AI governance
Automated decisions and Australian privacy policies: what changes from 10 December 2026?
What the Australian Privacy Principle transparency changes mean for covered Australian organisations.
From 10 December 2026, an Australian Privacy Principles (APP) entity that arranges for a computer program to use personal information to make, or substantially and directly assist in making, a decision that could reasonably be expected to significantly affect a person's rights or interests may need additional information in its privacy policy. Preparation starts with the decisions, data and systems behind the public wording. This guide was checked on 2 September 2026 against material from the Office of the Australian Information Commissioner; check its final guidance before relying on this note after publication.
The decision
What changes the answer
- The obligation concerns qualifying automated decisions that use personal information; ordinary uses of artificial intelligence (AI) or automation may sit outside this specific provision.
- Many businesses with annual turnover of $3 million or less are currently outside the Privacy Act, although important exceptions apply.
- The inventory should cover purchased software, configured workflows and outsourced services alongside tools built internally.
- Privacy wording should match actual operating controls, vendor arrangements and complaint pathways.
Where the decision commonly goes wrong
- Assuming the small-business exemption applies without checking exceptions
- Treating a human click as proof that a decision was not substantially automated
- Publishing a broad AI statement that does not identify the kinds of information and decisions involved
- Relying on draft guidance after the OAIC publishes a final position
A sensible way to decide
- 01
Confirm whether the Privacy Act covers the organisation
Use the Commissioner's small-business checklist and qualified advice where the answer depends on health services, personal-information trading, contracting or related entities.
- 02
Inventory decisions across applications
Ask where software recommends, ranks, approves, rejects, prices, prioritises or materially changes a person's access, work, money or services.
- 03
Map personal information and responsibility
Record the information used, decision type, system owner, vendor, human intervention and the path for challenge or correction.
- 04
Assess significance
Document why a decision may or may not significantly affect rights or interests. Escalate uncertain interpretations for legal review.
- 05
Update policy and operating controls
Make the privacy-policy statement specific enough to be useful, then align notices, staff procedures, vendor records and review dates with the public wording.
Check before committing
- Privacy Act coverage checked
- Decision inventory completed
- Personal-information types mapped
- Human role recorded
- Policy wording legally reviewed where needed
- Complaints and correction path tested
Material checked for this note
- Office of the Australian Information Commissioner — Australian Privacy Principle 1
- Office of the Australian Information Commissioner — Transparency in automated decision making
- Office of the Australian Information Commissioner — Small business and the Privacy Act
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.