If your organisation uses software to help decide things about people, automated decision-making transparency is now a task with a date on it. From 10 December 2026, Australian privacy law requires you to tell people, in your privacy policy, about the automated decisions you make about them. This post gives you the inventory to run before the date, and how to turn it into a privacy policy section a person can actually read.
What automated decision-making transparency requires on 10 December 2026
The obligation comes from the Privacy and Other Legislation Amendment Act 2024, which amended Australian Privacy Principle 1. Put plainly: if you are an APP entity and you use personal information in an automated decision that could affect a person's rights or interests, your privacy policy has to say so. It has to describe the kinds of personal information you use, and the kinds of decisions you make that way.
From 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.
Two things stand out. The disclosure sits in your privacy policy, a document you already publish. And the test is about the effect on a person, not the technology. If a decision could change what someone gets, pays, or is offered, it is in scope.
- 10 December 2026
- ADM transparency disclosure begins
- 18 May to 15 June 2026
- OAIC consultation window on the guidance
- over 12%
- Projected growth of Health Care and Social Assistance, five years to 2030
Automated decision-making is broader than you think
It is tempting to read this as a rule about artificial intelligence. It is wider than that. A decision counts when software makes it, or materially shapes it, without a person weighing the specifics each time.
That covers a rules engine that approves or declines an application. An eligibility script that sorts people into tiers. A model that ranks job candidates. A flag that pushes a case to the top of a queue. If the output changes what happens to a person, the age or cleverness of the code does not matter.
Why your team probably cannot answer this today
Here is the awkward part. Most teams cannot produce this list today, and it is not a failure of effort. Decisions are spread across systems built at different times, by different people, for different reasons.
A scoring rule lives in a spreadsheet macro. A triage flag sits inside a case management tool a vendor set up years ago. A ranking step is buried in a hiring platform. No single person holds the full picture, so the honest first answer is often, we are not sure.
The regulator's guidance is still settling. The OAIC ran its consultation on the draft from 18 May to 15 June 2026, and intends to release the guidance by September 2026. The start date, though, does not move. It is 10 December 2026, so the sensible plan is to build your inventory now and refine the wording as the guidance lands.
Run an ADM inventory: four columns
You do not need a governance programme to start. You need one table with four columns, filled in for every system that scores, ranks, gates or flags a person.
- System: the tool or piece of code that makes or shapes the decision.
- Personal information in: what data about a person feeds it.
- Decision out: what the system decides or recommends.
- Who is affected: the people the decision lands on.
Two example rows show the shape. A triage flag: system, the case management tool; information in, referral details and health notes; decision out, priority level; who is affected, people waiting for a service. A candidate ranking: system, the hiring platform; information in, work history and test scores; decision out, shortlist order; who is affected, job applicants.
Turn the inventory into a privacy policy section
The inventory is your working document. The privacy policy is not. The obligation asks for the kinds of personal information used and the kinds of decisions made, not a data flow dump that no reader could follow.
So group similar systems. Describe the kinds of personal information in plain terms: contact details, health information, employment history. Describe the kinds of decisions: eligibility, prioritisation, ranking. You are giving a person a fair picture of when a machine is deciding about them, in words they can read once and understand.
Decide what needs a human in the loop
Writing the list forces a second question you cannot avoid once you see it: should this decision be fully automated at all? Transparency is the trigger to review that, not just to publish.
It matters most where the stakes are high. Health Care and Social Assistance is Australia's largest and fastest-growing employing industry, projected to grow by over 12% in the five years to 2030, according to Jobs and Skills Australia. Decisions in care and eligibility shape what a person receives, so those are the rows where a human check often belongs before the outcome stands.
What to do before December
The work is small if you start now and larger if you wait. A short, dated plan keeps it manageable.
- List every system that scores, ranks, gates or flags a person.
- Fill the four columns for each one, and note anything you are unsure about.
- Group the systems and draft the privacy policy section in plain language.
- Mark the decisions that should have a human in the loop, and change those first.
- Review the wording once the OAIC guidance is published, then finalise before 10 December 2026.
Sources
- OAIC, Consultation on guidance for transparency in automated decision-making (accessed 2026-09-08)
- Jobs and Skills Australia, Australian Jobs 2026 (accessed 2026-09-08)