INSIGHT

Mandatory automated decision-making disclosure requirements are coming – key takeaways from the OAIC guidance

By David Rountree, Valeska Bloch, Isabelle Guyot
AI Cyber Data & Privacy Technology, Media & Telecommunications

New disclosure expectations part of rapidly evolving privacy and AI regulatory landscape 7 min read

New privacy obligations requiring disclosure of certain automated decision-making (ADM) processes commence on 10 December 2026. The Office of the Australian Information Commissioner's (OAIC) final guidance confirms the requirements extend well beyond truly 'automated' or AI driven decision and may capture a broad range of software, decision-support tools and embedded technologies.

Organisations will be required under new Australian Privacy Principles (the APPs) 1.7–1.9 to include mandatory disclosures in their privacy policies on the use of personal information in automated or semi-automated decisions that 'significantly affect the rights or interests of an individual'. In practice, the test is complex, multi-limbed and requires significant guidance and assessment.

On 30 September, the OAIC released its final guidance on the new requirements, updating its APP 1 Guidelines and releasing an APP 1.7-1.9 Transparency Obligation Fact Sheet. This follows consultation on a prior Issues Paper, which we covered here). This gives organisations approximately 10 weeks from the release of the guidance to implement the requirements.

In this Insight, we examine the key aspects of the guidance, what organisations should be focusing on now, and why an ADM audit should be a priority.

Key takeaways

To be ready by 10 December, organisations should:

  • Conduct an ADM audit: Map all computer programs and internal processes used in decision-making processes (including third-party tools and AI products) to assess whether they meet the three criteria in APP 1.7.
  • Assess third-party arrangements: During and after procurement, monitor third-party ADM use and identify, assess and oversee how a third-party product or service uses ADM, including how ADM is used to make or assist decisions and the types of decisions. This will be critical for meeting disclosure obligations.
  • Review and update your privacy policy: Prepare and issue updates to your privacy policy by the 10 December deadline.

We have set out below the scope of the requirements and the key takeaways from the guidance.


What is the ADM obligation?

This is a transparency measure only. Unlike overseas equivalents (such as the EU's General Data Protection Regulation (the GDPR))1 it does not provide a right to contest decisions or request information, nor does it impose an obligation on organisations to directly notify individuals.

The requirements are intended to provide greater transparency to individuals about the circumstances in which their personal information is being used in automated decisions. According to the OAIC, this is to arm consumers with the appropriate information to enable them to exercise information access or review options in other frameworks, including anti-discrimination law, administrative law and specific industry regulation, such as the General Insurance Code of Practice.

Trigger for disclosure – APP 1.7

APP entities will need to include information in their privacy policies about ADM where:

  1. the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision;
  2. the decision could reasonably be expected to significantly affect the rights or interests of an individual; and
  3. personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision.

Information to be addressed in disclosure – APP 1.8

The information to be disclosed in the privacy policy is:

  1. the kinds of personal information used in the operation of such computer programs;
  2. the kinds of such decisions made solely by the operation of such computer programs; and
  3. the kinds of such decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs.

Further guidance – APP 1.9

For the purposes of subclauses 1.7 and 1.8:

  1. making a decision includes refusing or failing to make a decision; and
  2. doing a thing includes refusing or failing to do a thing;
  3. a decision may affect the rights or interests of an individual, whether the rights or interests of the individual are adversely or beneficially affected; 
  4. the following are examples of the kinds of decisions that may affect the rights or interests of an individual:
    1. a decision made under a provision of an Act or a legislative instrument to grant, or to refuse to grant, a benefit to the individual;
    2. a decision that affects the individual’s rights under a contract, agreement or arrangement;
    3. a decision that affects the individual’s access to a significant service or support.

The definition of ADM will capture a broader range of decisions than in other jurisdictions such as the EU GDPR, which targets decisions 'based solely on automated processing'. This means that APP entities also subject to the EU GDPR and deploying ADM systems globally will need to consider if these systems must be disclosed in their Privacy Policy, even if they do not meet the requirements for disclosure under GDPR.

