Automated Decisions: New Privacy Rules 2026

On 10 December 2026, a quiet but consequential change to Australian privacy law switches on. From that date, organisations covered by the Australian Privacy Principles must disclose, in their privacy policy, when they use a computer program to make decisions that significantly affect people. The change was introduced by the Privacy and Other Legislation Amendment Act 2024, the first tranche of reforms to the Privacy Act 1988, and it lands squarely on any business that has quietly woven automation and AI into its operations over the past few years.
The deadline is closer than it looks. The Office of the Australian Information Commissioner ran a consultation on its draft guidance for the new transparency obligation, with submissions closing in June 2026, and final guidance is expected before the requirement commences. That leaves a narrow window for an operations director, privacy officer, or general counsel to do the unglamorous work underneath the obligation: find every automated decision in the business, understand what personal information feeds it, and write something honest and specific in the privacy policy.
This is not a tick-box exercise that the legal team can knock over in an afternoon. To describe your automated decisions accurately, you first have to know they exist, and in most organisations that knowledge is scattered across a lending platform here, a recruitment screening tool there, a pricing engine in the finance stack, and a handful of AI features switched on inside SaaS products nobody fully audited. The transparency requirement is, in practice, a forcing function for AI governance.
What the new obligation actually says
The reform adds new content requirements to APP 1, the principle that governs open and transparent management of personal information. Practitioners refer to the new limbs as APP 1.7 and APP 1.8. The substance is straightforward to state and harder to comply with.
An obligation arises where three conditions are met together:
- A computer program makes, or does a thing that is substantially and directly related to making, a decision.
- That decision could reasonably be expected to significantly affect the rights or interests of an individual.
- Personal information about the individual is used in the operation of the computer program.
Where those conditions are met, the privacy policy must set out information about the kinds of personal information used in those programs and the kinds of decisions made. The drafting deliberately captures more than fully automated decisions. A program that does something "substantially and directly related to making" a decision is in scope, which reaches the common pattern where software produces a score, a ranking, or a recommendation that a human then rubber-stamps.
That phrase matters. Many organisations comfort themselves that they are safe because "a person always signs off". Under this reform, a human in the loop who routinely defers to the machine does not take the decision out of scope. If the computer program is doing the substantive work, the transparency obligation applies.
Is a decision in scope for the ADM transparency rule?
What counts as "significantly affecting" someone
The threshold is whether a decision could reasonably be expected to significantly affect the rights or interests of an individual. The explanatory material and the OAIC's guidance work point to the kinds of decisions that clearly clear the bar:
- Granting or refusing credit, a loan, or a financial product.
- Underwriting, pricing, or declining insurance.
- Approving or rejecting a tenancy or housing application.
- Decisions affecting access to significant services or support, including healthcare.
- Decisions affecting rights under a contract, including eligibility and entitlements.
- Employment screening and shortlisting that determines who progresses.
The uncomfortable truth is how many of these now run through software by default. A finance lender uses a decisioning engine. An insurance broker runs automated risk scoring. A property manager screens applicants through a tenancy platform. A large employer filters thousands of applications through an applicant tracking system that ranks candidates. Each of these is a candidate for disclosure, and each sits in a different team with a different vendor and a different level of documentation.
This is the same governance gap we examined in our guide to AI agent governance, data access and human override. The transparency obligation makes that gap a published, regulated artefact rather than an internal concern.
Why this is harder than rewriting a privacy policy
The legal text of the disclosure is the last 5 percent of the work. The first 95 percent is discovery and mapping. You cannot describe the "kinds of personal information used in the operation of the computer program" if you do not have a current inventory of which programs make consequential decisions and which data they consume.
Consider a typical organisation with separate finance, operations, HR, and customer service teams. Automated decisioning tends to accumulate in three ways: purpose-built systems the business commissioned, AI features switched on inside existing SaaS tools, and informal automations built by individual teams in low-code platforms. Each layer is progressively harder to see.
