

AI and Privacy in Australia: What Businesses Need to Change Before 10 December 2026
Australian automated decision-making privacy rules start on 10 December 2026. Learn what APP entities should audit across AI, automation, CRM and business systems.
Your business may already be making automated decisions about customers without calling it AI. From 10 December 2026, some Australian businesses will need to disclose how those systems use personal information.
The change sits inside Australia's Privacy Act, not a standalone AI law. The Office of the Australian Information Commissioner says new APP 1 obligations will apply from 10 December 2026 where an APP entity has arranged for a computer program to use personal information to make, or substantially and directly contribute to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.
That wording matters. The obligation is not limited to ChatGPT, generative AI or machine learning. Traditional software can be relevant too: scoring engines, eligibility rules, workflow automation, risk-rating tools, recommendation systems, CRM automations, spreadsheet logic and vendor platforms may all need review if their output meaningfully contributes to a significant decision about a person.
This article is general technology and implementation guidance, not legal advice. Applicability depends on whether your organisation is an APP entity and whether the statutory conditions are met. The practical point for business leaders is still clear: updating a privacy-policy page should be the last step, not the first. You need to know where automated decisions happen, what personal information is used, which systems or vendors are involved, and how human reviewers rely on the output.
For VaniTech, this connects directly to responsible AI adoption, CRM and workflow automation, application development, privacy-aware system design and website implementation. Related service areas include AI workflow automation, system integration, CMS implementation, ongoing support and small business website solutions.
The Visible Change Is a Privacy Policy. The Real Work Is a Systems Audit.
The new APP 1.7 to 1.9 obligations create a transparency requirement, but the disclosure can only be accurate if the organisation understands its automated workflows first.
commencement date for APP 1.7 to 1.9 automated decision privacy-policy obligations
10 Dec 2026
core trigger elements: computer program, significant decision and personal information
3
disclosure areas in APP 1.8 covering personal information and kinds of automated decisions
3
annual turnover threshold for many organisations covered by the Privacy Act, subject to exceptions
$3m+
What Changes on 10 December 2026?
APP 1 already requires APP entities to manage personal information in an open and transparent way and maintain a clearly expressed, up-to-date APP Privacy Policy. The new automated decision-making provisions add more specific disclosure requirements from 10 December 2026.
In practical terms, APP 1.7 asks whether the APP entity has arranged for a computer program to make, or do something substantially and directly related to making, a decision; whether that decision could reasonably be expected to significantly affect an individual's rights or interests; and whether personal information about the individual is used in the operation of the program.
| Provision | Practical meaning | Business question |
|---|---|---|
| APP 1.7 | Sets the trigger for when automated decision disclosures are required in an APP Privacy Policy. | Do we use a computer program to make or materially support significant decisions about individuals using personal information? |
| APP 1.8 | Sets the kinds of information the privacy policy must contain when the APP 1.7 trigger is met. | Can we describe the kinds of personal information used and the kinds of automated decisions involved? |
| APP 1.9 | Clarifies that making a decision includes refusing or failing to make a decision, and that the rule can apply whether the outcome is beneficial or adverse. | Are we considering approvals, refusals, failures to decide, service access, eligibility and contract-related outcomes? |
The obligation does not apply to every Australian small business automatically. OAIC guidance says Australian Government agencies and organisations with annual turnover above $3 million generally have responsibilities under the Privacy Act, subject to exceptions. Some small businesses are also covered, including private sector health service providers, businesses that sell or purchase personal information, credit reporting bodies, Commonwealth contractors, Consumer Data Right accredited businesses, related businesses, prescribed businesses and businesses that have opted in.
If your business is close to the boundary, handles sensitive information, operates in health, finance, education, childcare, tenancy, credit, identity, insurance, recruitment or government contracting, or is rolling out AI-driven automation, get legal advice on whether you are an APP entity and how the new obligation applies.
What Counts as Automated Decision-Making?
Do not start by asking whether a system is branded as AI. Start by asking whether software meaningfully influences a significant decision about a person using their personal information.
AI and Machine Learning
Models that classify, predict, recommend, summarise, score, rank or generate outputs about individuals can be relevant where those outputs feed into significant decisions.
Rules Engines
Traditional if-this-then-that eligibility, approval, rejection or triage logic can matter if it determines or materially supports the outcome.
Scoring and Risk Tools
Credit scores, fraud scores, safety scores, account risk ratings, priority scores or suitability ratings should be reviewed if they affect access, pricing, terms or service.
Workflow Automation
CRM, case-management and operations workflows can become decision systems when they automatically route, escalate, reject, delay or prioritise people.
Recommendations and Rankings
A recommendation engine may be relevant where ranking or filtering materially affects access to opportunities, services, pricing, support or contractual outcomes.
Vendor Platforms
The system does not need to be owned by the business. Third-party tools and outsourced processes may still need assessment if they are arranged for your decision workflow.
