From the journal

Australia's Automated Decision-Making Transparency Obligation Takes Effect 10 December 2026

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts APP 1.7 into the Privacy Act 1988 (Cth), requiring APP entities that use personal information in automated decision-making likely to significantly affect individual rights to disclose this in their APP Privacy Policy from 10 December 2026. The obligation applies to banks, insurers, employers, and technology platforms. It imposes a transparency duty, not a prohibition on automation or a right of human review.

3 min read

The Privacy and Other Legislation Amendment Act 2024 (Cth) received royal assent on 29 November 2024 and inserts new sub-principles APP 1.7, 1.8, and 1.9 into the Privacy Act 1988 (Cth). APP 1.7 takes effect on 10 December 2026 and imposes a mandatory disclosure obligation on all APP entities that arrange for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect the rights or interests of an individual. The obligation is a transparency rule: it does not prohibit automated decision-making and does not grant individuals a right to demand human review.

APP 1.7 requires the APP Privacy Policy to identify: the kinds of personal information used in the automated decision; the kinds of decisions the computer program produces; and how an individual can seek further information about the logic involved. APP 1.8 applies supplementary requirements where sensitive information within the meaning of section 6 of the Privacy Act 1988 (Cth) is involved. APP 1.9 requires entities to update their APP Privacy Policy if the categories of automated decision change materially. The Office of the Australian Information Commissioner (OAIC) is consulting on draft guidance on what constitutes a significant effect on the rights or interests of an individual and what information about the logic involved must be disclosed.

Banks, consumer lenders, insurers, employers, online platforms, and AI-enabled product vendors that use automated credit scoring, claims processing, employment screening, or customer risk profiling must identify whether any such system makes decisions within the scope of APP 1.7 before 10 December 2026. Compliance requires an inventory of ADM systems and the personal information they use, a determination of whether each system produces decisions likely to significantly affect individual rights, and revision of the APP Privacy Policy to include the required disclosures for each in-scope system. The obligation applies to Australian-incorporated entities and to foreign entities that collect or hold personal information of Australian individuals in the course of carrying on business in Australia.

The OAIC's draft guidance has not yet definitively resolved whether ADM systems that produce recommendations rather than final decisions fall within APP 1.7. Entities that use AI to generate recommendations subject to human sign-off before execution should analyse whether the human review element is sufficiently meaningful to take the system outside the scope. Non-compliance with APP 1.7 is an interference with privacy under section 13G of the Privacy Act 1988 (Cth), giving the OAIC jurisdiction to investigate and issue compliance notices, infringement notices, or civil penalty proceedings for serious or repeated breaches. Penalties under the Privacy Act reach AUD 50 million or 30 percent of adjusted turnover for bodies corporate.

Licentium advises regulated entities on privacy compliance for AI and automated systems. Work we undertake includes APP 1.7 readiness assessments, ADM system inventories, APP Privacy Policy redrafting, cross-jurisdictional AI governance analysis under the EU AI Act, and GDPR Article 22 compliance benchmarking.

Source: Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision-Making, Privacy Act 1988 (Cth) APP 1.7 (as amended 2024)

AI Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.