Ledger IT

Automated decisions and your privacy policy: what changes on 10 December 2026

From 10 December 2026, organisations covered by the Privacy Act must explain automated decision-making in their privacy policies. What counts, and how to prepare.

Published
Reading time
3 minutes
Written by
The Ledger IT team
Two people working at computers in a technology office
On this page
  1. What the new rule requires
  2. Who it applies to
  3. What might count
  4. How to prepare before December
  5. Common questions
  6. Sources

The short version

  1. 01From 10 December 2026, APP entities must explain in their privacy policy when personal information is used in automated decisions that could significantly affect people.
  2. 02It isn’t only about AI: rules-based software that makes, or substantially shapes, a decision can count.
  3. 03Start with an inventory of where software approves, rejects, scores or prioritises people — then update the policy.

The Privacy and Other Legislation Amendment Act 2024 brought in a new transparency obligation about automated decision-making. It starts on 10 December 2026 — and with AI features now built into so much business software, more organisations are affected than they might expect.

What the new rule requires#

If your business is covered by the Privacy Act, your privacy policy will need to address automated decision-making when three things are true:

  1. 01A computer program makes a decision, or does something substantially and directly related to making it.
  2. 02The decision could significantly affect an individual’s rights or interests.
  3. 03Personal information is used in the process.

Where that applies, the policy must describe the kinds of personal information used and the kinds of decisions made using automated decision-making.

Who it applies to#

The obligation applies to APP entities — organisations covered by the Australian Privacy Principles. That generally includes businesses with annual turnover above $3 million, along with some smaller businesses such as private health service providers.

What might count#

The rule isn’t limited to AI, and commentators expect the OAIC to read it broadly. Places worth checking in a typical business:

  • Recruitment tools that automatically screen or rank job applicants.
  • Credit, payment or account approvals decided or scored by software.
  • Pricing or eligibility that changes based on a customer’s personal information.
  • Fraud or risk flags that block a transaction or suspend an account.
  • AI assistants recommending outcomes that staff routinely accept.

How to prepare before December#

  1. 01Map your decisions. List every place software approves, rejects, scores, ranks or prioritises people — customers, applicants and staff.
  2. 02Check your tools. Many business apps now include AI features switched on by default. Find out what they do with personal information.
  3. 03Assess significance. Note which decisions could meaningfully affect someone’s rights or interests.
  4. 04Update your privacy policy to describe the kinds of personal information and decisions involved, in plain language.
  5. 05Keep it current. Add a privacy check to how you adopt new software, so the policy doesn’t drift.

The OAIC consulted on guidance for the new obligation earlier this year, so watch for its final guidance before December.

If you’re not sure what your systems do with personal information, that’s a technology question as much as a legal one. We help clients audit their software and automations so the answers are clear — and your lawyer can write the policy with confidence.

Common questions

When do the automated decision-making privacy rules start?

10 December 2026. They were introduced by the Privacy and Other Legislation Amendment Act 2024.

Does the automated decision-making obligation only apply to AI?

No. It applies to computer programs that make, or do something substantially and directly related to making, decisions that could significantly affect individuals — whether or not the program uses AI.

What must a privacy policy say about automated decision-making?

It must describe the kinds of personal information used in automated decisions, and the kinds of decisions made using automated decision-making.

Sources

  1. 01OAIC — Consultation on guidance for transparency in automated decision-making
  2. 02OAIC — Chapter 1: APP 1 Open and transparent management of personal information
  3. 03White & Case — Australian Privacy Update: automated decision making transparency requirement
  4. 04Bird & Bird — Australia’s new ADM transparency obligation

Written by the Ledger IT team

The same Melbourne engineers who answer our support line and look after client environments day to day. About us

Share

Keep reading

All insights

Free discovery and quote

No cost, no obligation; we’ll tell you what you need before we tell you what it costs.