APP 1.7: What to Disclose Before 10 December 2026
6 September 2026
From 10 December 2026, APP 1.7 requires a business to disclose in its privacy policy if it uses a computer program to make, or substantially support, a decision that could significantly affect someone's rights or interests. Three things must be disclosed: the personal information used, the decisions made solely by the program, and the decisions it substantially supports.
If you searched "automated decision making privacy act," this is it. Australian Privacy Principle 1 covers how a business manages personal information generally - see the full list of all 13 APPs for where this sits in the wider framework. From 10 December 2026, three new subsections of APP 1 - 1.7, 1.8 and 1.9 - add a specific requirement: disclosing when automated systems are involved in decisions about people.
What actually triggers the obligation
The APP 1.7 test has three elements, all of which must be present. A computer program has to be arranged to make, or substantially and directly help make, a decision. That decision has to be one that could reasonably be expected to significantly affect someone's rights or interests. And personal information about that person has to be used to make it. If any one of the three is absent, the obligation under APP 1.7 is not triggered for that system.
The definition of "computer program" is deliberately broad. It's not limited to generative AI or machine learning - a rules-based CRM that scores leads, an automated eligibility checker, or a chatbot that triages support requests can all qualify, depending on what they're deciding and whether personal information feeds into it.
The APP 1.7 trigger test - all three must be true
- 1. A computer program is arranged to make a decision, or do something substantially and directly related to making one - Covers generative AI, but also rule-based scoring systems, CRM workflows, and everyday business software
- 2. The decision could reasonably be expected to significantly affect an individual's rights or interests - Includes decisions that help someone, not just ones that harm them
- 3. Personal information about that individual is used in making the decision - If no personal information is involved, APP 1.7 doesn't apply
The misconception that trips up most businesses
A human reviewing the automated output does not automatically remove the disclosure obligation. If the automated system's recommendation is a key factor in the final decision, the obligation can still apply - a human "signing off" on what the system produced doesn't change that. This point comes up across every source covering this requirement, which suggests it's the single most common wrong assumption businesses are making about it.
What you actually have to disclose
Three things, and only three things, under APP 1.8: the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions the program substantially supports. "Kinds," not specifics - this is a category-level disclosure, not a line-by-line audit trail of every decision made.
- 1 - The kinds of personal information used in the operation of such computer programs
- 2 - The kinds of decisions made solely by the operation of such computer programs
- 3 - The kinds of decisions for which something substantially and directly related to making the decision is done by such computer programs
Do you have to reveal how your system actually works?
No. This is worth stating plainly because it's the fear most likely to stop a business owner from taking this seriously: the Explanatory Memorandum to the amending Act specifically notes the disclosure isn't expected to include commercial-in-confidence detail about how a system works internally. The obligation covers the kind of decision and the kind of data - not a scoring formula, model weights, or a vendor's proprietary logic.
Which of your tools actually count?
A short checklist, since "automated decision-making" sounds more exotic than it usually is in practice:
- A chatbot or intake form that triages, ranks or routes enquiries
- Lead-scoring or eligibility-checking software, rules-based or AI-driven
- Automated pricing, quoting or approval workflows
- Any AI tool a decision-maker relies on as a "key factor," even with a human making the final call
If personal information feeds into any of these and the outcome could meaningfully affect someone, APP 1.7 may be relevant.
What happens if a business doesn't comply
The penalties that apply are the same general Privacy Act regime that already covers privacy policies - there's no separate, higher figure specifically for missing ADM disclosure. Infringement notices for a privacy policy missing required content run to 200 penalty units - around $72,800 at current rates, indexed annually (the OAIC quoted $66,000 in late 2025, before the July 2026 indexation). Civil penalties for serious or repeated breaches can scale much higher under the 2024 amendments - but that's the general serious-breach maximum, not a number specific to this requirement.
There's also no separate grace period after 10 December 2026. The roughly two years since the amending Act passed in 2024 is the lead-in time businesses have had - Commissioner Carly Kind has described it publicly as "a small change but really important for businesses." Once the date arrives, it arrives.
Separately, and worth not confusing with this requirement: the OAIC's first privacy compliance sweep started in January 2026, checking around 60 businesses across sectors like real estate, pharmacies and car dealerships for basic privacy policy adequacy under APP 1.4. That sweep isn't checking automated decision-making disclosure - it can't yet, since the obligation doesn't commence until December. But it's a real, current sign the regulator is actively checking privacy policies.
If you want the full picture of what applies to your specific business beyond this one requirement, AI Framework maps it against the Commonwealth and state instruments that apply to your industry in one pass.
FAQ
Does a chatbot or lead-scoring tool count as automated decision-making? It can, if personal information feeds into it and the outcome could significantly affect someone - regardless of whether the tool uses AI or simple rules. Check it against the three-part APP 1.7 test above.
If a human reviews the automated output, are we exempt? Not automatically. If the automated system's output is a key factor in the final decision, disclosure can still be required even with a human making the final call.
Do we have to disclose how our algorithm or scoring system works? No. The disclosure covers the kinds of personal information used and the kinds of decisions made - not the internal logic, model, or vendor's proprietary system.
If we already comply with the GDPR or the EU AI Act, are we covered? No - APP 1.7 is a separate Australian test with its own three-part definition. Compliance with an overseas framework doesn't automatically satisfy it.
Is there a grace period after 10 December 2026? No. The roughly two years since the 2024 amending Act passed is the only lead-in time - there's no further leniency window once the requirement commences.
For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.
This page covers one requirement. If your business handles personal information and uses AI, address it today with AI Framework.
This post is general information, not legal advice.
Current as at September 2026.