The Privacy and Other Legislation Amendment Act 2024 (Cth) received royal assent on 29 November 2024 and inserts new sub-principles APP 1.7, 1.8, and 1.9 into the Privacy Act 1988 (Cth). APP 1.7 takes effect on 10 December 2026 and imposes a mandatory disclosure obligation on all APP entities that arrange for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect the rights or interests of an individual. The obligation is a transparency rule: it does not prohibit automated decision-making and does not grant individuals a right to demand human review.
APP 1.7 requires the APP Privacy Policy to identify: the kinds of personal information used in the automated decision; the kinds of decisions the computer program produces; and how an individual can seek further information about the logic involved. APP 1.8 applies supplementary requirements where sensitive information within the meaning of section 6 of the Privacy Act 1988 (Cth) is involved. APP 1.9 requires entities to update their APP Privacy Policy if the categories of automated decision change materially. The Office of the Australian Information Commissioner (OAIC) is consulting on draft guidance on what constitutes a significant effect on the rights or interests of an individual and what information about the logic involved must be disclosed.
Banks, consumer lenders, insurers, employers, online platforms, and AI-enabled product vendors that use automated credit scoring, claims processing, employment screening, or customer risk profiling must identify whether any such system makes decisions within the scope of APP 1.7 before 10 December 2026. Compliance requires an inventory of ADM systems and the personal information they use, a determination of whether each system produces decisions likely to significantly affect individual rights, and revision of the APP Privacy Policy to include the required disclosures for each in-scope system. The obligation applies to Australian-incorporated entities and to foreign entities that collect or hold personal information of Australian individuals in the course of carrying on business in Australia.
The OAIC's draft guidance has not yet definitively resolved whether ADM systems that produce recommendations rather than final decisions fall within APP 1.7. Entities that use AI to generate recommendations subject to human sign-off before execution should analyse whether the human review element is sufficiently meaningful to take the system outside the scope. Non-compliance with APP 1.7 is an interference with privacy under section 13G of the Privacy Act 1988 (Cth), giving the OAIC jurisdiction to investigate and issue compliance notices, infringement notices, or civil penalty proceedings for serious or repeated breaches. Penalties under the Privacy Act reach AUD 50 million or 30 percent of adjusted turnover for bodies corporate.
Licentium advises regulated entities on privacy compliance for AI and automated systems. Work we undertake includes APP 1.7 readiness assessments, ADM system inventories, APP Privacy Policy redrafting, cross-jurisdictional AI governance analysis under the EU AI Act, and GDPR Article 22 compliance benchmarking.