Automated decision making and the 10th December 2026 deadline: what it means for your Salesforce customer data
There is a date worth putting in your diary if you run customer data on Salesforce: 10th December 2026. From that day, Australian privacy law changes how organisations have to talk about the automated decisions they make about people. It is not a headline feature, it did not get a keynote, and that is exactly why a lot of teams have not clocked it yet.
The short version: if you use personal information in automated decision-making that could significantly affect someone, your privacy policy will need to say so, in plain terms. For anyone consolidating customer data in Salesforce, that is a data question long before it is a legal one. And the good news is that the platform you are already running gives you most of what you need to answer it well.
What actually changes on 10th December 2026
The new obligation sits inside Australian Privacy Principle 1, the principle that governs open and transparent management of personal information. From the commencement date, an APP entity that uses personal information in an automated decision-making tool or process has to include specific information in its privacy policy.
Two things have to be disclosed. First, the kinds of personal information used in those automated decisions. Second, the types of decisions that are made, or substantially facilitated, by a computer program. In practice that means your privacy policy can no longer be silent about the fact that software is helping decide things about your customers.
The obligation does not cover every automated step. It applies to decisions that could reasonably be expected to significantly affect the rights or interests of an individual. Think eligibility for a loan or an insurance policy, an employment or housing outcome, or access to a service or to healthcare. Routine, low-impact automation is a different matter. The line sits at real consequences for a real person.
The OAIC ran a consultation on its draft guidance for these transparency requirements, which opened on 18th May 2026 and closed on 15th June 2026, with final guidance expected to follow. So some of the finer detail is still settling. The commencement date, however, is fixed, and the direction of travel is clear.
Why this is a customer-data question first
Here is the part that catches people out. The obligation is about disclosure, but you cannot disclose what you cannot see. To describe the automated decisions you make, you first have to know where those decisions actually happen, what personal information feeds them, and who or what acts on the result.
For most organisations, that map runs straight through the systems that already hold the customer record. If you have unified your customer data in Salesforce Data 360, that is where a lot of the answer lives: the identities you have resolved, the attributes you have brought together, and the segments and signals that downstream tools act on. Your Sales Cloud and Service Cloud processes, your flows, your models and your automations are where personal information turns into a decision. The transparency obligation lands on that whole chain, not on a policy document in isolation.
This is why we treat 10th December 2026 as a governance milestone rather than a compliance chore. The work that makes you ready is the same work that makes your Salesforce ecosystem better: knowing what data you hold, where it sits, what is allowed to touch it, and being able to trace any given decision back to the information and the logic behind it.
The wider backdrop
The deadline does not arrive in a vacuum. Australia recorded 1,205 data breach notifications in 2025, the highest number since the mandatory scheme began in 2018, and up 8 per cent on the year before, according to the Office of the Australian Information Commissioner. A separate statutory tort for serious invasions of privacy has been in force since 10 June 2025. Regulators, boards and customers are all paying more attention to how personal information is handled, not less.
None of that is a reason for alarm. It is a reason to make sure the foundations under your customer data are solid, so that when scrutiny comes, the honest answer is a confident one.
A practical way to get ready
You do not need a rebuild. You need a clear line of sight. A sensible sequence looks like this.
Start by finding the automated decisions that matter. Walk through where personal information in Salesforce feeds a decision that could significantly affect a person, and write them down. Most teams are surprised by how many there are, and by how many are genuinely low-impact and therefore out of scope.
Then check the data behind each one. What personal information goes in, where did it come from, and do your consent and permission settings reflect how it is actually being used. Data 360 is a good vantage point here, because unification is exactly where these questions become answerable.
Next, make each decision explainable. For the decisions in scope, you should be able to describe, in plain language, the kinds of information used and the type of decision made. That description is what feeds your updated privacy policy, and it is far easier to write when the underlying data is well governed.
Finally, close the loop between the policy and the platform. The words in the privacy policy should match what the systems actually do. Keeping those two in step is an ongoing discipline, not a one-off edit.
The bottom line
The 10th December 2026 transparency obligation is a modest change on paper and a useful prompt in practice. It asks a fair question: can you explain the automated decisions you make about people. Organisations that have invested in a clean, well-governed customer data foundation on Salesforce will find they are most of the way there already. Those that have not will find the deadline is a good reason to start.
If you would like a second set of eyes on where automated decisions live in your Salesforce estate, and what your privacy policy needs to say about them, that is exactly the kind of groundwork we do. It is also the kind of work that leaves your team more capable, not more dependent, which is rather the point.
If you haven’t yet started in your data foundations work or the implementation of Data 360, well if you’re reading this, you know where we are!
——
This article is general information, not legal advice. For advice on your obligations, speak with a qualified privacy lawyer.
Sources: Office of the Australian Information Commissioner (APP 1 automated decision-making transparency guidance consultation; Notifiable Data Breaches report, 6 July 2026; statutory tort for serious invasions of privacy); Gilbert + Tobin and White & Case privacy updates on the 10 December 2026 commencement.