From the journal

Australia Privacy Act Automated Decision-Making Transparency Obligation Commences 10 December 2026

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a new automated decision-making (ADM) transparency obligation into Australian Privacy Principle 1 of the Privacy Act 1988 (Cth), requiring APP entities to disclose in their privacy policies the kinds of personal information used in ADM systems and the kinds of decisions those systems make where decisions could significantly affect individual rights. The obligation commences 10 December 2026.

2 min read

The Privacy and Other Legislation Amendment Act 2024 (Cth) amended the Privacy Act 1988 (Cth) to insert a new automated decision-making (ADM) transparency obligation under Australian Privacy Principle 1 (APP 1). The amendment is final legislation. The obligation commences on 10 December 2026 and applies to all APP entities subject to the Privacy Act.

Under the amended APP 1, an APP entity must include in its APP Privacy Policy information about: the kinds of personal information the entity uses in the operation of computer programs that make decisions, and the kinds of decisions those programs make, where the decisions could reasonably be expected to significantly affect the rights or interests of an individual. The obligation covers decisions made solely by operation of a computer program, without human intervention. The Office of the Australian Information Commissioner (OAIC) is preparing guidance, expected by September 2026, to define what constitutes a significant effect on rights or interests.

Banks, insurers, telecommunications providers, healthcare entities, and any APP entity using algorithmic scoring, automated credit assessment, insurance underwriting models, or automated content moderation systems must audit their existing decision-making processes and update their APP Privacy Policies before 10 December 2026. Entities operating cross-border digital services that collect personal information from Australian individuals may also fall within the Privacy Act through its extraterritorial provisions and face the same disclosure obligation.

The scope of computer programs covered and the threshold for significant effect on rights or interests are not yet authoritatively defined in the amended legislation. The OAIC guidance expected in September 2026 will be the primary interpretive source before commencement. Entities also operating in the European Union or United Kingdom face potential interaction with AI Act transparency obligations and automated decision-making rights under Article 22 of the UK GDPR, which may require separate but overlapping disclosures.

Licentium advises technology operators, financial services firms, and cross-border digital businesses on AI and data protection compliance. We can assist with ADM obligation gap analyses, privacy policy redrafting, and multi-jurisdiction compliance mapping where Australian, EU, and UK obligations interact. Work we undertake includes AI system audits, privacy documentation, automated decision-making legal assessments, and regulatory engagement strategy.

Source: Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision Making, Privacy and Other Legislation Amendment Act 2024 (Cth), APP 1

More from the journal

See all
Illia Prokopiev

Foreign Ownership of a Delaware or Wyoming Entity: Federal Tax Classification, Information Reporting, Withholding, and State Duties

A non-U.S. person may own a Delaware or Wyoming LLC or a Delaware corporation, yet formation alone does not settle the federal tax result, the reporting burden, confidentiality, or the right to work in the country. This part takes the U.S. entity as chosen and examines classification, Form 5472 reporting, source and effectively connected income, partner and shareholder withholding, tax residence and immigration, duties beyond the formation state, real property and estate exposure, and treaty and home-country dependencies.

Illia Prokopiev

Structuring Cross-Border Digital-Asset Ventures (Part 2)

A cross-border digital-asset group must allocate protocol stewardship, token issuance, customer-facing regulated services, pooled investment, treasury, and founder functions before it selects any jurisdiction. The question presented is where each of those functions can lawfully sit across sixteen jurisdictions and the European Union and EEA overlay, as of 27 August 2026.

Illia Prokopiev

Function-First Entity Design for Cross-Border Digital-Asset Ventures

Cross-border digital-asset ventures often separate several legal roles. Those roles include the venture issuer, operating company, customer-facing licensee, token issuer, pooled vehicle, treasury body, and protocol administrator. The Question Presented is which roles eight jurisdictions can support as of 27 August 2026.