Does Your Privacy Policy Need an Automated Decision-Making Statement by December 2026?
Last updated 19 August 2026 · 6 min read
Direct Answer
Yes, if your business is an APP entity and uses a computer program — including an AI tool, a scoring model, or a rules-based system — to make or substantially assist a decision that could reasonably be expected to significantly affect an individual's rights or interests. From 10 December 2026, new Australian Privacy Principle 1.7 and 1.8 require your privacy policy to state the kinds of personal information used in that automated decision-making and the kinds of decisions made using it. The obligation comes from the Privacy and Other Legislation Amendment Act 2024, which amended the Privacy Act 1988, and applies only to decisions with a real, significant effect — hiring, credit, pricing, insurance, or service eligibility — not routine internal drafting or low-stakes automation. If none of your automated systems meet that significance threshold, no statement is required; if any do, the statement must be added before the commencement date.
Detailed Explanation
Most Australian privacy discussion around AI has focused on what a business is allowed to feed into an AI tool. This requirement is about the opposite direction: what a business has to tell people about decisions an automated system makes, or materially helps make, about them.
The Privacy and Other Legislation Amendment Act 2024 inserted new transparency provisions into Australian Privacy Principle 1 — commonly referred to as APP 1.7 and 1.8 — which commence on 10 December 2026, 24 months after the amending Act received Royal Assent. From that date, an APP entity that arranges for a computer program to make, or substantially assist in making, a decision that could reasonably be expected to significantly affect an individual's rights or interests must say so in its privacy policy: specifically, the kinds of personal information used in that decision-making, and the kinds of decisions made using it.
This is a disclosure obligation, not a new right to object or a mandatory human-review requirement. Unlike the EU's GDPR, which gives individuals a right to contest a fully automated decision and, in some cases, demand human intervention, the Australian version only requires the privacy policy to name the practice — it doesn't require you to change how the decision is made, or offer an opt-out. That makes it a lower-friction compliance step than it might sound, but a real one: a privacy policy that's silent on automated decision-making, once your business is actually using it for a qualifying decision, will be non-compliant from the commencement date.
The definition is deliberately broad on the technology side and deliberately narrow on the impact side. It is not limited to AI or machine-learning systems — a rules-based scoring spreadsheet or an eligibility-checklist engine can trigger it just as easily as a trained model, because the trigger is what the decision affects, not how the program works. But it only applies where the decision could reasonably be expected to significantly affect someone's rights or interests — hiring, credit, insurance, pricing, or service eligibility are the clear cases; day-to-day operational automation with no real effect on a specific person generally isn't.
What the Privacy Policy Statement Needs to Cover
Once a business determines it has a qualifying automated decision-making process, the privacy policy needs to state, at minimum:
- The kinds of personal information used in the automated decision-making — not necessarily a field-by-field list, but a genuine description of the categories involved (application details, transaction history, behavioural data, and so on).
- The kinds of decisions made using it — described specifically enough that a reader understands what's actually being decided (loan approval, job-application screening, pricing eligibility), not a vague reference to "automated processes."
The OAIC was still consulting on detailed guidance for exactly how much specificity this requires, with an Issues Paper open for submissions and final guidance expected before the December 2026 commencement date. Until that guidance lands, the safest approach is to describe the process the way you'd want it explained to you if it were being used to assess you — specific enough to be meaningful, without needing to reveal proprietary scoring logic or trade-secret detail.
Does Your Business Actually Need One?
Work through this in order:
- Confirm you're an APP entity. Most businesses with turnover over $3 million are; some smaller businesses are too, depending on what they handle (health information, credit reporting, and a few other categories). If your business sits outside the APPs entirely under the existing small-business exemption, this amendment doesn't change that.
- Inventory where a computer program makes or substantially assists a decision about a specific person. This includes AI tools, but also older rules-based systems that predate any "AI" branding — a lead-scoring formula, an automated eligibility check, a fraud-flagging rule set.
- Filter for genuine significance. Only decisions that could reasonably be expected to significantly affect someone's rights or interests trigger the requirement — see how do you reduce bias and discrimination risk in AI-automated decisions about people for the adjacent question of which processes carry the highest scrutiny generally; the same list (hiring, credit, insurance, pricing) is the practical starting point here too.
- Draft the statement and add it to your privacy policy before 10 December 2026. This sits alongside, not instead of, your existing Privacy Act obligations — see does GDPR apply to a business using AI tools if you also have EU exposure, since GDPR's Article 22 automated-decision-making right is a separate and stricter requirement layered on top for that audience.
