GO
Overall Score
SilentCall
1. One-liner
Finds the software quietly deciding about your customers, and writes the disclosure Australian law demands by 10 December.
2. Trend signal — why now?
On 10 December 2026, APP 1.7–1.9 switch on in Australia. Every APP entity that lets a computer program make — or substantially and directly contribute to — a decision that significantly affects someone’s rights or interests must say so in its privacy policy. Not “AI systems.” Any computer program.
This is the tail end of the Privacy and Other Legislation Amendment Act 2024, which got Royal Assent on 10 December 2024 with a 24-month runway. That runway expires in 14 weeks. It is enacted law with a fixed date — not a proposal, not a discussion paper.
Three things make this the right moment rather than six months ago:
The regulator went from guidance to enforcement in January 2026. The OAIC ran its first-ever privacy policy compliance sweep, examining roughly 60 organisations across six sectors picked for in-person data collection: real estate agencies, chemists, licensed venues, car rental, car dealerships, pawnbrokers and second-hand dealers. Non-compliant privacy policies now carry infringement notices up to $66,000, and court penalties up to $330,000. The regulator is looking at exactly the mid-market operators who are least likely to know what APP 1.7 is.
The guidance doesn’t exist yet. The OAIC’s ADM consultation closed 15 June 2026; final guidance is expected September 2026. That leaves roughly ten weeks between guidance and deadline. Everyone advising on this says the same thing — don’t wait for the guidance, you won’t have time.
The definition is broader than anyone expects. Bird & Bird’s read is that the OAIC is signalling a broad interpretation. Unlike GDPR Article 22, which needs solely automated processing, Australia’s test captures programs that are “a key factor in facilitating human decision making.” Rule-based scripts and spreadsheets are in scope as readily as machine learning. Veronica Scott of Pinsent Masons makes the point that a decision can significantly affect someone even when it benefits them — faster access to a service counts.
The gap this creates is specific, and it is not the writing. It is the finding. From a practitioner brief: “Organisations cannot disclose what they have not mapped, and most have no register of the automated tools already making consequential decisions.” HR advisers call it “automation you did not know you had” — vendor-embedded functionality nobody deliberately bought.
Provenance:
- Signal 1 (demand): OAIC launched first-ever privacy policy compliance sweep January 2026, ~60 organisations across six mid-market sectors; penalties to $66,000 per infringement, court penalties to $330,000 — https://www.minterellison.com/articles/oaic-ramps-up-privacy-enforcement-are-you-ready — 2026-08-30
- Signal 2 (feasibility): APP 1.7 commences 10 December 2026 under an enacted Act; OAIC guidance not published until ~September 2026, definition broader than GDPR and captures rule-based systems and vendor-embedded features — https://www.twobirds.com/en/insights/2026/australia/australias-new-adm-transparency-obligation-oaic-signals-a-broad-reading-ahead-of-december-2026 — 2026-08-30
- Signal 3 (economic): OneTrust AI Governance runs $50,000–$150,000+ first year, priced on admin users plus AI inventory — the discovery capability exists but only above the mid-market’s ceiling — https://aicompliancevendors.com/vendors/onetrust-ai-governance — 2026-08-30 Category: Regulatory arbitrage
3. The opportunity
Two markets exist and neither serves the middle.
Above: OneTrust AI Governance, IBM watsonx.governance, the big consultancies (Protiviti, Salinger, PADISO). OneTrust starts around $50K and mid-market deployments run $100–200K. These tools genuinely do AI inventory — that’s the point of them. They are sold to organisations with a Chief Privacy Officer and a procurement cycle.
Below: privacy-policy generators. Privacy Act Shield, WebLegal, ComplianceKit, a dozen Australian IT shops with a blog post and a template. These produce the document. They ask you what you do and turn your answers into paragraphs.
The middle is a $5M-turnover Australian real estate group with 40 staff, no privacy officer, an office manager who inherited compliance, and 25 SaaS subscriptions. They cannot buy OneTrust. And the policy generator is useless to them, because the generator’s first question is “do you use automated decision-making?” — and they genuinely do not know.
