Privacy law
Automated decision-making and the Privacy Act: the APP 1.7 rules from 10 December 2026
From 10 December 2026, organisations that use software or AI to make, or substantially help make, significant decisions about people must say so in their privacy policy. Here is what APP 1.7 to 1.9 require, who they cover and a checklist to be ready.
By the AusGPT team · Updated · 9 min read
General information only, not legal advice. Check the primary sources linked below, and get advice for your situation.
From 10 December 2026, the Privacy Act requires organisations to explain automated decision-making in their privacy policies. If your organisation has arranged for a computer program to make a decision, or to do something "substantially and directly related" to making it, and the decision could reasonably be expected to significantly affect someone's rights or interests, and the program uses that person's personal information, your privacy policy must describe it.
The new rules are Australian Privacy Principles (APP) 1.7 to 1.9. They are a transparency obligation: you have to disclose what you do, not stop doing it. The Office of the Australian Information Commissioner (OAIC) published updated APP 1 guidelines, a fact sheet and a flowchart on 30 September 2026, and it reads "computer program" broadly enough to cover spreadsheets, rules engines, machine learning and generative AI.
What APP 1.7 to 1.9 say
The obligation was inserted into Schedule 1 of the Privacy Act 1988 by Part 15 of Schedule 1 to the Privacy and Other Legislation Amendment Act 2024. APP 1.7 says the privacy policy of an APP entity must contain the information in APP 1.8 if:
(a) the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; and (b) the decision could reasonably be expected to significantly affect the rights or interests of an individual; and (c) personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision.
APP 1.8 then lists what the policy must contain:
- the kinds of personal information used in the operation of such computer programs
- the kinds of such decisions made solely by the operation of such computer programs
- the kinds of such decisions for which a thing that is substantially and directly related to making the decision is done by the operation of such computer programs.
APP 1.9 widens the terms. Making a decision includes "refusing or failing to make a decision", a decision can affect rights or interests "adversely or beneficially", and the examples given include decisions to grant or refuse a benefit under a law, decisions that affect a person's rights under a contract, and decisions that affect "access to a significant service or support".
When it starts
Part 15 commences "the day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent". The Act received Royal Assent on 10 December 2024, and the commencement table gives the date as 10 December 2026.
The application provision matters as much as the date. The obligation applies to decisions made after commencement, whether the arrangement for the program, the use of personal information or the collection of that information happened before or after that date. Systems you already run are covered from day one. There is no grandfathering.
Who it applies to
APP 1.7 applies to APP entities: Australian Government agencies and organisations covered by the Privacy Act. Most businesses with an annual turnover of $3 million or less are exempt, but the OAIC lists businesses covered regardless of turnover, including health service providers, businesses trading in personal information, contractors under Commonwealth contracts and credit reporting bodies.
The obligation sits with the entity that "arranged for" the program, which is usually the organisation using personal information to make the decision, even when a vendor runs the software. The OAIC treats procuring third-party software, configuring off-the-shelf software and relying on advisory outputs as examples of arranging for a program. It also expects software providers to give customers clear, high-level information about how their products can be used to make decisions, so the customer can write an accurate disclosure.
The key terms, as the OAIC reads them
| Term | OAIC interpretation (APP 1 Guidelines, September 2026) |
|---|---|
| Computer program | Takes its ordinary meaning and is read broadly: rule-based processes, AI and machine learning, common software, apps and word-processing tools, and generative AI including chatbots. |
| Substantially and directly related | "Substantially" means a key factor in facilitating the human's decision. "Directly" means a direct connection with making the decision. Advisory outputs can qualify. |
| Significantly affect | The impact must be more than trivial and have the potential to considerably influence the person's circumstances or outcomes. |
| Rights or interests | Includes access to food, healthcare, aged care, disability support, financial assistance, education, banking and credit, telecommunications, utilities, employment and housing. |
| Vulnerability | A decision may be significant for a child or a person experiencing vulnerability even if it is minor for most people. |
The guidelines list factors for judging whether an advisory output is "substantially and directly related": how much the human relies on it, whether staff can and do override it, whether it is advisory or determinative, whether the decision-maker can see how it reached its output, and how deeply it is built into the workflow. A scholarship ranking that the panel is free to ignore is still in scope, in the OAIC's example, because the panel considers it.