Things to Consider
- This is additive to your existing privacy policy, not a replacement for it. The ADM statement is a new required section, not a reason to rewrite the whole document.
- The OAIC has flagged privacy policies in general — and AI-related disclosures specifically — as an active enforcement focus. Treat the December 2026 date as a hard deadline to have addressed, not a soft target, given the regulator's stated interest in checking privacy policies for exactly this kind of gap.
- A rules-based tool doesn't get a pass because it "isn't really AI." The obligation is written around what the decision affects, not the underlying technology — a legacy scoring spreadsheet used for something like a credit decision is squarely in scope.
- Guidance is still being finalised. The specificity expected in the "kinds of personal information" and "kinds of decisions" language was still under OAIC consultation as this page was written — verify current guidance before finalising wording, and treat this page as a starting framework rather than a template to copy verbatim.
Common Mistakes
- Assuming this only applies to AI tools. The trigger is the decision's effect on a person, not whether machine learning is involved — rules-based systems making significant decisions are equally in scope.
- Waiting until close to December 2026 to check. Confirming whether your business has any qualifying automated decision-making process, and drafting an accurate statement, is a task worth starting well before the deadline — especially given the OAIC's guidance on the significance threshold was still being finalised at the time of writing.
- Writing a vague, catch-all statement instead of an accurate one. A generic line like "we may use automated systems" without naming the actual kinds of information and decisions involved is unlikely to satisfy the requirement once OAIC guidance clarifies the expected level of detail.
- Treating this as a substitute for reviewing whether the automated decision is fair. Disclosure and fairness are separate questions — see how do you reduce bias and discrimination risk in AI-automated decisions about people for the substantive review this statement doesn't replace.
Frequently Asked Questions
- Does this apply to a small business under the $3 million turnover threshold?
- Only if your business is already an APP entity despite being under that threshold — for example, because it provides a health service, trades in personal information, or is otherwise specifically covered. The small-business exemption in the Privacy Act hasn't been removed by this amendment; if your business already falls outside the APPs entirely, the new ADM transparency requirement doesn't create a new obligation for you. If you're unsure whether you're an APP entity, that's the question to resolve first, not the ADM statement itself.
- Does a rules-based tool count, or only AI?
- The requirement is written broadly around "a computer program" making or substantially assisting a decision, not specifically around AI. A rules-based eligibility checklist, a credit-scoring spreadsheet formula, or a lead-routing rule engine can all trigger it if the decision it supports meets the significant-effect threshold — the mechanism doesn't have to be a trained model.
- What counts as 'significantly affecting' someone's rights or interests?
- The OAIC's guidance on this threshold was still under consultation as this page was written, with final guidance expected before the December 2026 commencement date. As a working guide, decisions about hiring, credit or lending, insurance, pricing that varies by individual, or eligibility for a service are the clearest examples; routine, low-stakes automation — spam filtering, scheduling, general customer segmentation — is unlikely to qualify. Check current OAIC guidance before finalising your own policy wording, since this line is exactly what the regulator is still clarifying.
References
Related Questions
Does GDPR Apply to a Business Using AI Tools (and What Do You Actually Need to Do)?
For an Australian business, the Privacy Act 1988 and Privacy Principles are the primary law for AI tools; GDPR only adds duties if you handle EU personal data.
How Do You Automate Handling Privacy Act Access and Correction Requests?
Automating APP 12 access and APP 13 correction requests under the Privacy Act 1988: intake, identity checks, the 30-day clock, and what to log.
How Do You Reduce Bias and Discrimination Risk in AI-Automated Decisions About People?
Bias in AI-automated decisions usually comes from training data or criteria, not the automation itself — here's how to define fair criteria.
Do You Have to Tell Customers They're Talking to an AI Chatbot, Not a Human?
Often yes for an Australian business: Consumer Law and new Privacy Act duties push toward disclosure, and the EU AI Act adds a duty with EU customers.
How Do You Automate Consent Management for Marketing and Data Collection?
Automating consent capture, preference centres, and withdrawal for marketing and data collection under Australia's Privacy Act and Spam Act rules.
Do Accountants and Bookkeepers Need an AML/CTF Program Under Tranche 2?
Accountants and bookkeepers providing certain designated services are AUSTRAC reporting entities under Tranche 2 — routine tax work alone is not captured.