On 10 December 2026, a new transparency rule in the Privacy Act 1988 starts to apply. Organisations bound by the Australian Privacy Principles (APP entities) will have to say in their privacy policies when a computer program uses personal information to make, or substantially help make, a decision that could significantly affect an individual. The policy must describe the kinds of personal information involved and the kinds of decisions.
The rule is not limited to sophisticated AI. The OAIC has said the term "computer program" is intended to be read broadly, and that it covers pre-programmed rule-based processes as well as AI and machine learning. Many organisations already run tools that meet the test without anyone having labelled them as automated decision-making. With about ten weeks to go, the practical work is finding them.
What the law says
The obligation was inserted into Schedule 1 of the Privacy Act by Part 15 of Schedule 1 to the Privacy and Other Legislation Amendment Act 2024. It appears as APP 1.7 to 1.9. Under the Act's commencement table, the Part starts the day after the end of the 24 months that began on the day the Act received Royal Assent, which is 10 December 2026.
APP 1.7 requires an APP entity's privacy policy to contain the information described in APP 1.8 if three conditions are met:
- the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision;
- the decision could reasonably be expected to significantly affect the rights or interests of an individual; and
- personal information about the individual is used in the operation of the computer program to make the decision or do that related thing.
APP 1.8 then lists what the policy must say: the kinds of personal information used in the operation of such programs, the kinds of such decisions made solely by the programs, and the kinds of such decisions for which a substantially and directly related thing is done by the programs.
APP 1.9 adds interpretive detail. Making a decision includes refusing or failing to make one. A decision can affect a person's rights or interests whether the effect is adverse or beneficial. The provision also gives three examples of decisions that may affect rights or interests: a decision under an Act or legislative instrument to grant or refuse a benefit, a decision that affects the individual's rights under a contract, agreement or arrangement, and a decision that affects the individual's access to a significant service or support.
What this rule does and does not do
It is a disclosure obligation. It does not ban automated decision-making, require a human to review each decision, or create a right to contest an outcome. The OAIC's issues paper says as much: the obligation gives no right to contestability or to request information, and no obligation to notify, and it only requires information to be provided in the privacy policy.
That does not make it trivial. A privacy policy that omits a covered use, or describes it inaccurately, is a compliance gap that a complainant, journalist or regulator can point to. The policy also has to remain accurate after 10 December, which means someone must own it.
The rule sits inside the existing Privacy Act coverage. The OAIC describes its remit as Australian Government agencies and organisations with an annual turnover of more than $3 million, plus some other organisations. A small business that is genuinely outside the Act stays outside it, but that conclusion should be tested rather than assumed, because the Act also reaches some other organisations. Confirm the position for your entity.
Where the scope questions are still open
Three phrases in APP 1.7 do most of the work, and the OAIC has been consulting on all three.
"Computer program"
The OAIC's issues paper quotes the Explanatory Memorandum, which says the term takes its ordinary meaning and covers "pre-programmed rule-based processes, artificial intelligence and machine learning processes". The paper adds that generative AI tools, including chatbots, fall within it, and that commonly used software can too.
"Substantially and directly related to making a decision"
This wording brings in tools that recommend or guide a human decision-maker, not only tools that decide alone. The Explanatory Memorandum, as quoted by the OAIC, says "substantially" means the thing is a key factor in facilitating the human's decision, and "directly" means it has a direct connection to the decision. The OAIC's illustration is a spreadsheet formula that scores and triages callers to a crisis hotline. If that score is a key factor in the order in which a human attends calls, it is covered. A formula used only to turn a date of birth into an age is not substantially related, even if it is directly related.
The practical reading is that a human in the loop does not remove a tool from scope. If staff routinely follow the tool's score, ranking or recommendation, it is a candidate for disclosure.
"Significantly affect the rights or interests"
The OAIC's issues paper, drawing on the Explanatory Memorandum, gives the APP 1.9 examples and adds granting admission to a country or entitlement to a housing benefit, a contract for a life insurance policy, and access to healthcare services. It also says that using computer programs to target people with content and advertisements may have a significant effect if, for example, it results in differential pricing for significant goods or services, or limits access to employment opportunities. The paper says the effects must be more than trivial, and that the same decision may weigh more heavily on a child or a person experiencing vulnerability.
Where the line sits for something like a modest price difference is one of the questions the OAIC put to stakeholders. Treat borderline cases as needing a documented judgement, not a quick dismissal.
Where OAIC guidance stands
The OAIC published an issues paper on 18 May 2026, and submissions closed on 15 June 2026. The paper said the OAIC intends to release guidance by September 2026. When this article was prepared, the OAIC's APP 1 guidelines page still said detailed guidance on the new automated decision provisions would be published in 2026, and final guidance had not yet appeared. Check the OAIC website before you finalise your wording, because the guidance may settle several of the questions above.
