
Privacy Act, from 10 December 2026
The Privacy Act's automated decision-making disclosure
What to write before 10 December 2026, who has to write it, and why a person making the final call does not get you out of it.

Syed Mosawi
Founder • Sep 23, 2026 • 10 min read
On 10 December 2026 a short new section of the Privacy Act 1988 (Cth) starts to bite. If your organisation uses a computer program to make decisions about people, or to do something that substantially shapes those decisions, your privacy policy has to say so. It has to say what kinds of decisions, and what kinds of personal information the program uses.
Three things about this obligation catch businesses out. It is not limited to artificial intelligence, so a scoring formula in a spreadsheet can trigger it. It is not limited to fully automated decisions, so a person making the final call does not take you outside it. And it attaches to the business that arranged for the program to be used, not to the vendor that built it, so your recruitment platform, your credit engine and your customer service chatbot are all your problem to disclose.
This guide sets out what the law says, who it covers, how the regulator has said it will read the key phrases, and what the section of your privacy policy needs to contain. It is general information rather than legal advice, and the Office of the Australian Information Commissioner has said it will publish guidance before the start date. Read that when it lands. The statutory text will not change.
What the law says
The Privacy and Other Legislation Amendment Act 2024 (Cth) inserted three new paragraphs into Australian Privacy Principle 1, the principle that requires every covered entity to keep a clearly expressed and up-to-date privacy policy. They commence on 10 December 2026.
APP 1.7 sets a three-limb test. The obligation applies where an entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision; the decision could reasonably be expected to significantly affect the rights or interests of an individual; and personal information about the individual is used in the operation of the program to make the decision or do that thing.
APP 1.8 then says what the privacy policy must contain when all three limbs are met: the kinds of personal information used in the operation of such programs, the kinds of decisions made solely by the operation of such programs, and the kinds of decisions for which the program does a thing substantially and directly related to making the decision.
APP 1.9 closes two doors. Making a decision includes refusing or failing to make one, and a decision may affect a person's rights or interests whether the effect is adverse or beneficial. Approving people automatically counts as much as declining them.
Who has to comply
The obligation binds APP entities: Australian Government agencies and organisations with an annual turnover above $3 million, together with a set of smaller businesses the Act covers regardless of turnover. On the OAIC's list those include private sector health service providers, which reaches gyms, child care centres and private schools as well as clinicians; businesses that sell or purchase personal information; credit reporting bodies; contracted service providers under Australian Government contracts; businesses accredited under the Consumer Data Right; registered employee associations; businesses that have opted in; and businesses related to a covered business. Operating a residential tenancy database, or being a reporting entity under anti-money laundering law, brings those particular activities in too.
Everyone else sits under the small business exemption for now. The government has said it intends to remove that exemption in a second tranche of privacy reform. As at September 2026 that tranche has not been introduced to Parliament and has no commencement date, so treat any claim that small businesses are already caught with care. Two practical points still apply. If you are exempt today, your larger customers are not, and their supplier questionnaires increasingly ask the same questions. And if you plan to grow past $3 million, the disclosure is easier to write now than to reconstruct later.
The three-limb test, with the regulator's examples
Limb one is about the program's role. The Explanatory Memorandum says “computer program” takes its ordinary meaning and covers pre-programmed rule-based processes as well as artificial intelligence and machine learning. The OAIC's issues paper adds that generative AI tools used to produce text, images, video or code, including chatbots, all fall within the definition. Ordinary software, apps and word-processing tools are in scope too. What narrows the limb is the phrase “substantially and directly related to making a decision”. The Explanatory Memorandum reads “substantially” as the program being a key factor in facilitating the human's decision, and “directly” as the thing having a direct connection with making it.
The regulator's own example: a pre-programmed formula in a spreadsheet that scores and triages callers to a crisis hotline, where the score is a key factor in a person deciding whose call to attend first, is substantially and directly related to the decision. The same spreadsheet used only to work out an age from a date of birth is directly related but not substantially. The first is in scope. The second is not.
That example answers the most common question about this law. A human in the loop does not, on its own, take an arrangement outside APP 1.7. If the program's output steers the decision, the fact that a person signs it off is beside the point. Recruitment platforms that rank applicants, underwriting engines that recommend a premium, customer service tools that flag which refunds to approve and case management systems that escalate complaints are the obvious candidates.
Limb two is about significance. The decision must be one that could reasonably be expected to significantly affect a person's rights or interests. The Explanatory Memorandum and the issues paper give admission to a country, entitlement to a housing benefit, a life insurance contract and access to healthcare as examples. They also note that targeting people with content or advertisements can qualify where it produces differential pricing for significant goods or services, or limits access to employment. The issues paper asks how large a price difference has to be before it counts, which tells you the OAIC has not settled that edge yet.
Limb three is about personal information. Information about the individual must be used in the operation of the program to make the decision or do the related thing. A program that decides on the basis of aggregate or non-personal data, with nothing about the affected person fed in, does not meet this limb.
The vendor's tool is still your disclosure
APP 1.7 speaks of the entity that has “arranged for” a computer program to be used. The issues paper explains that this fixes the obligation on the organisation that arranged for the program to make or assist a decision, even where a different organisation operates the software. Its examples of arranging include procuring another company's AI system to screen and rank job applications, permitting or directing employees to use an AI chat tool to draft performance assessments that determine promotions, contracting a software company to approve or decline refunds automatically, and running a case management system that escalates particular complaints on its own.