Examples in and out of scope
The OAIC's fact sheet gives a non-exhaustive list of decisions that would generally be in scope, including:
- recruitment software that sorts candidate profiles and makes hiring decisions
- programs that approve or reject loan or credit applications, or assess insurance eligibility
- programs that prioritise health or disability services, or decide eligibility for a government benefit or housing assistance
- programs that decide admission to an education or training program, or scholarships and grants
- AI-generated reports used to rank employee performance or decide promotions, bonuses or pay
- differential or personalised pricing for significant goods, and facial recognition watchlist matching.
One of its worked examples is a health and aged care provider whose spreadsheet formula scores clients and ranks who to contact first. That is in scope. So is using the ranking to decide whom not to contact, because refusing or failing to act counts as a decision.
Out of scope: a person who makes the decision themselves and uses software for something other than facilitating it, such as a word processor to write the decision up. Decisions whose effect is trivial are also outside the rule, although the OAIC's rideshare example shows that suspending an account can be significant for someone who relies on the service to get to medical appointments.
Where generative AI fits
The OAIC is explicit that generative AI tools, "including chatbots", are computer programs for APP 1.7. Its fact sheet goes further: it considers machine learning or generative AI outputs used to make decisions that significantly affect people "would generally fall within scope of the transparency obligation unless subject to extensive human oversight and control."
That doesn't make every use of an AI assistant automated decision-making. Most everyday uses involve no decision about an individual:
- Usually outside APP 1.7: drafting emails and letters, summarising a policy or meeting, writing marketing copy, translating, brainstorming, answering general questions.
- Likely inside APP 1.7: asking an AI tool to score job applicants, recommend whether a client qualifies for a service, draft a performance assessment that determines a promotion, or triage complaints into those that get a response and those that don't.
The guidelines name this case directly: an employer that "permits or directs employees" to use an AI chat tool to draft performance assessments that determine promotion decisions has arranged for a computer program. Policy matters here. If staff use AI tools informally for decisions about people, your organisation may be covered without knowing it.
In the OAIC's remuneration example, managers use a generative AI tool to propose bonuses and pay rises, with HR oversight and director sign-off, and it is still in scope because managers rely on the output. The OAIC says the picture could change if staff interrogated the outputs, reviewed the underlying evidence and documented why they departed from the recommendation.
APP 1.7 is only one obligation. The OAIC's separate guidance on commercially available AI products recommends, as best practice, that organisations don't enter personal information, especially sensitive information, into publicly available generative AI tools.
What to put in your privacy policy
The OAIC wants information that is plain, specific to your organisation and meaningful to a reasonable person, without "unnecessary amounts of granular technical detail". You may group decisions and kinds of information, but sensitive information such as health information or biometric templates should be clearly identified. Its own examples add a short section headed "Decisions made by computer programs" that lists the kinds of personal information and the kinds of decisions.
An illustrative structure (adapt it to what you actually do):
Decisions made by computer programs. We use software to help assess applications for [service]. It uses [identity details, contact details, income information, health information you provide]. The software makes some decisions automatically, such as [confirming basic eligibility]. For other decisions, such as [prioritising applications], it produces a recommendation that our staff consider before deciding. Contact [privacy contact] to ask about a decision.
The commercial-in-confidence exclusion is narrow. You don't need to disclose trade secrets, such as how a fraud model weights data points, but you still disclose that personal information is used for those decisions. And information about your use of a program for significant decisions that would expose you to "ridicule, embarrassment or public criticism" is not covered by the exclusion.
What happens if you don't comply
The 2024 Act added APP 1.7 to the list of provisions in section 13K of the Privacy Act. That means the OAIC can deal with a missing or inadequate disclosure through infringement notices and compliance notices, and the maximum civil penalty for a section 13K contravention is 200 penalty units. Conduct that is a more serious interference with privacy can attract the higher penalties in sections 13G and 13H.
Checklist: ready by 10 December 2026
- Inventory decision systems. List every system that touches decisions about people: core platforms, SaaS tools with scoring or automation features, spreadsheets with formulas, rules in your CRM or case management system, and AI tools staff use.
