EU AI Act GPAI obligations are now in force. Is your documentation ready? See GRC Toolkits →
Blog

Regulatory insight, plain-English guidance.

AI governance, compliance and finance, explained without the jargon — timed to the deadlines that actually matter.

Your APP 1.7 disclosure obligations are not optional. If your business uses AI or automated systems anywhere in hiring, lending, pricing, insurance, or customer service decisions, your privacy policy is about to become legally incomplete — and most organisations don’t yet know it.

From 10 December 2026, new APP 1.7–1.9 obligations under the Privacy Act 1988 (Cth) require entities to disclose, in their privacy policy, the kinds of personal information used in automated decision-making (ADM) and the kinds of decisions ADM makes or substantially supports. The OAIC has confirmed a compliance sweep is already underway, and it isn’t limited to obviously “AI-heavy” sectors — HR screening tools, credit scoring, insurance underwriting models, and even rules-based eligibility engines can all trigger the obligation.

This isn’t best-practice guidance. It’s a Privacy Act requirement, and a breach is treated as an interference with privacy — enforceable under the regime strengthened by the Privacy and Other Legislation Amendment Act 2024.

The three-part trigger test

Before you touch your privacy policy, work out whether your APP 1.7 disclosure obligation actually applies to you. It comes down to three questions:

  1. Does a computer program use personal information to make, or materially inform, a decision about an individual?
  2. Is the decision made solely by the program, or is it substantially or directly supported by it (a human “rubber-stamping” an algorithmic output still counts)?
  3. Could the decision reasonably be expected to significantly affect the individual’s rights or interests — employment, credit, insurance, tenancy, service access?

If you answer yes to all three, disclosure is required. Most businesses assume this only applies to sophisticated AI models. In practice, a spreadsheet-based scoring rule or a basic eligibility filter can trigger it just as easily as a machine learning model.

What your privacy policy actually needs to say

Once ADM is in scope, your privacy policy must disclose:

This sits alongside — not instead of — your existing APP 1.2/1.3 and APP 5.1 transparency obligations. Worth noting: even where an organisation’s underlying data practices are defensible, transparency and notification failures have proven costly in recent Privacy Act enforcement action, regardless of whether the collection itself was justified.

What “done” looks like before 10 December

A defensible position isn’t just an updated policy paragraph. It’s:

Where the ADM Transparency Pack fits

We built the AU Privacy Act ADM Transparency Pack to take this from a legal reading exercise to a same-day-issue deliverable: a disclosure policy template, an ADM register/inventory tracker with the trigger test built in, an individual-facing notice pack, and an internal staff briefing — all editable in Word, Excel, and PowerPoint, mapped directly to APP 1.7–1.9.

It’s a drafting aid, not a substitute for your own legal review — but it gets you from “we haven’t looked at this yet” to a defensible first draft in an afternoon, not a multi-week engagement.

The deadline is fixed. The compliance sweep is already running. The organisations that treat this as a five-minute policy tweak are the ones the OAIC’s spot-checks are built to catch.

In short: an APP 1.7 disclosure is now a standing requirement for any Australian entity using automated decision-making that touches personal information — not an optional privacy-policy nicety. Getting the wording right, and evidencing how you got there, is what separates a defensible policy from a liability.

Get the ADM Transparency Pack →

Leave a Reply

Your email address will not be published. Required fields are marked *