Where automated decisions hide, and how visible they are
| Metric | Decision source | Typical visibility to a privacy officer | Improvement |
|---|---|---|---|
| Commissioned decision engine (lending, pricing) | Owned by one team | Documented but rarely mapped to privacy policy | Medium |
| AI feature inside a SaaS product | Vendor-controlled | Often undisclosed in contracts and unmonitored | Low |
| Low-code or spreadsheet automation | Built by a team locally | Usually invisible to central governance | Very low |
| Third-party scoring or enrichment service | Embedded via API | Data flows poorly understood | Low |
The work of mapping these decisions is exactly the work that good AI governance requires anyway. The transparency deadline simply gives it a date. Organisations that already maintain an AI register, as recommended in our AI governance framework for Australian businesses, are well ahead. Those that do not will find the discovery phase is where the real effort sits.
A workflow to get compliant
The path from "we are not sure what we run" to a defensible, published disclosure follows a clear sequence. It is best run as a small cross-functional effort with finance, operations, HR, IT, and legal at the table, because automated decisions cross all of those boundaries.
ADM transparency compliance workflow
Discover. Build a single register of decisions, not systems. The unit that matters is the decision (approve a loan, shortlist a candidate, set a premium), because that is what the law regulates. For each one, capture the owning team, the software involved, and whether a human meaningfully intervenes.
Triage. Apply the "significantly affects rights or interests" test to each decision. Be honest about the borderline cases. A marketing audience segmentation is unlikely to clear the bar; an automated eligibility decision for a financial hardship program almost certainly does.
Map the data. For every in-scope decision, document the kinds of personal information the program uses. This is the raw material for both the disclosure and any later access or correction request. If the data includes sensitive information, the stakes and the scrutiny rise.
Assess. Transparency about a decision invites questions about its quality. Before you publish, confirm the decision is accurate, that it does not produce discriminatory outcomes, and that a genuine human override path exists. This is where the principle of meaningful human control, covered in our piece on why AI projects fail and how to avoid it, becomes a compliance issue rather than a best-practice one.
Disclose. Write the privacy policy language in plain English. The OAIC has signalled that generic boilerplate will not satisfy the obligation. Describe the kinds of decisions and the kinds of information specifically enough that a reasonable person understands what is happening to their data.
Monitor. Automated decisions change as vendors update products and teams build new automations. Treat the register as a living document with a named owner and a review cadence that outlasts December 2026.
What "good" disclosure looks like
The OAIC's consultation made clear that the aim is genuine transparency. A compliant disclosure identifies the kinds of decisions made wholly or substantially by automated means and the kinds of personal information those programs use, in language a customer can follow.
Weak disclosure says: "We may use automated systems to process your information." Strong disclosure says: "We use an automated system to assess applications for credit. This system uses your identity details, income and expense information, credit history, and transaction data to produce a decision or recommendation. You can ask us to explain a decision and request human review." The second version tells the reader what is decided and what is used. That is the standard the reform is reaching for.
The cost of getting ADM transparency wrong
The penalty structure behind those numbers is worth reading closely. The 2024 reforms introduced a tiered penalty regime, with the most serious or repeated interferences with privacy attracting very large civil penalties, alongside lower-tier infringement notices that can attach to specific failures such as a non-compliant privacy policy. For most businesses, the more immediate risk sits below the headline maximum: an OAIC inquiry that exposes a fleet of undisclosed, undocumented automated decisions, followed by an expensive scramble to remediate under scrutiny.
How the transparency rule connects to wider AI obligations
The ADM transparency requirement does not exist in isolation. It sits inside a tightening web of Australian regulation that businesses now have to read together. Financial services firms already face automated decisioning expectations through their regulators, a theme we covered in financial services AI compliance under APRA and ASIC. General privacy obligations around AI tools are explored in our guide to Privacy Act compliance for AI in Australia. And the broader question of how Australian privacy law compares to overseas regimes is covered in GDPR versus the Privacy Act, which is relevant because many of the SaaS tools driving automated decisions were built for the European market and its automated decision provisions.
