Privacy Act 2026

Automated Decision-Making Disclosure: What You Must Add to Your Privacy Policy by 10 December 2026 (Australia)

From 10 December 2026, Australian privacy policies must disclose automated decision-making that significantly affects people. What the new APP 1 obligation requires, which tools trigger it, and how to write the disclosure — plain English, source-checked.

By Daniel Ebiau, AMLCompliant ·

One of the most concrete deadlines in Australia's 2026 privacy reform is this: from 10 December 2026, your privacy policy must disclose certain automated decision-making (ADM). Miss it and your policy is non-compliant under APP 1 — the exact kind of administrative breach the OAIC can act on. Here is what the obligation is, who it hits, and how to write the disclosure.

What the law actually requires

The Privacy and Other Legislation Amendment Act 2024 adds a new APP 1 transparency requirement. From 10 December 2026, where a computer program makes — or does a thing substantially and directly related to making — a decision that could reasonably be expected to significantly affect an individual's rights or interests, your privacy policy must disclose:

  • the kinds of personal information used in that decision-making, and
  • the kinds of decisions made (or substantially supported) by the program.

(Source: OAIC ADM consultation.)

The OAIC opened its draft ADM guidance consultation on 18 May 2026, with submissions closing 15 June 2026. Final guidance had not been issued as at June 2026, so treat any specific "final guidance" date you see as an estimate, not a fixed fact.

Which tools trigger it?

The test is about the effect of the decision, not how fancy the technology is. A plain rules engine can count just as much as a machine-learning model. Common triggers in small Australian businesses include:

  • Credit or eligibility decisions (approve/decline, limits)
  • Pricing that materially changes what a person pays
  • Tenant screening or rental application scoring
  • Hiring/screening filters that reject candidates
  • Risk scoring — including AML/CTF customer risk scoring, which is why Tranche 2

firms should pay attention (see AML Tranche 2 and the Privacy Act)

If you are unsure whether your use of software or AI counts as "automated decision-making," read are you making automated decisions?

How to write the disclosure (an outline)

A compliant ADM section of your privacy policy generally needs to:

  1. State that you use automated decision-making in specified situations.
  2. List the kinds of decisions the program makes or substantially supports

(e.g. "assessing eligibility for X", "scoring AML/CTF customer risk").

  1. List the kinds of personal information the program uses (e.g. identity

details, transaction history, financial information).

  1. Use plain language a customer can understand — APP 1 is about transparency.
  2. Keep an internal ADM inventory so the disclosure stays accurate as tools

change: each tool, the decision it affects, the data it uses.

The disclosure itself is part of your broader privacy policy — see how to write a privacy policy that complies in 2026.

Don't conflate the penalties

A non-compliant privacy policy (including a missing ADM disclosure) sits in the low penalty tier — up to $330,000 for incorporated entities, with infringement notices up to $66,000. That is a different tier from the high-tier serious-interference penalties. Keep them separate; the detail is in Privacy Act penalties 2026.

General information only, not legal or compliance advice. Current to June 2026; ADM guidance was still in consultation as at June 2026. Confirm your obligations at oaic.gov.au or with a qualified adviser. Last verified: 8 June 2026.

Run the free ML/TF risk assessment →

Frequently asked questions

When does the automated decision-making disclosure obligation start?
It is mandatory from 10 December 2026, as a new APP 1 transparency obligation under the Privacy and Other Legislation Amendment Act 2024. Source — OAIC.
What exactly has to be disclosed?
Where a computer program makes — or does something substantially and directly related to making — a decision that could reasonably be expected to significantly affect a person's rights or interests, your privacy policy must disclose the kinds of personal information used and the kinds of decisions made. Source — OAIC.
Is this legal advice?
No. General information drawn from OAIC guidance, current to June 2026. Confirm your obligations with the OAIC or a qualified adviser.
automated decision-makingadmprivacy policyapp 1oaicprivacy act 1988