Menu

Automated decision-making must appear in privacy policies from 10 December: OAIC guidance

Comingwave team · 6 minute read · published

Three team members in a bright meeting room study a wall screen showing an abstract flow of connected shapes.

Automated decision-making gets its own line in Australian privacy policies from 10 December 2026, and the privacy regulator has now explained what it expects. On 30 September 2026 the Office of the Australian Information Commissioner (OAIC) published a fact sheet, a flowchart and updated guidelines on the new transparency obligation. If your organisation is covered by the Privacy Act and uses software, including AI tools, to make or shape decisions that significantly affect people, your privacy policy will need to say so. The guidance reaches further than many businesses expect: a scoring formula in a spreadsheet can count.

This article is general information for business owners and managers, not legal advice.

What the OAIC published on 30 September 2026

The OAIC's statement, New resources on transparency for use of AI and automated decision-making, confirms the start date and lists the new material: a fact sheet on Australian Privacy Principles (APP) 1.7 to 1.9, a supplementary fact sheet for government agencies, a flowchart, and an update to the APP 1 Guidelines. The OAIC says the resources reflect feedback from 90 written submissions to its consultation.

The obligation itself is not new law this month. It was added to APP 1 by the Privacy and Other Legislation Amendment Act 2024 and takes effect on 10 December 2026.

When the obligation applies

Under APP 1.7, an APP entity must add information to its privacy policy when three things are all true:

  1. The entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision.
  2. The decision could reasonably be expected to significantly affect the rights or interests of an individual.
  3. Personal information about the individual is used in the operation of the program.

When they are, APP 1.8 requires the privacy policy to set out the kinds of personal information used by such programs, the kinds of decisions made solely by them, and the kinds of decisions where the program does something substantially and directly related to the decision.

"Computer program" is read broadly

The OAIC fact sheet says a computer program includes pre-programmed rule-based processes, artificial intelligence and machine learning, software, apps or word-processing tools, and generative AI, including chatbots. Its first worked example is a care provider using a spreadsheet formula to rank clients for appointments. The OAIC treats that as in scope.

Bought-in software still counts

"Arranged for" covers in-house software, procurement of a third-party program, configuring off-the-shelf software, and relying on advisory outputs. In the OAIC's example, an organisation that buys a software-as-a-service product to help allocate housing has arranged for the program, whether or not it can customise the decision settings.

A human in the loop does not automatically take you out

The fact sheet says a decision may be in scope even where the program's output does not replace the whole decision-making process or is subject to human review. The OAIC considers that machine learning or generative AI outputs used to make significant decisions would generally fall within the obligation unless subject to extensive human oversight and control. Its example involves managers using a generative AI tool to suggest staff bonuses: the recommendation is a key factor, so it is in scope even though a director signs off.

"Significantly affect" means more than trivial

The OAIC lists decisions it would generally consider in scope. Several are common in small and medium businesses:

  • recruitment software used to sort candidate profiles and make hiring decisions
  • reports created by AI used to rank employee performance or decide promotions, bonuses or pay
  • differential or personalised pricing by online retailers for significant goods
  • programs used to approve or reject a loan or credit application, or assess eligibility for insurance
  • programs that determine admission to an education or training program
  • facial recognition used in a retail store for watchlist matching

Is a small business covered?

The obligation applies to APP entities, meaning organisations and agencies covered by the Privacy Act. The OAIC's small business guidance says most small businesses with an annual turnover of $3 million or less are not covered, but some are regardless of turnover, including health service providers and businesses that trade in personal information.

So a medical or allied health practice of any size, and a recruitment agency or online retailer above the threshold, should assume the rule applies and work through the flowchart. If you are covered and unsure whether a particular tool is in scope, the OAIC's advice is to take a cautious approach and include the information.

Everyday toolTypical useLikely in scope?
Applicant tracking system with AI rankingShortlisting candidates for interviewYes: the OAIC names recruitment software
Generative AI assistantDrafting performance reviews that drive pay decisionsYes, unless human oversight is extensive
Spreadsheet scoring formulaRanking clients for priority serviceYes, where the service is significant to the person
E-commerce pricing plug-inDifferent prices by postcode or customer profileYes for significant goods
Website chatbotAnswering opening hours and delivery questionsUnlikely: no significant decision about a person
Email spam filterSorting incoming mailUnlikely: more than trivial impact is required

The last two rows are our reading of the OAIC's tests, not examples from the fact sheet.

What to do before 10 December

  1. Build an inventory. List every system that scores, ranks, filters, prices or recommends something about a person. Include AI features switched on inside software you already own, and spreadsheets.
  2. Run each one through the three conditions. Record the answer and the reasoning. The OAIC has published a flowchart to help with this step.
  3. Write down the personal information each program uses. Flag sensitive types such as health information or biometrics; the OAIC says these should be clear in the policy.
  4. Ask your vendors. The OAIC says providers of third-party software should give clear, high-level information about how their software can be used to make decisions. Ask what personal information the product uses and whether its output is a recommendation or a final decision.
  5. Update the privacy policy. Group similar decisions if that helps, but keep the description meaningful to a reasonable person. Avoid granular technical detail.
  6. Do not hide behind confidentiality. Commercial-in-confidence information and trade secrets are excluded, but the OAIC says information is not excluded merely because disclosure could bring embarrassment or criticism.
  7. Set a review date. New software features arrive through updates, so the inventory needs an owner.

The inventory is the hard part, because decision logic is usually scattered across a CRM, an HR system, an online store and a few spreadsheets. Comingwave is a technology company that provides business systems and integrations, data and dashboards and IT consulting to small and medium businesses. If you want help mapping which systems use personal information and how, you can request a quote.

Key takeaways

  • From 10 December 2026, APP entities must describe certain automated decision-making in their privacy policies.
  • The OAIC published its fact sheet, flowchart and updated APP 1 Guidelines on 30 September 2026.
  • Rule-based tools, spreadsheets, purchased software and generative AI can all be "computer programs".
  • Human review does not automatically remove a decision from scope.
  • Most businesses under $3 million turnover are outside the Privacy Act, but health providers and some others are covered at any size.

Frequently asked questions

When do the automated decision-making privacy rules start?

The transparency obligation in APP 1.7 to 1.9 takes effect on 10 December 2026.

Do the rules apply only to artificial intelligence?

No. The OAIC says a computer program includes pre-programmed rule-based processes, software and apps, as well as AI, machine learning and generative AI.

Does a human checking the result take us out of scope?

Not necessarily. The OAIC says a decision may be in scope even where the output is subject to human review, particularly where the output is a key factor in the decision.

Do we have to publish how our algorithm works?

No. The policy must describe the kinds of personal information used and the kinds of decisions made. Commercial-in-confidence information and trade secrets are excluded.

Is my small business covered by this obligation?

Only if it is an APP entity. The OAIC says most small businesses with turnover of $3 million or less are not covered by the Privacy Act, with exceptions such as health service providers.

Need help with your business technology?

Tell us what you need. We reply within one business day.

Get a free quote