APP 1.7 commences 10 December 2026

Your privacy policy has to explain your AI. Most don’t.

From 10 December 2026, Australian privacy law requires you to disclose where software uses personal information to make or support decisions about people. We find where that is happening in your business, and produce the documentation that answers for it.

Fixed fees, quoted upfront. Written deliverables. No retainer required to start.

—
days until APP 1.7 commences
Obligation
APP 1.7, automated decision-making transparency
Source
Privacy and Other Legislation Amendment Act 2024
Commences
10 December 2026
Applies to
APP entities, including health service providers of any size
What changed

A narrow obligation with real enforcement behind it

The Privacy and Other Legislation Amendment Act 2024 inserted a new transparency requirement into Australian Privacy Principle 1. It is not an AI strategy question. It is a documentation question with a date on it.

APP 1.7
Your privacy policy must set out the kinds of personal information used in automated decisions, and the kinds of decisions made with it.
“Significantly affect”
The trigger is software that uses personal information to make, or directly support, a decision reasonably expected to significantly affect someone’s rights or interests.
Already enforceable
The OAIC’s infringement and compliance notice powers commenced 11 December 2024. Civil penalties apply to a non-compliant policy.
Guidance now
The OAIC consulted through 2026 and its final transparency guidance is landing now. The shape of a compliant policy is knowable today.
The problem

You are probably already in scope and haven’t noticed

Almost nobody bought “an AI system.” They bought ordinary software that quietly added automated scoring, ranking or drafting. Each of these can meet the APP 1.7 test depending on how the output is used.

Recruitment screeningRanking, shortlisting or scoring applicants in your ATS
Credit and lending decisionsServiceability scoring, pre-qualification, risk flags
Insurance pricing and claimsAutomated pricing factors or claim triage
Tenancy and property applicationsApplicant scoring or automated ranking
CRM lead scoringPrioritising who gets contacted, called or declined
Client onboarding and KYCAutomated identity, risk or eligibility checks
Clinical decision supportSoftware that informs triage or treatment pathways
AI-drafted client adviceWhere generated output shapes the advice given

Being in scope is not a problem. Being in scope without documentation is.

Engagements

Start small. Only continue if it’s warranted.

Most businesses need the first step and nothing else for a while. Every engagement is a fixed fee, quoted before anything starts, and the review is credited against a build if you proceed within sixty days.

Step one

Exposure review

Find every place software touches a decision about a person, and establish which ones meet the test.

Fixed fee · about one week
  • Systems and vendor sweep
  • Decision significance assessment
  • Written findings with a risk ranking
  • Clear yes or no on whether you need more
Book a review
Ongoing

Assurance

Obligations do not stop on 10 December. New tools arrive, and national AI legislation is expected from 2027.

Monthly retainer · cancel any time
  • Triage of any new system before rollout
  • Register and policy kept current
  • Regulatory change monitoring
  • Annual written review
Ask about assurance
Deliverables

What you actually receive

Documents you can hand to a regulator, a board, an auditor or an insurer. Not a slide deck of recommendations.

01

Automated decision register

Every system, what personal information it uses, what decision it touches, and whether it meets the significance test.

02

Privacy policy disclosure

Plain-English APP 1.7 wording, drafted to match what your systems genuinely do rather than boilerplate.

03

Significance assessments

A written, reasoned position for each decision — the record that shows you considered the question properly.

04

Human review pathway

How a person challenges a decision, who reviews it, in what time, and how the outcome is recorded.

05

Vendor position

What your software suppliers will and won’t tell you about their models, and where that leaves your obligations.

06

Staff briefing

A working session so the people operating these systems know what they can and cannot do with the output.

Who this is for

Businesses where a software decision affects a real person

APP entities — broadly, organisations over $3 million turnover, plus health service providers and government contractors regardless of size.

Brokers, advisers and credit providers

The densest obligations of any segment. APP 1.7 sits on top of ASIC licensee duties, APRA CPS 230 service-provider registers and AUSTRAC AML/CTF documentation.

Best fit

Recruitment and in-house HR

Applicant screening is the clearest example of a significant automated decision, and ATS platforms have quietly added scoring.

High exposure

Health and allied health

In scope regardless of turnover because you handle health information, and decision-support tools are spreading fast.

No size threshold

Property and real estate

Tenancy application ranking and lead scoring both sit squarely inside the definition.

Often overlooked
Questions

Straight answers

Is this a legal service?

No. This is compliance and documentation work. We produce the register, the assessments and the draft disclosure wording. If you want the final policy reviewed by a lawyer, we will say so and work alongside them.

We only use ChatGPT for drafting. Are we caught?

Possibly not. The test is whether personal information feeds a decision that significantly affects someone. General drafting usually falls outside it, but the same tool used to screen applicants does not. That distinction is exactly what the review settles.

Can’t our software vendor tell us this?

Some will, most won’t in useful detail, and the obligation is yours either way. Establishing what your vendors will confirm in writing is part of the work.

What happens after 10 December 2026?

The obligation is ongoing, not a one-off filing. New systems need assessing before rollout, and the Commonwealth is expected to legislate broader AI requirements from 2027.

Is there really a penalty?

The OAIC can issue infringement and compliance notices — powers that commenced in December 2024 — and civil penalties apply to a privacy policy that fails the requirement.

We’re in Western Australia. Does location matter?

No. This is Commonwealth law and the work is done remotely. We are based in the South West and work with clients across Australia.

Find out if you’re in scope

A short conversation is usually enough to tell whether you have an obligation worth acting on before December.