> ## Content Index
> Fetch the complete content index at: https://www.bushletter.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Businesses will have to tell customers when software makes decisions about them
- URL: https://www.bushletter.com/privacy-act-forces-firms-to-disclose-automated-decisions/
- Published: 2026-08-21T05:00:00.000Z
- Updated: 2026-08-21T04:59:59.000Z
- Description: Three new subclauses of the Australian Privacy Principles will reshape how covered organisations write their privacy policies.
- Author: Editor
- Tags: Legal, Australia

![Zara Kincaid](https://res.cloudinary.com/dz77sb7j1/image/upload/v1774262611/bushletter/authors/zara-kincaid.png)

By **Zara Kincaid** · 2026-08-04

TLDR

Australian organisations covered by the Privacy Act must update their privacy policies to name automated systems that make or substantially drive decisions affecting individuals. The duty catches ordinary business software, including credit checks, fraud scoring and screening tools, not only AI. Affected organisations need a system audit completed before 10 December 2026.

KEY TAKEAWAYS

01Privacy policies must name personal information used and decisions driven by automated programs from December 2026.

02Ordinary rule-based software triggers the duty, not only AI tools like machine learning or generative chatbots.

03The OAIC reads 'substantially' as meaning the program is a key factor in a human's decision, not mere admin support.

04Organisations with annual turnover above $3 million are caught; those below that threshold remain exempt.

05A system audit identifying automated workflows, data inputs and decision ownership must precede any policy disclosure.

## What the law now requires

Three new subclauses of the Australian Privacy Principles will reshape how covered organisations write their privacy policies. The amendments to APP 1 (subclauses 1.7, 1.8 and 1.9) commence on 10 December 2026, giving organisations roughly eighteen months from mid-2025 to audit their software ecosystems and rewrite their public disclosures.[\[1\]](https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information?ref=bushletter.com) The amendments sit inside Schedule 1 of the Privacy Act 1988, which already obliges covered entities to manage personal information openly and maintain an up-to-date privacy policy.

APP 1.7 is the trigger clause. It applies whenever an APP entity has arranged for a computer program to make, or to do a thing substantially and directly related to making, a decision expected to significantly affect an individual's rights or interests, and personal information is used in that process.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com) APP 1.8 then specifies what must appear in the privacy policy: the kinds of personal information the program uses, the kinds of decisions made solely by such programs, and the kinds of decisions for which a program does something substantially and directly related to making the decision.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com)

The Office of the Australian Information Commissioner has summarised the obligation. From 10 December 2026, APP entities using personal information in ADM that may significantly impact individuals' rights or interest will need to explain in their privacy policies: the kind of personal information used in ADM, the kind of decisions made using in ADM.[\[4\]](https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making?ref=bushletter.com)

## The machinery behind the words

The term "computer program" is deliberately wide. The OAIC's issues paper confirms it covers pre-programmed rule-based processes, artificial intelligence, machine learning and generative AI tools including chatbots, meaning organisations cannot treat the obligation as something that applies only to cutting-edge AI deployments.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com) A decades-old eligibility calculator built in a spreadsheet formula sits inside scope just as a large language model does, provided the other conditions are met.

The two adverbs in APP 1.7, "substantially" and "directly", do the real work of defining scope. According to the OAIC's issues paper, "substantially" means the program is a key factor in facilitating a human's decision-making, not merely incidental administrative support, and "directly" means a direct connection to making the decision. An Excel formula used to triage hotline calls is captured, while a simple sum that happens to inform a conversation is not.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com)

That distinction matters for firms that believe their software is just a tool rather than a decision-maker. If a fraud scoring engine produces a risk rating that an employee almost always accepts or acts upon, the engine is likely a key factor. The fact that a human technically makes the final call does not push the arrangement outside scope.

## What is caught and what is not

The OAIC's issues paper lists practical examples on both sides of the line. On the inside: procuring a third-party AI system to screen and rank job applications; directing employees to use an AI chat tool to draft performance assessments; contracting software to automatically approve or decline refunds; and using case management systems that auto-escalate complaints.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com) Each of these uses personal information and ties directly to a decision that affects someone's rights or interests.

On the outside: developing and hosting automated application-approval software without using it yourself; and maintaining the infrastructure for a fraud detection system without being the entity that uses it to block or flag transactions.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com) The distinction is between operating a system and merely hosting or supplying it. Vendors who build the tools but do not run them against real applicants or customers sit outside the obligation; the entity that deploys the tool does not.

That framing carries a practical consequence for procurement teams. When an organisation contracts a third-party platform to handle credit eligibility, refund processing or complaint routing, the disclosure obligation attaches to the contracting organisation, not to the software vendor. Outsourcing the computation does not outsource the privacy obligation.

