Back to Blog

Automated Decision-Making Privacy Rules Start 10 December 2026

APP 1 will require specific privacy-policy text for certain computer-driven decisions. You cannot write it without an inventory.

Automated Decision-Making Privacy Rules Start 10 December 2026

Quick verdict

From 10 December 2026, APP entities must add prescribed information to their privacy policy where a computer program makes, or does something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about that individual is used in the operation of the program.

This is already law. It arrived in the Privacy and Other Legislation Amendment Act 2024. The OAIC consulted on guidance in May 2026 and planned to publish it by September 2026. Waiting for the final guidance before you hunt for in-scope systems leaves too few weeks to find vendor features and shadow tools.

Best for: privacy officers, counsel and CIOs at APP entities. Honest limit: Cipher does not draft your privacy policy as a law firm. We help you find the systems and produce the evidence the paragraph has to rest on.

Last updated: 31 August 2026.


What must we put in the privacy policy on 10 December 2026?

Where the three-limb test is met, APP 1.8 requires the policy to describe the kinds of personal information used in those computer programs, the kinds of decisions made solely by those programs, and the kinds of decisions where the program does a thing that is substantially and directly related to making the decision. You do not have to publish the model weights. You do have to be specific enough that a person can recognise the decision.


The three-limb test (plain language)

Limb In practice Usually in Often out
A computer program makes a decision, or does a thing substantially and directly related to making one Includes refusing or failing to decide. Includes a score that a human almost always accepts Credit decisioning, insurance underwriting, hiring rankers, benefit eligibility, complaint triage that closes a case A spellcheck in a word processor; a dashboard with no decision attached
The decision could reasonably be expected to significantly affect rights or interests Beneficial or adverse. Context matters. Vulnerability raises the bar Job, housing, credit, insurance, healthcare access, essential service, contractual rights A marketing subject-line test with no access consequence (still check privacy and spam rules)
Personal information about the individual is used in the operation of the program The input is about that person, not only aggregate stats Application file, transaction history, HR record, support transcript used to decide their outcome A model trained only on public non-personal text, used with no personal input — rare in real operations

OAIC primary source: the ADM issues paper (May 2026). Firm walkthroughs from Norton Rose Fulbright, White & Case and Hamilton Locke match that three-limb structure. If your counsel uses different words, use theirs.


Why this is an inventory problem, not a copywriting problem

The policy sentence is the last hour. The first ten hours are finding every computer program that sits near a decision. In Power Days the systems that surprise people are not the flagship “AI project”. They are:

  • A CRM that auto-prioritises leads or closes tickets
  • An ATS that ranks candidates before a human opens the CV
  • A lender’s scorecard that a credit officer rubber-stamps
  • A chatbot that grants a refund or a fare exception (Air Canada is the teaching case)
  • A vendor “AI insights” toggle that started writing the first draft of a hardship decision

If you cannot name the system, the personal information, and whether a human can change the outcome, you cannot write APP 1.8 honestly. How to build the list: AI inventory for shadow AI.


What the December rule does not do

It does not ban automated decisions. It does not force a human in the loop. It does not create an individual right to an explanation of the model. It is a transparency duty in the privacy policy. Other laws can still require more: consumer law on misleading outcomes, employment law on hiring, APRA on material systems, and your own contracts.

Do not treat a new paragraph as the whole of AI governance. The paragraph is one artefact. The record behind it is the accountability layer described in Can you prove it?


A six-week path that actually finishes

  1. Week 1 — owners. Name one accountable executive and a privacy lead. Pull procurement, SaaS SSO, expense cards and the engineering secret store.
  2. Week 2 — inventory. Every AI and ADM row: purpose, personal information, decision, human override, vendor, residency.
  3. Week 3 — three-limb filter. Counsel marks in / out / needs facts. Do not let engineering self-exempt “it’s only a recommendation”.
  4. Week 4 — evidence pack. For each in-scope row: data fields, whether the program decides or supports, who can override.
  5. Week 5 — draft policy text. Group by kind of decision, not by vendor brand. People do not search your policy for “Workday”.
  6. Week 6 — publish and freeze a copy. Keep the inventory living. The policy will need a 2027 pass when OAIC enforcement examples arrive.

A Power Day collapses weeks 1–4 if the owners are in the room. Week 5 stays with counsel. We do not publish your privacy policy for you.

Unique insight: the teams that miss December are the ones that booked “privacy policy rewrite” in November and discovered in week one that nobody had a system list. Book the hunt first.

FAQ

We are under the small-business exemption. Does this apply? The duty sits on APP entities. Many small businesses are exempt; some are not (health, credit, trading in personal information, or a contract that deems you an APP entity). Ask counsel. Inventory is still useful when a customer’s questionnaire arrives.

Does a human clicking “accept” take us out of scope? Not automatically. A program that does a thing substantially and directly related to the decision can still trigger the rule. Rubber-stamp review is the fact pattern OAIC discussion keeps returning to.

Is ChatGPT in scope? Only if personal information about an individual is used and the output is used to make or support a decision that significantly affects them. A writer using ChatGPT on public copy is a different row from a case officer pasting a customer file into ChatGPT to decide a hardship request. Both rows belong on the inventory. Only the second is likely APP 1.8.

Will OAIC guidance change the test? Guidance interprets the Act. It does not move 10 December. Start the inventory before the PDF lands.


Related: Prove it · 2026–2027 timeline · AI inventory · Power Day

Share this article

Share:

Using AI without an evidence trail?

Power Hour onboarding, then a Power Day: inventory, owners, data flows, and a living record. We build the evidence layer — we do not certify you.