Automated Decision-Making Transparency: The 10 December 2026 Privacy Act Deadline
There is a compliance deadline sitting in most Australian organisations' blind spot, and it lands on 10 December 2026.
From that date, if you use a computer program to make decisions about people, or to do something substantially and directly related to making those decisions, your privacy policy has to say so. Not in general terms. In specific terms, covering what information the program uses and what kinds of decisions it touches.
Most organisations we speak to assume this is an AI regulation, and therefore assume it does not apply to them because they have not deployed a large language model. That reading is wrong on both counts. The obligation is drafted around computer programs, not artificial intelligence, and the reach is much wider than the AI conversation would suggest.
Here is what the requirement actually says, who it catches, and what a defensible response looks like with about fifteen weeks to go.
Where the obligation comes from
The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024. It was tranche one of the long-running Privacy Act reform program, and most of its provisions commenced the following day.
The automated decision-making transparency requirement was deliberately held back. It inserts new Australian Privacy Principles 1.7, 1.8 and 1.9 into Schedule 1 of the Privacy Act 1988, and it commences two years after Assent, on 10 December 2026. The delay was designed to give organisations time to work out what their systems actually do.
That time is nearly up.
What the obligation requires
The trigger sits in APP 1.7. It applies where an APP entity has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that:
- involves the use of personal information about an individual, and
- could reasonably be expected to significantly affect the rights or interests of that individual.
- the kinds of personal information used in the operation of the computer programs
- the kinds of decisions made solely by the operation of those programs
- the kinds of decisions for which something substantially and directly related to making the decision is done by the operation of those programs
That distinction matters for scoping. It means the deliverable is a document. It also means the hard work is not the document, it is knowing what to put in it.
Why the scope is wider than people expect
Two drafting choices make this obligation broader than its European counterpart, and broader than most compliance teams assume.
First, it is not limited to solely automated decisions. Article 22 of the GDPR is built around decisions based solely on automated processing. APP 1.7 catches those, but it also catches decisions where a computer program does something "substantially and directly related to making the decision". A human being sitting at the end of the process with the authority to override does not take you outside the obligation if the software did the substantive work.
Think about a credit decisioning engine that produces a recommendation an assessor almost always accepts. Or a resume screening tool that determines which applications a recruiter ever sees. Or a fraud model that flags a transaction for review. In each case a person makes the final call, and in each case the program has done something substantially and directly related to making the decision.
Second, "computer program" is not "artificial intelligence". The provision does not say model, algorithm, or AI system. A deterministic rules engine written in 2009 is a computer program. A scoring spreadsheet with logic in it is arguably a computer program. If it uses personal information and it materially shapes a decision with real consequences, you are in scope.
The practical effect is that this obligation reaches insurers, lenders, employers, universities, government agencies, health providers, property managers, telcos, and any SaaS business making eligibility, pricing, access or entitlement decisions about individuals. That is a very large share of the Australian economy.
What counts as "significantly affect"
This is where the drafting gets genuinely uncertain, and where you will need to make a judgement call.
The Act does not define "could reasonably be expected to significantly affect the individual's rights or interests". The OAIC opened a consultation on guidance for this obligation on 18 May 2026, closing 15 June 2026, and the issues paper sought views on exactly this question. Commentary on the consultation suggests the regulator is signalling a broad reading. Final guidance has not been published, and no publication date has been announced.
That leaves you in the position of having to scope now against guidance that may arrive after you have decided.
Our advice is to work from consequence rather than technology. Ask what happens to the individual on the other side of the decision. Decisions that determine whether someone gets credit, a job, insurance cover, a tenancy, a government benefit, medical triage priority, or access to a service they rely on are squarely in the zone. Decisions that change which promotional banner someone sees are not.
Where you land in the middle, err towards disclosure. The cost of listing a decision category in your privacy policy that turns out not to have been required is close to zero. The cost of omitting one that was required is a transparency failure sitting in a public document, which is exactly the kind of thing a regulator finds quickly.
What to actually do between now and December
Fifteen weeks is enough time if you start with discovery rather than drafting.
Step 1: Build an inventory of decisioning systems.
This is the whole job. Most organisations do not have a list of every place software touches a decision about a person, and the list is usually longer than the executive team expects. Work through:- Customer-facing systems: onboarding, eligibility, pricing, credit, claims, fraud, collections, account restriction or closure
- Employment systems: applicant tracking and screening, rostering, performance scoring, access provisioning
- Third-party and embedded services: anything a vendor operates on your behalf that produces a decision or a score
- Anything with "engine", "score", "rules", "model" or "automation" in its name
Step 2: Classify against the APP 1.7 test.
