Act now
Regulatory alert
From 10 December 2026, your privacy policy has to disclose automated decisions
An amendment to Australian Privacy Principle 1 commences on 10 December 2026. If a computer program uses personal information to make a decision that could significantly affect someone's rights or interests, your privacy policy has to say so. It is a disclosure obligation, not a ban, and it reaches ordinary businesses rather than only AI companies.
Published . Next review .
- Commences
- 10 December 2026
- Instrument
- APP 1 amendment, Privacy and Other Legislation Amendment Act 2024
- Obligation
- Disclose in your privacy policy, not seek consent
- Regulator guidance
- OAIC intends to publish before commencement
What actually changes
From the commencement date, an APP entity has to include information in its privacy policy where it has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual's rights or interests. Two things have to be described: the kinds of personal information used, and the kinds of decisions made that way.
Note the shape of it. This is a transparency obligation sitting inside APP 1, the principle about open and transparent management of personal information. It does not ask you to stop making automated decisions, it does not require consent, and it does not require you to explain any individual decision. It requires you to write down, in advance and in public, that you make them and roughly what they are.
Why this reaches more businesses than it sounds like
The phrase people anchor on is "automated decision-making", and they picture a model deciding a loan. The trigger is broader: a computer program, using personal information, producing a decision that could significantly affect someone's rights or interests. Nothing in that requires machine learning.
So the rule can catch a rules engine that screens job applicants, a scoring step that routes a customer to a collections queue, an eligibility check that approves or refuses a service, or an automated risk flag that changes how someone is treated. Plenty of businesses running none of what they would call AI are running at least one of those, often inside a system somebody configured years ago.
The other trap is partial automation. A decision does not stop being automated because a person signs it off at the end. If the program is producing the decision and the human is confirming it, that is the case the obligation is aimed at, and it is the case worth getting advice on rather than assuming your way out of.
What to do between now and then
- Inventory the automated decisionsWalk each process and list every place a program produces an outcome about a person: eligibility, scoring, routing, screening, pricing, flagging. Include the ones nobody calls AI. This is the slow part and it is the input to everything else.
- Record what personal information each one usesThe disclosure has two halves and this is the half most inventories forget. For each decision, note the kinds of personal information that feed it.
- Mark the ones that could significantly affect someoneRights or interests: access to a service, money, employment, credit, a benefit, how someone is treated. Flag the borderline ones rather than resolving them now, and revisit when the OAIC guidance lands.
- Draft the privacy policy wordingKinds of information, kinds of decisions. Write it in the plain terms a customer would use, not in the names of your internal systems.
- Decide who owns it after DecemberAutomated decisions get added to systems all the time. Whoever owns the privacy policy needs to hear about it when that happens, or the policy is accurate once and stale by March.
What is still unsettled
The hard edge is "significantly affect", which is doing most of the work in the test and is not defined to a threshold anyone can apply mechanically. The OAIC ran a consultation on guidance for this obligation and has said it intends to publish before the commencement date. Until that lands, a business with borderline cases is reading the same words a regulator has not yet worked an example against.
The practical read: the inventory is worth doing now regardless, because it is the input to every version of the guidance and it is the part that takes weeks rather than days. Deciding which of those systems clears the threshold is the part worth waiting for guidance on.
Where this touches what we build
DevPro builds AI workflow systems and agents that act inside real business processes, so this obligation lands on the kind of system we deliver. It is one of the reasons the work is built the way it is: named approval checkpoints rather than silent automation, and recorded outcomes rather than a decision nobody can reconstruct.
One build on this site was designed entirely around a client's version of that requirement: access that is requested with a reason, approved by an owner, expires on a clock and is reportable. A system that can already answer who decided what, and on what basis, is most of the way to answering a regulator.
Common questions
- Does this apply to a small business?
- It applies to APP entities. Most small businesses with turnover under the threshold are exempt from the Privacy Act, but that exemption has exceptions, and separate reforms are drawing more businesses into coverage. Check whether you are an APP entity first, because that question decides the rest.
- Do we need consent to make automated decisions?
- No. This obligation is about what your privacy policy says, not about obtaining permission. Other parts of the Privacy Act still govern how you collect and use the personal information itself.
- A human approves every decision. Are we out?
- Not automatically. If the program produces the decision and the person confirms it, that is the situation the obligation is aimed at. Where the human is genuinely making the decision, with the program only providing information, the position is different. That distinction is worth getting properly advised on rather than assumed.
- What happens if we do nothing?
- The obligation sits in APP 1, so a failure to include the required information is a privacy policy that does not comply with APP 1. The cheapest response available is also the most useful one: write down where you use automated decisions, which is work you need done under any version of the guidance.
The OAIC said it intends to publish its guidance before commencement. Re-check this alert when that lands, because the guidance is what will settle the edge cases below.
Sources
This is general information about a rule that applies in Australia, written for people who build and run systems. It is not legal advice, and DevPro is not a law firm. Where the answer turns on your own circumstances, get advice from someone qualified to give it.
Talk to us about your own systems