Australia · Privacy and data governance
Automated decisions: prepare your privacy policy for 10 December
Before you can describe an automated decision in your privacy policy, you need to understand how it is made. Start the conversation with the teams and vendors running your systems.

What is changing?
From 10 December 2026, new APP 1 privacy-policy obligations apply to APP entities where a computer program uses personal information to make a decision, or perform something substantially and directly related to making it, and the decision could reasonably be expected to significantly affect an individual’s rights or interests.
This is an enacted commencement, separate from broader privacy-reform proposals. The scope is not limited to generative AI or entirely automated decisions. A human participating in the process does not, by itself, settle whether the disclosure requirement applies.
What must the policy explain?
For arrangements within scope, the policy must describe the kinds of personal information used, the kinds of decisions made solely by computer programs, and the kinds of decisions supported by substantially and directly related computer processing. Both beneficial and adverse decisions can be relevant.
These are transparency obligations. Updating a policy is not a substitute for assessing whether the underlying collection, use or disclosure of personal information complies with other applicable requirements.
Four questions to put to your teams now
- Where does software influence a significant outcome? Start with systems that assess access to services or contractual rights. Consider screening, eligibility and account-restriction processes as candidates for assessment, not automatic conclusions that every system is covered.
- What information is used? Ask the system owner and vendor to identify inputs, generated scores or profiles, and how they contribute to the decision. Record what remains unclear.
- What does the person reviewing the result actually do? Map whether staff make an independent assessment or routinely adopt a recommendation. Document the whole process, not simply the product’s AI label.
- Who will own the policy update? Bring privacy, technology, procurement and operational teams together. Assign responsibility for accurate wording and for checking it when systems or vendors change.
How Watchdog can help
Watchdog can help map relevant decision processes, assess the disclosure scope and turn technical information into clear privacy-policy wording.
