AI privacy dashboard showing automated decision workflows personal data systems vendors and disclosure review
Back to Blog
Posted by Mahdi
AI and Privacy

AI and Privacy in Australia: What Businesses Need to Change Before 10 December 2026

Australian automated decision-making privacy rules start on 10 December 2026. Learn what APP entities should audit across AI, automation, CRM and business systems.

Your business may already be making automated decisions about customers without calling it AI. From 10 December 2026, some Australian businesses will need to disclose how those systems use personal information.

The change sits inside Australia's Privacy Act, not a standalone AI law. The Office of the Australian Information Commissioner says new APP 1 obligations will apply from 10 December 2026 where an APP entity has arranged for a computer program to use personal information to make, or substantially and directly contribute to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.

That wording matters. The obligation is not limited to ChatGPT, generative AI or machine learning. Traditional software can be relevant too: scoring engines, eligibility rules, workflow automation, risk-rating tools, recommendation systems, CRM automations, spreadsheet logic and vendor platforms may all need review if their output meaningfully contributes to a significant decision about a person.

This article is general technology and implementation guidance, not legal advice. Applicability depends on whether your organisation is an APP entity and whether the statutory conditions are met. The practical point for business leaders is still clear: updating a privacy-policy page should be the last step, not the first. You need to know where automated decisions happen, what personal information is used, which systems or vendors are involved, and how human reviewers rely on the output.

For VaniTech, this connects directly to responsible AI adoption, CRM and workflow automation, application development, privacy-aware system design and website implementation. Related service areas include AI workflow automation, system integration, CMS implementation, ongoing support and small business website solutions.

Deadline Signal

The Visible Change Is a Privacy Policy. The Real Work Is a Systems Audit.

The new APP 1.7 to 1.9 obligations create a transparency requirement, but the disclosure can only be accurate if the organisation understands its automated workflows first.

commencement date for APP 1.7 to 1.9 automated decision privacy-policy obligations

10 Dec 2026

core trigger elements: computer program, significant decision and personal information

3

disclosure areas in APP 1.8 covering personal information and kinds of automated decisions

3

annual turnover threshold for many organisations covered by the Privacy Act, subject to exceptions

$3m+

What Changes on 10 December 2026?

APP 1 already requires APP entities to manage personal information in an open and transparent way and maintain a clearly expressed, up-to-date APP Privacy Policy. The new automated decision-making provisions add more specific disclosure requirements from 10 December 2026.

In practical terms, APP 1.7 asks whether the APP entity has arranged for a computer program to make, or do something substantially and directly related to making, a decision; whether that decision could reasonably be expected to significantly affect an individual's rights or interests; and whether personal information about the individual is used in the operation of the program.

ProvisionPractical meaningBusiness question
APP 1.7Sets the trigger for when automated decision disclosures are required in an APP Privacy Policy.Do we use a computer program to make or materially support significant decisions about individuals using personal information?
APP 1.8Sets the kinds of information the privacy policy must contain when the APP 1.7 trigger is met.Can we describe the kinds of personal information used and the kinds of automated decisions involved?
APP 1.9Clarifies that making a decision includes refusing or failing to make a decision, and that the rule can apply whether the outcome is beneficial or adverse.Are we considering approvals, refusals, failures to decide, service access, eligibility and contract-related outcomes?

The obligation does not apply to every Australian small business automatically. OAIC guidance says Australian Government agencies and organisations with annual turnover above $3 million generally have responsibilities under the Privacy Act, subject to exceptions. Some small businesses are also covered, including private sector health service providers, businesses that sell or purchase personal information, credit reporting bodies, Commonwealth contractors, Consumer Data Right accredited businesses, related businesses, prescribed businesses and businesses that have opted in.

If your business is close to the boundary, handles sensitive information, operates in health, finance, education, childcare, tenancy, credit, identity, insurance, recruitment or government contracting, or is rolling out AI-driven automation, get legal advice on whether you are an APP entity and how the new obligation applies.

What Counts as Automated Decision-Making?

Do not start by asking whether a system is branded as AI. Start by asking whether software meaningfully influences a significant decision about a person using their personal information.

AI and Machine Learning

Models that classify, predict, recommend, summarise, score, rank or generate outputs about individuals can be relevant where those outputs feed into significant decisions.

Rules Engines

Traditional if-this-then-that eligibility, approval, rejection or triage logic can matter if it determines or materially supports the outcome.

Scoring and Risk Tools

Credit scores, fraud scores, safety scores, account risk ratings, priority scores or suitability ratings should be reviewed if they affect access, pricing, terms or service.

Workflow Automation

CRM, case-management and operations workflows can become decision systems when they automatically route, escalate, reject, delay or prioritise people.

Recommendations and Rankings

A recommendation engine may be relevant where ranking or filtering materially affects access to opportunities, services, pricing, support or contractual outcomes.

Vendor Platforms

The system does not need to be owned by the business. Third-party tools and outsourced processes may still need assessment if they are arranged for your decision workflow.

Real Business Examples to Review

The new requirement is highly context-dependent. A low-impact automation that sends a reminder email is not the same as a system that changes someone's access to money, insurance, healthcare, housing, employment opportunities or essential services. The examples below are not legal conclusions. They are practical review candidates.

