Skip to content

Guide · Privacy Act · automated decisions

What the Privacy Act AI changes mean for your business

From 10 December 2026, covered Australian organisations must disclose in their privacy policy where personal information is used in automated decisions that could significantly affect individuals. This guide explains the obligation, its boundaries and the practical work to prepare.

General information only · not legal advice · review your circumstances with a qualified privacy professional

What is changing

The Privacy Act now requires disclosure of automated decisions

The reform rolls out in stages. The automated decision-making transparency obligations take effect on 10 December 2026.

The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024 and rolls out in stages. The automated decision-making transparency obligations take effect on 10 December 2026.

From that date, organisations covered by the Privacy Act 1988 (Cth) must disclose in their privacy policy where personal information is used in computer programs to make, or substantially assist in making, decisions that could significantly affect individuals.

The same reforms also introduced a statutory tort for serious invasions of privacy (commenced mid-2025) and increased the regulator's enforcement tools, including infringement notices of up to $66,000 per contravention for certain breaches.

Source: Norton Rose Fulbright, Privacy Act reform summary and the OAIC.

Royal Assent
10 Dec 2024contextPrivacy and Other Legislation Amendment Act 2024 passed.
Statutory tort
Mid-2025contextDirect cause of action for serious invasions of privacy commenced.
WA PRIS Act
1 Jul 2026contextWA public sector comes under a formal privacy regime.
ADM transparency
10 Dec 2026contextDisclosure obligation for automated decision-making commences.

Plain English

What automated decision-making actually means

These categories are illustrative. Whether a specific process is in scope depends on your circumstances. Review with a qualified privacy professional.
In scope

Decisions made with personal information

  • Screening job applicants against criteria using a computer program
  • Scoring or ranking customers for risk, creditworthiness, or eligibility
  • Triaging service requests or complaints using AI
  • Filtering or prioritising individuals using personal data
  • Setting individualised pricing or offers based on personal attributes
Probably in scope

Recommendations that strongly influence outcomes

  • AI tools that recommend whether to approve, decline, or escalate
  • Automated email or lead routing systems that segment individuals
  • AI that flags individuals for further action based on personal data
  • Scoring tools where the output strongly influences the outcome
Likely out of scope

Tools without an individual decision

  • Chatbots that answer general questions without using personal data to decide outcomes
  • AI used to draft internal documents with no decision about an individual
  • Analytics tools that aggregate data without making individual level decisions
  • AI used for internal scheduling or resource management with no individual impact

Who is affected

Which organisations the obligation applies to

The automated decision-making transparency obligation applies to organisations already covered by the Privacy Act 1988 (Cth).

The automated decision-making transparency obligation applies to organisations already covered by the Privacy Act 1988 (Cth). That covers most private sector organisations with annual turnover above $3 million, certain health service providers, and others covered regardless of turnover.

Whether the small business exemption (for organisations with under $3 million turnover) applies in your situation depends on your specific circumstances. The OAIC is the primary source for current guidance on exemption scope. Check oaic.gov.au and the Attorney-General's Department.

01

Private sector with turnover above $3m

Generally covered. If you use AI in decisions affecting customers, employees, or other individuals, the ADM transparency obligation likely applies.

02

Health service providers

Covered regardless of turnover. Health data is sensitive information under the Privacy Act and the ADM obligation applies where personal health information is used in automated decisions.

03

Commonwealth agencies

Already subject to the Privacy Act and to the mandatory DTA Policy for the Responsible Use of AI in Government. The ADM obligation adds to existing transparency requirements.

04

Smaller businesses

Whether the small business exemption applies depends on your specific circumstances. Check with the OAIC or a privacy professional rather than assuming you are exempt.

Preparation checklist

Seven steps to prepare before December 2026

Work through the sequence in order. This checklist is also available as a dedicated resource: Privacy Act 2026 Compliance Checklist.

  1. 01

    Map where AI touches personal information

    List every AI tool or automated process your organisation uses. For each one, record what personal information goes in, what decisions or outputs it produces, and whether those outputs could significantly affect an individual. This is the foundation. Without it you cannot know which processes are in scope.

  2. 02

    Identify which processes are automated decisions

    An automated decision, in the context of the Privacy Act reforms, is one where a computer program uses personal information to make, or substantially help make, a decision that could significantly affect an individual. Screening applications, scoring leads, triaging service requests, and setting pricing based on individual data are common examples. Flag each one.

  3. 03

    Draft your ADM disclosure for each in scope process

    For each automated decision process, write a plain language disclosure covering what is being decided, how automation is involved, what personal information is used, and what human review (if any) is in place. Our free ADM disclosure template gives you the structure to do this.

  4. 04

    Update your privacy policy before 10 December 2026

    Embed the ADM disclosures in your privacy policy, or reference a dedicated disclosure document from it. The privacy policy is where the legal obligation sits. A disclosure buried in a separate document that your policy does not reference may not satisfy the requirement.

  5. 05

    Put human oversight in place for significant decisions

    The ADM transparency obligation is about disclosure, not about requiring human override. However, good practice (and risk management) is to ensure a named person reviews automated outputs before they produce decisions that significantly affect individuals. Document who that person is and what their role in the process is.

  6. 06

    Review your cross-border data flows

    Many AI vendors process data offshore. If personal information leaves Australia, the Privacy Act cross-border disclosure obligations apply in addition to the ADM transparency requirement. Check each vendor's data residency position and update your privacy policy accordingly.

  7. 07

    Set a review cadence for automated processes

    Automated processes change as vendors update their models and new tools are adopted. A one-off disclosure that is never reviewed becomes inaccurate and therefore non-compliant. Set a calendar reminder to review each ADM disclosure at least annually, and whenever the underlying process changes.

FAQ

Questions about the 2026 obligations

Review the real system

Not sure where your AI use sits against the 2026 obligations? Start with the processes

Map the automated decisions, the personal information involved and the disclosures already in place before choosing the remediation work.
General information only · not legal advice