Microsoft Teams

The Privacy Act changed. Is your process still up to date?

Mandatory breach notification tightened. Automated decision-making now needs formal governance. Penalties went up significantly. None of this requires ISO 27701 certification to fix — but it does require knowing what changed and checking a handful of specific things now.

  • Breach Notification
  • Automated Decisions
  • No New Tools Needed
  • Standalone from ISO 27701
Take the Free Privacy Checklist Book a 30-Min Call

What actually changed

Three changes matter most for a mid-market Australian business right now — and most businesses haven't updated their processes to match any of them.

Tighter breach notification

The window and threshold for notifying the OAIC and affected individuals has narrowed. "We'll decide if it's notifiable when it happens" is no longer a defensible process.

Automated decision-making governance

Using automated or AI-assisted systems for decisions that materially affect people — credit, employment, pricing, eligibility — now carries specific transparency and accountability expectations.

Higher penalties

Regulator tolerance for informal or undocumented privacy practices has dropped. It's increasingly treated as an aggravating factor, not a neutral one.

Five things to check this month

A practical checklist you can work through today — no certification programme required to get started.

1. A timed breach-response runbook

Not a policy statement — an actual process: who assesses, against what criteria, on what clock, and who decides it's notifiable.

2. A register of automated decisions

Every place your business uses automated or algorithmic decision-making about a person, listed in one place — most businesses can't answer this without checking.

3. A named privacy owner

Not "the IT team" — a specific, named individual accountable for the breach-response decision and the automated-decision register.

4. Vendor breach-notification flow-down

If a vendor holding your customers' data is breached, do your contracts guarantee you find out in time to meet your own notification clock?

5. Evidence, not memory

If a regulator asked for evidence tomorrow, could you produce it — or would you be writing it from scratch after the fact?

Not sure where you stand?

The free ISO 27701 checklist covers all five of these areas alongside the full privacy management scope — a fast way to see exactly where your gaps are.

How this relates to ISO 27701

ISO 27701 is the broader, certifiable privacy management framework — the right answer if you need a defensible, audit-ready privacy programme end to end, particularly for enterprise procurement or regulated-sector customers. But you don't need to be pursuing certification to have a compliant breach-response clock or automated-decision register — those are baseline Privacy Act obligations now, not framework extras.

Take the Free Privacy Checklist ISO 27701 Services

Common questions

Do I need ISO 27701 to fix this?

No. A breach-response runbook and an automated-decision register are baseline compliance steps, achievable without pursuing certification.

What counts as "automated decision-making"?

Any system that makes or materially informs a decision about a person without a human individually reviewing it — credit scoring, resume screening, dynamic pricing, and similar.

How fast can this be fixed?

The runbook and register are usually a matter of weeks, not months — most of the underlying process already exists informally and needs documenting and assigning an owner.

Related

Free Privacy Checklist Score your privacy readiness in 12 minutes ISO 27701 Privacy Information Management What a Good ROPA Looks Like Practical implementation guide

Worried about the breach-notification or automated-decision changes?

A 30-minute call is enough to tell you whether your current process meets the reformed obligations.

Book a Call