Skip to main content
AI governance

Automated decisions need more than a privacy policy update

New Australian transparency rules cover more than fully automated AI. Businesses should map consequential decisions, personal information, vendors and human judgement before updating their privacy policy.

By Andy Vu9 min read

Updating a privacy policy can look like a writing task.

For some Australian businesses, a new transparency obligation makes it a workflow task first.

From 10 December 2026, an organisation covered by the Australian Privacy Principles may need to explain how computer programs use personal information to make, or substantially inform, decisions that significantly affect an individual's rights or interests.

The practical work is not adding a generic sentence about artificial intelligence. It is finding the decisions, understanding how each system influences them and describing the use of personal information clearly enough to be meaningful.

What changed on 30 September 2026

The legal change was introduced by the Privacy and Other Legislation Amendment Act 2024. On 30 September 2026, the Office of the Australian Information Commissioner published final implementation resources for the automated decision-making transparency obligation.

The OAIC also updated Chapter 1 of the Australian Privacy Principles Guidelines and released a fact sheet and assessment flowchart.

From 10 December, the additional privacy policy disclosure applies when all three conditions are met:

  • an APP entity has arranged for a computer program to make a decision, or do something substantially and directly related to making it;
  • the decision could reasonably be expected to significantly affect an individual's rights or interests; and
  • personal information about that individual is used by the program in making or informing the decision.

Where the obligation applies, the privacy policy must describe the kinds of personal information used, the kinds of decisions made solely by programs and the kinds of decisions that programs substantially and directly help to make.

This is general information, not legal advice. A business should obtain appropriate privacy or legal advice where its coverage or obligations are unclear.

Not every small business is covered

The first question is whether the organisation is an APP entity.

The OAIC explains that most businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but some are. Examples include private health service providers, businesses that trade in personal information, Commonwealth contracted service providers and some businesses covered because of particular activities.

Businesses above the turnover threshold, and smaller businesses within an exception, should assess the new obligation. A small business that is not an APP entity should not present the disclosure as a legal requirement without advice.

The same inventory can still be useful. A business should know when software influences hiring, access, pricing or another important outcome, even where this particular privacy policy obligation does not apply.

The rule covers more than fully automated AI

The phrase automated decision-making can make the obligation sound narrower than the final guidance.

The OAIC interprets computer program broadly. It includes rule-based processes, software, apps, spreadsheets, machine learning and generative AI. A formula that ranks people can matter just as much as a newer model.

Human involvement does not automatically place a workflow outside the rule either.

The guidance says an advisory output may still be substantially and directly related to a decision when it is a key factor in the human's judgement. Relevant questions include how heavily staff rely on the output, whether they genuinely override it, what evidence they review and how tightly the program is integrated into the workflow.

A person clicking approve after accepting a recommendation almost every time is not the same as independent human judgement.

Which decisions deserve attention first

Do not begin by listing every piece of software in the business.

Begin with decisions that can meaningfully change a person's circumstances.

The OAIC's non-exhaustive examples include recruitment screening, employee performance and remuneration, access to health or disability services, loan and insurance eligibility, personalised pricing for significant goods and decisions about financial support, education or housing.

For an SMB, the first review might ask whether software helps to:

  • screen, rank or reject job applicants;
  • score staff performance, recommend promotions or influence bonuses;
  • set materially different prices using a person's profile or location;
  • suspend an account or limit access to a significant service;
  • prioritise health, care or support requests;
  • approve, reject or escalate an application, complaint or request with a significant outcome.

Not every automated email, recommendation or refund decision will be significant. Context matters, including the type of outcome, the information used and whether the person is experiencing vulnerability.

Build a decision register before changing the policy

A useful first deliverable is a small decision register.

For each potentially significant decision, record:

  • the decision and the people it may affect;
  • the personal information used;
  • the program, model, spreadsheet or rule involved;
  • the vendor and any connected systems;
  • the output the program produces;
  • how a person uses that output;
  • whether staff can and do override it;
  • the possible beneficial and adverse effects;
  • the business owner responsible for the workflow;
  • the policy wording, review date and evidence supporting the assessment.

This does not require a new governance platform. A controlled spreadsheet or simple internal register can be enough for a first pass.

The register makes the privacy policy a result of understood practice. It also exposes workflows where nobody can explain the source data, the vendor's role or the point at which a recommendation becomes a decision.

Third-party software does not remove the responsibility

Many businesses will not have built the relevant system.