The practical implication is that the work you do for ADM transparency is reusable. A decision register, a data map, and a human-override review are exactly what you need to satisfy regulators across privacy, financial services, and emerging AI guidance. Build the asset once and amortise it across every obligation.
A realistic timeline to December 2026
For an organisation starting from a standing position in mid-2026, the schedule is tight but achievable if discovery starts now. The discovery and mapping phases consume the most calendar time because they depend on people in different teams surfacing systems that central functions cannot see.
Path to 10 December 2026 compliance
The organisations that will struggle are those that treat this as a December problem. Discovery in a business with years of accumulated automation routinely takes longer than expected, because the hardest decisions to find are the ones embedded in vendor products and local automations. Starting the register now buys back more time than anything else on the list.
Which sectors are most exposed
Some sectors will find that almost every consequential customer interaction now runs through an automated or semi-automated decision. The transparency obligation lands hardest on them, and they are also the sectors where the OAIC has signalled it will look first.
- Financial services and lending. Credit decisioning, affordability assessment, and fraud scoring are heavily automated and squarely within "significantly affects rights or interests". These businesses also answer to APRA and ASIC, so the disclosure has to be consistent across regulators.
- Insurance. Underwriting, pricing, and claims triage increasingly use automated models. A declined claim or a sharply higher premium is exactly the kind of consequential decision the reform targets.
- Property and real estate. Tenancy application screening platforms rank and filter applicants, often with limited human reconsideration. A refused application affects a person's access to housing.
- Recruitment and large employers. Applicant tracking systems that score and shortlist candidates make decisions that affect employment, and the data involved is personal and sometimes sensitive.
- Health and allied services. Any automation that affects access to care, eligibility, or prioritisation clears the significance threshold comfortably.
If your business sits in one of these sectors, assume you are in scope and start the discovery now. Assume you have automated decisions to disclose. The open questions are how many, and how well you understand them.
Five questions for the board
Boards do not need to understand model architectures, but they do need assurance that the organisation can answer the questions the regulator and customers will ask. Before December 2026, a board should be able to get a confident answer to each of the following.
- Do we have a complete register of the automated decisions we make that significantly affect individuals?
- For each one, do we know what personal information the system uses?
- Can a person ask for, and receive, a human review of an automated decision that affects them?
- Are we confident the decisions are accurate and free of unlawful discrimination?
- Is our privacy policy specific enough to satisfy the new obligation, rather than generic boilerplate?
If the honest answer to any of these is "not yet", that gap is the work between now and the deadline. None of it is exotic. All of it takes calendar time, because it depends on people across the business surfacing systems that central functions cannot see on their own.
Where Solve8 fits
Solve8 works with Australian businesses on exactly this intersection of AI capability and governance. The same enterprise integration discipline that underpins our delivery work, drawn from large-scale systems experience across resources and infrastructure, applies directly to mapping where automated decisions live and what data they consume. We help organisations build the decision register, map data flows through automated systems, assess fairness and human-override design, and translate the technical reality into privacy disclosure that is accurate rather than evasive.
If your AI roadmap is moving faster than your governance, the ADM transparency deadline is a useful reason to close the gap. Our AI strategy service and custom AI development work both build governance in from the start, so the systems you commission are documented and explainable by design rather than retrofitted under deadline pressure. To map your automated decisions before December, get in touch with our team.
The bottom line
The ADM transparency requirement is modest on its face: add some honest detail to a privacy policy. Underneath, it asks businesses to do something most have never done: see all of their automated decisions at once, understand the personal information behind them, and stand behind them publicly. That is a governance maturity step, and the 10 December 2026 date is the deadline for taking it. The businesses that start the discovery now will publish a confident, specific disclosure. The ones that wait will publish boilerplate and hope, which is precisely what the reform was designed to end.
Related reading
- Privacy Act compliance for AI in Australia
- AI agent governance, data access and human override
- AI governance framework for Australian businesses
- Financial services AI compliance under APRA and ASIC
- GDPR versus the Privacy Act for Australian business
Ready to map your automated decisions before the deadline? Explore our AI strategy service or contact the Solve8 team.