Savira - Making Compliance Easy
Blog post

Automated decision-making: what changes in December 2026

From 10 December 2026, Australian businesses using automated decision-making must say so in their privacy policy. Here is what to update and when.

Compliance updates6 min read

If software helps your business decide who gets a loan, a rental, a job interview, an insurance policy or access to a service, there is a new privacy policy rule with your name on it. It starts on 10 December 2026, and the Office of the Australian Information Commissioner (OAIC) has been consulting on how it will work in practice.

The short answer: automated decision-making is when a computer program makes a decision, or does something substantially and directly related to making one, using personal information. From 10 December 2026, organisations covered by the Privacy Act 1988 (Cth) must say in their privacy policy what personal information those programs use and what kinds of decisions they make.

What counts as automated decision-making?

Automated decision-making (ADM) is broader than most people expect. It is not just "AI". A scoring model, a rules-based eligibility check, a screening tool that filters applicants before a human sees them: all of it can count.

The rule bites when three things line up:

  • a computer program is involved in making the decision

  • personal information is used in how that program operates

  • the decision could reasonably be expected to significantly affect the rights or interests of an individual

That last one is the filter. Deciding which customers see which banner ad is not it. Deciding who gets finance, housing, employment, insurance or access to a significant service is.

Two details worth knowing. A "decision" includes refusing to make one, or failing to make one at all. And it does not matter whether the outcome helps or hurts the person, both are in scope.

Likely in scope:

  • Software that approves or declines a loan or payment plan

  • A tool that scores and rejects job applicants automatically

  • Automated tenancy or rental application screening

  • A system that sets insurance eligibility or premiums

  • Automated triage that decides access to a health service

Likely not in scope:

  • A spam filter sorting your inbox

  • Autocomplete in a support reply

  • Personalised product recommendations

  • Rostering staff who have already been hired

  • Sending a receipt after checkout

That second list is a guide, not a ruling. If a tool quietly shapes who gets something that matters, treat it as in scope until you have looked properly.

What does the privacy policy actually have to say?

From 10 December 2026, an APP entity's privacy policy has to set out:

  1. the kinds of personal information used in the operation of those computer programs

  2. the kinds of decisions made solely by the operation of those computer programs

  3. the kinds of decisions where the program does something substantially and directly related to making the decision

Point three is the one people miss. If a human signs off at the end but software did the scoring, ranking or filtering that shaped the outcome, it still needs to be disclosed. "A person clicks the button" is not an exit from this rule.

Note the wording is "kinds". You are describing categories, not publishing your model or your source code.

Does this apply to my small business?

Only if you are an APP entity. Most Australian businesses turning over $3 million or less a year are still outside the Privacy Act because of the small business exemption, so this rule would not apply to them.

But plenty of small businesses are covered anyway, including health service providers, businesses that buy or sell personal information, contracted service providers to the Australian Government, and businesses related to a larger covered entity. If you are not certain which side of the line you sit on, start with whether the Privacy Act covers your business, because that answer decides everything else.

Worth adding: the small business exemption has been under review for years. If it goes, this rule comes with it.

What is the OAIC consulting on?

In May 2026 the OAIC opened a consultation on guidance for the new ADM transparency requirements, published an issues paper, and asked for submissions by 15 June 2026. Submissions have now closed.

The tricky terms are exactly the ones you would expect: what a "computer program" is, what "substantially and directly related" covers, and what "significantly affect the rights or interests of an individual" actually means. The finished guidance is what will make those calls concrete, so it is worth watching for.

What to do before 10 December 2026

1. Write down where software makes or shapes decisions

Walk through your customer journey and your hiring process and list every point where a tool scores, ranks, filters, approves or declines. Include third-party tools, not just anything you built.

2. Mark the ones that matter to people

For each one, ask whether the outcome meaningfully affects someone's money, housing, job, health or access to a service. Those are your in-scope list.

3. Note what personal information goes in

For each in-scope tool, record the kinds of personal information it uses. This is also the raw material for your disclosure, so keep it in plain words.

4. Draft the privacy policy wording now

Add a short, honest section covering the three points above. Do not wait for December, because the same review usually turns up other gaps in your privacy policy worth fixing at the same time.

5. Watch for the final OAIC guidance

Definitions may tighten. Diarise a review once the guidance lands, and again before 10 December 2026.

FAQ

Does this ban automated decision-making?

No. It is a transparency rule, not a prohibition. You can keep using these tools, you just have to be upfront about the fact that you do and what they decide.

What if a human reviews every automated decision?

You may still need to disclose it. The rule covers programs that do things substantially and directly related to making a decision, which includes scoring or shortlisting that a person then signs off on.

Do we have to explain how the model works?

No. The requirement is to describe the kinds of personal information used and the kinds of decisions made, not to publish the logic behind them.

When exactly does this start?

10 December 2026. Your privacy policy needs to be updated by then, not started then.

This is general information, not legal advice. Every business handles information a bit differently, so if you're not sure how this applies to yours, it's worth checking with a lawyer or privacy adviser.

Source: Consultation on guidance for transparency in automated decision making, OAIC. If you want the privacy policy side handled without the guesswork, see how Savira keeps your consent and privacy basics in order.

Consultation on guidance for transparency in automated decision making

Published 18 May 2026

Source: Office of the Australian Information Commissioner website – www.oaic.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. This summary is Savira's own and is not endorsed by the OAIC.