The contrast the OAIC draws is with merely operating a system: a company that develops and hosts software which approves or rejects customer applications but does not use it itself, or one that maintains the infrastructure for a fraud detection system. Those businesses are not the ones who arranged the use. The lesson for a buyer is blunt. During and after procurement you need to know how a supplier's product uses automation to make or assist decisions about your customers and staff, and what kinds of decisions those are, because the disclosure sits with you.
What goes in the privacy policy
The three lists in APP 1.8 are the whole of the requirement. Written plainly, the new section of a privacy policy looks something like this.
Automated decision-making
We use computer programs, including artificial intelligence, to make some decisions about individuals, and to do things that are substantially and directly related to making decisions, using personal information.
Decisions made solely by computer programs: whether to approve a refund request under our returns policy.
Decisions a computer program substantially assists, with a person making the final decision: whether to shortlist a job applicant; whether to invite an applicant to interview.
Kinds of personal information used: identity and contact details; transaction history; employment history, qualifications and references.
Human review: email privacy@example.com.au and a person will review any automated decision within ten business days.
Two points on depth. The Explanatory Memorandum confirms that commercial-in-confidence information about automated decision-making systems is excluded, so you are not being asked to publish how a model works or which vendor you use. And the OAIC frames the extent of disclosure as a balance: enough meaningful information for people to understand the use of automated decision-making, without detail so excessive that it obscures the point. Kinds of decisions, not every decision. Kinds of personal information, not a data dictionary.
The human review line in the example is not required by APP 1.8. It is there because the issues paper points to the transparency practices it regards as good, including the Digital Transformation Agency's standard for government AI transparency statements, which insists on plain language and a contact point for enquiries. A route to a human is also the practical expression of the contestability principle that Responsible AI certification assesses. If you are writing the section anyway, one sentence on how to question a decision is cheap to add and hard to argue against.
What the obligation does not do
It does not require consent for automated decisions, and it does not require a notice at the moment a decision is made. It is a privacy policy content requirement. Other laws already constrain what you decide and how: consumer law, anti- discrimination law, credit reporting rules and the Australian Consumer Law's prohibition on misleading conduct all apply to automated decisions in the same way they apply to human ones. The disclosure sits on top of them, not in place of them.
What happens if you miss the date
The requirement lives inside APP 1, the duty to have a clearly expressed and up-to-date privacy policy. The same 2024 reforms gave the OAIC infringement notice and compliance notice powers for a lower tier of contraventions, alongside its existing civil penalty powers, and law firms writing on the reform expect those notices to reach privacy policies that fail to include the new content. The practical risk is less a fine on day one and more a regulator asking, in the course of some other complaint, why your policy is silent on a system that plainly makes decisions about people.
Eleven weeks: a plan that fits
Inventory first. List every system that makes, recommends, scores, ranks, triages, flags or escalates anything about a customer, an applicant or an employee. Include the tools staff use informally. Include the automation a vendor switched on in a product update without telling you.
Run the three limbs on each one. Role, significance, personal information. Record the answer and the reason, especially for the systems you conclude are out of scope. That record is what you will want when the OAIC guidance arrives and when a supplier changes a feature.
Map the personal information. For each in-scope system, list the kinds of personal information it uses and the kinds of decisions it makes or assists, in the words a customer would use.
Draft the section and have it reviewed. The three lists, in plain language, with a human review route if you can offer one. Your privacy adviser should see it before it is published, because significance in particular is a judgement call.
Build the change trigger. Add a question to procurement and change management: does this tool make or substantially assist decisions about people using their personal information? A set-and-forget policy will drift out of date the first time a vendor ships an AI feature.
A free builder for the first four steps
We built a free automated decision-making disclosure builder that walks through exactly this. It checks whether the Privacy Act covers you, using the OAIC's own list of triggers. It runs the three limbs on each system you list, with the regulator's examples beside every option. It then drafts the privacy policy section with the three required lists, plus an internal register that keeps your reasoning for the systems you left out. Your answers stay in your browser. Nothing is stored unless you choose to email the draft to yourself.
Where certification fits
The disclosure tells people what your systems decide. Responsible AI certification shows them how you govern those systems: accountability, fairness, human oversight and a way to contest a decision, assessed against the Australian AI Ethics Principles by an independent assessor. Every business that applies for certification answers the automated decision-making questions as part of its application, and its profile on the public register shows how it uses AI and how its decisions can be contested. Certification is not a determination of Privacy Act compliance, and Responsible AI Australia is neither a law firm nor a regulator. It is the evidence layer that sits beside the disclosure.
Sources
- OAIC, Automated Decision-Making Transparency Obligation (APP 1) Issues Paper, May 2026
- OAIC, Consultation on guidance for transparency in automated decision making
- OAIC, Rights and responsibilities: who the Privacy Act covers
- Privacy and Other Legislation Amendment Act 2024 (Cth)
- Hamilton Locke, Transparency in automated decision-making: what regulated entities need to know and do before December 2026, 4 June 2026
This article is general information, not legal advice. It restates the statutory text of Australian Privacy Principles 1.7 to 1.9 and the positions in the OAIC's May 2026 issues paper as they stood on 23 September 2026. Whether a particular system is caught is a judgement for your privacy adviser, and the OAIC's final guidance may add detail.