That is the whole business. The bottleneck is not drafting. It is discovery. The disclosure is three paragraphs; producing it honestly requires knowing that your tenant-screening provider runs a risk score, that your ATS auto-rejects below a threshold, that your CRM’s lead scoring prioritises who gets called back. Each of those is a decision that significantly affects a person’s interests, and none of them appear on an org chart.
This is the artifact-vs-deadline gap in a new costume. The vendors sell the artifact. Nobody sells finding out what goes in it.
Why hasn’t someone done it? Because until January 2026 the OAIC had never run a sweep, so privacy policy accuracy was theatre. And because “audit your automation footprint” reads like consulting work — you bill for it by the day, you don’t productise it. The reason you can productise it now is that the discovery is mostly a known-vendor problem: the same 200-odd SaaS products show up across Australian mid-market firms, and each one’s ADM behaviour is a fact you determine once and reuse forever.
4. Target market
Primary customer: Operations manager, practice manager, or GM at an Australian business with $3M–$50M turnover and 15–150 staff, in a sector that screens or scores people. Real estate and property management, recruitment agencies, RTOs and private colleges, medical and allied health practices, car dealerships and finance brokers, labour hire, insurance brokers. These are the sectors where an automated decision refuses someone a tenancy, a job, a place, or a loan — and where the OAIC has already pointed its sweep.
They are above the $3M small-business exemption, so they are APP entities today. This matters enormously: I am not selling against a maybe. The Tranche 2 removal of the small business exemption is not enacted and has no timetable, so I ignore it entirely. My customer is already covered.
Why they buy, in their words: The most useful quote I found is from Amjid Ali, a finance-industry AI specialist, in ACS’s Information Age: “Most business owners I speak with think AI regulation in Australia is still years away” — but the requirement has “a hard date, it applies to ordinary businesses, and the clock is already running.”
The practitioner framing of the pain is blunter: “Organisations cannot disclose what they have not mapped, and most have no register of the automated tools already making consequential decisions.” And the specific fear, from HR advisory: “automation you did not know you had” sitting inside vendor-embedded functionality.
Concrete hidden-ADM examples that practitioners are actually flagging: CRM lead-scoring engines that prioritise follow-up; accounting software anomaly-detection; document processing tools extracting personal data; customer service chatbots categorising complaints; applicant tracking systems that filter before a human sees the file; tenancy and booking risk-scoring services. From the LeadComply guidance: “A CRM that scores leads and prioritises follow-up actions is an AI system.”
Rough TAM reasoning: I won’t invent a number for how many Australian businesses clear $3M turnover — I couldn’t source one and I’m not going to fabricate it. What I can bound: the OAIC’s sweep sectors alone (real estate, pharmacy, licensed venues, car rental, dealerships, pawnbrokers) run to tens of thousands of businesses, and the screening-heavy sectors I’m targeting — real estate agencies, recruiters, RTOs, brokers — plausibly number in the tens of thousands above the threshold. At 400 customers I have a $1M business. That does not require market dominance; it requires being the obvious answer in four verticals. New Zealand adds genuine spillover: NZ organisations operating in Australia are caught, NZ has no APP 1.7 equivalent, and the OAIC’s reach is not limited to Australian-incorporated entities — so NZ firms have zero domestic capability to lean on.
Why now for them: Fixed date, live regulator, and a definition their lawyer can’t confidently apply without knowing their software stack.
5. Product sketch (MVP)
- Stack intake in under 20 minutes. Connect Google Workspace or Microsoft 365 to read the app-consent list, forward one month of vendor invoices, or paste a list. Most mid-market firms can name their stack; they just can’t classify it.
- ADM verdict per system, from a maintained vendor library. For each product detected: in scope / out of scope / depends-on-configuration, with the reasoning written against the statutory test — is the program making the decision, or substantially and directly related to making it, and does the decision significantly affect rights or interests.
- The “depends” interview. Where the verdict hinges on how the customer configured it — does your ATS auto-reject, or rank? does anyone actually read the ranking? — a short guided Q&A resolves it. This is where most real answers live.
- Human-in-the-loop test. For substantially-assisted decisions, a few questions that establish whether human involvement is meaningful or merely confirmatory, because “a human clicked approve” is not automatically a defence.
- Generated APP 1.7 disclosure block. Plain-English paragraphs covering the kinds of personal information used, decisions made solely by automation, and decisions substantially assisted — drafted to drop into an existing privacy policy, not to replace it.