- Ask staff how they use AI. Find out whether anyone uses chat assistants to assess, rank or recommend outcomes for customers, clients, applicants or employees.
- Apply the three limbs to each system, using the OAIC's flowchart. When in doubt, the OAIC says to take a cautious approach and disclose.
- Consider vulnerable cohorts. Check whether outcomes could be materially different for children, people with disability or other people experiencing vulnerability.
- Ask vendors for information on what decisions their software makes or recommends and which personal information it uses.
- Sort decisions into two groups: those made solely by a program, and those where a program does something substantially and directly related.
- Draft the privacy policy section in plain language, flag sensitive information, and have it reviewed by whoever owns privacy compliance.
- Publish before 10 December 2026. Government agencies may also want to cross-link their Information Publication Scheme disclosures, as the OAIC suggests.
- Make it repeatable. Add an APP 1.7 check to procurement, new AI features and system changes, and record each assessment in your AI register.
- Set a staff rule for AI tools: which tools are approved, what information may go into them, and that AI outputs used in decisions about people must be reviewed and the reasoning recorded.
If you are building an AI register and policy at the same time, the government's Guidance for AI Adoption includes templates that fit this work.
Give staff an approved AI workspace, processed in Australia
AusGPT gives your team Claude AI with conversations and documents stored and processed in Australia. $29 per user per month, with a free trial.
What APP 1.7 doesn't do
APP 1.7 is a disclosure rule. It does not, by itself, require you to explain an individual decision to the person affected, offer a human review, or stop using automated decisions. It doesn't change the other APPs either: collection, use and disclosure, accuracy (APP 10) and security (APP 11) still apply to the personal information that flows through these systems. Further Privacy Act reforms have been proposed. See our guide to the 2026 Privacy Act reforms for what is law and what is still a draft.
Sources
- Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024), Schedule 1 Part 15
- OAIC: APP Guidelines Chapter 1, APP 1 (updated 30 September 2026)
- OAIC: APP 1.7-1.9 Transparency Obligation Fact Sheet (September 2026)
- OAIC: APP 1.7-1.9 Transparency Obligation Flowchart
- OAIC: New resources on transparency for use of AI and automated decision-making (30 September 2026)
- OAIC: Small business and the Privacy Act
- OAIC: Guidance on privacy and the use of commercially available AI products
Frequently asked questions
- When does the automated decision-making obligation start?
- APP 1.7 to 1.9 commence on 10 December 2026. They apply to decisions made after that date, even if the software was set up, or the personal information collected, before it.
- Does APP 1.7 apply to my small business?
- Only if your organisation is an APP entity. Most businesses with an annual turnover of $3 million or less are not covered by the Privacy Act, but some are covered regardless of turnover, including health service providers and businesses that trade in personal information. Check the OAIC's small business guidance.
- Does a human reviewing the output take a decision outside APP 1.7?
- Not necessarily. The OAIC says a decision can be in scope even where the program's output is subject to human review. The question is whether the program is a key factor with a direct connection to the decision. For machine learning or generative AI outputs used in significant decisions, the OAIC's view is that they are generally in scope unless subject to extensive human oversight and control.
- Is using ChatGPT, Copilot or Claude at work automated decision-making?
- Not by itself. Drafting emails, summarising documents or brainstorming doesn't involve a decision about an individual. It becomes relevant when staff are permitted or directed to use an AI tool in a way that is a key factor in a significant decision about a person, such as drafting performance assessments that determine promotions.
- Do I have to publish my algorithm or how decisions are weighted?
- No. APP 1.8 asks for the kinds of personal information used and the kinds of decisions involved. The OAIC says commercial-in-confidence information, such as trade secrets, is excluded, but that exclusion is narrow and doesn't cover information that is merely embarrassing.
- What happens if my privacy policy doesn't include the information?
- APP 1.7 is listed in section 13K of the Privacy Act, so the OAIC can issue an infringement notice or a compliance notice for a failure, and the maximum civil penalty for that provision is 200 penalty units. More serious interferences with privacy can attract higher penalties under other provisions.
Keep reading
Secure AI for your team, processed in Australia
Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.