One point in the issues paper is worth planning around now. On the phrase "arranged for", the OAIC says entities must consider whether they arranged for a computer program to make or assist a decision, or simply operate it. Its examples of arranging include procuring another entity's AI system to screen and rank job applications, allowing employees to use an AI chat tool to draft performance assessments that determine promotion decisions, and contracting a software company to approve or decline refunds automatically. The paper also says entities should keep oversight of how third-party products use automated decision-making. These are the OAIC's consultation positions, not final guidance, but they show the direction of travel.
A ten-week readiness plan
Weeks 1 to 2: inventory automated decisions
Start with decisions, not technology. Ask each business unit where a system scores, ranks, approves, declines, flags, prices, routes or recommends something about a person. Ask the same question of IT and procurement, because business units often adopt tools without telling either. Include rules-based workflows, scoring spreadsheets and case management escalation rules alongside anything marketed as AI.
Areas that usually surface results include recruitment screening, credit and lending, insurance underwriting and claims, dynamic or personalised pricing, eligibility and entitlement checks, fraud and transaction flags, and customer service triage.
Weeks 3 to 4: filter for personal information and significance
For each item, record three things: whether personal information about an individual is used, what the decision is, and what could reasonably happen to the person as a result. Apply the three APP 1.7 conditions in writing, and record the reasoning for tools you decide are out of scope. That record will matter if a regulator or a complainant asks later.
Weeks 4 to 6: map the data flows
APP 1.8 asks for the kinds of personal information used, so you need to know them. For each in-scope tool, list the categories of data it takes in, where they come from, and whether any are sensitive information. Note whether a decision is made solely by the program or whether the program supports a human who decides. APP 1.8 asks for those two groups separately.
Weeks 5 to 8: vendor and SaaS due diligence
Embedded features are the hardest part of the inventory. HR platforms, CRMs, contact centre software, fraud engines and productivity suites increasingly ship with scoring or recommendation features that are switched on by default or by a licence upgrade. Ask each vendor what automated features exist, what personal information they use, and what they produce. Add contract terms that require notice of new automated features, and keep the answers on file. If the OAIC's reading of "arranged for" holds, buying the tool and directing its use may be enough to bring it into your policy.
Weeks 7 to 9: update the APP 1 privacy policy
Draft the disclosure at the level the statute asks for: kinds of personal information, and kinds of decisions, split between those made solely by a program and those where a program does a substantially and directly related thing. The OAIC's issues paper says the disclosure should balance enough meaningful information for individuals to understand the use of automated decision-making against excessive detail that obscures the point. It also notes the Explanatory Memorandum excludes commercial-in-confidence information about these systems from the requirement. Plain language works better than a list of product names.
Weeks 9 to 10: put governance around it
The policy has to stay true after go-live. Assign an owner for the inventory. Add a check to procurement, change management and AI use approvals so that a new tool or a new feature triggers a privacy review before launch. Schedule a periodic review of the inventory, and align it with any wider AI governance work such as an AI policy or an AI management system. Privacy, legal, security, HR and operations each hold part of the picture, so the owner needs authority to ask all of them.
How this fits with broader AI regulation
Australia has not adopted a standalone AI Act. The National AI Plan, announced on 2 December 2025, says the government will build on existing legal and regulatory frameworks, and the IAPP reported that it relies on those frameworks and a new AI Safety Institute rather than the mandatory guardrails for high-risk settings that the government had been exploring. For most organisations, that leaves existing law such as the Privacy Act, consumer law and anti-discrimination law as the working rules for AI. APP 1.7 is one of the few AI-relevant obligations with a fixed start date.
Key takeaways
- From 10 December 2026, APP entities must disclose in their privacy policies the kinds of personal information and kinds of decisions involved in covered automated decision-making.
- The trigger is a decision that could reasonably be expected to significantly affect an individual's rights or interests, made or substantially and directly supported by a computer program using personal information.
- "Computer program" includes rule-based tools and spreadsheets as well as AI. A human in the loop does not take a tool out of scope if the tool is a key factor in the decision.
- The rule requires transparency only. It does not prohibit automated decision-making or create a right to contest a decision.
- Embedded AI features in vendor software may count if your organisation arranged for them to be used. Vendor due diligence is part of compliance.
- Final OAIC guidance had not been located when this article was prepared. Check the OAIC website before finalising policy wording.
- The Privacy Act's small business exemption still applies where it accurately covers you, but confirm it rather than assuming it. Seek legal advice on your organisation's specific obligations.
CyberCorp's GRC specialists help Australian organisations inventory automated decisions, assess them against APP 1.7 to 1.9, and build the governance that keeps privacy policies accurate. Schedule a GRC Assessment to start your readiness work, or learn more about our Compliance Assurance services.


