Quick Summary

Overview: New Australian Privacy Principle provisions will require regulated entities to make particular automated decision-making uses visible in their APP Privacy Policies. The obligation covers more than AI and can include computer programs that make, or directly support, significant decisions.

  • The new APP 1.7 to 1.9 requirements commence on 10 December 2026.
  • They apply where personal information is used and a decision could significantly affect rights or interests.
  • Privacy policies must describe the kinds of information used and relevant kinds of decisions.
  • Practical next step: Inventory automated decisions now and identify which ones use personal information.
Published5 August 2026
Last reviewed5 August 2026
CategoryPrivacy and transparency
Estimated reading time8 minute read
Computer program representing automated decision-making systems and privacy transparency obligations.

Automated decisions can be produced or materially supported by computer programs, including conventional software and AI systems.

Businesses increasingly use software to score, rank, recommend, approve, decline and prioritise. From 10 December 2026, some of those systems will need to be described more clearly in the organisation's APP Privacy Policy.

The change comes from the Privacy and Other Legislation Amendment Act 2024, which adds clauses 1.7, 1.8 and 1.9 to Australian Privacy Principle 1.

It is an important transparency requirement, but it is more specific than a general duty to explain every algorithm. The legal test and the information that must be published both matter.

When does the new rule apply?

The new obligation applies when all three elements are present:

  • an APP entity has arranged for a computer program to make a decision, or do something substantially and directly related to making a decision
  • the decision could reasonably be expected to significantly affect an individual's rights or interests
  • personal information about that individual is used in the program's operation for that decision or related step

The wording reaches beyond decisions made entirely by software. A program may be covered when it performs something substantially and directly related to the decision, even if a person formally makes the final call.

The amendments apply to relevant decisions made from 10 December 2026. They can apply even if the arrangement, information or system existed before that date.

It is not only about artificial intelligence

The legislation uses the term “computer program”, not “artificial intelligence”. A rules engine, scoring model, matching tool or automated workflow may be relevant even if it does not use machine learning or generative AI.

That is why an inventory should start with decisions, not product labels. Searching only for tools marketed as AI can miss older automated systems that perform more consequential work.

What counts as a significant decision?

The decision must be one that could reasonably be expected to significantly affect rights or interests. The legislation gives examples including decisions about a benefit under law, rights under a contract or arrangement, and access to a significant service or support.

Making a decision includes refusing or failing to make one. The effect can be adverse or beneficial. The question is the significance of the potential effect, not whether the organisation believes the outcome helps the person.

In a business setting, potentially relevant uses may include eligibility, credit, insurance, access to essential services or decisions that materially affect a contractual position. Workplace systems may also need careful assessment where they influence employment opportunities or significant worker interests.

What must the privacy policy say?

Where the test is met, the APP Privacy Policy must contain information about:

  • the kinds of personal information used in the operation of the computer programs
  • the kinds of decisions made solely by the operation of those programs
  • the kinds of decisions for which a program does something substantially and directly related to making the decision

This is meaningful disclosure, but it is not the same as publishing source code, model weights or every technical detail. APP entities still need a clearly expressed and up-to-date policy that ordinary readers can understand.

Other privacy duties continue to apply. Updating the policy does not by itself resolve whether personal information was collected lawfully, used for a permitted purpose, kept accurate, secured appropriately or disclosed overseas in compliance with the Privacy Act.

Does every business have to comply?

No. The new requirement applies to APP entities. Many private-sector organisations are covered by the Privacy Act, but some small businesses may be exempt unless an exception applies. Australian Government agencies are also APP entities.

Businesses should not assume they are outside the Act based only on size. Health service providers, businesses trading in personal information, contracted service providers and other categories can be covered. Organisations should check their own position and seek advice where necessary.

A practical workplace example

A large employer uses a computer program to analyse application data and generate a shortlist score. A recruiter reviews the score before choosing candidates for interview.

The employer would need to assess whether the scoring step is substantially and directly related to a decision, whether the decision could significantly affect an applicant's rights or interests, and whether personal information is used. Calling the recruiter the final decision-maker does not automatically place the system outside the test.

What businesses should do now

  1. Inventory decisions: list computer programs that approve, decline, rank, score, recommend, match or prioritise people.

  2. Map personal information: record the information used, inferred or created during each workflow.

  3. Assess significance: identify potential effects on rights, contracts, benefits, services, support and other important interests.

  4. Check the human role: document whether the program decides, recommends or performs a step substantially and directly related to the decision.

  5. Review suppliers: obtain enough information from vendors to describe the use accurately and manage privacy risks.

  6. Update the policy: draft clear descriptions of information types and decision types before commencement.

  7. Build review pathways: tell staff how people can ask questions, correct information and seek meaningful human review.

As at 5 August 2026, organisations should monitor the OAIC's developing detailed guidance and test their draft disclosures against the final material when it is published.

For related guidance, see privacy information, AI, privacy and worker data, human oversight of AI, AI use registers and the AI governance checklist.

workplaceaigovernance.com.au/blog/automated-decision-making-transparency-2026/

Frequently Asked Questions

When do the new automated decision transparency obligations start?

The new APP 1.7 to 1.9 requirements commence on 10 December 2026 and apply to relevant decisions made from that date.

Do the obligations apply only to artificial intelligence?

No. The legislation refers to computer programs and can cover rules-based automation as well as AI or machine learning.

What must an APP Privacy Policy disclose?

It must describe the kinds of personal information used and the relevant kinds of decisions made solely by programs or substantially and directly supported by programs.

Does every Australian business have to comply?

The obligation applies to APP entities. Businesses should check whether the Privacy Act applies to them, including any small-business exemption or exception.

Key Facts

  • The new transparency obligation commences on 10 December 2026.
  • It applies to computer programs, not only systems labelled as AI.
  • Personal information and a potentially significant effect on rights or interests are both part of the test.
  • The obligation can cover a program that directly supports a human decision.
  • The required disclosure belongs in the entity's APP Privacy Policy.

Useful Australian Resources

These links are provided for general education and context. They are not a substitute for advice about your organisation's circumstances.

In Short

From 10 December 2026, APP entities must add specified automated decision-making information to their privacy policies when the legal test is met.

Next step: Inventory automated decisions, map personal information and prepare clear privacy-policy disclosures before commencement.