Key issues from the OAIC guidance

The guidance largely confirms the direction set out in the initial OAIC Issues Paper regarding the scope and application of the disclosure obligations (see our article on it here). Regardless, given the nature of the new obligation, there remains significant scope for interpretation and assessment.

The critical takeaways are as follows:

  • 'Computer program' is broad: The initial trigger for disclosure is the involvement of a 'computer program' in making, or doing a thing substantially and directly related to making, a decision. The guidance confirms this is broad, covering rule-based tools, AI/ML, everyday software (including spreadsheets), and generative AI/chatbots. Simple, long-standing tools can be captured, not just sophisticated AI.
  • Human review doesn't take a tool out of scope: A computer program is 'substantially and directly related' to a decision if its output is a key factor with a direct connection to the human's decision, whether advisory or determinative. The guidance provides factors: reliance on the output, likelihood of override, whether output is advisory versus determinative, whether output is explainable, and the level of integration/complexity. Practically, the guidance suggests that in most cases where the 'computer program' output is a material input into any assessment or decision, it should be captured by the disclosure obligations regardless of human oversight.  
  • 'Significantly affects rights or interests' scope has been clarified, though questions remain as to its boundaries: The guidance includes a list of likely in-scope rights  (including legal and moral rights) and interests (health, housing, finance, employment, utilities, etc.), and a practical vulnerability test (materially different outcomes for a vulnerable cohort versus the general population). The guidance also states that targeted content or advertising may be captured if it results in differential or personalised pricing, but also where it impacts 'access' to 'significant goods or services' or 'employment opportunities'. The examples provided in the guidance clarify that targeted employment advertising would be in scope, but provide no further guidance on what advertising of 'significant' goods or services otherwise captures. This raises the question of where the line sits for targeted advertising generally.  
  • 'Arranged for' means the onus is on the user of personal information: The disclosure obligation will sit with a user of a product which facilitates any ADM, not vendors in a technology supply chain that provide a relevant 'computer program' or process. In practice, this means that the user is responsible for disclosing inbuilt/embedded ADM, though the user may require information on its operation from its suppliers. Contractual arrangements should clearly indicate who is making a 'decision'.  
  • Commercial-in-confidence exclusion exists, but potentially narrow in scope: The Explanatory Memorandum initially flagged that 'commercial-in-confidence' information about ADM systems was not expected to be included, providing some comfort that this obligation would not require disclosure of the underlying logic or scoring involved in any automated assessment. The guidance provides some limited further commentary, noting the OAIC's view that it would only apply to information whose disclosure would genuinely harm commercial interests (trade secrets/commercially sensitive data), not merely information with 'commercial value' or information that would result in 'ridicule, embarrassment or public criticism'.
  • Level of detail of disclosure: The guidance provides context on the OAIC's expectations regarding the detail and granularity to be included in disclosures. Helpfully, it is not prescriptive, allowing entities to assess what is appropriate in their circumstances, noting that:
    • 'technical' detail does not appear to be required;
    • categorisation appears permissible – ie, not requiring each sub 'decision' in a process to be disclosed;
    • where there are separate processes that have different outcomes/purposes or use different information, the preference appears to be that these be separately identified. This may result in categorisation based on types of decisions/processes undertaken;
    • use of more sensitive data points should be called out more clearly (eg, biometric data or health information).

Next steps

Organisations must complete their internal assessments and finalise their uplifts before the obligations commence on 10 December. This will require mapping internal processes (including third-party processes), determining whether they meet the threshold and then preparing the appropriate policy uplift. Given the complex nature of the assessments, this final stretch of runway is short, and our team is available to help.

Footnotes

  1. Under Articles 22, 13(2)(f) and 14(2)(g) of the GDPR requirement, individuals have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them; the right to obtain meaningful information about the logic involved, and the significance and envisaged consequences of such processing; and the right to obtain human intervention, express their point of view and contest the decision.