They may use recruitment software, an ecommerce personalisation tool, a case management system or an AI service supplied by another company. The OAIC says an entity can still have arranged for the program when it procures, configures, authorises, integrates or relies on third-party software.

The APP entity using personal information to make the decision will typically retain the transparency obligation. The vendor should provide enough high-level information for the customer to make an appropriate disclosure.

Before relying on a vendor, ask for:

  • the categories of personal information used;
  • the decisions or recommendations the product can make;
  • how configurable rules and models influence the output;
  • where human review occurs and what reviewers can see;
  • processing locations, retention and access arrangements;
  • audit, export and deletion capabilities;
  • notice of material changes to the product or its data use.

If a supplier cannot provide enough information to understand a consequential workflow, that is an adoption constraint, not merely a documentation gap.

Good AI Integration keeps the decision model, data flow and vendor boundary visible instead of hiding them behind one connection.

The disclosure should be meaningful, not exhaustive

The final guidance does not require a business to publish its source code, model weights or genuinely commercial-in-confidence detail.

It does require more than a vague statement that the business may use AI.

The privacy policy can group related categories, but a reasonable person should still be able to understand the kinds of personal information used and the kinds of significant decisions involved. Sensitive information such as health data or biometric templates should be made clear.

The OAIC recommends plain language, logical grouping and enough context for a person to seek more information or challenge a decision. Excessive technical detail can obscure the disclosure just as easily as generic wording.

A lawyer or privacy adviser may review the final wording. The underlying facts still need to come from the people who understand the workflow, software, data and operational responsibility.

Keep human review real and observable

Human approval remains important, but it should not be treated as a label that makes the assessment disappear.

For a consequential workflow, define what the reviewer receives, what they must check, when they can override the output and how that reasoning is recorded. Test whether reviewers have enough time and evidence to exercise judgement rather than simply confirm the program's recommendation.

Useful measures include:

  • how often people agree with, change or reject the output;
  • the reasons for overrides;
  • error and complaint patterns;
  • differences in outcomes across relevant groups;
  • the time needed for proper review;
  • cases where the source information is missing or contradictory.

This evidence helps the business assess whether the program is advisory in practice, whether the workflow remains reliable and whether the privacy policy still reflects reality.

An AI Workflow Development engagement can make these review points, exceptions and records part of the system rather than leaving them inside an informal instruction.

Use the deadline as a workflow review

A practical preparation path is:

  1. Confirm whether the organisation is an APP entity and obtain advice where coverage is uncertain.
  2. Identify decisions that could significantly affect an individual's rights or interests.
  3. Map the personal information, programs, vendors and human influence behind each decision.
  4. Shortlist the workflows that may meet all three parts of the obligation.
  5. Ask vendors for missing information and review relevant contracts.
  6. Confirm the assessment and disclosure with appropriate privacy or legal expertise.
  7. Update the privacy policy before 10 December and give the register a responsible owner.
  8. Review the register when a workflow, data source, vendor or decision changes.

Start with one high-impact workflow rather than attempting to catalogue every routine automation at once. Recruitment, performance assessment, personalised pricing and access to significant services are sensible places to look first.

Do not replace a system that works merely to meet the deadline. Understand it, document it and change only what the assessment shows is unclear, unsafe or no longer appropriate.

Privacy, security and maintenance still need separate decisions

The new obligation is about transparency in an APP privacy policy. It is not a complete approval framework for automated decisions.

The business still needs to assess whether collecting and using the personal information is lawful and appropriate, whether sensitive information is necessary, whether access and retention are controlled, and whether the workflow could create inaccurate, unfair or discriminatory outcomes.

Security controls, incident response, complaint handling and reliable fallbacks still need owners. So do model changes, vendor releases and rule updates that may alter the way a decision is made.

Keep the decision register, acceptance criteria and review evidence in a form the business can export. Vendor interfaces and model names will change. The organisation should not have to rediscover why a consequential workflow works the way it does each time a supplier changes the product.

The next decision

The 10 December deadline creates a clear action, but the privacy policy is not the best place to start.

Start with the decision.

Find where personal information enters the workflow, what the program does, how much the person relies on it and what the outcome can mean for the individual. Then write a disclosure that reflects the real system.

When several workflows, vendors or business owners are involved, a Fractional Technical Partner can help create the decision register, coordinate the technical assessment and separate implementation questions from matters that need privacy or legal advice.

AI governance

AI meeting notes need a business policy

Google Meet is switching on automatic AI notes by default for some business plans. Review consent, sharing, retention and human verification before the setting becomes normal practice.

Continue reading

Have a technical question worth thinking through?

Start the conversation