From 10th December 2026, firms covered by the Privacy Act have to say in their privacy policy where computer programs are involved in decisions that significantly affect individuals.
Who this is for
- Brokers whose systems touch decisions about individuals: personal lines, sole traders and partnerships, named insureds and guarantors on commercial policies, people covered under group or business policies, and claimants
- Compliance, risk and operations people who will have to produce the actual privacy policy wording
- Anyone whose quoting, renewals or claims triage runs partly on software they did not build
Who this is not for
- Firms under the AUD 3 million turnover threshold, who sit outside the Privacy Act entirely unless something else brings them in
- Anyone wanting legal sign-off on their wording. This is the mapping and the drafting position, and final review sits with your own lawyer
Most brokers are already using automated decision making somewhere, whether that is a quote comparison running across insurers, a renewal that goes through on existing data without a fresh needs analysis, or a feature in the broking platform that just appeared in the latest release.
The rules are not limited to AI, and they include tools that feed into a decision as well as tools that make one. So the focus of this session is about understanding where decisions are made within your processes and how technology supports them.
Fiona will go through the process she uses: finding the decisions, working out what sits behind each one, testing them against the criteria, and documenting it for your legal/risk team to update your privacy policy.
By the end of the session you will be able to run this in your own firm, and you will have the resources to do it.
Speaker
Fiona Morgan - Founder, AI Fully Informed