Legal Insights

Ten weeks to go: OAIC releases guidance on new automated decision-making transparency obligations under APP 1

• 07 October 2026 • 11 min read

On 30 September 2026, the Office of the Australian Information Commissioner (OAIC) released a suite of new resources to guide compliance with automated decision-making (ADM) transparency obligations that will commence on 10 December 2026 under Australian Privacy Principle 1 (APP 1). The new provisions (i.e. APP 1.7 to 1.9) require APP entities to include specific information in their privacy policies about the use of computer programs to make, or substantially and directly inform, decisions that significantly affect individuals’ rights or interests.

With only around ten weeks until the new obligations commence, the OAIC’s guidance is both welcome and pressing. Organisations that have not yet begun their assessment work should consider doing so as a matter of priority.

The practical challenge many of our clients are facing is that affected systems are frequently not labelled as AI or centrally governed as AI tools. Instead, they may be embedded in routine processes across HR, finance, marketing, customer service and operations, making a cross-functional review essential.


Quick links: 

What changes on 10 December 2026?
What has the OAIC released?
Key takeaways from the guidance
Why it matters - APP 1 as the cornerstone
Our insights
What should you be doing now?
How Maddocks can help


What changes on 10 December 2026? 

From 10 December 2026, an APP entity’s privacy policy must contain specific disclosures about the entity’s use of computer programs in decision-making. This obligation is triggered by a three-limb test:

  • Limb 1 – Arrangement: the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision. This captures in-house and proprietary software, procurement of third-party programs, configuration or customisation of off-the-shelf software, authorisation of determinative decisions by a program, and reliance on advisory outputs.
     
  • Limb 2 – Significance: the decision could reasonably be expected to significantly affect the rights or interests of an individual. ‘Significantly’ means more than trivial - there must be the potential to considerably influence an individual’s circumstances or outcomes. Rights include moral or legal entitlements; interests include concerns, benefits, stakes or claims. Vulnerability is a relevant consideration.
     
  • Limb 3 – Personal information: lastly, to trigger the disclosure obligation, personal information about the individual must be used in the operation of the program.

Where all three limbs are satisfied, the entity’s privacy policy must describe:

  1. the kinds of personal information used in the operation of such programs;
  2. the kinds of decisions made solely by a computer program; and (c) the kinds of decisions for which ‘a thing substantially and directly related to the decision’ is done by a computer program.

What has the OAIC released? 

The OAIC has released a fact sheet, supplementary guidance for government agencies, a decision-making flowchart and updated APP 1 Guidelines.

Together, these resources explain the three-limb test, provide worked sector examples and include sample privacy policy wording.

Key takeaways from the guidance 

  • Broad meaning of ‘computer program’

    The OAIC adopts a deliberately expansive interpretation. A ‘computer program’ includes pre-programmed rule-based processes, artificial intelligence and machine learning systems, software applications, word-processing tools, and generative AI including chatbots. It is not limited to sophisticated or novel technologies.

  • ‘Arranged for’ is broadly framed

    An entity will have ‘arranged for’ a computer program where it has developed, procured, configured, customised, authorised or relied upon that program. This includes reliance on advisory outputs and the use of third-party vendor software, regardless of whether the entity has visibility into the program’s inner workings.

  • Advisory outputs and human review

    A computer program need not replace an entire decision-making process to be in scope. Advisory outputs that inform, influence or shape a human decision may still satisfy the ‘substantially and directly’ test. The OAIC considers that machine learning and generative AI outputs used for significant decisions will generally be in scope unless they are subject to extensive human oversight and control.

    The guidance illustrates this through the ‘Esperance’ example, where a generative AI tool suggesting employee bonuses remains in scope despite HR review and director approval, unless staff actively interrogate the outputs, review underlying KPIs, narrow parameters, seek additional evidence and document their reasoning for any divergence.

  • HR and recruitment are likely to be a key risk area

    Many organisations are already using AI and other automated tools across the employment lifecycle.

    The OAIC’s examples make clear that these uses may fall within the new disclosure obligations even where an HR professional or manager makes the final decision. Tools that rank candidates or generate performance scores may still be substantially and directly related to decisions that significantly affect individuals.

    In our experience, these systems are not always identified as AI, or recorded in an organisation’s central AI register. They may be embedded in recruitment platforms, HR information systems or services supplied by third-party vendors. HR, recruitment, employment and privacy teams should therefore be closely involved in the assessment process.

    We have previously considered the broader employment law risks associated with using AI in HR and recruitment: AI in the Workplace: What HR, safety and employment law professionals need to know

  • ‘Significantly affect’ and vulnerability

    The threshold of ‘significantly’ means more than trivial. The guidance confirms that even comparatively small financial differences can be significant. The ‘Daintree’ example finds that postcode-based pricing of essential goods (amounting to $132 more per year on baby formula) is sufficient. Vulnerability of the affected cohort is a relevant factor in assessing significance.

