From the journal

Australia Privacy Act ADM Transparency Obligations Commence 10 December 2026 Under APP 1

From 10 December 2026, APP entities in Australia must disclose in their APP Privacy Policy the use of personal information in automated decision-making that could significantly affect individual rights or interests, under APP 1.7, 1.8, and 1.9 inserted by the Privacy and Other Legislation Amendment Act 2024. Guidance from the OAIC is expected before September 2026.

2 min read

New automated decision-making transparency obligations take effect in Australia on 10 December 2026 under subclauses 1.7, 1.8, and 1.9 of Schedule 1 to the Privacy Act 1988, inserted by the Privacy and Other Legislation Amendment Act 2024. These are final, enacted provisions; the effective date is fixed by statute.

The amended Australian Privacy Principle 1 (APP 1) requires APP entities to include specified information in their APP Privacy Policy where the entity arranges for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect the rights or interests of an individual. APP 1.7 requires disclosure of the kinds of personal information used in automated decision-making. APP 1.8 requires disclosure of the kinds of decisions made using that personal information. APP 1.9 requires disclosure of the sources from which personal information was collected for those purposes. The Office of the Australian Information Commissioner intends to publish compliance guidance before September 2026.

The obligations apply to all APP entities using algorithmic or AI-based systems over personal data where the output could significantly affect individual rights or interests. This covers banks assessing credit eligibility, insurers pricing risk, employers screening candidates, health providers triaging patients, and government agencies processing welfare or licensing decisions. Affected entities must audit current automated decision systems, identify which processes meet the significance threshold, and update APP Privacy Policies before 10 December 2026.

The Privacy and Other Legislation Amendment Act 2024 amended additional Australian Privacy Principles beyond APP 1; the ADM transparency rules represent one element of a broader privacy reform cycle. The OAIC is consulting on guidance and updating its APP 1 materials progressively. Entities with complex ADM architectures should complete disclosure assessments before the OAIC guidance is published so any required revisions can be incorporated before the 10 December 2026 commencement date.

Licentium advises technology companies, financial institutions, and regulated entities on AI governance and privacy compliance obligations in Australia and across multiple jurisdictions. Work we undertake includes automated decision-making audits, APP 1 compliance assessments, AI governance policy design, privacy impact assessments, and regulatory readiness reviews for organizations deploying algorithmic systems.

Source: Office of the Australian Information Commissioner, APP 1 Open and Transparent Management of Personal Information (ADM Amendments, Privacy and Other Legislation Amendment Act 2024, effective 10 December 2026)

More from the journal

See all
Illia Prokopiev

Foreign Ownership of a Delaware or Wyoming Entity: Federal Tax Classification, Information Reporting, Withholding, and State Duties

A non-U.S. person may own a Delaware or Wyoming LLC or a Delaware corporation, yet formation alone does not settle the federal tax result, the reporting burden, confidentiality, or the right to work in the country. This part takes the U.S. entity as chosen and examines classification, Form 5472 reporting, source and effectively connected income, partner and shareholder withholding, tax residence and immigration, duties beyond the formation state, real property and estate exposure, and treaty and home-country dependencies.

Illia Prokopiev

Structuring Cross-Border Digital-Asset Ventures (Part 2)

A cross-border digital-asset group must allocate protocol stewardship, token issuance, customer-facing regulated services, pooled investment, treasury, and founder functions before it selects any jurisdiction. The question presented is where each of those functions can lawfully sit across sixteen jurisdictions and the European Union and EEA overlay, as of 27 August 2026.

Illia Prokopiev

Function-First Entity Design for Cross-Border Digital-Asset Ventures

Cross-border digital-asset ventures often separate several legal roles. Those roles include the venture issuer, operating company, customer-facing licensee, token issuer, pooled vehicle, treasury body, and protocol administrator. The Question Presented is which roles eight jurisdictions can support as of 27 August 2026.