Australia's New Automated Decision Rule: What Your CRM Rules Should Show

If your business serves customers in Australia and uses software to decide who gets a quote, a service or a callback, a new privacy rule may apply to you. From December 10, 2026, certain organizations must describe those automated decisions in their privacy policy. The fastest way to prepare is to list every automatic rule in your CRM and check each one against the legal test.
On September 30, 2026, the Office of the Australian Information Commissioner published new resources on this obligation. They include a fact sheet and a flowchart. This post explains what the rule says and how to turn it into a simple CRM audit.
What the rule requires
The rule sits in the Australian Privacy Principles, in subclauses 1.7 to 1.9 of the Privacy Act. It is a transparency duty. It does not ban automation, and the sources reviewed for this post do not describe a new right to demand a human review.
An organization must update its privacy policy when three things are all true:
- It arranged for a computer program to make a decision, or to do something substantially and directly related to making that decision.
- The decision could reasonably be expected to significantly affect a person's rights or interests.
- The program uses personal information about that person.
When all three apply, the policy must state the kinds of personal information the program uses. It must also state the kinds of decisions made solely by a program. Finally, it must state the kinds of decisions where a program does something substantially and directly related to the decision.
Who the rule covers
The duty binds organizations the Privacy Act calls APP entities. Not every business is one, and size is part of the question. The regulator's announcement does not address small business exemptions, so do not guess.
Check your own status with the regulator's guidance or a privacy adviser. Do the audit below either way. It also improves your records, and it costs little.
Why a CRM matters here
A CRM often runs more automatic rules than its owner remembers. Staff add them one at a time over the years. Few people write them down.
Many of these rules use personal information. A form answer, a postcode, a budget or a past purchase can all feed a rule. That is why the CRM is the right place to start.
Step 1: List every automatic rule
Open your CRM settings and export or copy every rule that acts without a person clicking. Look in these places:
- Lead scoring and grading rules
- Routing rules that assign leads to a person or a queue
- Automatic tags and segments
- Workflows that send, pause or stop messages
- Rules that mark a lead as unqualified or closed
- Any AI feature that ranks, summarizes or recommends
Write each rule in one plain sentence. For example, "A lead outside our service area gets the status Not a fit." If you cannot explain a rule in one sentence, that is a finding by itself.
Step 2: Record what data each rule uses
For every rule, list the fields it reads. Name the field, such as postcode, job type, budget range or source. Then note whether it holds personal information about an identifiable person.
This list answers the first required disclosure, the kinds of personal information used. It also shows you data you collect but never needed. Remove those fields from your forms.
Step 3: Sort rules by effect on the person
Now ask the second question of the test. Could this decision reasonably be expected to significantly affect the person's rights or interests? Sort each rule into one of three groups.
Low effect
These rules order your own work. A score that decides which lead your team calls first is one example. A tag that groups people for a newsletter is another. Most of these will not meet the test, but record your reasoning.
Possible effect
These rules change what a person can get. A rule that blocks a booking is one example. Another is a rule that removes someone from a quote process or sets a price tier automatically. Review these closely against the examples in the regulator's materials.
Clear effect
These rules decide access to a significant service, a contract term or a credit-like arrangement. They need the strongest review. If a program decides alone, your policy may need to say so.
The regulator's flowchart is built for this sorting step. Use it rather than relying on a hunch.
Step 4: Separate solo decisions from assisted ones
The policy must tell the two apart. A program that decides on its own is one category. A program that does something substantially and directly related to a human decision is another.
Suppose a score suggests a lead is a poor fit and a staff member approves the rejection. The program may still be doing something substantially and directly related to the decision. Note that in your list. Do not assume a human click removes the rule from scope.
Step 5: Update the privacy policy in plain language
If any rule meets the test, add a short section to your privacy policy. Keep it specific and readable. Describe the kinds of data, the kinds of decisions and whether a program decides alone or assists a person.
Avoid vague lines such as "we may use technology to improve service." That does not tell a customer anything. A good entry names the type of decision in everyday words.
Date the change in your own records. Keep the rule list with it, so you can show how the policy matches your real settings.
Step 6: Set up a review habit
Policies drift when someone adds a new workflow. Add one question to your process: does this new rule use personal information to affect what a person can get? If yes, update the list and the policy before it goes live.
Review the full rule list every quarter. Delete rules nobody can explain. A smaller rule set is easier to describe and easier to defend.
Keep the human path open
The rule does not require it, but good practice does. Give people a way to ask about a decision. A staff member should be able to read a rule, see why it fired and change the result.
This helps your sales too. A good lead wrongly marked as a poor fit is lost revenue. A manual check on rejected leads often finds them.
A short audit table
Keep one row per rule with these columns: rule name, plain-language description, fields used, effect group, solo or assisted, owner and last review date. A spreadsheet is enough. Keep it with your other customer data records so it moves with you if you change systems.
What to do this month
- Export your CRM rules this week.
- Sort them using the regulator's flowchart.
- Draft the privacy policy wording for any rule that meets the test.
- Have a qualified adviser confirm whether your business is covered.
- Finish before December 10, 2026.
Rules for automated decisions are changing in several countries, and your CRM holds the evidence. A clear, current list of what your system does automatically makes every future disclosure easier.
Frequently asked questions
Does lead scoring in my CRM trigger the new Australian rule?
Not automatically. The rule applies only when a computer program makes or substantially and directly shapes a decision that could reasonably significantly affect a person's rights or interests, and uses personal information to do so. A score that only orders a call list is a different case from a rule that refuses service. Review each rule against the three parts of the test.
Who has to comply with the December 10, 2026 obligation?
The obligation binds organizations the Privacy Act calls APP entities. Whether your business is one depends on its size and activities. Check your status with the Office of the Australian Information Commissioner or a privacy adviser before assuming you are in or out.
What must the privacy policy say?
It must describe the kinds of personal information the programs use, the kinds of decisions made solely by a program, and the kinds of decisions where a program does something substantially and directly related to making the decision.
Sources
Want to see your own follow-up gaps? See what AppWT CRM does or book a walkthrough.