The short version
From 10 December 2026, organisations covered by the Privacy Act 1988 must include new information in their privacy policies when they use personal information in computer programs that make, or substantially and directly support, decisions that could reasonably be expected to significantly affect an individual's rights or interests. The Office of the Australian Information Commissioner (OAIC) published fact sheets and a flowchart on 30 September 2026 to help organisations apply the rule.
It is a transparency obligation. It does not ban automation and does not create a new right to have a person review a decision. But getting it wrong is visible: your privacy policy is public, and regulators, journalists and customers can compare it with what your systems actually do.
Who it applies to
The obligation applies to APP entities, the organisations bound by the Australian Privacy Principles. Broadly, that means:
- Australian Government agencies
- businesses and not-for-profits with annual turnover above A$3 million
- some smaller businesses that are covered regardless of turnover, such as health service providers
When it is triggered
All three conditions must be met:
- A computer program is involved. You have arranged for a computer program to make a decision, or to do something substantially and directly related to making it. This includes machine learning and AI, but also rules engines, scoring tools and automated workflows.
- The decision is significant. It could reasonably be expected to significantly affect an individual's rights or interests. Decisions about access to services, credit, insurance, employment, benefits and pricing are typical candidates.
- Personal information is used in the operation of the program.
What your privacy policy must say
Where the conditions are met, your privacy policy must describe:
- the kinds of personal information used in the operation of those computer programs
- the kinds of decisions made solely by the operation of computer programs
- the kinds of decisions where a thing substantially and directly related to making the decision is done solely by computer programs
The test is about kinds, not every individual system. But you cannot describe the kinds accurately until you know what systems you have.
Where organisations get caught out
- Vendor tools. Scoring, fraud, recruitment and pricing features inside software you buy often count, even if you never thought of them as "AI".
- Shadow automation. Spreadsheet models and scripts that quietly decide who gets approved, prioritised or flagged.
- "Human in the loop" that is not. If a person rubber-stamps whatever the system recommends, the program is still doing something substantially related to the decision.
- Over-disclosure. Vague catch-all wording can mislead as much as silence, and creates questions you cannot answer.
A six-step readiness plan
- Inventory. List every system, vendor feature and model that makes or supports decisions about people, including spreadsheets.
- Assess significance. For each, decide whether the decision could reasonably be expected to significantly affect rights or interests, and record why.
- Map personal information. Document the kinds of personal information each in-scope program uses.
- Classify the role of the program. Does it make the decision solely, or do something substantially and directly related to it?
- Draft and approve the disclosure. Write clear, accurate privacy policy wording and have your legal team approve it.
- Govern it. Add new and changed systems to an AI register so the disclosure stays accurate, aligned with the six essential practices in Australia's Guidance for AI Adoption.
The disclosure is the easy part. Knowing what your systems actually decide is the work.
How we help
Our ADM & AI Governance Readiness engagement does steps one to four and drafts step five for your lawyers, in two to three weeks for a fixed fee. You finish with an AI register you can keep current, and a governance position you can explain to your board.