Use read-only cloud connectors or an outbound private gateway.
Serious or repeated privacy interference can lead to Federal Court penalties. From 10 December 2026, covered entities must also explain qualifying automated decisions in their privacy policies—including the personal information used and the kinds of decisions made.
Find the automated decisions hidden across your systems.
PrivacyComply helps Australian organisations discover automated decision-making, assess its privacy impact, prepare policy disclosures and maintain a defensible evidence trail.
New privacy-policy transparency obligations commence for covered automated decisions.
Understand your exposure →A clear workflow for a difficult obligation.
Bring technical discovery, privacy review and policy preparation into one controlled workspace.
Identify scoring, ranking, recommendation and automated-decision signals.
Confirm purpose, personal information, decisions and individual impact.
Prepare traceable policy wording and export supporting evidence.
From source systems to defensible evidence.
The walkthrough uses the populated Nexus Finance Group demo workspace and covers every product destination, all 30 pre-packaged connectors, SaaS and private-network connection models, security controls, and the complete installation configurator.
- $499 Managed Cloud: direct read-only access to public SaaS APIs
- $5,000 Managed Private: outbound-only gateway for internal systems
- Custom Self-Hosted: customer infrastructure, keys and control
The same compliance platform. Different levels of isolation and control.
Choose based on where your systems live, who must operate the platform and who must control the encryption keys.

The Privacy Gateway runs inside the client network. It makes outbound-only connections, keeps source credentials locally encrypted, minimises records before transfer, and adds message-level encryption inside TLS.
Privacy obligations are determined by coverage and conduct—not a simple company-size tariff.
Organisations over $3 million annual turnover are generally covered by the Privacy Act. Some smaller businesses are also covered because of their activities, including health services and trading in personal information.
$3m or less turnover
Many are exempt, but important exceptions apply. A covered small business enters the same corporate maximum-penalty framework.
Penalty positionSame statutory framework if coveredBest-fit optionManaged Cloud · $499/moTypically covered
Multiple SaaS platforms, growing ADM use and limited privacy resources increase discovery and documentation complexity.
Penalty positionMaximum uses the same statutory formulaBest-fit optionManaged Cloud or PrivateComplex systems and exposure
Private networks, sensitive information and multiple business units increase operational impact; the turnover limb can materially increase exposure.
Penalty positionSame formula; turnover limb may dominateBest-fit optionManaged Private or Self-HostedThis is a statutory maximum, not an automatic penalty and not specific to ADM disclosure alone. Courts determine penalties based on the contravention. PrivacyComply supports compliance work but does not provide legal advice or guarantee compliance.
Match the deployment to your systems and risk model.
Managed Cloud
A managed compliance workspace for organisations using public SaaS platforms and vendor APIs.
- ✓ Public SaaS connectors
- ✓ ADM discovery and register
- ✓ Policy disclosure drafting
- ✓ Evidence exports and monitoring
- ✓ OpenAI or Claude
- ✓ Managed updates and backups
Managed Private
A dedicated environment plus secure gateways for systems inside private networks and cloud VPCs.
- ✓ Everything in Managed Cloud
- ✓ Dedicated application and database
- ✓ Outbound-only private gateway
- ✓ Private APIs, databases and files
- ✓ Dedicated encryption keys
- ✓ Priority operations and support
Enterprise Self-Hosted
Deploy the complete platform in your cloud, Kubernetes environment, data centre or private VM estate.
- ✓ AWS, Azure, GCP or Fly
- ✓ Linux VM and Kubernetes
- ✓ Customer-controlled keys and storage
- ✓ OIDC and enterprise identity
- ✓ Air-gapped option
- ✓ Installation and maintenance agreement
GST treatment is confirmed during checkout or quotation. Plans do not include legal advice or guarantee regulatory compliance.
Keep credentials local. Encrypt findings everywhere.
Gateway traffic uses mutual TLS and message-level encryption. Sensitive stored data uses per-tenant envelope encryption, with keys kept separately from the database.
Explore the security model →Start with the systems you already use.
Build a reviewable inventory of automated decisions before policy updates become urgent.