  • What the sector examples tell us

    The guidance draws heavily on sectors that are already under regulatory scrutiny:

    • Healthcare and aged care: tools may be used to triage patients, assess eligibility, prioritise access to services or inform care decisions using health and other sensitive information.
       
    • Property and housing: programs may assess rental applications, rank applicants, allocate housing or inform decisions about eligibility, pricing and access.
       
    • Financial services: automated processes may support credit scoring, lending, fraud detection and insurance pricing.

    Each of these examples involve sensitive information, vulnerable individuals and decisions with potentially significant consequences. Given the sensitivity of the information and potential consequences for individuals, organisations in these identified sectors should pay particular attention to compliance with these new obligations and ensuring transparency about how automated systems are used.

  • Third-party vendors

    The transparency obligation rests with the APP entity that uses personal information in the operation of a computer program - not the vendor.

    However, the OAIC expects vendors to provide clear, high-level information about how their software can be used, so that customer entities can make the necessary privacy policy disclosures.

  • Commercial-in-confidence

    The guidance makes clear that entities are not required to disclose commercially sensitive information, trade secrets, or proprietary algorithmic detail. However, information cannot be withheld simply because it may expose the entity to ridicule, embarrassment or public criticism. 

    The OAIC suggests considering factors such as uniqueness, competitive advantage, and whether an arm’s-length buyer would pay for the information. For example, the specific weighting used by a bespoke tool to detect fraudulent transactions may be confidential, but the fact that personal information is being used by a fraud detection tool is not.

  • Level of detail and grouping

    Disclosures should be understandable, avoid overwhelming technical detail, and be tailored to the entity’s audience. Entities may group categories of decisions and personal information, but the groupings must be meaningful to a reasonable person. Sensitive information such as health data or biometric templates should be described with particular clarity.

  • Not just AI

    It is critical to appreciate the breadth of the new obligations under APP 1.7–1.9. These obligations are not limited to artificial intelligence. They apply wherever an entity has arranged for a computer program to make or inform decisions that significantly affect individuals’ rights or interests. That language captures a very wide range of everyday business processes, many of which would not ordinarily be characterised as ‘AI’.

    Non-AI examples that may fall within scope include:

    • spreadsheet formulae used to triage, score or rank clients (e.g. in aged care or health services);
    • rule-based eligibility calculators used to determine government benefits, housing
    • allocation, or insurance;
    • configured or customised off-the-shelf software (e.g. SaaS platforms for service delivery or HR);
    • pricing engines that vary prices by postcode or demographic factors;
    • programs which target advertising or job advertisement based on age, gender or other personal attributes;
    • automated fraud detection rules; and 
    • credit scoring and loan approval algorithms.

    A wide range of business processes may potentially be caught by the new obligation - extending well beyond any ‘AI register’ that an organisation may already maintain.

    Entities should avoid the trap of assuming these obligations are only about AI.

Why it matters – APP 1 as the cornerstone

APP 1 is the most fundamental obligation in the Australian Privacy Principles. A privacy policy that accurately describes an entity’s personal information handling practices is the foundation upon which the other APPs rest. If the privacy policy is inaccurate or incomplete, risks of non-compliance with other APPs is increased - particularly when a data breach occurs, a complaint is made, or the OAIC conducts an investigation.

Many organisations may find themselves non-compliant on 10 December 2026 simply because they have not identified and assessed all relevant computer programs across their business. The exercise is not straightforward: it typically requires consultation across multiple business units (i.e. marketing, finance, customer, operations and technology teams), many of which may have deployed some form of automated processing.

There is also the prospect of regulatory scrutiny. Last summer, the OAIC conducted a privacy compliance sweep to assess compliance with APP 1 obligations by certain sectors which collect information through in-person collections. It is possible that the OAIC may undertake a similar privacy policy compliance sweep over the coming summer period, this time targeting the new ADM transparency requirements in specific sectors. Organisations should ensure their assessment is complete and their privacy policies are updated well before the holiday period.

Following recent reforms, the OAIC has the power to issue infringement notices in respect of certain APP 1 privacy policy deficiencies. 

Organisations should consider whether their APP 5 collection notices require aligned updates - if computer programs are being used in ways that are newly disclosable in the privacy policy, the notices given at the point of collection may also need revision to remain accurate and consistent.

Our insights

“The OAIC promised this guidance in September and delivered on that promise at the eleventh hour. The guidance is helpful, providing practical examples across different sectors of when these new obligations will apply. However, there is now limited time before the 10 December 2026 commencement date.