- The register itself. A dated, exportable record of every system assessed, the verdict, the reasoning, and who signed off — the evidence that you did the mapping, which is what you hand over if the OAIC asks.
- Vendor questionnaire generator. One-click emails asking each supplier whether their product makes or assists decisions and what personal information it uses. Practitioners are explicitly telling clients to interrogate vendors; nobody gives them the letter.
- Drift alerts. Your CRM ships an AI scoring feature in March. Your register is now wrong. We tell you.
6. AI angle — what’s load-bearing
Remove the AI and this is a spreadsheet with a vendor list, which is what consultants already sell at day rates.
Two places the model does real work:
Applying an undefined legal test to a specific configuration. “Substantially and directly related to making a decision” has no case law, no OAIC guidance until September, and deliberately vague drafting. Determining whether a particular firm’s use of a particular product crosses that line is a judgement over statutory text, explanatory memorandum, and the customer’s own description of their workflow. That is a language problem, and it is exactly the reasoning a $600/hour privacy lawyer performs — for a document that will be identical across hundreds of firms using the same eight products.
Building and maintaining the vendor library. Reading vendor documentation, release notes, and feature pages across hundreds of SaaS products to determine what decision-support each one performs, and re-reading when they ship features. Doing this by hand across a moving target is the reason no consultancy productises it.
The drafting is the easy part and I’m not pretending otherwise.
7. Localization angle
Australia-first by necessity, not by flavour. APP 1.7 is a specific statutory test with a specific commencement date; the product is an opinion about Australian law. Pricing in AUD, sold through Australian channels.
The natural expansion is not “same product, other countries” — it’s the same shape against other ADM transparency regimes. NZ is the immediate adjacency because trans-Tasman firms are caught by APP 1.7 with no domestic equivalent to lean on. Beyond that, EU AI Act transparency duties and the emerging US state ADMT rules (California’s CPPA finalised ADMT regulations) are the same discovery problem against different tests. The vendor library — what does this product actually decide — is jurisdiction-neutral and transfers wholesale. That is the asset.
8. Business model — path to $1M–$5M ARR
Pricing:
- Register — A$149/mo. Up to 25 systems, annual re-assessment, disclosure block, drift alerts.
- Register Pro — A$349/mo. Up to 75 systems, vendor questionnaire automation, multi-entity, change history and sign-off trail.
- Onboarding assessment — A$1,500 one-off. Guided first pass, done-with-you. Most customers before December will buy this, and it front-loads cash.
ACV: ~A$3,600 blended (mix of tiers, most on Register with a chunk on Pro), plus first-year setup.
Rough math to $1M ARR: 280 customers on Register Pro, or ~400 blended across tiers. In a country with tens of thousands of screening-heavy businesses above the threshold, 400 is a niche position, not a land grab.
Rough math to $5M ARR: Needs three things to be true. Retention past the deadline — the register has to be a living document, which drift alerts and annual re-assessment are designed to make true. NZ and trans-Tasman expansion. And an accountant/broker channel selling it as a bundled service to their own client books, which is where the volume actually is.
Expansion path: System count is the natural meter and it only goes up. Multi-entity for groups. Then the adjacent obligations — the human-review pathway the guidance will likely require, and access/correction request handling — sold to a customer who has already handed you a map of their entire decision-making stack.
The honest risk to the revenue: this has a date on it. Post-December demand is renewal and laggards, not the December rush. I’m underwriting this as a business that must convert the deadline into a recurring register, and if it can’t, it’s a good consulting year and a mediocre SaaS company.
9. Go-to-market wedge — first 100 customers
1. The sweep sectors, by name. The OAIC published which six sectors it swept. Real estate agencies are the sharpest: they run tenancy screening, which is the textbook APP 1.7 example, and they’re already spooked. State real estate institutes publish member directories. Scrape agency principals in Sydney, Melbourne, Brisbane. The email is not a pitch — it’s their situation: “The OAIC swept 60 businesses in your sector in January. On 10 December your privacy policy has to disclose your tenancy screening. Here’s what your screening provider does, specifically.” Personalised because we already know what PropertyMe or Snug does. 2,000 agencies, 3% to a paid assessment = 60 customers.
