MAXIMUM CORPORATE PENALTY$50 million+or the greater of 3× benefit or 30% of adjusted turnover
WHY YOUR ORGANISATION MAY FACE ENFORCEMENT

Serious or repeated privacy interference can lead to Federal Court penalties. From 10 December 2026, covered entities must also explain qualifying automated decisions in their privacy policies—including the personal information used and the kinds of decisions made.

Undisclosed qualifying ADMPersonal information mishandlingSerious or repeated non-compliance
Understand the exposure
APP 1.7–1.9 · commencing 10 December 2026

Find the automated decisions hidden across your systems.

PrivacyComply helps Australian organisations discover automated decision-making, assess its privacy impact, prepare policy disclosures and maintain a defensible evidence trail.

Read-only discoveryPrivate-network readyOpenAI or ClaudeAustralian-focused
PrivacyComply · ADM Discovery
COMPLIANCE OVERVIEW
73Readiness score
3 systems need reviewPotential ADM transparency obligations detected
New ADM signalLead scoring · Salesforce
APP 1.8Disclosure mapped
10 DEC 2026

New privacy-policy transparency obligations commence for covered automated decisions.

Understand your exposure →
From discovery to evidence

A clear workflow for a difficult obligation.

Bring technical discovery, privacy review and policy preparation into one controlled workspace.

01Connect

Use read-only cloud connectors or an outbound private gateway.

02Discover

Identify scoring, ranking, recommendation and automated-decision signals.

03Review

Confirm purpose, personal information, decisions and individual impact.

04Disclose

Prepare traceable policy wording and export supporting evidence.

See PrivacyComply in action

From source systems to defensible evidence.

The walkthrough uses the populated Nexus Finance Group demo workspace and covers every product destination, all 30 pre-packaged connectors, SaaS and private-network connection models, security controls, and the complete installation configurator.

  • $499 Managed Cloud: direct read-only access to public SaaS APIs
  • $5,000 Managed Private: outbound-only gateway for internal systems
  • Custom Self-Hosted: customer infrastructure, keys and control
21-screen populated demo, connector and installation walkthrough · 2 minutes
Three ways to deploy

The same compliance platform. Different levels of isolation and control.

Choose based on where your systems live, who must operate the platform and who must control the encryption keys.

Managed Cloud, Managed Private with the Privacy Gateway, and Self-Hosted security architecture
PRIVACY GATEWAY · OUR SECURITY BOUNDARYPrivate systems stay private.

The Privacy Gateway runs inside the client network. It makes outbound-only connections, keeps source credentials locally encrypted, minimises records before transfer, and adds message-level encryption inside TLS.

Outbound onlyLocal credential vaultmTLS readyReplay protected
01 · $499 AUD / MONTHManaged Cloud
PrivacyComply Cloud
Encrypted HTTPS
SalesforceHubSpotMicrosoft 365
03 · CUSTOM PRICINGSelf-Hosted
Your infrastructure
Complete Platform
PostgreSQLStorageAI choice
CapabilityManaged CloudManaged PrivateSelf-Hosted
Public SaaS APIsIncludedIncludedIncluded
Private-network systemsGatewayDirect or gateway
Application isolationManaged tenantDedicated stackCustomer environment
Key custodyPrivacyComplyDedicated / optional dual controlCustomer KMS or HSM
OperationsPrivacyComplyPrivacyComplyCustomer or support agreement
Best fitCloud-first teamsRegulated/private estatesStrict infrastructure control
Understand the exposure

Privacy obligations are determined by coverage and conduct—not a simple company-size tariff.

Organisations over $3 million annual turnover are generally covered by the Privacy Act. Some smaller businesses are also covered because of their activities, including health services and trading in personal information.

Small business

$3m or less turnover

Many are exempt, but important exceptions apply. A covered small business enters the same corporate maximum-penalty framework.

Penalty positionSame statutory framework if coveredBest-fit optionManaged Cloud · $499/mo
Medium organisation

Typically covered

Multiple SaaS platforms, growing ADM use and limited privacy resources increase discovery and documentation complexity.

Penalty positionMaximum uses the same statutory formulaBest-fit optionManaged Cloud or Private
Large or regulated

Complex systems and exposure

Private networks, sensitive information and multiple business units increase operational impact; the turnover limb can materially increase exposure.

Penalty positionSame formula; turnover limb may dominateBest-fit optionManaged Private or Self-Hosted
Maximum corporate penalty for serious privacy interferenceGreater of $50 million, 3× benefit, or 30% of adjusted turnover

This is a statutory maximum, not an automatic penalty and not specific to ADM disclosure alone. Courts determine penalties based on the contravention. PrivacyComply supports compliance work but does not provide legal advice or guarantee compliance.

Simple commercial options

Match the deployment to your systems and risk model.

For cloud-first teams

Managed Cloud

$499AUD / month

A managed compliance workspace for organisations using public SaaS platforms and vendor APIs.

  • Public SaaS connectors
  • ADM discovery and register
  • Policy disclosure drafting
  • Evidence exports and monitoring
  • OpenAI or Claude
  • Managed updates and backups
Start Managed Cloud
Recommended for private systems

Managed Private

$5,000AUD / month

A dedicated environment plus secure gateways for systems inside private networks and cloud VPCs.

  • Everything in Managed Cloud
  • Dedicated application and database
  • Outbound-only private gateway
  • Private APIs, databases and files
  • Dedicated encryption keys
  • Priority operations and support
Discuss Managed Private
For complete infrastructure control

Enterprise Self-Hosted

Custom

Deploy the complete platform in your cloud, Kubernetes environment, data centre or private VM estate.

  • AWS, Azure, GCP or Fly
  • Linux VM and Kubernetes
  • Customer-controlled keys and storage
  • OIDC and enterprise identity
  • Air-gapped option
  • Installation and maintenance agreement
Request an architecture review

GST treatment is confirmed during checkout or quotation. Plans do not include legal advice or guarantee regulatory compliance.

Security by architecture

Keep credentials local. Encrypt findings everywhere.

Gateway traffic uses mutual TLS and message-level encryption. Sensitive stored data uses per-tenant envelope encryption, with keys kept separately from the database.

Explore the security model →
Source credentials remain in client networkOutbound-only private gatewayEncrypted in transit and at restOpenAI, Claude or AI disabledCustomer-controlled keys for self-hosting
Prepare before the deadline

Start with the systems you already use.

Build a reviewable inventory of automated decisions before policy updates become urgent.

Compare deployment optionsExisting customer sign in →