Key Takeaways
- Australia's new Privacy Act automated decision transparency rules start on 10 December 2026 and cover qualifying decisions made from that date, including decisions under existing software arrangements, according to the OAIC's APP 1 guidelines.
- APP entities must describe the kinds of personal information used, the kinds of decisions made solely by computer programs, and the kinds of decisions substantially and directly assisted by computer programs in their privacy policies, where the three statutory conditions apply.
- Most Australian businesses with annual turnover of $3 million or less remain outside the Privacy Act as at September 2026, but the small business exemption has exceptions.
- A human approval step does not automatically exclude an AI workflow: software that recommends or guides a significant decision can fall within the rule, as explained in the OAIC's May 2026 issues paper.
- The new Commonwealth automated decision obligation requires privacy policy transparency; the obligation itself does not create a right to contest a decision or require individual notifications, according to the OAIC.
From 10 December 2026, covered businesses need to explain qualifying automated decision making in their privacy policies. The practical job is to identify where software uses personal information to make, recommend or guide decisions with significant effects on people. I'd start with those workflows before rewriting the policy.
This article provides general information, not legal advice. Use the linked OAIC guidance and get advice on how the rules apply to your business.
When Do the Privacy Act Automated Decision Rules Start?
The commencement date is 10 December 2026. The Privacy and Other Legislation Amendment Act 2024 introduced APPs 1.7, 1.8 and 1.9. The OAIC confirms that the amendments apply to decisions made from that date, regardless of when the software arrangement began.
So an existing system belongs in your review. Buying or configuring software before December does not, by itself, put later decisions outside the rules.
The OAIC's May 2026 issues paper said guidance was intended by September 2026. When I checked on 24 September 2026, I couldn't find the OAIC's final guidance on its site, so check its current material before finalising your policy.
Which Automated Decisions Do the New Rules Cover?
The OAIC sets out three conditions. All must apply:
- The APP entity has arranged for a computer program to make a decision, or do something substantially and directly related to making a decision.
- The decision could reasonably be expected to significantly affect an individual's rights or interests.
- The program uses personal information about that individual to make the decision or do the related thing.
AI is only part of the scope. The issues paper includes ordinary software, apps, word-processing tools and generative AI within its discussion of computer programs.
The OAIC also says decisions can be beneficial or adverse, and include refusing or failing to decide. I'd therefore review favourable decisions and stalled applications alongside refusals.
What Must a Privacy Policy Say About Automated Decisions?
Where the conditions apply, APP 1.8 requires three kinds of information:
| Required information | Question for your workflow review |
|---|---|
| Kinds of personal information used by the programs | What information about the person goes into the process? |
| Kinds of decisions made solely by computer programs | What does the software decide without a human decision-maker? |
| Kinds of decisions for which programs do something substantially and directly related to making the decision | Where does the software's output play a key role in a person's decision? |
A sentence saying you use AI tells the reader very little about those matters. In its 8 September 2026 commentary, Corrs Chambers Westgarth warns that generic statements about using technology to improve services will not suffice.
I'd prepare a plain description of each relevant workflow first, then have the policy wording reviewed against what the system actually does.
Does the Small Business Exemption Apply to the New Rules?
The new rules apply to APP entities. The OAIC says most small businesses are not covered by the Privacy Act, but some are covered regardless of turnover.
The OAIC's exceptions include health service providers, businesses trading in personal information, contractors providing services under a Commonwealth contract, credit reporting bodies and AML/CTF reporting entities. The page also lists other exceptions and businesses that have opted in.
For a law firm, accounting practice or conveyancer that has become an AML/CTF reporting entity, I'd make the OAIC's small business checklist an early stop. A small team or modest turnover is not enough to settle coverage.
Does Using AI to Draft Emails Count as an Automated Decision?
Drafting an email does not settle the question either way. Check what the draft does in the decision process against the three conditions.
As an illustration, polishing the wording of an appointment confirmation differs from recommending that someone be refused a significant service. If the recommendation uses personal information and becomes a key factor in the decision, a person clicking approve does not automatically remove the workflow from scope.
The OAIC's issues paper explains that software can recommend or guide a human decision-maker. It describes "substantially" as being a key factor in facilitating the decision and "directly" as having a direct connection with making it.
For client intake automation, I'd examine what happens after the enquiry summary: who gets accepted, prioritised or referred, and how much the software influences that choice.
What Should a Business Do Before December 2026?
- Establish coverage. Work through the OAIC's small business checklist and resolve uncertainty before assuming an exemption.
- Map decisions. Record the personal information used, the software's output, the decision-maker and the possible effect on the individual.
- Include supplier products. Ask what embedded scoring and recommendations do. Norton Rose Fulbright's commentary recommends reviewing third-party arrangements because the obligation concerns entities that have arranged for automated decision making.
- Review policy wording. Describe the relevant information and decision categories, using the workflow map as the starting point.
- Assign ongoing ownership. I'd nominate someone to review the description when inputs, rules or approval steps change.
Truespeak is built for Australian service businesses that want automation designed, built and then run for them, with a person approving anything sensitive.
Through managed AI operations, Truespeak monitors systems, reviews exceptions and records outcomes. Human approval and workflow records make the process easier to describe in a privacy policy. Neither replaces a legal assessment.
Frequently Asked Questions
Do existing automation systems need review?
Yes. The rules cover qualifying decisions made from 10 December 2026, even if the software arrangement began earlier.
Does human approval remove the disclosure requirement?
Human approval does not automatically exclude a workflow. Software that recommends or guides a human decision can be covered where all three conditions apply, including a significant expected effect on the individual's rights or interests.
Must businesses notify each affected person under this obligation?
The new Commonwealth automated decision obligation itself requires information in the privacy policy, not individual notifications. Separate obligations need their own assessment.
Where should businesses check their small business exemption?
Use the OAIC's small business checklist. Most small businesses are exempt, but exceptions apply regardless of turnover, including for health service providers and AML/CTF reporting entities.
Sources
Checked 26 Sept 2026.
