09 October 2026
New guidance from the Office of the Australian Information Commissioner (OAIC) will assist businesses to identify the immediate steps they should take to prepare for the upcoming transparency obligation concerning automated decision making (ADM).
From 10 December 2026, organisations that use computer programs (including software, algorithms or artificial intelligence) to make or inform significant decisions about individuals’ rights or interests must explain that use in their privacy policies. That obligation is set out in the new Australian Privacy Principles (APPs) 1.7 – 1.9.
Recently, the OAIC issued its final guidance on the new transparency obligation, which follows an issues paper released by the OAIC in May 2026. The guidance confirms the broad scope of the transparency obligation, with the OAIC urging organisations to treat borderline use cases as in scope. As a result, the compliance burden on organisations is likely to be greater than many expect, particularly where computer programs are integrated across multiple business functions. Organisations should therefore begin mapping potentially in-scope systems, evaluating how those systems inform decision-making, and working with third-party technology providers to gather the information needed to support compliance. Doing so will ensure they are well-placed to update their privacy policies ahead of the 10 December deadline.
We explore the key takeaways from the finalised guidance, and the practical steps businesses should take before 10 December 2026.
Under the new APP 1.7, the automated decision making (ADM) transparency obligation applies where three conditions are met:
Where these conditions are satisfied, APP 1.8 requires entities to disclose the following details of their use of ADM in their privacy policy:
The OAIC's new resources, including fact sheets for businesses and government agencies, a scope-assessment flowchart and updated APP 1 guidance, provide practical guidance for organisations applying the new APPs to their activities.
The term ‘computer program’ is defined broadly and includes rule-based processes, machine learning and generative AI tools, chatbots, and everyday software such as apps, word-processing tools and spreadsheets. The examples of in-scope programs provided in the OAIC guidance include a spreadsheet formula used to rank clients for access to health services. Businesses should avoid interpreting the term narrowly and consider how the transparency obligation may apply to all programs used across their operations, including everyday software.
The OAIC guidance provides examples of when organisations may have ‘arranged for’ a computer program to inform or make a decision. Those examples include:
Importantly, using third-party software to facilitate a decision does not transfer the disclosure obligation to the third-party vendor, even if the organisation has no control over the software’s parameters. The OAIC expects organisations’ contractual arrangements with their third-party software providers to clarify which entity retains responsibility for, and control over, the relevant decision. Organisations should also consider whether they have appropriate contractual rights (or other mechanisms) to obtain any information from their vendors where required to make the ADM disclosures in their policies.
The concept of a ‘decision’ is broad. It includes choosing to take, or not to take, an action, and deliberately doing or refusing to do something, where the outcome could reasonably be expected to benefit or disadvantage an individual. The OAIC guidance includes a non-exhaustive list of decisions that would generally be in scope of the transparency obligation:
To be captured by the new transparency obligation, a program must be substantially and directly related to making a decision. The OAIC guidance defines ‘substantially’ as meaning the program is a ‘key factor in facilitating’ the decision.
Programs can still be captured where the output is either advisory or determinative. Human involvement in a decision will not itself exclude a program from scope (e.g. a decision may be captured even where the output is reviewed or contributes only partially to the decision-making process). The OAIC's view is that machine learning or generative AI outputs used for significant decisions will generally be captured ‘unless subject to extensive human oversight and control’. The OAIC does not define ‘extensive human oversight and control’. However, it indicates that relevant measures may include interrogating outputs, reviewing the underlying inputs, narrowing the program's parameters, relying on additional evidence and documenting why a decision departs from the output.
Ultimately, a computer program may be substantially and directly related to a decision where it:
Given this breadth, organisations that have already mapped automated decisions for the purposes of Article 22 of the European Union’s General Data Protection Regulation (GDPR) should not rely solely on that work. Article 22 governs decisions based solely on automated processing. Unlike the new Australian obligation, meaningful human involvement will generally take decisions outside the scope of the Article 22 requirements.
The new transparency obligation applies only where a decision significantly affects an individual's rights or interests. An impact is ‘significant’ if it is more than trivial and has the potential to materially influence the individual's circumstances or outcomes. A ‘right’ is a moral or legal entitlement to have or do something, while an ‘interest’ is a relevant concern, benefit, stake or claim.
The OAIC lists access to essential food, healthcare and aged care, financial assistance, education, banking and credit, telecommunications, utilities, employment and housing as interests that would generally be in scope.
The guidance includes two illustrative scenarios, which demonstrate the range of potential rights and interests organisations will need to consider:
The assessment must also account for the circumstances of vulnerable individuals, as the same decision may have a greater impact on people experiencing vulnerability than on the broader population. Businesses should not assume that routine pricing, marketing or recruitment tools fall outside the regime. These tools warrant particular scrutiny, especially where they influence access to essential goods, employment or services.
The guidance provides practical direction on how organisations can satisfy the disclosure requirement in APP 1.8 and determine the appropriate level of detail for their privacy policy disclosures. In particular, disclosures:
Generic, high-level transparency statements will not be sufficient to satisfy the obligation.
Businesses have been concerned that the new disclosure requirements could expose the confidentiality of proprietary models or algorithms to competitors. While the legislation addresses this directly by excluding commercially sensitive information and trade secrets from the transparency obligation, the exclusion is narrower than it might first appear. It covers only information whose release could harm the entity's commercial interests, not all information with commercial value. Information that would expose a business to ridicule, embarrassment or public criticism is not exempt from disclosure. In deciding whether information qualifies, the OAIC suggests asking:
In practice, the distinction is generally between how a tool works (which may be protected) and the fact that it is used (which must be disclosed). For instance, in the OAIC's banking example, the way a proprietary fraud model weights its data points could be kept confidential, but the bank would still have to disclose that personal information is used to detect fraud and to decide loan and credit applications.
In light of the OAIC’s final guidance, APP entities should now:
Authors
Partner
Partner
Associate
Associate
Associate (Admitted in England & Wales, not admitted in Australia)
Law Graduate
Tags
This publication is introductory in nature. Its content is current at the date of publication. It does not constitute legal advice and should not be relied upon as such. You should always obtain legal advice based on your specific circumstances before taking any action relating to matters covered by this publication. Some information may have been obtained from external sources, and we cannot guarantee the accuracy or currency of any such information.