2. Accountants, brokers, and IT MSPs as the channel. Australian mid-market compliance is bought through trusted advisers. MSPs in particular are already writing the blog posts — Otto IT, Zeno, Epic IT, Nifty Computing all have Privacy Act 2026 content up, which means they’re fielding the questions and have nothing to sell. White-label the register, they keep 30%. Twenty MSPs with 40 relevant clients each is the entire $1M target in one channel.
3. Free ADM exposure scan as the lead magnet — with the number withheld. Public tool: pick your industry and your software from a list, get an instant count of how many of your systems are likely in scope and which three are riskiest. The verdicts and reasoning — the thing you’d hand a regulator — sit behind the paywall. My standing lesson here is that giving away the whole diagnostic kills the paid product; the scan must create the alarm and stop.
4. Ride the September guidance. OAIC final guidance lands ~September 2026, roughly ten weeks before commencement. That is a news event in every Australian compliance newsletter. Have a same-week teardown out: what the guidance actually says about which systems are in scope, product-agnostic and genuinely useful. This is the one moment the audience is actively searching.
5. Law firm referral, downward. Firms like Lander & Rogers are selling privacy policy review services. They do not want a $5M real estate agency’s 25-app inventory — it’s unbillable grind. Be the thing they refer down to, and the thing that hands their bigger clients a clean register so their review is fast.
10. Build complexity — justification
Low. Standard web app, OAuth reads of Google Workspace and M365 app-consent lists, LLM calls for classification and drafting, PDF/DOCX export. No infrastructure novelty.
The real work isn’t engineering — it’s the vendor library. Getting the top 200 Australian mid-market SaaS products classified with defensible reasoning is weeks of research with model assistance, and it needs a privacy lawyer’s review before anything ships. Budget A$15–25K for that review; it is not optional, because the product is an opinion about the law and a wrong opinion published at scale is the whole risk.
Solo technical founder plus a privacy consultant on retainer: 6–8 weeks to a paid pilot. The deadline makes this schedule non-negotiable — shipping in November is shipping into the tail.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Compliance tooling. Must be framed as an assessment aid, not legal advice — standard disclaimer, lawyer-reviewed library. |
| Ethical — no harm / dark patterns | ✅ | Increases transparency about automated decisions. The deadline is real; urgency isn’t manufactured. |
| Market exists (evidence above) | ✅ | Enacted obligation, fixed date, live regulator sweep, incumbent priced at $50K+. |
| 1–5 person team can build this | ✅ | Solo founder + privacy consultant. |
| Launchable with <$50K / ₹40L | ✅ | A$25–35K, dominated by legal review of the library. |
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 16/20 | Hard date, $66K infringement notices, $330K court penalties, active sweep. Not 18+ because it’s an annual-ish compliance task, not a daily bleed — and a firm can bluff a vague disclosure and probably not get caught. |
| Demand evidence | 15 | 12/15 | Strong regulatory and enforcement evidence; OneTrust’s $50K+ pricing proves the capability is valued. Docked because I have expert and practitioner voice, not customers saying “I’d pay for this” — the classic pre-deadline evidence gap. |
| Build feasibility | 15 | 13/15 | Off-the-shelf stack, 6–8 weeks. Docked for the vendor library grind and mandatory legal review. |
| Distribution clarity | 15 | 12/15 | Named sectors from the regulator’s own sweep, scrapeable directories, MSP channel already producing content on this exact topic. Docked because the MSP channel is unproven for this product. |
| Revenue mechanics | 15 | 11/15 | A$149–349/mo is right for the wallet and 400 customers is achievable. Docked hard on retention: the deadline drives year one, and year two is a real question. |
| Time to first revenue | 10 | 8/10 | The A$1,500 assessment is pre-sellable before the software is finished. Weeks, not months. |
| Defensibility | 10 | 4/10 | Execution-only. The vendor library compounds and is genuinely annoying to rebuild, but a funded competitor could match it in a quarter. Being first with the sectors is the moat, and that’s a thin one. |
| Total | 100 | 76/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · content-heavy
Needs someone who can ship a clean web app fast and write credibly about Australian privacy law — the content is the distribution here. Domain expertise is buyable via a retained privacy consultant, but it is not skippable.
