Automated decision-making privacy policy rules explained
From 10 December 2026, your privacy policy must explain any automated decision-making that affects people. Here is what to include.
If your business uses software to make decisions about people, or to help make them, your privacy policy has a new job. On 30 September 2026 the Office of the Australian Information Commissioner (OAIC) published resources to help businesses get ready for the new automated decision-making rules for privacy policies, which start on 10 December 2026.
In short: if the Privacy Act 1988 (Cth) covers your business, and you use a computer program to make, or substantially help make, decisions that could significantly affect someone's rights or interests using their personal information, your privacy policy must say so from 10 December 2026.
What is changing on 10 December 2026?
The change comes from the Privacy and Other Legislation Amendment Act 2024. It adds new requirements to APP 1, the Australian Privacy Principle about managing personal information openly and transparently. APP 1 is also where the existing list of what a privacy policy has to include lives.
The new parts are APP 1.7 and APP 1.8. APP 1.7 sets out when the rule applies to you. APP 1.8 sets out what you then have to add to your policy.
This is a transparency rule. It does not ban automated decisions or tell you how to run your software. It requires you to be upfront about it in your privacy policy.
When do the automated decision-making rules apply to you?
All three of these have to be true:
A computer program is involved in the decision. You have arranged for a program to make the decision, or to do something substantially and directly related to making it.
The decision matters. It could reasonably be expected to significantly affect a person's rights or interests.
Personal information is used. The program uses personal information about that person to make the decision, or to do the related thing.
Two things worth noticing in the wording. First, the law says "computer program", not "AI", so don't assume it only catches the newest tools. Second, it says you have "arranged for" a program to do this, so a tool you subscribe to may count just as much as one you built yourself.
If only one or two of the conditions apply, the new requirements are not triggered. Whether a particular decision is "significant" is the part most likely to depend on your circumstances.
What does your privacy policy need to say?
If all three conditions are met, APP 1.8 says your policy must describe:
The kinds of personal information used in the operation of those programs.
The kinds of decisions made solely by the program, with no person making the call.
The kinds of decisions where the program does something substantially and directly related to making the decision, such as scoring, sorting or recommending, with a person involved as well.
Notice the word "kinds" throughout. The law asks you to describe types of information and types of decisions, so plain language categories will usually do a better job for your customers than technical detail.
What has the OAIC released?
The OAIC has updated its APP 1 Guidelines and published three resources:
A fact sheet on the new transparency obligation, which is the best starting point for most businesses.
A flowchart that walks you through whether the obligation applies.
A supplementary fact sheet for government agencies, which most small businesses can skip.
The OAIC says the resources reflect feedback from 90 written submissions made during its consultation, from academia, civil society, government and industry.
How to get your privacy policy ready
1. List the tools that decide things about people
Think beyond anything labelled AI. Include booking, application, screening, approval, pricing and fraud tools, and anything that automatically accepts, declines, ranks or flags a customer, applicant or staff member.
2. Run each one through the OAIC flowchart
Use the APP 1.7-1.9 Transparency Obligation Flowchart to check each tool against the three conditions. Keep a note of your reasoning, including for tools you decide are out of scope.
3. Sort decisions into two groups
For the tools that are in scope, separate the decisions the program makes on its own from the ones where it helps a person decide. Your policy needs to cover both groups.
4. Update your privacy policy
Add a plain English section describing the kinds of personal information used and the kinds of decisions involved. Make sure it matches what you tell people at the point of collection, too.
5. Get it done before 10 December 2026
Then add it to your annual review, and revisit it whenever you add or change a tool that touches customer data. The OAIC is already checking privacy policies against APP 1, so this is not a section to leave for later.
Common questions
Does this only apply to AI tools?
No. The law refers to a "computer program", so it can cover simpler automated systems as well as AI. What matters is whether the three conditions are met, not what the software is called.
Does my business have to comply?
The obligation applies to APP entities, meaning businesses and agencies covered by the Privacy Act 1988 (Cth). Some small businesses are covered regardless of their size because of what they do, so check properly rather than assuming you are exempt.
What counts as a decision that significantly affects someone?
It depends on the decision and the person. The updated APP 1 Guidelines and the OAIC fact sheet are the place to start, and if you are unsure about a specific tool, get advice.
Do I have to explain how the software works?
APP 1.8 asks for the kinds of personal information and the kinds of decisions involved. If you are unsure how much detail your situation calls for, the OAIC guidance and a privacy adviser can help you judge it.
If your privacy policy needs a refresh anyway, Savira's privacy policy tools can help you keep it current as your systems change.
This is general information, not legal advice. Every business handles information a bit differently, so if you're not sure how this applies to yours, it's worth checking with a lawyer or privacy adviser.
Source: Office of the Australian Information Commissioner website – www.oaic.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. This summary is Savira's own and is not endorsed by the OAIC.