## Who must comply

Coverage follows the existing Privacy Act threshold. Under section 6D of the Privacy Act 1988, small business operators with annual turnover of $3 million or less are exempt from the Australian Privacy Principles, including the new APP 1 obligations.[\[3\]](https://www.legislation.gov.au/C2004A03712/2024-10-14/text/epub?ref=bushletter.com) That exemption is unchanged by the amendments. Organisations above the threshold, and all health service providers, credit reporting bodies and certain other categories regardless of turnover, need to treat the December 2026 commencement as a hard deadline.

The coverage test is annual turnover, not headcount or industry sector. A mid-sized logistics firm running automated scheduling and eligibility software, a fintech using algorithmic credit decisioning, and a retailer whose returns portal auto-approves or auto-declines claims are all squarely inside scope if they clear the $3 million mark. The obligation is sector-neutral; there is no carve-out for finance, employment or e-commerce.

## The audit that must come first

Privacy consultant Tim Fitzsimmons identified a sequencing problem that many organisations will discover only when they try to write the disclosure. One practical issue for many organisations will be that the privacy policy disclosure is the end point, not the starting point. Before an entity can make a meaningful automated decision making disclosure, it needs to know five things: where automated or system-assisted decisions are actually occurring; what personal information is being used; whether the system is materially influencing a decision, not merely supporting administration; who owns the workflow, escalation pathway and review process; and what evidence exists if the decision is later queried or challenged.[\[4\]](https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making?ref=bushletter.com)

That ordering problem is not trivial. Most privacy policies are written by legal or compliance teams who work from what they have been told by technology and operations staff. If the operations team cannot map which software tools materially influence which decisions, the legal team cannot write an accurate disclosure, and a policy that says "we use automated tools in some decisions" without specifying the kinds of personal information or the kinds of decisions is not compliant with APP 1.8.

The audit Fitzsimmons described requires crossing departmental lines. Procurement records, vendor contracts, IT asset registers and operations manuals all need to be interrogated to find every automated or system-assisted decision point that touches personal information. Credit checks, fraud scoring, refund approvals, complaint escalation, job application ranking and performance review drafting tools are the obvious candidates, but algorithmic pricing engines and eligibility calculators built into internal case management systems may also be caught depending on how materially they influence staff decisions.[\[2\]](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com)

Organisations that leave the audit until late 2026 risk discovering, with weeks to spare, that their privacy policies require substantial rewriting across multiple business units. The OAIC has not signalled any grace period beyond the 10 December 2026 commencement date, and the existing enforcement architecture under the Privacy Act applies from that date forward.[\[1\]](https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information?ref=bushletter.com)

SOURCES & CITATIONS

1. [Chapter 1: APP 1, Open and transparent management of personal information, OAIC](https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information?ref=bushletter.com)
2. [Automated Decision-Making Issues Paper, OAIC](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0027/263925/ADM-Issues-Paper.pdf?ref=bushletter.com)
3. [Privacy Act 1988, section 6D, small business operator definition, Federal Register of Legislation](https://www.legislation.gov.au/C2004A03712/2024-10-14/text/epub?ref=bushletter.com)
4. [OAIC consultation: guidance for transparency in automated decision making](https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making?ref=bushletter.com)

FREQUENTLY ASKED QUESTIONS

Does the new obligation apply only to AI systems?

No. The OAIC's issues paper confirms the term 'computer program' covers pre-programmed rule-based processes as well as AI, machine learning and generative tools. An eligibility calculator built in a spreadsheet formula can trigger the obligation if it substantially and directly influences a decision affecting an individual's rights or interests and uses personal information.

What exactly must a privacy policy say under APP 1.8?

The policy must disclose: the kinds of personal information used in the operation of covered computer programs; the kinds of decisions made solely by such programs; and the kinds of decisions for which a program does something substantially and directly related to making the decision. Generic references to 'automated tools' are unlikely to satisfy the specificity the amendments require.

If we contract a third-party vendor to run an automated screening tool, who carries the disclosure obligation?

The organisation that arranges for and uses the tool carries the obligation, not the vendor. Outsourcing the computation to a software supplier does not outsource the APP 1.7 duty. Your privacy policy must make the required disclosure, even if you did not build the system.

When do the new rules take effect and what is the coverage threshold?

APP 1.7, 1.8 and 1.9 commence on 10 December 2026\. The small business exemption under section 6D of the Privacy Act shields organisations with annual turnover of $3 million or less. All entities above that threshold, and certain categories such as health service providers regardless of turnover, must comply.

![Zara Kincaid](https://res.cloudinary.com/dz77sb7j1/image/upload/v1774262611/bushletter/authors/zara-kincaid.png)

[Zara Kincaid](https://bushletter.com/author/zara-kincaid/?ref=bushletter.com)

Zara Kincaid writes about artificial intelligence and search. Her focus is what happens to businesses when the front page of the internet stops being a list of links and starts being an answer.