We read 33 of Australia's biggest brands' privacy policies twice. Two are ready for December.
From 10 December 2026 the law makes many businesses disclose, in their privacy policies, the kinds of automated decisions they make about people. We checked who already does, in June and again in July. Two in thirty-three. One of them rewrote its policy in between.
From 10 December 2026, Australian privacy law requires many businesses to disclose, in their privacy policy, that they make automated decisions about people: the kinds of decisions, and the kinds of personal information behind them. We read the current Australian privacy policies of 33 of the country's largest consumer brands, across banking, lending, insurance, superannuation, telco, energy, retail and wagering. We read them on 29 June 2026 and again over 28 to 30 July. Two met the bar. Twenty-seven said nothing about automated decisions at all.
The second read is the interesting one, because the number moved. When we looked in June, one policy in thirty-three cleared the bar: ING, a bank owned in the Netherlands, whose policy states plainly that "your credit score is calculated based on automated decision-making" and names the decisions and the data behind them. By the time we looked again, Telstra had rewritten its privacy statement. The new version took effect on 1 July 2026, two days after our first read, and it now names the kinds of solely or substantially automated decisions it makes, including identity and creditworthiness verification, and the kinds of personal information behind them. That is the whole obligation, written out, in the Australian statement.
At Commonwealth Bank the pattern is different and more common. The Australian policy carries a single line saying automated decisions may be made. The substantive disclosure, the one naming credit eligibility, affordability and the term of the loan, sits in the section written for the European Economic Area and the United Kingdom. The disclosure Australians get is the one Europe made them write.
The obligation is also wider than it sounds. The Australian test catches any decision a computer program is substantially involved in, not only the fully automated ones, so a person signing off on a model's recommendation still counts. It reaches credit, insurance, pricing, eligibility, and hiring. If you turn over more than three million dollars, or you hold health or credit data at any size, the question is not whether this applies to you. It is whether you can answer it.
A privacy policy is easy to edit. The hard part is standing behind it. The disclosure is the legal floor. The moment it is published, boards, customers, and the regulator can ask you to show your working, and answering well means producing the record of why the machine decided what it did. If that record lives in a supplier's environment, you cannot produce it on your own terms. The brands that will struggle in December are not the ones with bad policies. They are the ones who rent the record.
From December, the decisions you let machines make go on the record. Naming them is easy. Standing behind them is not.
How we read this. We read the current public Australian privacy policy of 33 of the country's largest consumer brands on 29 June 2026, and read all 33 again over 28 to 30 July 2026, across banking, consumer lending, buy-now-pay-later, insurance, superannuation, telecommunications, energy, retail, wagering and airlines. We marked a policy ready only if it disclosed automated decision-making, the kinds of decisions, and the kinds of personal information, in the Australian policy itself, setting aside clauses written for Europe. On the July read, two were ready (ING and Telstra), four said something without meeting the bar (Commonwealth Bank, Coles, Tabcorp and Sportsbet), and twenty-seven used no automated-decision wording at all. One caution on comparing the two reads. The ready count is comparable, and Telstra's move is a dated policy rewrite rather than a reclassification. The middle category is not comparable: our June read counted a passing mention of AI as partial, and the July read requires wording about automated decisions or automated technology, so most of the fall in that category is our method tightening rather than companies removing disclosures. The law is the Privacy and Other Legislation Amendment Act 2024 (new Australian Privacy Principle 1.7), with guidance from the OAIC. The obligation is a transparency duty only: unlike the European rules it gives no right to contest a decision and requires no direct notice to an individual. It commences 10 December 2026, so none of these brands is in breach today. They are not ready. We will re-run this each quarter to the deadline.
FIELD NOTES
We re-run this audit each quarter to the December deadline. Leave an address and you get the next read.
You are on the list. The next note comes from a real person, not a sequence. Unsubscribe in one click.
Almost there. We just sent a confirmation link to your inbox. Click it and you are on the list.
That did not go through on our side. Nothing wrong with your email. Try again in a minute.
Own the record before December.
NTWRK builds the pieces that have to explain themselves, the record of why included, inside your own environment and handed over with the keys.