Work with us
AI regulation in Australia / Privacy Act reform: automated decision-making transparency

Privacy Act reform: automated decision-making transparency

From 10 December 2026, privacy policies must explain the automated decisions that significantly affect people and the personal information behind them. Enacted law with a fixed commencement date.

Status
Enacted, commencing · Australia (Commonwealth) · AGD
Applies to
APP entities that use computer programs, including AI, to make or substantially inform decisions that could significantly affect a person's rights or interests
Key date
10 December 2026: Automated decision-making transparency obligation commences
Primary source
Official document →
Last reviewed
28 September 2026

What it is

A new transparency rule in the Privacy Act, added by the Privacy and Other Legislation Amendment Act 2024 and commencing on 10 December 2026. New paragraphs 1.7 to 1.9 of Australian Privacy Principle 1 require an entity’s privacy policy to disclose when it uses a computer program to make, or substantially contribute to, decisions that could reasonably be expected to significantly affect a person’s rights or interests, and what personal information the program uses. It is the first Australian privacy rule written specifically with automated and AI decision-making in mind. It is law now; the obligation bites in December 2026 and applies to decisions made from that date whatever the age of the system.

What it requires

Three additions to your privacy policy, where the trigger is met: the kinds of personal information used in the operation of the computer programs; the kinds of decisions made solely by those programs; and the kinds of decisions in which a program does something “substantially and directly related to making the decision”. The trigger is a decision that “could reasonably be expected to significantly affect the rights or interests of an individual”. The OAIC’s examples are decisions to grant or refuse a benefit under legislation, decisions that affect rights under a contract such as an insurance policy, and decisions affecting access to a significant service such as healthcare. Refusing or failing to decide counts as a decision, and the rule applies whether the outcome helps or harms the person. It is a disclosure obligation: it does not prohibit automated decisions or give a right to a human review.

Does this reach your business?

If the Privacy Act covers you (turnover over $3 million, or a covered category) and you use software to decide, or to feed a decision, about a person in a way that matters to them: credit, insurance, hiring, tenancy, eligibility, pricing, access to a service. AI recommendation and scoring tools inside a CRM or HR system are the common way a smaller business meets the trigger without noticing. If your AI use is drafting, summarising and internal analysis, the rule does not reach you, but the boundary is what the system does, not what it is called.

What we recommend

Our advice is to do the inventory now and the policy wording later, because the wording is easy once you know the answer. For every system that touches decisions about people, write down: what decision, whether a person makes it or the system does, what personal information goes in, and whether the person affected would consider it significant. If any line meets the trigger, draft the three disclosures for your privacy policy and have them live before 10 December 2026. While you are there, decide whether the person can ask for a human to look again; the law does not require it, but the Guidance for AI Adoption does, and it is the question customers ask first.

Questions people ask

10 December 2026. It applies to decisions made from that date, even by systems set up earlier.

No. It requires your privacy policy to disclose them, the kinds of decisions and the personal information used.

Those that could reasonably be expected to significantly affect a person's rights or interests: benefits, contractual rights such as insurance, access to significant services, and similar. Routine drafting or internal analysis does not count.

Not this rule. It is transparency only. Other laws and the Guidance for AI Adoption cover contestability.