From 10 December 2026, Australian privacy policies must disclose automated decision-making that significantly affects people. The obligation is already law, the date is fixed, and roughly four months remain. Here is the test that decides whether you are captured, and what your policy needs to say.

This one is already law
Most privacy commentary in Australia is still focused on what might happen next. That is understandable, because the second tranche of Privacy Act reform has attracted a lot of attention. However, it also creates a blind spot.
The automated decision-making obligation is not a proposal. It passed as part of the first tranche, in the Privacy and Other Legislation Amendment Act 2024. Parliament simply gave organisations a two-year runway. That runway ends on 10 December 2026.
So while Tranche 2 remains uncertain, this requirement is settled. Consequently it deserves priority over speculative planning.
The automated decision-making test has two parts
The obligation does not capture every algorithm in your business. Instead, it applies a two-limb test. Both limbs must be satisfied.

First, a computer program must be involved in the decision. The wording is deliberately broad. It covers programs that make the decision outright. Importantly, it also covers programs that do something substantially relevant to making the decision.
That second phrase matters more than people expect. A human being can still sign off the outcome. Nevertheless, if a model produced the score that drove the answer, the program did something substantially relevant.
Second, the decision must be significant. Specifically, it must be one that could reasonably be expected to significantly affect the rights or interests of an individual.
Both limbs together set the boundary. As a result, a program that sorts your inbox is out of scope, while a program that scores loan applications is squarely in.
Who is most likely to be captured
In practice, automated decision-making turns up in the same sectors again and again. If you operate in any of these areas, assume you are in scope until you prove otherwise.
- Credit and lending. Automated scoring, limit setting and approval decisions.
- Recruitment. Resume screening, ranking and video assessment tools.
- Insurance. Risk rating, premium calculation and claims triage.
- Government and eligibility. Benefit, licence and concession assessments.
- Tenancy and property. Applicant screening and reference scoring.
- Pricing and access. Personalised pricing or automated account restrictions.
Notably, you do not need to have built the model yourself. If a vendor tool drives the decision, the obligation still sits with you.
What your privacy policy has to say
The automated decision-making requirement is a transparency requirement. Therefore it changes your privacy policy rather than your model. You must set out that these decisions happen, describe the kinds of personal information the programs use, and describe the kinds of decisions involved.
Generic wording will not survive scrutiny. For example, a line saying you may use technology to process applications tells a reader nothing. In contrast, a useful disclosure names the decision type and the data categories behind it.
Keep it readable, too. The point of the reform is comprehension, not legal coverage.
Automated decision-making and the OAIC
Enforcement context is worth noting. The Office of the Australian Information Commissioner has already begun sweeping privacy policies for compliance. Those sweeps look for exactly this kind of gap.
Meanwhile the Attorney-General confirmed in February 2026 that a second tranche of reform is progressing, although no bill and no timetable exist yet. In short, the direction is one way. Regulators expect policies to improve, not stay still.
A four-step automated decision-making review
Four months is enough time, provided you start with discovery rather than drafting. This sequence works.
- Inventory your decision points. List the decisions that affect customers, applicants or employees. Then note which ones involve software.
- Apply the two-limb test to each. Record your reasoning, including the decisions you rule out and why.
- Map the data. For every in-scope decision, identify the categories of personal information the program uses.
- Rewrite the policy section. Draft plain-language wording, then have someone outside the project read it.
Above all, keep the working papers. If the regulator asks how you reached your scoping conclusions, that record is your answer.
Where this overlaps with AI governance
Many organisations are already building AI governance programs, and automated decision-making fits neatly inside them. Sensibly, this obligation should plug into that work rather than run beside it.
An AI inventory answers most of step one. Model documentation answers most of step three. Because the underlying discovery is shared, teams that have started on enterprise risk management for AI usually find this straightforward.
Organisations without that foundation face more work. Even then, the obligation is narrow enough to handle on its own.
What automated decision-making disclosure does not require
Scope creep around automated decision-making is a real risk, so it helps to be clear about the limits. Several obligations that people expect are simply not part of this reform.
You do not have to stop using automated decisions. The requirement is transparency. Therefore you can continue to run the same models, provided you describe them properly.
You do not have to explain individual decisions. A right for a person to demand the reasoning behind their own specific outcome was discussed during consultation. However, it did not make it into the first tranche. This obligation operates at the level of your privacy policy, not the individual case.
You do not have to publish model logic. Source code, feature weights and vendor algorithms stay confidential. You describe the kinds of information used and the kinds of decisions made, and nothing further.
You do not have to cover trivial automation. Workflow routing, spam filtering and scheduling tools rarely meet the significance limb. Still, write down why you excluded them.
That said, do not read the limits too generously. The phrase about doing something substantially relevant to a decision pulls in more systems than a narrow reading suggests. When a case is genuinely borderline, disclosing it is the lower-risk choice.
Getting the scoping right
With automated decision-making, the hard part is not the drafting. It is deciding which decisions are significant, and documenting that judgement defensibly. That is where most of the risk sits.
You can read the amending legislation on the Federal Register of Legislation, and the regulator publishes guidance on the Australian Privacy Principles.
If you would like help scoping your own decisions, our security and compliance advisory team works through exactly this exercise with Australian organisations, including clients in Sydney and Melbourne. Feel free to contact us for a short scoping conversation.


