Automated Decisions and Your Privacy Policy: The 10 December 2026 Deadline
10 October 2026 · Compliance365
From 10 December 2026, organisations covered by the Privacy Act must say in their privacy policy when they use computer programs to make, or substantially and directly inform, decisions that could significantly affect people. This came from the 2024 amendments and is already law.
The OAIC published its guidance on 30 September 2026. This post covers who is caught, what "computer program" means (it is wider than AI), and what to put in the policy.
What the law requires
The new provisions are APP 1.7 to 1.9. If you are an APP entity, your privacy policy must describe:
- the kinds of personal information used in computer programs that make or help make these decisions;
- the kinds of decisions made solely by a computer program; and
- the kinds of decisions a computer program substantially and directly assists a person to make.
It is a transparency duty. It does not create a new right to contest a decision, and it does not require you to notify each person individually. It does mean your public privacy policy has to be accurate about how you decide things.
Are you caught? The three questions
Commentary on the OAIC guidance breaks the test into three parts. You are caught when all three are true:
- A computer program you arranged makes the decision, or does something substantially and directly related to making it.
- The decision could reasonably be expected to significantly affect someone’s rights or interests.
- Personal information about that person is used in the program.
The OAIC reads “computer program” broadly. It covers pre-programmed rule-based processes, not only machine learning or generative AI. A spreadsheet formula that scores applications, or a workflow rule that rejects some automatically, can be in scope.
Where it shows up in ordinary businesses
Look for any point where software decides, ranks or filters people and the outcome matters to them. Common examples:
- Credit, payment terms or account approval based on an automated score.
- Recruitment screening, where a system filters or ranks applicants before a person looks.
- Eligibility or pricing decisions made by rules in a quoting or onboarding system.
- Fraud or risk flags that block a transaction or close an account.
- Health and services triage, such as a booking system that allocates urgent appointments from answers to a questionnaire.
A decision isn’t caught just because software is involved. A tool that only formats data, or a recommendation a person routinely overrides, may not “substantially and directly” inform the decision. Record your reasoning either way.
Who it applies to
It applies to APP entities: most Australian Government agencies, and organisations with annual turnover over $3 million. Some smaller organisations are covered regardless of turnover, including health service providers. If you are under the threshold and not otherwise covered, it doesn’t apply to you, though your larger customers may still ask.
What to do before 10 December
- Make an inventory of systems that make or inform decisions about people: HR, finance, onboarding, customer service, and any AI tools staff use. Note what personal information each one uses.
- Apply the three questions to each, and write down the outcome and why.
- Update your privacy policy with plain descriptions of the kinds of decisions and the kinds of information used. The OAIC expects specifics, not a generic line about “using technology”.
- Give the inventory an owner and review it when you add or change a system. A new AI feature in an existing product counts.
- Check your contracts with vendors whose systems make these decisions for you, so you know what the system actually does.
If you already keep an AI system inventory for ISO 42001, most of step 1 is done. See what a good AI inventory looks like. Our Privacy Act readiness guide covers the rest of the 2024 changes, and the ISO 42001 service covers AI governance more broadly.
Sources
- OAIC, New resources on transparency for use of AI and automated decision-making (30 September 2026)
- Allens, Mandatory automated decision-making disclosure requirements are coming
- Maddocks, OAIC releases guidance on new ADM transparency obligations under APP 1
- Bird & Bird, OAIC signals a broad reading ahead of December 2026
This is general information, not legal advice. Last reviewed 10 October 2026.
Found this useful? Get the ISO/Privacy/AI readiness checklists.
Browse resources