The date to circle
On 10 December 2026, three new Australian Privacy Principles start to apply: APP 1.7, 1.8 and 1.9. They were added by the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024 with a two-year runway. That runway now has about ten weeks left.
The rule is short. If an organisation covered by the Privacy Act has arranged for a computer program to use personal information to make a decision, or to do something substantially and directly related to making a decision, and that decision could reasonably be expected to significantly affect an individual's rights or interests, its privacy policy must say so.
What the privacy policy must contain
Under APP 1.8, the policy must describe:
- the kinds of personal information used by the program;
- the kinds of decisions made solely by the operation of the program; and
- the kinds of decisions where the program does something substantially and directly related to making the decision.
The word "kinds" matters. The rule asks for categories that a reader can understand, not source code, model weights or a list of every individual decision.
The question is no longer whether you use AI. It is whether people can find out which decisions a program makes about them.
Who is covered
The obligation sits on APP entities: Australian Government agencies and most private organisations with annual turnover above the small-business threshold, plus some smaller businesses that the Act brings in, such as health service providers. If you are not sure whether the Privacy Act applies to you, start with the OAIC's guidance rather than assuming you are exempt.
Solely, or substantially and directly related
Two kinds of automation are in scope.
Solely automated decisions are made by the program with no meaningful human involvement. An agent that approves or declines an application on its own is the obvious example.
Substantially and directly related covers the much larger middle ground: a program that scores, ranks, filters, flags or recommends, where a person then makes the formal decision. A human signing off at the end does not, by itself, take the decision out of the rule if the program's output shaped it in a substantial and direct way.
For teams running AI agents, this second category is where most work will land. Triage agents, eligibility screeners, fraud flags and "next best action" tools all deserve a look.
Solely automated and substantially assisted decisions are both in scope. A human signing off at the end does not take a decision out of the rule.
The significant-effect test
The rule only bites where the decision could reasonably be expected to significantly affect an individual's rights or interests. Decisions about access to services, credit, insurance, employment, housing, government benefits or health care are the clearest candidates. Personalising the colour of a button is not. The OAIC's guidance gives the regulator's view of where the line sits, and it is worth reading directly.
Timing: data collected before 10 December still counts
The obligation applies to decisions made on or after 10 December 2026. It does not matter that the personal information was collected earlier. An agent deployed in 2025 that keeps making significant decisions after 10 December needs to be described in the privacy policy from that date.
A practical ten-week checklist
- Inventory. List every program and agent that uses personal information and touches a decision about a person.
- Classify. For each one, note whether it decides solely, or does something substantially and directly related to a decision.
- Test the effect. Ask whether the decision could reasonably be expected to significantly affect someone's rights or interests. Record your reasoning.
- Describe the kinds. Write plain-language categories of personal information and decisions.
- Update the privacy policy. Publish the new section before 10 December, and make it easy to find.
- Keep it current. New agents, new data sources and new decision types should trigger a review.
How this compares with EU Article 50
A transparency field is a pointer to your disclosure, not a substitute for it.
The EU AI Act takes a different angle. Article 50 is about telling people when they are dealing with AI: providers must design systems that interact directly with people so that people are informed they are interacting with an AI system, unless that is obvious from the context, and certain AI-generated or manipulated content must be marked or disclosed. Those obligations apply from 2 August 2026, although organisations should check the latest EU timelines and guidance, which continue to evolve.
The two rules overlap but are not the same. Australia's APP 1.7 is about decisions and the privacy policy. Article 50 is about interactions and content at the point of contact. An organisation operating in both markets may need to satisfy both, in different places.
Where open records fit
The OCC Agent Record, the open record format published at Open Conformance, now includes optional fields that let an operator point to these disclosures: the kinds of decisions an agent makes solely, the kinds it substantially assists, the kinds of personal information it uses, a link to the privacy policy, and how AI interaction is disclosed under Article 50. The field definitions and an example are at openconformance.org/occ/adm-transparency.
Those fields are a pointer, not a substitute. Publishing them does not make a privacy policy lawful, and OCC does not assess or certify legal compliance. What they do is make the disclosure findable in a consistent, machine-readable place, next to the rest of what an operator says about its agent.
The bottom line
Ten weeks is enough time to find your automated decisions and describe them honestly. It is not enough time to start in December.
Sources & Further Reading
- 1.Privacy and Other Legislation Amendment Act 2024 (Cth)
- 2.OAIC, APP Guidelines Chapter 1: open and transparent management of personal information
- 3.OAIC guidance for organisations and government agencies
- 4.EU AI Act, Article 50: transparency obligations for providers and deployers of certain AI systems
- 5.Open Conformance: automated decisions and transparency fields in the OCC Agent Record






