Automated decision-making transparency in your privacy policy (APP 1.7–1.9)
From 10 December 2026, APP entities that use computer programs to make or substantially assist decisions that significantly affect individuals must say so in their APP privacy policy.
Who must comply
APP entities (turnover over $3M, or within a s 6D(4) carve-out) whose computer programs make or substantially assist decisions that could significantly affect individuals.
What triggers it
Using personal information in a computer program that makes, or substantially and directly assists, a significant decision about an individual (credit, insurance, pricing, hiring, access to services).
When due
Privacy policy updated by 10 December 2026, then kept current whenever an automated decision process is added or changed.
Evidence required
Register of automated decision processes (what decision, which personal information, solely automated or assisted, significance assessment); updated APP privacy policy with the APP 1.8 statements; owner and review date for each process.
Max penalty
A breach of an APP is an interference with privacy, enforceable by the OAIC under the Privacy Act's general enforcement and civil penalty regime.
Effective from
10 December 2026
Who must comply with this? The applicability test by industry, business structure and size.
Summary
The Privacy and Other Legislation Amendment Act 2024 inserted APP 1.7–1.9. From 10 December 2026, APP 1.7 requires an APP entity to include the information in APP 1.8 in its APP privacy policy if (a) it has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision, (b) the decision could reasonably be expected to significantly affect the rights or interests of an individual, and (c) personal information about the individual is used in the program's operation. APP 1.8 requires the policy to describe the kinds of personal information used and the kinds of decisions made solely by the program or substantially assisted by it. The OAIC's APP 1 guidelines (version 2.0, updated 30 September 2026) give examples such as differential pricing and limits on access to employment, and note that commercially sensitive information about the system need not be disclosed. The obligation applies only to APP entities — removal of the small business exemption is a separate, proposed reform and not law.
Enforced by
Source legislation
Topics
Related
- CWLTHNotifiable Data Breach (NDB) schemeUnder the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- CWLTHAPP 3 collection of sensitive informationAPP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
- CWLTHPrepare for the proposed removal of the small business exemptionRemoving the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
- CWLTHComply with credit reporting obligations (Part IIIA Privacy Act)Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
- CWLTHAPP 8 cross-border disclosureBefore disclosing personal information overseas, APP 8 requires reasonable steps so the recipient meets the APPs — unless an exception applies. Steps and exceptions.
- CWLTHComply with doxxing criminal offence (Criminal Code s 474.17C)From 11 December 2024, using a carriage service to dox personal data with menace is criminal.
Reading
Frequently asked questions
- Who must comply with Automated decision-making transparency in your privacy policy (APP 1.7–1.9)?
- APP entities (turnover over $3M, or within a s 6D(4) carve-out) whose computer programs make or substantially assist decisions that could significantly affect individuals.
- What triggers Automated decision-making transparency in your privacy policy (APP 1.7–1.9)?
- Using personal information in a computer program that makes, or substantially and directly assists, a significant decision about an individual (credit, insurance, pricing, hiring, access to services).
- When is Automated decision-making transparency in your privacy policy (APP 1.7–1.9) due?
- Privacy policy updated by 10 December 2026, then kept current whenever an automated decision process is added or changed.
- What is the maximum penalty for Automated decision-making transparency in your privacy policy (APP 1.7–1.9)?
- A breach of an APP is an interference with privacy, enforceable by the OAIC under the Privacy Act's general enforcement and civil penalty regime.
- What evidence is required for Automated decision-making transparency in your privacy policy (APP 1.7–1.9)?
- Register of automated decision processes (what decision, which personal information, solely automated or assisted, significance assessment); updated APP privacy policy with the APP 1.8 statements; owner and review date for each process.
Source: https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information. Rules Mate is not a law firm. Always verify against the live regulator source before acting.