On this page
The short version
- 01From 10 December 2026, APP entities must explain in their privacy policy when personal information is used in automated decisions that could significantly affect people.
- 02It isn’t only about AI: rules-based software that makes, or substantially shapes, a decision can count.
- 03Start with an inventory of where software approves, rejects, scores or prioritises people — then update the policy.
The Privacy and Other Legislation Amendment Act 2024 brought in a new transparency obligation about automated decision-making. It starts on 10 December 2026 — and with AI features now built into so much business software, more organisations are affected than they might expect.
What the new rule requires#
If your business is covered by the Privacy Act, your privacy policy will need to address automated decision-making when three things are true:
- 01A computer program makes a decision, or does something substantially and directly related to making it.
- 02The decision could significantly affect an individual’s rights or interests.
- 03Personal information is used in the process.
Where that applies, the policy must describe the kinds of personal information used and the kinds of decisions made using automated decision-making.
Who it applies to#
The obligation applies to APP entities — organisations covered by the Australian Privacy Principles. That generally includes businesses with annual turnover above $3 million, along with some smaller businesses such as private health service providers.
What might count#
The rule isn’t limited to AI, and commentators expect the OAIC to read it broadly. Places worth checking in a typical business:
- Recruitment tools that automatically screen or rank job applicants.
- Credit, payment or account approvals decided or scored by software.
- Pricing or eligibility that changes based on a customer’s personal information.
- Fraud or risk flags that block a transaction or suspend an account.
- AI assistants recommending outcomes that staff routinely accept.
How to prepare before December#
- 01Map your decisions. List every place software approves, rejects, scores, ranks or prioritises people — customers, applicants and staff.
- 02Check your tools. Many business apps now include AI features switched on by default. Find out what they do with personal information.
- 03Assess significance. Note which decisions could meaningfully affect someone’s rights or interests.
- 04Update your privacy policy to describe the kinds of personal information and decisions involved, in plain language.
- 05Keep it current. Add a privacy check to how you adopt new software, so the policy doesn’t drift.
The OAIC consulted on guidance for the new obligation earlier this year, so watch for its final guidance before December.
If you’re not sure what your systems do with personal information, that’s a technology question as much as a legal one. We help clients audit their software and automations so the answers are clear — and your lawyer can write the policy with confidence.
Common questions
When do the automated decision-making privacy rules start?
10 December 2026. They were introduced by the Privacy and Other Legislation Amendment Act 2024.
Does the automated decision-making obligation only apply to AI?
No. It applies to computer programs that make, or do something substantially and directly related to making, decisions that could significantly affect individuals — whether or not the program uses AI.
What must a privacy policy say about automated decision-making?
It must describe the kinds of personal information used in automated decisions, and the kinds of decisions made using automated decision-making.
Sources
- 01OAIC — Consultation on guidance for transparency in automated decision-making
- 02OAIC — Chapter 1: APP 1 Open and transparent management of personal information
- 03White & Case — Australian Privacy Update: automated decision making transparency requirement
- 04Bird & Bird — Australia’s new ADM transparency obligation






