that decide which ads or content someone gets shown
- Systems that flag content for removal on social media
If these decisions can reasonably affect someone’s rights or interests, then businesses must say so in their privacy policies. Not buried in fine print either…it needs to be clear.
Why this matters for small and medium businesses
It might be tempting for smaller businesses to just assume that these laws are aimed squarely at the tech giants.
But the cold hard reality is that the net is cast much wider.
Any business that runs a website with logins, or that otherwise offers an online service or collects user information or uses AI and algorithms to make decisions is potentially in scope. Even businesses under the $3 million annual turnover exemption may be caught if they handle children’s data or engage in certain types of high-risk processing.
So yes, while the headlines might feature global tech giants like Meta, Google, and TikTok, make no mistake that a growing online store in Melbourne, a fitness app in Sydney, or a tutoring service in Brisbane might also need to pull their socks up.
It’s not just about avoiding penalties, although the fines are eye-watering (up to $50 million or 30% of turnover!).
It’s really more about credibility. Customers are increasingly willing to drop a brand that plays fast and loose with their data.
In fact, these days being ahead of the curve on privacy is simply part of maintaining a competitive advantage.
Deep dive into the Children’s Online Privacy Code
Age assurance without being invasive
The code requires businesses to make a reasonable effort to know whether their users are children, but it doesn’t want companies that are stockpiling passports and birth certificates like a dodgy nightclub bouncer.
Instead, businesses are expected to use proportionate methods. For example, low-risk services might just ask users to confirm their age, while higher-risk services may need extra verification.
The idea is to strike a balance by aiming to keep kids safe without creating new risks by over-collecting sensitive data.
Privacy by default
One of the key themes of the code is “privacy by default”. For children, accounts must start out private. Location sharing and public friend requests and targeted ads cannot be switched on unless a parent actively allows it.
That means a 12-year-old setting up a new profile should automatically have the safest settings enabled, with no pressure to turn them off just to join in.
Clear, kid-friendly consent
Consent notices need to be written so that both kids and parents can understand them without needing a law degree.
Think short, simple language, clear buttons, and no manipulative design.
And consent must be reversible. If a parent changes their mind, or if a child simply decides that they don’t want to share anymore, the process should be very quick and easy.
Less hoarding, more deleting
The days of “collect everything just in case” are over. The code now requires businesses to minimise the data that they collect from children and to delete it when it is no longer needed.
This naturally forces companies to think twice before holding onto information forever.
Safety baked into design
This is not just about policies. It’s also about product design. Apps and services should be built with tools that make reporting, blocking, and understanding features so that it’s easy for kids.
It’s about weaving safety into the fabric of the platform, and not bolting it on later!
Unpacking Automated Decision Making transparency
Automated decision making might sound like something straight out of a sci-fi film, but it’s already part of everyday life.
The challenge is making sure people know when machines are calling the shots, and what that actually means for them.
Defining ADM
Automated decision making (ADM) is exactly what it sounds like: a computer system that takes in personal information and then runs it through an algorithm or model before spitting out a decision without a human giving it a proper once-over.
Think about applying for a loan and getting an instant yes or no, or ordering something online only to have the payment blocked as “suspicious.”
Maybe a job application is screened before a recruiter ever lays eyes on it, or a post is automatically removed because a system decided it broke the rules.
These are all examples of ADM in action.
The real kicker is whether the decision has a meaningful impact on someone’s life. If it shapes access to money, work, essential services, reputation, or opportunities, then it’s not just a minor convenience. It’s something with weight.
And that’s precisely where the new rules step in, because regulators want businesses to stop hiding behind the curtain of “the system decided” and start explaining what’s going on.
Updating privacy policies
Here’s the practical bit.
From December, every business that is covered by the Privacy Act will need to spell out exactly how and where they use automated decision making.
No more vague one-liners buried in the fine print.
The privacy policy must clearly set out:
- What kind of automated decisions are being made? Is it fraud detection, résumé screening, targeted advertising, or something else?
- What types of data are being used? Is the system drawing on payment history, browsing behaviour, location data, or a combination?
- Whether humans are involved in oversight (as in does a person ever check the system’s calls), or is it 100% machine-driven?
- How people can challenge or appeal a decision. What steps can someone take if they think the machine got it wrong?
The aim is not to give away company secrets or explain every line of code. Instead, it’s about being upfront enough that the average customer knows when automation is in play and what their options are if they disagree with the outcome.
It’s the difference between telling someone, “Trust us, we’ve got a clever system running in the background,” versus, “Here’s how the system works, here’s when it affects you, and here’s what you can do if you’re not happy with the result.”
Trust through transparency
Most people already assume that AI and algorithms are part of the digital world, so businesses don’t need to pretend otherwise.
