Preparing for Australia’s new automated decision-making (ADM) obligations for privacy policies.
On this page:
- New automated decision-making privacy policy requirements from 10 December 2026
- When do the ADM privacy policy obligations apply? (APP 1.7)
- What must privacy policies disclose? (APP 1.8)
- Automated decision-making: practical examples and grey areas
- Enforcement, penalties and timing
- How organisations can prepare before 10 December 2026
- Our cyber and information security experts
From 10 December 2026, APP entities will be required to review and update their privacy policies to disclose when automated tools are used to make decisions that significantly affect individuals. This change is introduced by new Australian Privacy Principles (APPs) 1.7, 1.8 and 1.9 and applies to decisions made on and after that date, even if the underlying systems or data were established earlier.
New automated decision-making privacy policy requirements from 10 December 2026
The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts APPs 1.7, 1.8 and 1.9 into the Privacy Act 1988 (Cth), commencing on 10 December 2026. The new automated decision-making (ADM) rules require APP entities to be transparent in their privacy policies about using computer programs to make, or substantially assist with, decisions that significantly affect individuals’ rights or interests. These provisions implement Proposals 19.1 and 19.2 of the Government’s Privacy Act Review Response (September 2023).
When do the ADM privacy policy obligations apply? (APP 1.7)
An APP entity’s privacy policy must include certain specified information if the following conditions are met:
- The entity has arranged for a computer program to make a decision, or to do something that is “substantially and directly related to making” a decision.
- The decision could reasonably be expected to significantly affect the rights or interests of an individual.
- Personal information about the individual is used in the operation of that computer program to make the decision or do the thing substantially and directly related to making the decision.
The term “computer program” takes its ordinary meaning and is intended to encompass a broad range of technologies, from pre-programmed rule-based processes to artificial intelligence and machine learning.
Importantly, the obligation captures not only fully automated decisions but also scenarios where a computer program recommends or guides a human decision-maker, provided the program’s role is both “substantially” (a key factor in the decision) and “directly” (a direct connection to the decision) related to that decision.
The Explanatory Memorandum provides the following examples:
- If Microsoft Excel is used to calculate a sum, this may be “directly related to” making a decision, but would not be “substantially related to” making a decision if it was only used for the purpose of adding numbers to arrive at a given sum.
- However, if Microsoft Excel is used to generate a score about an individual that is a key factor in a human decision-maker’s decision, this would be “substantially related to” making the decision.
A “decision” includes refusing or failing to make a decision. APP 1.9 provides non-exhaustive examples of decisions that may significantly affect rights or interests, including decisions under legislation to grant or refuse a benefit, decisions affecting contractual rights and decisions affecting access to a significant service or support.
What must privacy policies disclose? (APP 1.8)
If the conditions in APP 1.7 are satisfied, the entity’s privacy policy must set out:
- The kinds of personal information the computer program uses.
- The kinds of decisions made solely by the computer program.
- The kinds of decisions where the computer program does a thing that is substantially and directly related to making the decision (ie where the program recommends or assists, rather than decides alone).
Automated decision-making: practical examples and grey areas
- Risk-scoring platforms: Some organisations use a third‑party platform to generate a customer risk score from personal information. If a “high risk” outcome automatically delays or blocks access to a service until additional checks are completed, that tool is likely a key and direct factor in a decision that significantly affects the rights or interests of an individual under a contract, agreement or arrangement – bringing the arrangement within scope of the new privacy policy requirements. Where humans review the score before acting, the analysis will turn on whether the tool’s output is genuinely a key factor with a direct link to the outcome, rather than a minor input.
- Spreadsheet tools: By contrast, a simple spreadsheet that just calculates a person’s age from their date of birth would not, by itself, usually be “substantially and directly” related to making a decision. However, a spreadsheet‑based scoring or triage tool that ranks applications and determines which cases proceed (or sets the order of review) may be within scope because it plays a key and direct role in decisions that materially affect people.
Enforcement, penalties and timing
If required ADM information is missing from an entity’s privacy policy, the Australian Information Commissioner may take regulatory action under the Privacy Act. This includes an infringement notice under section 13K(1) – effectively an “on-the-spot” fine – with a maximum of 200 penalty units for an individual ($72,800) or 1,000 penalty units for a body corporate ($364,000), based on the current penalty unit of $364 (for offences committed on or after 1 July 2026).
How organisations can prepare before 10 December 2026
- Map where computer programs (including third-party platforms) use personal information to make, or materially contribute to, decisions that affect access to services, contractual rights or statutory benefits, and identify whether any decisions are made solely by the program or are substantially assisted.
- Update privacy policies to include clear descriptions of the kinds of personal information used and the kinds of decisions in each category (solely automated and substantially assisted), ahead of the 10 December 2026 commencement.
- Monitor OAIC guidance as it is finalised to ensure policy wording aligns with the regulator’s interpretation of “substantially” (a key factor) and “directly” (a direct connection to the decision).
- Where there is doubt about whether a particular use-case triggers the APP 1.7 requirements, err on the side of disclosure – more transparency is the object of the reform, and the cost of over-disclosure is far lower than the cost of an infringement notice.
This article provides general commentary only. It is not legal advice. Before acting on the basis of any material contained in this article, seek professional advice.
Our cyber and information security experts
Related Insights
Privacy Act prosecutions begin

Deep Dive into Privacy Act Reforms

Privacy Act Review Report proposes sweeping changes to privacy protections and extending privacy obligations to small businesses.

Privacy law in practice: Lessons from the OAIC’s latest data breach report

Time to review your data collection policies and practices?
