Skip to content

Guide | Privacy Act | automated decisions

What the Privacy Act AI changes mean for your business

From 10 December 2026, APP entities must include information in their privacy policy when a computer program uses personal information to make, or do something substantially and directly related to making, a decision that could significantly affect an individual's rights or interests. This guide explains the obligation, its boundaries and the practical work to prepare.

General information only. Not legal advice. Review your circumstances with a qualified privacy professional.

Does this apply

Start with three checks

The answer depends on the organisation, the information used and the effect of the decision. These checks show where to read next without pretending to replace legal advice.

What is changing

The Privacy Act will require disclosure of automated decisions

The reform rolls out in stages. The automated decision-making transparency obligations take effect on 10 December 2026.

The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024 and rolls out in stages. The automated decision-making transparency obligations take effect on 10 December 2026.

From that date, APP entities must include information in their privacy policy when they arrange for a computer program to use personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.

The same reforms also introduced a statutory tort for serious invasions of privacy (commenced mid-2025) and increased the regulator's enforcement tools, including infringement notices of up to $66,000 per contravention for certain breaches.

Sources Privacy and Other Legislation Amendment Act 2024 and OAIC guidance for APP 1.

Royal Assent
10 Dec 2024Privacy and Other Legislation Amendment Act 2024 passed.
Statutory tort
Mid-2025Direct cause of action for serious invasions of privacy commenced.
WA PRIS Act
1 Jul 2026WA public sector comes under a formal privacy regime.
ADM transparency
10 Dec 2026Disclosure obligation for automated decision-making commences.

Plain English

What automated decision-making actually means

These categories are illustrative. Whether a specific process is in scope depends on your circumstances. Review with a qualified privacy professional.
In scope

Decisions made with personal information

  • Screening job applicants against criteria using a computer program
  • Scoring or ranking customers for risk, creditworthiness, or eligibility
  • Triaging service requests or complaints using AI
  • Filtering or prioritising individuals using personal data
  • Setting individualised pricing or offers based on personal attributes
Probably in scope

Recommendations that strongly influence outcomes

  • AI tools that recommend whether to approve, decline, or escalate
  • Automated email or lead routing systems that segment individuals
  • AI that flags individuals for further action based on personal data
  • Scoring tools where the output strongly influences the outcome
Likely out of scope

Tools without an individual decision

  • Chatbots that answer general questions without using personal data to decide outcomes
  • AI used to draft internal documents with no decision about an individual
  • Analytics tools that aggregate data without making individual level decisions
  • AI used for internal scheduling or resource management with no individual impact

Who is affected

Which organisations the obligation applies to

The automated decision-making transparency obligation applies to organisations already covered by the Privacy Act 1988 (Cth).

The automated decision-making transparency obligation applies to organisations already covered by the Privacy Act 1988 (Cth). That covers most private sector organisations with annual turnover above $3 million, certain health service providers, and others covered regardless of turnover.

Whether the small business exemption (for organisations with under $3 million turnover) applies in your situation depends on your specific circumstances. The OAIC is the primary source for current guidance on exemption scope. Check oaic.gov.au and the Attorney-General's Department.

01

Private sector with turnover above $3m

Generally covered. If you use AI in decisions affecting customers, employees, or other individuals, the ADM transparency obligation likely applies.

02

Health service providers

Covered regardless of turnover. Health data is sensitive information under the Privacy Act and the ADM obligation applies where personal health information is used in automated decisions.

03

Commonwealth agencies

Already subject to the Privacy Act and to the mandatory DTA Policy for the Responsible Use of AI in Government. The ADM obligation adds to existing transparency requirements.

04

Smaller businesses

Whether the small business exemption applies depends on your specific circumstances. Check with the OAIC or a privacy professional rather than assuming you are exempt.

Preparation checklist

Seven steps to prepare before December 2026

Work through the sequence in order. This checklist is also available as a dedicated resource: Privacy Act 2026 Compliance Checklist.

  1. Map

    Find the systems and decisions

    Record where AI touches personal information and which outputs could significantly affect an individual.

  2. Disclose

    Write and publish accurate wording

    Describe each process plainly, then update the privacy policy before the obligation commences.

  3. Control

    Add oversight and keep it current

    Review human oversight, cross border data flows and the disclosure whenever the process changes.

Detailed checklistRead all seven preparation steps
Preparation step

Map where AI touches personal information

List every AI tool or automated process your organisation uses. For each one, record what personal information goes in, what decisions or outputs it produces, and whether those outputs could significantly affect an individual. This is the foundation. Without it you cannot know which processes are in scope.

Preparation step

Identify which processes are automated decisions

An automated decision, in the context of the Privacy Act reforms, is one where a computer program uses personal information to make, or substantially help make, a decision that could significantly affect an individual. Screening applications, scoring leads, triaging service requests, and setting pricing based on individual data are common examples. Flag each one.

Preparation step

Draft your ADM disclosure for each in scope process

For each automated decision process, write a plain language disclosure covering what is being decided, how automation is involved, what personal information is used, and what human review (if any) is in place. Our free ADM disclosure template gives you the structure to do this.

Preparation step

Update your privacy policy before 10 December 2026

Embed the ADM disclosures in your privacy policy, or reference a dedicated disclosure document from it. The privacy policy is where the legal obligation sits. A disclosure buried in a separate document that your policy does not reference may not satisfy the requirement.

Preparation step

Put human oversight in place for significant decisions

The ADM transparency obligation is about disclosure, not about requiring human override. However, good practice (and risk management) is to ensure a named person reviews automated outputs before they produce decisions that significantly affect individuals. Document who that person is and what their role in the process is.

Preparation step

Review your cross-border data flows

Many AI vendors process data offshore. If personal information leaves Australia, the Privacy Act cross-border disclosure obligations apply in addition to the ADM transparency requirement. Check each vendor's data residency position and update your privacy policy accordingly.

Preparation step

Set a review cadence for automated processes

Automated processes change as vendors update their models and new tools are adopted. A one-off disclosure that is never reviewed becomes inaccurate and therefore non-compliant. Set a calendar reminder to review each ADM disclosure at least annually, and whenever the underlying process changes.

FAQ

Questions about the 2026 obligations

From 10 December 2026, organisations covered by the Australian Privacy Act 1988 (Cth) must disclose in their privacy policies where personal information is used in computer programs or automated processes to make, or substantially help make, decisions that could significantly affect individuals. This requirement was introduced by the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024.

Review the real system

Not sure where your AI use sits against the 2026 obligations? Start with the processes

Map the automated decisions, the personal information involved and the disclosures already in place before choosing the remediation work.
General information only. Not legal advice.