Skip to content

Learn

What must an Australian business disclose about its automated decisions?

From 10 December 2026, if a computer program uses personal information to make, or substantially help make, a decision that could reasonably be expected to significantly affect someone's rights or interests, your privacy policy has to say so. The obligation is on the privacy policy; the hard part is finding every decision that qualifies.

Written for privacy, risk and compliance leaders in Australian organisations, and the operations people they will ask. Reviewed .

What the obligation says

The Privacy and Other Legislation Amendment Act 2024 added new paragraphs to Australian Privacy Principle 1, the principle that governs what an entity's privacy policy has to contain. According to the Office of the Australian Information Commissioner, those paragraphs commence on 10 December 2026.

From that date, an APP entity that has arranged for a computer program to use personal information to make a decision, or to do something substantially relied on in making a decision, where the decision could reasonably be expected to significantly affect an individual's rights or interests, must set out in its privacy policy the kinds of personal information used and the kinds of decisions made that way.

The Commissioner has also said the obligation applies to decisions made from that date regardless of when the arrangement was put in place. An automated decision that has been running quietly for five years is in scope from the day the provision commences.

This page is a plain summary written for the people who will have to do the finding. It is not legal advice, and the authority on what the provision requires is the Commissioner and the legislation itself.

What counts, and why it is broader than AI

The provision is written about computer programs, not about artificial intelligence. That distinction is the one most likely to catch an organisation out.

A rules engine that declines an application on a threshold is a computer program making a decision. A scoring spreadsheet that a person then approves may be a program doing something substantially relied on. A model that ranks cases for review shapes which people get looked at, which is a decision about their interests even though a human signs it.

So the inventory that matters is not the list of AI tools the organisation bought. It is the list of places where software decides something about a person, or does the work a decision is then based on. Those two lists overlap far less than people expect, and the second is much longer.

The half that nobody writes about

There is a great deal of published guidance on the obligation, most of it from law firms, and it is generally accurate about what the law requires. Very little of it addresses the operational question that follows: how do you find every automated decision you already make?

That gap exists because the finding is not a legal problem. It is a discovery problem, and it looks like this: decisions are embedded in processes, processes span systems and teams, nobody holds a list, and the people who could tell you do not describe what they do as an automated decision because to them it is just how the system works.

A practical way to find them

The approach that works is to start from the processes rather than from the systems, because a decision belongs to a process even when it happens inside a system nobody thinks of as decisive.

  • List the processes that touch individuals: customers, applicants, employees, claimants, patients, students. This is a shorter list than the full process inventory and it contains almost everything in scope.
  • For each one, walk the path an individual takes through it and mark every point where an outcome is determined, narrowed, ranked, scored, prioritised, flagged or routed. Include the points where a person signs off on something a system prepared.
  • At each marked point, ask what produces the outcome. A person applying judgement, a rule in a system, a model, a spreadsheet, or a configuration nobody has looked at in years. Write down which, and where it lives.
  • Ask what personal information goes in. The provision is about programs using personal information, so the inputs matter as much as the logic.
  • Ask who could reasonably be affected and how significantly. This is a judgement, and it is the one worth taking advice on rather than settling internally.

What to write, and what the writing exposes

The disclosure itself is not onerous once the finding is done. It describes the kinds of personal information used and the kinds of decisions made, in language a member of the public can follow, in the privacy policy where a member of the public can find it.

The difficulty is that writing it publicly forces an internal question that can be avoided indefinitely while the list is private: is this decision one we are comfortable describing? An organisation that finds itself reluctant to write a sentence about a particular decision has learned something more valuable than a compliance artefact.

It is also worth keeping the finding rather than only its output. A privacy policy paragraph is the visible tip; the register behind it is what lets you answer the next question, whether that comes from a regulator, a board, or an individual asking why.

Where a process model helps

Everything above can be done with a spreadsheet and a series of conversations, and for a small organisation that is the right answer.

It gets hard when the processes are many, cross several systems, and are not written down, because then the finding is gated on a mapping exercise nobody has done. That is the situation Omni is built for: a model of how the work actually happens, generated from the documents, transcripts and wiki pages the organisation already has, with the AI governance module holding the decisions and their owners in the same model as the processes they sit inside.

The point is not the software. It is that this obligation rewards organisations that already know how their work runs, and gives the ones that do not a deadline to find out.

Common questions

Does this apply to us if we do not use AI?
Possibly. The provision is written about computer programs using personal information to make or substantially assist a decision, not about artificial intelligence. Rules engines, scoring tools and automated eligibility checks can fall within it.
What if a human makes the final call?
A human in the loop does not automatically put the decision outside the provision, because it also covers a program doing something that is substantially relied on in making the decision. Whether a particular arrangement qualifies is a judgement worth taking advice on.
Is it enough to add a paragraph to the privacy policy?
That is the disclosure the provision requires. It is not enough to be confident the paragraph is complete, which needs a record of what you found and how you looked. The paragraph is the output; the register is the work.
Where is the authoritative guidance?
The Office of the Australian Information Commissioner, which consulted on guidance for this obligation and has said it intends to publish it ahead of commencement. Read the Commissioner and the legislation rather than any summary, this one included.

See it against your own processes

A demo runs on your material, not a canned dataset. Bring a process you find hard to explain.