Australian SaaS vendors need to update five areas of their Terms of Service in 2026 such as data processing liability between vendor and customer, liability allocation for automated decision-making features, direct marketing consent flows, data portability and deletion protocols, and limitation of liability caps.
Each has been reshaped by the same reforms, being the statutory tort for serious invasions of privacy, Australian Privacy Principle 7, and automated decision-making transparency obligations commencing 10 December 2026.
None of this is addressed in a Privacy Policy review. It arises in the master customer agreement, where most commercial risk is allocated.
That distinction is material. A Privacy Policy explains how personal information is handled. It does not determine liability when issues arise. Those matters are governed by contract, and for many Australian SaaS businesses, that contract has not been revisited since before these reforms commenced.
Realigning Data Handling Responsibilities Between Vendor and Customer
Australian privacy law does not adopt the terminology of controller and processor, however the underlying allocation is comparable. In most B2B SaaS arrangements, the customer determines the purpose of collection, while the vendor determines how the information is stored, secured, and processed.
Under the Australian Privacy Principles, both parties may hold independent obligations in respect of the same dataset. Australian Privacy Principle 11 requires any entity holding personal information to take reasonable steps to protect it.
Leaving this allocation implicitly creates commercial uncertainty. When an issue arises, responsibility becomes contested rather than defined.
The position should be addressed expressly through:
- allocation of responsibility for determining purpose of collection
- a data handling schedule addressing security standards, sub processing and cross border disclosure
- indemnities aligned with actual responsibility
The Notifiable Data Breaches scheme also requires specific contractual treatment. Where a breach originates in vendor systems but affects individuals connected to the customer, the agreement should determine in advance who assesses the breach, who issues notifications, and the applicable timeframe.
Automated Decision Making: A Liability Shield, Not Just an Obligation
From 10 December 2026, Australian Privacy Principle 1 requires disclosure of the use of personal information in automated decision making and the types of decisions produced.
That obligation rests with the entity making the decision, which will ordinarily be the customer.
This creates a drafting opportunity for SaaS vendors.
Terms of Service should define the scope of automated functionality by:
- describing inputs and outputs in clear terms
- enabling customers to meet disclosure obligations
- avoiding disclosure of proprietary systems, models or training data
A properly structured clause protects both compliance and intellectual property. An absent or unclear clause shifts this negotiation into a dispute context.
Direct Marketing and Consent Flows Inside the Product
Australian Privacy Principle 7 restricts the use or disclosure of personal information for direct marketing without consent or reasonable expectation together with a simple opt out mechanism.
In SaaS environments, this extends to product prompts, recommendation systems and re engagement communications.
The legal risk has shifted. Following the introduction of the statutory tort for serious invasions of privacy, non-compliant consent mechanisms may give rise to direct claims by individuals.
Terms of Service should distinguish between:
- data used for product functionality and improvement
- data used for direct marketing purposes
They should also allocate responsibility for obtaining and recording consent where end users interact with the platform.
Data Portability and Deletion as Contractual Commitments
Post termination data handling is a frequent source of dispute and is often insufficiently defined.
General statements such as commercially reasonable efforts lack certainty.
A more robust approach treats these obligations as defined contractual commitments:
- specified timeframes and formats for data extraction
- defined deletion schedules across production and backup systems
- continuing security obligations during any transition period
Under Australian Privacy Principle 11, personal information must be destroyed or de identified when no longer required. That obligation continues beyond termination of the contract.
Setting Liability Caps That Withstand an Unfair Contract Terms Challenge
Most SaaS agreements are standard form contracts. The unfair contract terms regime applies broadly, including to many small and medium enterprise customers.
A term found to be unfair may be declared void, and civil penalties may apply.
Liability caps must therefore be considered in the context of the agreement.
Key considerations include:
- avoiding imbalance between capped liability and uncapped indemnities
- carefully drafting carve outs for privacy breaches and regulatory penalties
- considering separate liability caps for data breach related loss
Loss arising from data breaches may scale differently from ordinary contractual loss and should be addressed accordingly.
Reviewing the Contract, Not Just the Policy
Privacy Policies and Terms of Service perform different functions and should be reviewed together.
If a Privacy Policy has been updated to reflect recent reforms, the master customer agreement should be reviewed on the same basis, particularly where the commercial terms, data handling provisions and liability framework predate those reforms.
At Warlows Legal, our technology and privacy law team advises SaaS vendors and B2B software providers on aligning commercial contracts with Australia’s evolving privacy framework, including data handling provisions, automated decision-making clauses and liability structuring under the unfair contract terms regime.
Disclaimer: The information on this website is general in nature and is provided for informational and educational purposes only. It does not constitute legal advice. Accessing or reading this article does not create a solicitor‑client relationship. For advice relating to your specific legal circumstances, please contact our firm directly to consult a lawyer.