Key assumptions to validate (3–5)
- Assumption: Mid-market operators genuinely cannot answer “which of your systems make automated decisions?” How to test: Ask 25 real estate and recruitment ops managers that exact question cold. If most rattle off an accurate list, the discovery premise is dead and this is just a policy generator.
- Assumption: They’ll pay A$1,500 for an assessment rather than ask their lawyer or ignore it. How to test: Pre-sell 10 assessments before writing code, at full price, with a delivery date.
- Assumption: The vendor library can be built to a standard a privacy lawyer will sign off on. How to test: Classify 20 common products, have a privacy consultant review, measure how many verdicts they’d defend unchanged.
- Assumption: There is a business after 10 December. How to test: Watch renewal intent in the pilot cohort — do they see the register as a living document or a one-off certificate? Ask them to commit to 12 months up front and see who flinches.
- Assumption: MSPs will white-label. How to test: Pitch five Australian MSPs already publishing Privacy Act content; a signed reseller before launch or the channel is speculative.
Risk flags
- Deadline cliff: The single biggest risk. Demand peaks 10 December 2026 and the shape of demand after that is unknown. If the register doesn’t become a maintained artefact, this is a strong consulting year that decays into churn.
- Guidance risk: OAIC final guidance lands ~September 2026 and could narrow the definition sharply — if “substantially and directly” gets read tightly, the number of in-scope systems collapses and so does the pain. It could also broaden it, which is upside. Either way the product’s core opinions get rewritten weeks before launch.
- Regulatory-advice exposure: Publishing verdicts on whether a system triggers a statutory obligation is close to legal advice. Needs lawyer-reviewed library, clear disclaimers, and probably PI insurance.
- Incumbent step-down: OneTrust or a well-funded ANZ privacy vendor launching a $200/mo SMB tier would compress this fast. The defence is sector-specific depth and being first, which is not much of a defence.
- Wrong buyer: If the decision sits with an external lawyer rather than the ops manager, the sales motion is completely different and the price point is wrong.
14. Structured verdict
Score: 76/100
Verdict: GO
Confidence: Medium
Best-fit builder: Technical solo founder who writes well, with a retained
Australian privacy consultant. AU-based or AU-networked —
this sells on local credibility.
Time to revenue: 4–6 weeks (pre-sold assessments), 8 weeks to SaaS revenue
Capital to launch: A$25–35K (~₹15–20L), mostly legal review of the vendor library
Top 3 assumptions to validate first:
1. Mid-market ops managers can't self-assess their ADM footprint — ask 25 cold
2. A$1,500 assessment pre-sells — 10 paid commitments before writing code
3. There's a business after 10 December — test 12-month commitment in the pilot
Kill criteria:
- Abandon if fewer than 5 of 25 target firms can't name their in-scope systems
(means discovery isn't the bottleneck and this is a commodity policy generator)
- Abandon if fewer than 5 of 40 pre-sale conversations convert to a paid assessment
- Abandon if OAIC's September guidance reads "substantially and directly" narrowly
enough that a typical mid-market firm has fewer than 3 in-scope systems
- Abandon if an established ANZ privacy vendor ships sub-A$300/mo ADM discovery
before the pilot closes
15. Next step — 1-week validation sprint
- Day 1–2: Build the vendor library for one vertical only — real estate. Classify the 15 products an Australian agency actually runs (PropertyMe, Console, Snug, tenancy screening providers, the common ATS and CRM tools) against the APP 1.7 test. Get a privacy consultant to review the verdicts for one paid hour. Target: 12 of 15 verdicts they’d defend unchanged.
- Day 3–4: Scrape 300 agency principals from state real estate institute directories. Send the sweep-sector email with their specific likely-in-scope systems named. No product, no demo — one question: “can you tell me which of these you’d have to disclose?” Measure reply rate and, more importantly, how many replies reveal they don’t know.
- Day 5: Offer the 10 warmest replies a A$1,500 assessment with a November delivery date. Take deposits.
Go/no-go: ≥3 paid deposits from 300 emails, and ≥60% of substantive replies demonstrating they can’t self-assess. Deposits prove willingness to pay; the confusion rate proves the discovery premise. Either one failing kills it — money without the discovery gap means I’m selling a document anyone can generate, and confusion without money means it’s a real problem nobody funds.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai