Overview

From 10 December 2026, organisations covered by Australia's Privacy Act 1988 (Cth) will need to be more transparent if they use personal information in automated decision-making that could significantly affect a person’s rights or interests. This impacts both private sector organisations and Commonwealth government entities and we refer to them both as organisations in this article.

For many organisations, the real challenge will not be understanding the legal rule. It will be identifying where automated tools are already shaping important decisions, who owns those systems, and whether current privacy policy wording is still fit for purpose.

In practice, this is not just a privacy policy update. It is a governance and operational readiness exercise involving your legal, privacy, technology, operations and procurement teams.

An organisation that starts to prepare early will be in the better position to assess risk, prioritise high-impact use cases and update their privacy policies before the new requirements take effect.

Background

From 10 December 2026, organisation will need to say more in their privacy policies about how they use automated decision-making (ADM). The Privacy Act 1988 (Cth) was amended in late 2024 to add these obligations in new APPs 1.7, 1.8 and 1.9.

These additions sit inside APP 1, which already requires organisations to handle personal information openly and to tell people, in plain language, what they do with it.

New APPs 1.7 to 1.9 require a privacy policy to say more where an organisation has arranged for a computer program to use personal information in making, or assisting with making, an important decision about someone.

Think of it like this: if your organisation uses a digital system or other "sorting machine" to sort, score, flag or prioritise people in a way that can materially impact them, the privacy policy may need to say so.

What has changed

The new rules apply where an organisation uses software to help make, or substantially shape, an important decision about someone, using that person's personal information.

Where that is the case, the privacy policy needs to explain, in plain terms, the kinds of personal information the software uses and the kinds of decisions it makes or influences. It does not matter whether the outcome is good or bad for the person, or whether the system refuses to decide at all: the disclosure obligation can still apply.

In many cases, the harder issue will not be understanding the words of the legislation. It will be identifying which systems and workflows are actually caught.

The Office of the Australian Information Commissioner (OAIC) is developing more detailed guidance to be released in September 2026, but organisations should not wait for that before starting their internal review.

The new ADM obligations will apply to decisions made from 10 December 2026, even if the computer program or system was set up earlier or the personal information was collected earlier.

What does ADM mean in plain English?

If your organisation uses a computer program, which can range from spreadsheet formulae to a fully-automated AI model, to help make an important call about a person, and the computer program uses that person’s information in doing so, your privacy policy may need to explain that at a high level.

This does not mean you need to publish your source code or reveal trade secrets. It does mean that generic privacy policy wording such as, "we use your personal information to provide our services", is unlikely to be enough where automated tools are making or materially shaping significant decisions.

A useful business example is a loan application process: Personal information goes into a system, the system sorts, scores or flags the application, and that output helps determine whether the customer gets credit, better terms, extra checks or a rejection. If that process can significantly affect the person, the privacy policy should not leave it hidden in the background.

Other examples could include:

Why does this matter?

For business owners and senior leaders, it is a governance exercise that requires legal, privacy, technology, operations and procurement teams to understand how important decisions about people are really being made. The practical challenge is understanding your own systems well enough to answer that question with confidence.

The immediate risk for organisations is not simply that their privacy policy needs to be redrafted to comply with the new rule. The real risk for many organisations is that they do not yet have a clear internal map of which systems use personal information to drive significant decisions. Organisations need this clear mapping in order to update their privacy policy.

These systems may touch a wide range of functions: eligibility assessments, fraud or risk scoring, recruitment screening, customer verification, service prioritisation, insurance decisions, credit-related workflows, compliance triage, and access controls.

What should my organisation be doing to prepare for APP 1.7 to 1.9?

The late-2026 deadline may sound distant, but the real work is operational. Most organisations will spend more time identifying relevant systems, owners and decision pathways than rewriting the policy itself.

A simpler business question is this: where does a system help decide what happens to a person? If the answer involves personal information and a meaningful outcome, the use case should be reviewed.

Step 1: Build an ADM register: Is there a computer tool in the decision chain?

Create a list of systems, tools and workflows that use personal information to score, rank, filter, predict, recommend or decide. Include AI tools, rules engines, fraud systems, eligibility tools, workflow automation, and vendor platforms.

If staff use a computer program only as a passive filing cabinet, the new ADM rules may not be engaged. But if a computer program ranks, scores, filters, predicts, recommends, flags or automatically determines an outcome, that is much closer to the target area.

For each use case, identify:

This often reveals that the real issue is not a fully automated final decision, but a system that performs the crucial step just before the final human sign-off.

If third-party programs help make significant decisions, ask your vendors now:

Step 2: Triage for significance: Is personal information part of the input?

Separate low-risk automation from high-impact decision-making. Focus first on decisions that may affect legal rights, contractual rights, access to services, benefits, employment opportunities, investigations, or other material outcomes.

If the computer program uses information about an identifiable person (such as name, contact details, behaviour, location, financial details, health information, employment history, biometrics or account activity) this element may be met.

Step 3: Is the tool making the decision, or doing something directly tied to it?

The ADM rules are not limited to a fully automated, "computer says no" decision or outcome. They also apply where a computer program performs the key sorting, scoring or recommendation step that drives the result, even if there is a human sign-off at the end.

Step 4: Could the decision significantly affect the person’s rights or interests?

This is the key filter: Not every automated process matters. The focus is on decisions with real-world consequences.

A low-stakes personalisation tool is less likely to matter. A system that affects access to finance, employment, insurance, services, benefits or investigation outcomes is much more likely to matter.

The OAIC’s current examples include decisions about benefits under legislation, contractual rights, and access to significant services or support. These point to a broad and practical concept of the impact on a person's rights or interests.

Step 5: If yes, does your privacy policy clearly explain the relevant categories?

If the answer to the earlier questions is yes, your organisation should review its privacy policy to ensure it describes the kinds of personal information used and the kinds of covered decisions. If your privacy policy is silent, generic or outdated, there is work to do before the ADM rules start.

Most current privacy policies were not written with automated decision-making transparency in mind. Review whether your policy currently says enough about:

A good test is whether a customer, employee, citizen or applicant can read the policy and understand that an important decision about them may involve an automated tool.

Step 6. Strengthen governance between legal, privacy, data and technology teams

These new ADM transparency obligations sit across silos. Legal teams often own the privacy policy, but technology and operations teams know how the systems actually work. Procurement teams may also hold key information where the relevant tool is supplied by a vendor. Someone needs to join those dots and own the uplift process.

Step 7. Prepare for future OAIC guidance

The OAIC is expected to provide more detail about the ADM rules in September 2026, but organisations should build their framework now so it can be refined when that further guidance lands.

What counts as a significant effect?

A useful test is to ask: could this decision meaningfully change what the person can get, do, keep, access or avoid?  

Examples likely to attract attention include decisions about:

By contrast, low-stakes personalisation or routine back-end optimisation may be lower-risk, although each use case still needs to be assessed.

Further information

For further information on how these changes may affect your organisation, and how you can prepare for the ADM changes, please contact our expert Data and Privacy team.

For Commonwealth government agencies, the ADM changes are in addition to AI transparency obligations that already apply under the Policy for the responsible use of AI in government.

This article was prepared by Partners Steven Hunwicks and Mathew Baldwin. Steven is a specialist cybersecurity, data privacy and technology lawyer at Thomsons.  Mathew is a technology and privacy specialist in our Australian Government team.