There are obligations regarding the use of automated decision making coming into force in December 2026. In this insight, these new obligations are broken down and discussed in practical terms to help businesses understand how to comply come December.
What changes on 10 December 2026?
New transparency obligations relating to automated decision-making (ADM) will commence under the Privacy Act 1988 (Cth) (Privacy Act) on 10 December 2026.
The changes were introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) and expand Australian Privacy Principle 1 (APP 1), which requires APP entities to manage personal information in an open and transparent way. From 10 December 2026, this will include greater transparency about certain uses of personal information in automated decision-making. These new obligations require APP entities to include disclosures in their Privacy Policy if:
they have arranged for a computer program to make, or do a thing that is substantially and directly related to making a decision;
the decision could reasonably be expected to significantly affect the rights or interests of an individual; and
personal information about the individual is used in the operation of the computer program to make the decision, is done by the operation of such computer programs.
Making a decision includes refusing or failing to decide. These obligations apply regardless of whether the decision is beneficial or detrimental to the individual.
Who needs to comply?
The new obligations will apply to entities already subject to the Australian Privacy Principles (APP entities). This generally means businesses with an annual turnover of more than $3 million.
Does this only apply to AI?
No. The new rules are not limited to artificial intelligence or generative AI. They apply more broadly to computer programs used in relevant decision-making processes.
Examples of Automated Decision-Making
Let’s break this down with two examples of what this might look in practice.
Consider, a human resources department or recruitment organisation that uses an automated system to analyse job applications. An applicant submits their CV, the system assesses or ranks the application and recommends that the applicant not progress. A human recruiter then reviews that recommendation and rejects the applicant. The fact that a human makes the final decision does not necessarily take the process outside the new provisions as legislation also captures circumstances where a computer program does something that is substantially and directly related to making the decision.
Another example is an automated tenant-screening system. A property manager may use software to assess rental applications against predetermined criteria. If the system automatically filters an applicant out of further consideration, ranks them in a way that materially affects whether their application is considered, or produces a recommendation that substantially influences the final tenancy decision, the process may fall within the new ADM provisions.
What must an APP privacy policy disclose and do now?
From 10 December 2026, APP entities must include the following information in their APP privacy policies:
the kinds of personal information used in the operation of computer programs;
the kinds of decisions made solely by the operation of computer programs; and
the kinds of decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs.
APP entities should use the coming months to understand where automated systems sit within their decision-making processes and determine whether their privacy policies will need to be updated.
What are the risks of non-compliance?
A breach of an APP in relation to an individual's personal information can constitute an interference with privacy under the Privacy Act and expose an entity to regulatory action.
The Privacy Act now contains a tiered civil penalty regime. An interference with privacy can attract a civil penalty of up to 2,000 penalty units ($78,200 as of 1 July 2026), while a serious interference with privacy can expose a body corporate to substantially higher penalties.
Cowell Clarke’s Privacy and Data Protection team can assist businesses to identify where the new ADM requirements may apply as well as review or update privacy policies and related compliance frameworks. If you would like to discuss how these changes may affect your business, please contact Julian Courtney-Stubbs or Sandra Bejo.
This publication has been prepared for general guidance on matters of interest only and does not constitute professional legal advice. You should not act upon the information contained in this publication without obtaining specific professional legal advice. No representation or warranty (express or implied) is given as to the accuracy or completeness of the information contained in this publication and to the extent permitted by law, Cowell Clarke does not accept or assume any liability, responsibility or duty of care for any consequences of you or anyone else acting or refraining to act in relation on the information contained in this publication or for any decision based on it.