Your privacy policy has to explain your AI. Most don’t.
From 10 December 2026, Australian privacy law requires you to disclose where software uses personal information to make or support decisions about people. We find where that is happening in your business, and produce the documentation that answers for it.
Fixed fees, quoted upfront. Written deliverables. No retainer required to start.
- Obligation
- APP 1.7, automated decision-making transparency
- Source
- Privacy and Other Legislation Amendment Act 2024
- Commences
- 10 December 2026
- Applies to
- APP entities, including health service providers of any size
A narrow obligation with real enforcement behind it
The Privacy and Other Legislation Amendment Act 2024 inserted a new transparency requirement into Australian Privacy Principle 1. It is not an AI strategy question. It is a documentation question with a date on it.
You are probably already in scope and haven’t noticed
Almost nobody bought “an AI system.” They bought ordinary software that quietly added automated scoring, ranking or drafting. Each of these can meet the APP 1.7 test depending on how the output is used.
Being in scope is not a problem. Being in scope without documentation is.
Start small. Only continue if it’s warranted.
Most businesses need the first step and nothing else for a while. Every engagement is a fixed fee, quoted before anything starts, and the review is credited against a build if you proceed within sixty days.
Exposure review
Find every place software touches a decision about a person, and establish which ones meet the test.
- Systems and vendor sweep
- Decision significance assessment
- Written findings with a risk ranking
- Clear yes or no on whether you need more
Compliance build
Produce the artefacts that make you defensible, written to survive a regulator asking how a decision was made.
- Rewritten privacy policy ADM disclosure
- Automated decision register
- Human review pathway, designed and documented
- Collection notices and internal procedure
- Staff briefing session
Assurance
Obligations do not stop on 10 December. New tools arrive, and national AI legislation is expected from 2027.
- Triage of any new system before rollout
- Register and policy kept current
- Regulatory change monitoring
- Annual written review
What you actually receive
Documents you can hand to a regulator, a board, an auditor or an insurer. Not a slide deck of recommendations.
Automated decision register
Every system, what personal information it uses, what decision it touches, and whether it meets the significance test.
Privacy policy disclosure
Plain-English APP 1.7 wording, drafted to match what your systems genuinely do rather than boilerplate.
Significance assessments
A written, reasoned position for each decision — the record that shows you considered the question properly.
Human review pathway
How a person challenges a decision, who reviews it, in what time, and how the outcome is recorded.
Vendor position
What your software suppliers will and won’t tell you about their models, and where that leaves your obligations.
Staff briefing
A working session so the people operating these systems know what they can and cannot do with the output.
Businesses where a software decision affects a real person
APP entities — broadly, organisations over $3 million turnover, plus health service providers and government contractors regardless of size.
Brokers, advisers and credit providers
The densest obligations of any segment. APP 1.7 sits on top of ASIC licensee duties, APRA CPS 230 service-provider registers and AUSTRAC AML/CTF documentation.
Best fitRecruitment and in-house HR
Applicant screening is the clearest example of a significant automated decision, and ATS platforms have quietly added scoring.
High exposureHealth and allied health
In scope regardless of turnover because you handle health information, and decision-support tools are spreading fast.
No size thresholdProperty and real estate
Tenancy application ranking and lead scoring both sit squarely inside the definition.
Often overlookedStraight answers
Is this a legal service?
No. This is compliance and documentation work. We produce the register, the assessments and the draft disclosure wording. If you want the final policy reviewed by a lawyer, we will say so and work alongside them.
We only use ChatGPT for drafting. Are we caught?
Possibly not. The test is whether personal information feeds a decision that significantly affects someone. General drafting usually falls outside it, but the same tool used to screen applicants does not. That distinction is exactly what the review settles.
Can’t our software vendor tell us this?
Some will, most won’t in useful detail, and the obligation is yours either way. Establishing what your vendors will confirm in writing is part of the work.
What happens after 10 December 2026?
The obligation is ongoing, not a one-off filing. New systems need assessing before rollout, and the Commonwealth is expected to legislate broader AI requirements from 2027.
Is there really a penalty?
The OAIC can issue infringement and compliance notices — powers that commenced in December 2024 — and civil penalties apply to a privacy policy that fails the requirement.
We’re in Western Australia. Does location matter?
No. This is Commonwealth law and the work is done remotely. We are based in the South West and work with clients across Australia.
Find out if you’re in scope
A short conversation is usually enough to tell whether you have an obligation worth acting on before December.