We have been assisting clients to prepare for these changes for more than a year, including through assessment tools designed to support a methodical review process and document key decision-making. The exercise can be complex, often requiring consultation across multiple business units such as marketing, finance, customer and operational teams which may all have deployed some form of automated processing. These need to be identified and then a careful application of the relevant legal test applied. Organisations that have not yet started should consider undertaking a rapid assessment as soon as possible and factor this work into end-of-year planning.

I also think there is some possibility that the OAIC will undertake a privacy policy compliance sweep over the summer period, similar to the exercise it conducted last year where it targeted certain sectors to see if they had dealt with in person collection. Organisations should ensure they have completed their assessment and updated their privacy policies to deal with mandatory disclosure obligations before then.”

— Sonia Sharma, Partner, Maddocks

“The challenge for organisations is not simply updating their privacy policy. It is identifying every relevant use of automated processing across the business, working out which systems fall within scope and documenting that assessment. With the obligations commencing on 10 December, this needs to be a coordinated, cross-functional exercise.”

— Harriet Royle, Special Counsel, Maddocks

“A key area of uncertainty for clients is the extent of human oversight required before a system or process falls outside the new disclosure requirements. Although OAIC's guidance assists in interpreting this threshold, the ultimate assessment will depend on a careful examination of the specific decision-making process, and the level of human involvement that occurs in practice.”

— Georgia Hunt, Special Counsel, Maddocks

What should you do now?

Consulting with relevant business units. Identify all teams across the organisation that may have deployed automated processing of personal information. A cross-functional approach is essential.

Relevant systems may include recruitment screening tools, employee performance and remuneration platforms, patient or client triage tools, tenancy and housing application systems, credit or insurance scoring models, fraud-detection systems, eligibility calculators and software used to prioritise access to services.

Carrying out an ADM assessment. APP entities will need to carry out a detailed assessment of its systems and processes to determine the extent of any ADM used and in each case consider whether:

  • a computer program makes a decision, or performs an act or function that is substantially and directly related to making a decision;
  • the decision significantly affects the rights or interests of an individual; and
  • the computer program uses the personal information of the individual to make the decision.

This is likely to be a detailed process for most complex organisations. While OAIC’s latest guidance provides helpful support to APP entities making this assessment, determining the boundaries of:

a.         whether a computer program is used to make, or is substantially and directly related to making, a decision; and

b.         what decisions ‘significantly’ affect an individual’s rights or interests, will likely involve many judgement calls.

APP entities will also need to make an assessment of third-party arrangements and the extent to which third-party providers adopt ADM in the services they provide to an organisation.

Entities should leave sufficient time to engage with service providers to ensure they have an accurate understanding of ADM embedded in its systems.

Clearly documenting assessment and decision-making processes. For each computer program identified, record the assessment of whether it falls within scope of APP 1.7–1.9, including the reasoning applied at each limb of the test. This documentation will be important in demonstrating compliance.
Updating privacy policies to include any required disclosures. If an assessment concludes that no relevant systems are being used, consider stating this expressly. Given the guidance, organisations should generally err on the side of caution (the OAIC has stated that entities in doubt should take a cautious approach and include the APP 1.8 information in their privacy policy). Also consider whether broader privacy policy updates are appropriate, including disclosures regarding AI use that may not trigger the mandatory provisions.
Updating PIAs and AI risk assessment frameworks. Incorporate the APP 1.7–1.9 assessment process and outcomes into existing privacy impact assessment and AI risk assessment frameworks to ensure ongoing compliance as new systems are deployed.
Providing training and education to relevant teams. Ensure that staff who procure, configure or rely upon computer programs understand the new obligations and can identify when the three-limb test may be triggered.

How Maddocks can help 

Our team has been assisting clients to prepare for the ADM transparency obligations for over a year. We have developed and refined an ADM assessment survey and supporting tools designed to facilitate a methodical, cross-functional review of an organisation’s use of computer programs in decision-making and to document the outcomes of that review. We are updating these tools to reflect the OAIC’s newly released guidance.

If you would like assistance with your ADM assessment, privacy policy updates, or any aspect of preparing for the 10 December 2026 commencement, please contact Sonia Sharma, Ooma Khurana, Harriet Royle or Georgia Hunt.

Sonia Sharma

Sonia has wide ranging experience advising on technology, cyber, telecommunication and general commercial matters, specialising in cyber and data resilience advice.

View profile

Ooma Khurana

Ooma provides specialist legal advice to both public and private sector clients with a focus on privacy, data protection and technology.

View profile

Harriet Royle

Harriet advises both private and public sector organisations on a range of commercial projects with a focus on complex IT outsourcing, transformation, information technology and telecommunications.

View profile

Georgia Hunt

Georgia is an experienced commercial lawyer advising government, professional services and education organisations.

View profile

Recent articles

Online Access