From the journal

Australia's Automated Decision-Making Transparency Obligation Takes Effect 10 December 2026

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts APP 1.7 into the Privacy Act 1988 (Cth), requiring APP entities that use personal information in automated decision-making likely to significantly affect individual rights to disclose this in their APP Privacy Policy from 10 December 2026. The obligation applies to banks, insurers, employers, and technology platforms. It imposes a transparency duty, not a prohibition on automation or a right of human review.

3 min read

The Privacy and Other Legislation Amendment Act 2024 (Cth) received royal assent on 29 November 2024 and inserts new sub-principles APP 1.7, 1.8, and 1.9 into the Privacy Act 1988 (Cth). APP 1.7 takes effect on 10 December 2026 and imposes a mandatory disclosure obligation on all APP entities that arrange for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect the rights or interests of an individual. The obligation is a transparency rule: it does not prohibit automated decision-making and does not grant individuals a right to demand human review.

APP 1.7 requires the APP Privacy Policy to identify: the kinds of personal information used in the automated decision; the kinds of decisions the computer program produces; and how an individual can seek further information about the logic involved. APP 1.8 applies supplementary requirements where sensitive information within the meaning of section 6 of the Privacy Act 1988 (Cth) is involved. APP 1.9 requires entities to update their APP Privacy Policy if the categories of automated decision change materially. The Office of the Australian Information Commissioner (OAIC) is consulting on draft guidance on what constitutes a significant effect on the rights or interests of an individual and what information about the logic involved must be disclosed.

Banks, consumer lenders, insurers, employers, online platforms, and AI-enabled product vendors that use automated credit scoring, claims processing, employment screening, or customer risk profiling must identify whether any such system makes decisions within the scope of APP 1.7 before 10 December 2026. Compliance requires an inventory of ADM systems and the personal information they use, a determination of whether each system produces decisions likely to significantly affect individual rights, and revision of the APP Privacy Policy to include the required disclosures for each in-scope system. The obligation applies to Australian-incorporated entities and to foreign entities that collect or hold personal information of Australian individuals in the course of carrying on business in Australia.

The OAIC's draft guidance has not yet definitively resolved whether ADM systems that produce recommendations rather than final decisions fall within APP 1.7. Entities that use AI to generate recommendations subject to human sign-off before execution should analyse whether the human review element is sufficiently meaningful to take the system outside the scope. Non-compliance with APP 1.7 is an interference with privacy under section 13G of the Privacy Act 1988 (Cth), giving the OAIC jurisdiction to investigate and issue compliance notices, infringement notices, or civil penalty proceedings for serious or repeated breaches. Penalties under the Privacy Act reach AUD 50 million or 30 percent of adjusted turnover for bodies corporate.

Licentium advises regulated entities on privacy compliance for AI and automated systems. Work we undertake includes APP 1.7 readiness assessments, ADM system inventories, APP Privacy Policy redrafting, cross-jurisdictional AI governance analysis under the EU AI Act, and GDPR Article 22 compliance benchmarking.

Source: Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision-Making, Privacy Act 1988 (Cth) APP 1.7 (as amended 2024)

AI Regulatory

More from the journal

See all

Finland Gambling Act Ends State Monopoly, Opens Licensed iGaming Market from July 2027

Finland's Gambling Act, approved by the President on 16 January 2026, ends the state monopoly held by Veikkaus Oy and introduces competitive licensing for private iGaming operators in online sports betting and casino verticals. The Finnish Gambling Authority accepts licence applications from 1 March 2026; licensed market operations begin 1 July 2027. Licensed operators pay a flat gross-gaming-revenue tax of 22%.

SEC Adds Regulation Crypto to Rulemaking Agenda with Token Safe Harbor, July 2026

On 7 July 2026, the U.S. Securities and Exchange Commission placed Regulation Crypto on its regulatory priority agenda, the first crypto-specific rulemaking in the agency's history under Chair Paul Atkins. The proposal would create a time-limited registration exemption for early-stage token projects, permit capital raises up to $75 million in a 12-month period, and establish a decentralisation safe harbor for tokens whose issuers have ceased all essential managerial efforts.

Delaware Enacts Stablecoin Modernization Package Aligning State Licensing with Federal GENIUS Act

Delaware Governor Matt Meyer signed the Banking, Money Transmission, and Stablecoin Modernization Package on 6 July 2026, creating a state licensing regime for payment stablecoin issuers under the Delaware Payment Stablecoin Act. Senate Bill 19 establishes reserve requirements, redemption standards, and capital obligations aligned with the federal GENIUS Act and directs the Commissioner of Banks to seek nationwide operating authority through a substantial-similarity certification.