Real Business Examples to Review
The new requirement is highly context-dependent. A low-impact automation that sends a reminder email is not the same as a system that changes someone's access to money, insurance, healthcare, housing, employment opportunities or essential services. The examples below are not legal conclusions. They are practical review candidates.
| Business process | Automated component | Why it needs review |
|---|---|---|
| Loan or finance eligibility | Credit scoring, income verification, fraud checks or approval recommendations. | It can affect access to credit, contractual rights, pricing or approval. |
| Insurance quoting and underwriting | Risk score, premium calculation, exclusion recommendation or policy eligibility rule. | It can affect contract terms, price and access to insurance cover. |
| Candidate screening | Resume ranking, background check scoring, interview shortlisting or suitability prediction. | It may affect access to work opportunities, especially if humans rely heavily on system output. |
| Healthcare or support access | Eligibility triage, priority routing, service allocation or care-plan recommendations. | OAIC examples include access to significant services such as healthcare. |
| Customer risk scoring | Fraud, AML, abuse, credit, vulnerability or account-risk rules in CRM or support systems. | It can affect account access, service levels, onboarding, review or refusal decisions. |
| Automated account decisions | Suspension, downgrade, cancellation, restriction, differential pricing or eligibility rules. | It can affect a customer's rights under a contract or access to important services. |
The most difficult cases are often hybrid workflows. A person may still click approve, decline or escalate, but the system may have already produced the score, recommendation, ranking or summary that materially shaped the decision. Gilbert + Tobin and Ashurst both warn against assuming that a human-in-the-loop process is automatically outside scope.

Why Updating the Privacy Policy Page Alone Is Not Enough
The privacy policy is the public-facing output. It is not the whole job. A short disclosure that says your business uses automated decision-making will not be useful if nobody has checked which decisions are affected, what personal information is used, whether vendors contribute to the decision, whether outputs are accurate, or whether other notices and customer terms say something inconsistent.
A good implementation starts inside the business:
- Identify decisions: list the customer, applicant, patient, employee, tenant, member or user decisions that could significantly affect rights or interests.
- Find automated contributions: map where software produces a score, ranking, eligibility outcome, recommendation, summary, triage result or risk rating.
- Map personal information: include information collected directly, imported from third parties, inferred by software or generated by AI output where it relates to an identifiable person.
- Check human review: document whether a person genuinely applies independent judgement or mostly follows the system output.
- Review vendors: confirm what third-party systems do in practice, what data they use, how outputs are generated, and what contractual information rights you have.
- Align disclosures: ensure privacy policy wording, collection notices, consent flows, customer terms, marketing copy and internal processes tell a consistent story.
Ashurst's 24 August 2026 analysis frames this well: ADM transparency should be treated as broader governance and risk management, not simply a privacy policy update. From a systems perspective, that means the source of truth should be an internal register or architecture map, with the website privacy policy generated from verified facts.
Six Areas to Review Before 10 December 2026
Most organisations should start with a narrow, high-impact audit of automated workflows before trying to rewrite public privacy disclosures.
Decision Inventory
List decisions that affect customers, applicants, patients, staff, members or users. Prioritise finance, insurance, healthcare, support access, eligibility, employment and account decisions.
System Map
Connect each decision to the CRM, website, app, form builder, case-management tool, AI product, rules engine, spreadsheet, data warehouse or vendor platform involved.
Personal Data Map
Record personal information used by each workflow, including direct inputs, imported data, behavioural data, inferred data, risk scores and AI-generated personal information.
Human Review
Document whether staff can understand, challenge and override outputs. A nominal human sign-off may not be enough if the system does the substantive decision work.
Vendor and Integration Review
Review third-party contracts, data processing, model behaviour, API outputs, logging, audit rights, retention, overseas processing and change-notification obligations.
Disclosure Implementation
Update the privacy policy only after the audit. Then keep the policy, collection notices, website forms, consent flows and internal system register in sync as systems change.
What the Privacy Policy May Need to Explain
Where APP 1.7 is triggered, APP 1.8 requires the privacy policy to contain information about the kinds of personal information used in the operation of relevant computer programs, the kinds of decisions made solely by such programs, and the kinds of decisions where a thing substantially and directly related to making the decision is done by such programs.
The disclosure should be written for people, not only lawyers or engineers. It should help an individual understand the broad nature of the decision and the personal information involved without exposing confidential implementation details, security-sensitive information or commercial-in-confidence model design.
A practical disclosure structure could include:
- the business area or process where automated decision-making is used
- the kinds of decisions involved, such as eligibility, risk assessment, pricing, prioritisation, account access or service allocation
- the kinds of personal information used, such as identity, contact, transaction, application, health, financial, location, behavioural, support, device, risk or inferred information
- whether decisions are made solely by a computer program or whether the program substantially and directly contributes to a human decision
- where people can ask questions, seek access or correction, or make a privacy complaint
That public wording should be backed by a more detailed internal record. The internal record should show the decision pathway, systems involved, personal data sources, vendor dependencies, human oversight, override process, logging, testing and owner responsible for keeping the disclosure current.
Frequently Asked Questions
Short answers for Australian businesses reviewing AI, automation, CRM and decision-support systems before 10 December 2026.
Sources Checked
- OAIC: Chapter 1, APP 1 Open and transparent management of personal information
- OAIC: Rights and responsibilities under the Privacy Act
- OAIC: Consultation on Guidance for Transparency in Automated Decision Making
- Gilbert + Tobin: Automated decision-making transparency under the Privacy Act
- Ashurst Perkins Coie: A quick guide to Australia's new privacy rules
- Ashurst Perkins Coie: Shifting from compliance to defensible decision-making
- OAIC: Guidance on privacy and the use of commercially available AI products
- Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024
Map the Systems Before You Rewrite the Privacy Policy
VaniTech can help identify automated workflows, CRM rules, AI tools, vendor integrations, personal-data flows and website implementation changes so your legal advice can be based on real system evidence.