What really frustrates customers, however, is when decisions are made in the shadows, with no explanation and no way to push back.
That’s when trust evaporates.
By being transparent, businesses can actually strengthen relationships with their customers. Explaining ADM use in simple and human language can flip a negative moment (like having an order blocked( into a reassurance that your safety systems are working as they should. It shows respect too because it shows that the company has nothing to hide.
And most importantly, it gives customers the confidence that even if a machine makes a mistake, they are not powerless.
The point here is that transparency is not just about compliance. It’s a way for businesses to say, “We value your trust, and we’re going to be straight with you.”
Practical steps for Aussie businesses before December 2025
The new privacy rules might feel like a mountain, but the truth is, most of the work is just about being organised and thoughtful.
Update privacy policies
A privacy policy can no longer be a dusty PDF hidden in the footer of a website. It needs to be a living and breathing document that is reflective of how the business actually handles data day to day.
That means adding clear and plain-language sections about children’s data, consent processes, and automated decision making. Customers shouldn’t need a legal degree to understand it.
Consent is not a one-size-fits-all tick-box anymore. People are tired of being lumped into all-or-nothing agreements.
Businesses need to break down consent into categories (like marketing, analytics, personalisation, and so on) so that customers can choose what they’re comfortable with.
When it comes to kids, the bar is even higher: all data-related features should be off by default unless a parent actively opts in.
Audit data collection
Now’s the time to shine a torch into every corner of the business and map exactly what personal information is being collected, why it’s being collected, how it’s used, and how long it’s kept.
Spoiler alert: most businesses find they’re holding onto data they don’t even use!
Train staff
Compliance is not just a job for the legal or IT team. It’s everyone’s responsibility.
That’s why staff across all departments need to understand what the new rules mean in practice. Customer service teams should be ready to explain, and again in everyday language, what happens when an automated system makes a decision. Developers should be designing with privacy by default in mind and by building safer settings right into the product. Managers need to know how to handle parent requests and complaints.
You get the idea.
Check vendors and partners
Even if a business gets its own house in order, it can still be caught out if partners or third-party vendors cut corners. If customer data passes through another company’s system, they need to be compliant too.
The contracts should make this crystal clear: no sneaky practices like using your customer data to train an AI model without permission!
Real-world examples
Sometimes the theory feels abstract, so here are some practical ways businesses are putting these principles into action:
- A kids’ gaming app automatically hides profiles from public view and only allows connections with approved friends, which instantly cuts off one of the biggest risks for children online.
- An online store that is upfront about automated fraud checks by warning that orders may be delayed and offering customers a way to request human review even if they think the system got it wrong.
- A tutoring platform for teenagers has a clear rule: if an account is inactive for 12 months, all the data must be permanently deleted. Parents love it for obvious reasons.
- A marketplace explains how its ranking algorithm affects seller visibility and provides a simple appeals process for sellers who feel disadvantaged.
Traps to avoid
Of course, there are a few potholes on the road to compliance, and businesses will want to steer clear of them:
- Copying a competitor’s privacy policy without tailoring it to your own practices is a recipe for trouble. Every business has its quirks, and policies should reflect reality.
- Writing vague ‘waffles’ like “we may use algorithms to improve services” won’t cut it anymore. Regulators and customers want specifics.
- Collecting sensitive information for age checks when it isn’t necessary only creates new risks and undermines trust.
- Promising to delete data without actually checking if the deletion happens in practice leaves businesses exposed. Trust but verify.
- Using “dark patterns” (like sneaky design tricks that nudge users into sharing more than they intended) isn’t just frowned upon, it’s a fast track to reputational damage.
Action plan leading up to December
Here’s an example of an action plan that you could implement for the months leading up to December:
- October: Map data, identify automated decision making systems, assess child user risks.
- Early November: Adjust designs for privacy by default, build or update consent tools.
- Late November: Rewrite privacy policies, train staff, check vendor contracts.
- Early December: Publish updated policies, test systems, run a compliance audit.
What compliance looks like in practice
By mid-December, a compliant business will have:
- Clear and updated privacy policies written in plain language
- Child-friendly defaults that limit exposure and risk
- Automated decision making processes openly explained
- Strong data deletion practices
- A team who is now ready to answer questions confidently!
Wrapping it all up
December 2026 is a turning point in Australia’s privacy journey.
With a dedicated code for protecting children online and mandatory transparency around automated decision making, businesses can no longer treat privacy as an afterthought.
The rules are tighter, yes, but they are also an opportunity if you think about it.
That’s because businesses that embrace these changes early will not only reduce legal risk; they will also build trust and credibility in an era where those are now priceless commodities.
Get your privacy and terms for your website sorted at https://sixfive.io/products/wordpress/legals/