Guide | Privacy Act | automated decisions
What the Privacy Act AI changes mean for your business
From 10 December 2026, APP entities must include information in their privacy policy when a computer program uses personal information to make, or do something substantially and directly related to making, a decision that could significantly affect an individual's rights or interests. This guide explains the obligation, its boundaries and the practical work to prepare.
Does this apply
Start with three checks
Does the process use personal information in a significant decision?
Is a disclosure or deeper review the next step?
What is changing
The Privacy Act will require disclosure of automated decisions
The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024 and rolls out in stages. The automated decision-making transparency obligations take effect on 10 December 2026.
From that date, APP entities must include information in their privacy policy when they arrange for a computer program to use personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.
The same reforms also introduced a statutory tort for serious invasions of privacy (commenced mid-2025) and increased the regulator's enforcement tools, including infringement notices of up to $66,000 per contravention for certain breaches.
Sources Privacy and Other Legislation Amendment Act 2024 and OAIC guidance for APP 1.
- Royal Assent
- 10 Dec 2024Privacy and Other Legislation Amendment Act 2024 passed.
- Statutory tort
- Mid-2025Direct cause of action for serious invasions of privacy commenced.
- WA PRIS Act
- 1 Jul 2026WA public sector comes under a formal privacy regime.
- ADM transparency
- 10 Dec 2026Disclosure obligation for automated decision-making commences.
Plain English
What automated decision-making actually means
Decisions made with personal information
- Screening job applicants against criteria using a computer program
- Scoring or ranking customers for risk, creditworthiness, or eligibility
- Triaging service requests or complaints using AI
- Filtering or prioritising individuals using personal data
- Setting individualised pricing or offers based on personal attributes
Recommendations that strongly influence outcomes
- AI tools that recommend whether to approve, decline, or escalate
- Automated email or lead routing systems that segment individuals
- AI that flags individuals for further action based on personal data
- Scoring tools where the output strongly influences the outcome
Tools without an individual decision
- Chatbots that answer general questions without using personal data to decide outcomes
- AI used to draft internal documents with no decision about an individual
- Analytics tools that aggregate data without making individual level decisions
- AI used for internal scheduling or resource management with no individual impact
Who is affected
Which organisations the obligation applies to
The automated decision-making transparency obligation applies to organisations already covered by the Privacy Act 1988 (Cth). That covers most private sector organisations with annual turnover above $3 million, certain health service providers, and others covered regardless of turnover.
Whether the small business exemption (for organisations with under $3 million turnover) applies in your situation depends on your specific circumstances. The OAIC is the primary source for current guidance on exemption scope. Check oaic.gov.au and the Attorney-General's Department.
Private sector with turnover above $3m
Generally covered. If you use AI in decisions affecting customers, employees, or other individuals, the ADM transparency obligation likely applies.
Health service providers
Covered regardless of turnover. Health data is sensitive information under the Privacy Act and the ADM obligation applies where personal health information is used in automated decisions.
Commonwealth agencies
Already subject to the Privacy Act and to the mandatory DTA Policy for the Responsible Use of AI in Government. The ADM obligation adds to existing transparency requirements.
Smaller businesses
Whether the small business exemption applies depends on your specific circumstances. Check with the OAIC or a privacy professional rather than assuming you are exempt.
Preparation checklist
Seven steps to prepare before December 2026
Work through the sequence in order. This checklist is also available as a dedicated resource: Privacy Act 2026 Compliance Checklist.
- Map
Find the systems and decisions
Record where AI touches personal information and which outputs could significantly affect an individual.
- Disclose
Write and publish accurate wording
Describe each process plainly, then update the privacy policy before the obligation commences.
- Control
Add oversight and keep it current
Review human oversight, cross border data flows and the disclosure whenever the process changes.
Detailed checklistRead all seven preparation steps
Map where AI touches personal information
List every AI tool or automated process your organisation uses. For each one, record what personal information goes in, what decisions or outputs it produces, and whether those outputs could significantly affect an individual. This is the foundation. Without it you cannot know which processes are in scope.
Identify which processes are automated decisions
An automated decision, in the context of the Privacy Act reforms, is one where a computer program uses personal information to make, or substantially help make, a decision that could significantly affect an individual. Screening applications, scoring leads, triaging service requests, and setting pricing based on individual data are common examples. Flag each one.
Draft your ADM disclosure for each in scope process
For each automated decision process, write a plain language disclosure covering what is being decided, how automation is involved, what personal information is used, and what human review (if any) is in place. Our free ADM disclosure template gives you the structure to do this.
Update your privacy policy before 10 December 2026
Embed the ADM disclosures in your privacy policy, or reference a dedicated disclosure document from it. The privacy policy is where the legal obligation sits. A disclosure buried in a separate document that your policy does not reference may not satisfy the requirement.
Put human oversight in place for significant decisions
The ADM transparency obligation is about disclosure, not about requiring human override. However, good practice (and risk management) is to ensure a named person reviews automated outputs before they produce decisions that significantly affect individuals. Document who that person is and what their role in the process is.
Review your cross-border data flows
Many AI vendors process data offshore. If personal information leaves Australia, the Privacy Act cross-border disclosure obligations apply in addition to the ADM transparency requirement. Check each vendor's data residency position and update your privacy policy accordingly.
Set a review cadence for automated processes
Automated processes change as vendors update their models and new tools are adopted. A one-off disclosure that is never reviewed becomes inaccurate and therefore non-compliant. Set a calendar reminder to review each ADM disclosure at least annually, and whenever the underlying process changes.
How VibeZero helps
Services and resources for the 2026 deadline
FAQ
Questions about the 2026 obligations
From 10 December 2026, organisations covered by the Australian Privacy Act 1988 (Cth) must disclose in their privacy policies where personal information is used in computer programs or automated processes to make, or substantially help make, decisions that could significantly affect individuals. This requirement was introduced by the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024.
Review the real system