The Office of the Australian Information Commissioner (OAIC) published final resources on September 30, 2026 explaining the automated decision-making (ADM) transparency obligation inserted into Australian Privacy Principle (APP) 1 by the Privacy and Other Legislation Amendment Act 2024. The package comprises an APP 1.7-1.9 fact sheet, a supplementary fact sheet for government agencies, a flowchart, and an update to the APP 1 Guidelines, built on 90 written consultation submissions. From December 10, 2026, APP entities that arrange for a computer program to make or inform a decision that could significantly affect an individual's rights or interests must disclose that use in their APP privacy policy.

Australian banks and credit providers, insurers, digital platforms and marketplaces, employers and recruitment firms, and Commonwealth agencies that use computer programs for credit, underwriting, claims, account, content, hiring, eligibility or service decisions must add the APP 1.8 information to their privacy policy by December 10, 2026, or the OAIC can investigate and take regulatory action under the Privacy Act 1988 for non-compliance with APP 1.

What did the OAIC publish on September 30, 2026?

The OAIC's media centre released four items that operationalise APP 1.7 and APP 1.8: the APP 1.7-1.9 Transparency Obligation fact sheet, a supplementary fact sheet for government agencies, an APP 1.7-1.9 Transparency Obligation flowchart, and an update to the APP 1 Guidelines chapter. The Privacy and Other Legislation Amendment Act 2024 (Royal Assent December 10, 2024) inserted these principles into the Privacy Act 1988, with the ADM transparency duty commencing on December 10, 2026, while the package's statutory tort for serious invasions of privacy and criminal doxxing offence commenced earlier on June 10, 2025.

Reform (Amendment Act 2024)What it doesCommences
Statutory tort of serious invasion of privacyPrivate right of action for serious invasions of privacyJune 10, 2025
Criminal doxxing offenceCriminalises the malicious release of personal dataJune 10, 2025
APP 1.7 / APP 1.8 ADM transparencyPrivacy policy disclosure of automated decision useDecember 10, 2026

Who must disclose automated decision use in their privacy policy?

The duty engages any APP entity that meets the three conditions in APP 1.7: it has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision (APP 1.7(a)); the decision could reasonably be expected to significantly affect an individual's rights or interests (APP 1.7(b)); and personal information about the individual is used in the operation of the program (APP 1.7(c)). APP entities are organisations with an annual turnover above AUD 3 million and certain small entities, plus all Commonwealth agencies.

By market exposure, the actors the OAIC's resources point to are banks and credit providers running automated credit decisions; insurers using programs for underwriting or claims; digital platforms and marketplaces making account, access or content decisions affecting users; employers and recruitment firms using programs in hiring or workforce decisions; and Commonwealth agencies using programs for eligibility or service decisions about individuals. A bank running program-based credit scoring, an insurer triaging claims by software, and a platform suspending accounts by algorithm all fall inside APP 1.7 when the outcome can significantly affect a person.

What must APP entities add to their privacy policy by December 10, 2026?

Where the APP 1.7 conditions are met, APP 1.8 requires the privacy policy to set out three categories of information:

  • the kinds of personal information used in the operation of such computer programs;
  • the kinds of decisions made solely by the operation of such computer programs; and
  • the kinds of decisions for which a thing that is substantially and directly related to making the decision is done by the operation of such computer programs.

Compliance leads should map every computer program that makes, or substantially informs, a decision significantly affecting individuals; identify the personal information each program uses; classify each decision as solely automated or substantially automated; and draft the three APP 1.8 disclosures into the privacy policy and any external-facing AI or ADM notices before the December 10, 2026 commencement. The OAIC flowchart is the fastest way to triage which decisions trigger the duty.

What happens if a privacy policy omits the APP 1.8 information?

From December 10, 2026, a privacy policy that omits the APP 1.8 information is non-compliant with APP 1, which requires APP entities to maintain a clear, up-to-date privacy policy. The OAIC can investigate and take regulatory action under the Privacy Act 1988, including determinations, civil penalty proceedings and enforceable undertakings, using the strengthened enforcement powers delivered by the same 2024 amendment package. A gap between the policy and actual program use is the exposure, not the existence of the program itself.

Live
Australia: Children's Online Privacy Code registration and automated decision-making transparency guidance
Monitor Australian privacy and digital governance instruments under the Privacy Act for the AI, data and digital governance industry.
Email 20+ news

Verify whether your organisation meets the APP 1.7 conditions for each computer program that handles personal information in decision-making, brief privacy, risk and product teams on the December 10, 2026 commencement, and review the OAIC's APP 1.7-1.9 resources against your current privacy policy before drafting the APP 1.8 disclosures. Continuous, per-jurisdiction monitoring from Obsidian surfaces commencements like this when the OAIC publishes, so policies stay aligned without a manual watch.