A stake in the ground on privacy
1 May 2026
Privacy is about to become a much more practical issue for strata managers. For a long time it's been a legal concept buried in terms and conditions, but that's changing. With AI systems reading emails, drafting responses, and making decisions, the question gets more immediate: who has access to what, and what are they allowed to do with it?
What changes on 10 December 2026?
The Privacy and Other Legislation Amendment Act 2024 inserts new subclauses into Australian Privacy Principle 1. From that date, where an organisation has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual's rights or interests, it must say so in its privacy policy, and say what kinds of information are used and what kinds of decisions are made.
Two details matter. The obligation applies to decisions made from that date, regardless of when the system was built or the data collected. And a decision includes a failure to decide, with effects that may be beneficial as well as adverse.
The direction of travel is similar to Europe's GDPR. More accountability, more rights for individuals, less room for ambiguity. For software platforms in this space that is a real shift. It is not enough to handle data responsibly anymore. Systems need to be designed with clear boundaries around how information is used, stored, and, importantly, removed.
Why this lands harder in strata than most industries
Think about what actually passes through a strata management inbox in a given week.
Health information inside insurance claims. Disability accommodation requests. Welfare correspondence about an owner who is struggling. NCAT case references and by-law breach notices. Bank account details for levy disbursements. How individuals voted on motions, and who held their proxy. Photographs of common property defects that incidentally include people.
Most industries handle one or two categories of sensitive information and build a process around each. Strata handles nearly all of them, in unstructured form, arriving by email, from parties who never consented to anything and often do not know the platform exists.
Point an AI system at that inbox without thinking hard about it and you have sent a great deal of other people's personal information to a third party overseas.
What we built instead
The design principle behind Antlar is that personal information should not leave Australia at all.
When content is sent to an AI feature, Antlar applies automated detection to identify personal information and replaces it with non-identifying placeholders before that content leaves Antlar's Australian infrastructure. The third-party AI providers receive only the placeholder version. They do not receive names, contact details, addresses, or financial identifiers of lot owners, committee members or anyone else.
When the AI returns a response, Antlar restores the original details inside its own infrastructure, so the authorised user sees the real names they expect. Restoration is never performed by a third party. The mapping that makes restoration possible is held on Australian infrastructure, accessible only to the Service itself, and is deleted alongside the scheme records on account termination.
Semantic search, the part that finds the relevant emails and documents before the AI ever sees a question, runs entirely on Antlar-operated Australian infrastructure. That content does not go overseas in any form.
Two further controls sit behind this. Responses coming back are re-scanned for personal information patterns, so anything substituted before transmission cannot reappear in an AI output. And our release process carries automated controls that prevent a new feature from sending content to an AI provider without the substitution being applied first. That second one matters more than it sounds. Privacy architecture fails at the edges, in the feature someone shipped quickly on a Friday.
Where it doesn't work, and why we say so
Placeholder substitution applies to text. It cannot apply to an image, because the image has to be readable for the AI to extract text from it. So when you upload a photograph of a strata roll or a certificate of currency for data entry, that image goes to the AI provider as it is. Authorised users review and confirm everything extracted before it is imported.
And no automated system identifies personal information with complete accuracy. Ours is good and gets better, but some personal information will not be detected and substituted in every case.
Both of those are in our privacy policy in plain terms. A privacy policy that claims perfect protection is telling you something about the company rather than about the software.
Who decides
On the automated decision-making question specifically, our position is the one this newsletter is named after.
Antlar classifies correspondence automatically, by topic and urgency and the lots involved, and any authorised user can correct that at any time. Beyond categorisation, AI surfaces recommendations, drafts and analyses. But where a decision could affect the rights or interests of a lot owner or a committee member, a human makes it. No change to compliance status, outbound correspondence or financial records is applied without human confirmation.
That is a product decision as much as a compliance one. It is also, conveniently, the thing that makes the December 2026 obligation straightforward for us to meet.
Have a read
Our privacy policy is written to be read, not to be survived. It sets out exactly which providers receive what, which data stays in Sydney, and what happens to it when a scheme leaves.
It is not usually front of mind, and it is not the sort of thing anyone volunteers feedback on. But if you manage schemes and something in there looks wrong, thin, or too clever, I would genuinely value hearing it. Email me.
Sources
Stay in the loop
Get Human in the Loop
Featuring strata compliance insights, product news and tips for committees and strata professionals.