For each system, decide whether the decision could reasonably be expected to significantly affect the individual's rights or interests, and whether the program makes the decision solely or does something substantially and directly related to making it. Record the reasoning. If your classification is challenged later, contemporaneous reasoning is worth far more than a conclusion.
Step 3: Do not forget the vendors.
The obligation attaches to the APP entity that arranged for the program, not to whoever wrote the code. If a supplier runs the scoring model, you still have to describe it. That means you need answers from them about what personal information the model uses. Some vendors will resist on commercial confidentiality grounds. Start those conversations now, because they take longer than you would like, and you may need contractual amendments.
Step 4: Draft the privacy policy update.
Write at the level of "kinds", which is what APP 1.8 asks for. You are not being asked to publish model weights or decision logic. You are being asked to describe categories of information and categories of decisions in terms an ordinary reader can follow.
Resist two temptations. The first is the catch-all sentence: "we may use automated systems in our decision-making processes" tells a reader nothing and does not meet the requirement. The second is over-disclosure into technical detail nobody can parse, which is a different way of failing the same transparency test.
Step 5: Wire it into your change process.
The reason this obligation will bite organisations in 2028 rather than 2026 is drift. Policies get written once and systems keep changing. Add a check to your change management and vendor onboarding processes so that any new decisioning capability triggers a privacy policy review. If you run an ISO 27001 or ISO 42001 management system, this belongs in your existing change control and supplier assessment procedures rather than in a standalone process nobody remembers.
How this sits alongside your other obligations
Three connections worth drawing.
The statutory tort is already live. The same 2024 Act created a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. It covers intrusion upon seclusion and misuse of information. An automated decision that mishandles personal information now carries direct litigation exposure independent of any regulatory action. Transparency is not the only reason to know what your systems do.
ISO 42001 does most of this work for you. If you have implemented an AI management system under ISO/IEC 42001, you should already hold an inventory of AI systems, an impact assessment for each, and defined accountability. Extending that inventory to cover non-AI decisioning programs is a much smaller job than building one from scratch. This is one of the clearest practical arguments for ISO 42001 that we have seen in the Australian market so far.
Australia's AI regulatory posture shifted in 2026. The mandatory AI guardrails proposal that dominated 2024 and 2025 commentary was not proceeded with in its original form, replaced by a lighter-touch approach and a new AI Safety Institute. A lot of the content still circulating assumes mandatory guardrails are coming. Be careful about planning against that assumption. In the meantime, the ADM transparency obligation is real, it is in force from December, and it applies whether or not your decisioning uses AI at all.
The other tranche one dates worth having on your radar
While you are in the Privacy Act, these are the adjacent items:- Statutory tort for serious invasions of privacy: commenced 10 June 2025
- Doxxing offences: commenced 11 December 2024
- Children's Online Privacy Code: the requirement commenced with the 2024 Act, and the OAIC released an exposure draft of the Code on 31 March 2026. It remains in consultation and is not yet finalised
- Small business exemption: still in force as at August 2026. Removal is flagged for tranche two, but no Bill has been introduced. Treat any specific removal date you read as speculation
The bottom line
This is a discovery problem dressed up as a documentation problem. The privacy policy wording will take an afternoon. Working out every place software shapes a decision about a person, including the systems your vendors run, is the part that takes fifteen weeks.
If you have not started, start with the inventory this month.
Want a hand with the inventory?
CyberNinja helps Australian and New Zealand organisations map automated decisioning, assess it against the new APP requirements, and build the governance to keep it current, including through ISO 42001 AI management systems. Get in touch if you would like to talk through your scope.
This article is general guidance, not legal advice, and reflects the position as at August 2026. The OAIC has not yet published final guidance on this obligation. Confirm your position against the current legislation and, where the stakes warrant it, with your legal advisers.
Sources
- Privacy and Other Legislation Amendment Act 2024 (Cth)
- Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principles
- OAIC: Consultation on guidance for transparency in automated decision-making
- OAIC: Statutory tort for serious invasions of privacy
- Bird & Bird: Australia's new ADM transparency obligation, OAIC signals a broad reading
- Johnson Winter Slattery: Practical implications of new transparency requirements for automated decision-making
Need Help With Your Security?
Our team of experts can guide you through implementation and certification. Start with a free assessment.
Start Free Assessment