Business processAutomated componentWhy it needs review
Loan or finance eligibilityCredit scoring, income verification, fraud checks or approval recommendations.It can affect access to credit, contractual rights, pricing or approval.
Insurance quoting and underwritingRisk score, premium calculation, exclusion recommendation or policy eligibility rule.It can affect contract terms, price and access to insurance cover.
Candidate screeningResume ranking, background check scoring, interview shortlisting or suitability prediction.It may affect access to work opportunities, especially if humans rely heavily on system output.
Healthcare or support accessEligibility triage, priority routing, service allocation or care-plan recommendations.OAIC examples include access to significant services such as healthcare.
Customer risk scoringFraud, AML, abuse, credit, vulnerability or account-risk rules in CRM or support systems.It can affect account access, service levels, onboarding, review or refusal decisions.
Automated account decisionsSuspension, downgrade, cancellation, restriction, differential pricing or eligibility rules.It can affect a customer's rights under a contract or access to important services.

The most difficult cases are often hybrid workflows. A person may still click approve, decline or escalate, but the system may have already produced the score, recommendation, ranking or summary that materially shaped the decision. Gilbert + Tobin and Ashurst both warn against assuming that a human-in-the-loop process is automatically outside scope.

Automated decision-making privacy audit workflow mapping decisions personal data systems vendors disclosures and governance
An ADM privacy audit should connect business decisions, personal data, systems, vendors, human review and public disclosures, rather than treating the privacy policy as a standalone page update.

Why Updating the Privacy Policy Page Alone Is Not Enough

The privacy policy is the public-facing output. It is not the whole job. A short disclosure that says your business uses automated decision-making will not be useful if nobody has checked which decisions are affected, what personal information is used, whether vendors contribute to the decision, whether outputs are accurate, or whether other notices and customer terms say something inconsistent.

A good implementation starts inside the business:

  • Identify decisions: list the customer, applicant, patient, employee, tenant, member or user decisions that could significantly affect rights or interests.
  • Find automated contributions: map where software produces a score, ranking, eligibility outcome, recommendation, summary, triage result or risk rating.
  • Map personal information: include information collected directly, imported from third parties, inferred by software or generated by AI output where it relates to an identifiable person.
  • Check human review: document whether a person genuinely applies independent judgement or mostly follows the system output.
  • Review vendors: confirm what third-party systems do in practice, what data they use, how outputs are generated, and what contractual information rights you have.
  • Align disclosures: ensure privacy policy wording, collection notices, consent flows, customer terms, marketing copy and internal processes tell a consistent story.

Ashurst's 24 August 2026 analysis frames this well: ADM transparency should be treated as broader governance and risk management, not simply a privacy policy update. From a systems perspective, that means the source of truth should be an internal register or architecture map, with the website privacy policy generated from verified facts.

Six Areas to Review Before 10 December 2026

Most organisations should start with a narrow, high-impact audit of automated workflows before trying to rewrite public privacy disclosures.

Decision Inventory

List decisions that affect customers, applicants, patients, staff, members or users. Prioritise finance, insurance, healthcare, support access, eligibility, employment and account decisions.

System Map

Connect each decision to the CRM, website, app, form builder, case-management tool, AI product, rules engine, spreadsheet, data warehouse or vendor platform involved.

Personal Data Map

Record personal information used by each workflow, including direct inputs, imported data, behavioural data, inferred data, risk scores and AI-generated personal information.

Human Review

Document whether staff can understand, challenge and override outputs. A nominal human sign-off may not be enough if the system does the substantive decision work.

Vendor and Integration Review

Review third-party contracts, data processing, model behaviour, API outputs, logging, audit rights, retention, overseas processing and change-notification obligations.

Disclosure Implementation

Update the privacy policy only after the audit. Then keep the policy, collection notices, website forms, consent flows and internal system register in sync as systems change.

What the Privacy Policy May Need to Explain

Where APP 1.7 is triggered, APP 1.8 requires the privacy policy to contain information about the kinds of personal information used in the operation of relevant computer programs, the kinds of decisions made solely by such programs, and the kinds of decisions where a thing substantially and directly related to making the decision is done by such programs.

The disclosure should be written for people, not only lawyers or engineers. It should help an individual understand the broad nature of the decision and the personal information involved without exposing confidential implementation details, security-sensitive information or commercial-in-confidence model design.

A practical disclosure structure could include:

  • the business area or process where automated decision-making is used
  • the kinds of decisions involved, such as eligibility, risk assessment, pricing, prioritisation, account access or service allocation
  • the kinds of personal information used, such as identity, contact, transaction, application, health, financial, location, behavioural, support, device, risk or inferred information
  • whether decisions are made solely by a computer program or whether the program substantially and directly contributes to a human decision
  • where people can ask questions, seek access or correction, or make a privacy complaint

That public wording should be backed by a more detailed internal record. The internal record should show the decision pathway, systems involved, personal data sources, vendor dependencies, human oversight, override process, logging, testing and owner responsible for keeping the disclosure current.

ADM Privacy FAQ

Frequently Asked Questions

Short answers for Australian businesses reviewing AI, automation, CRM and decision-support systems before 10 December 2026.

AI and Automation Audit

Map the Systems Before You Rewrite the Privacy Policy

VaniTech can help identify automated workflows, CRM rules, AI tools, vendor integrations, personal-data flows and website implementation changes so your legal advice can be based on real system evidence.