Operating guide · AI governance
Preparing an Australian Privacy Principles entity for automated-decision transparency
A decision inventory and privacy-policy readiness programme for the December 2026 change.
Gaps to close
- Meet a fixed commencement date
- Find configured and outsourced decisions
- Avoid over-claiming legal certainty
- Align public policy with real operations
Decisions to settle
- Which entities and activities are covered
- Which decisions could significantly affect rights or interests
- What public description is accurate
- What legal review is required
- When the inventory must be rechecked after vendor or workflow changes
How to know it is working
- Coverage decision is recorded
- System and process owners attest to the inventory
- Policy wording maps to actual decision types and data
- Complaints and correction pathways are operational
Working documents
- Automated-decision inventory
- Data and responsibility map
- Draft privacy-policy schedule
- Gap and review register
Putting the routine in place
- 01
Coverage and interpretation
Confirm Australian Privacy Principles entity status and establish legal escalation for uncertain scope and significance questions.
- 02
Decision discovery
Interview process and system owners about ranking, approval, rejection, pricing and other significant effects.
- 03
Data and control map
Record personal-information types, program role, human role, vendor, owner, notices and challenge path.
- 04
Policy and operation
Draft specific policy wording and align notices, contracts, staff procedure, complaints and review.