AI Framework

APP 1.7: What to Disclose Before 10 December 2026

From 10 December 2026, APP 1.7 requires a business to disclose in its privacy policy if it uses a computer program to make, or substantially support, a decision that could significantly affect someone's rights or interests. Three things must be disclosed: the personal information used, the decisions made solely by the program, and the decisions it substantially supports.

If you searched "automated decision making privacy act," this is it. Australian Privacy Principle 1 covers how a business manages personal information generally - see the full list of all 13 APPs for where this sits in the wider framework. From 10 December 2026, three new subsections of APP 1 - 1.7, 1.8 and 1.9 - add a specific requirement: disclosing when automated systems are involved in decisions about people.

What actually triggers the obligation

The APP 1.7 test has three elements, all of which must be present. A computer program has to be arranged to make, or substantially and directly help make, a decision. That decision has to be one that could reasonably be expected to significantly affect someone's rights or interests. And personal information about that person has to be used to make it. If any one of the three is absent, the obligation under APP 1.7 is not triggered for that system.

The definition of "computer program" is deliberately broad. It's not limited to generative AI or machine learning - a rules-based CRM that scores leads, an automated eligibility checker, or a chatbot that triages support requests can all qualify, depending on what they're deciding and whether personal information feeds into it.

The APP 1.7 trigger test - all three must be true

The misconception that trips up most businesses

A human reviewing the automated output does not automatically remove the disclosure obligation. If the automated system's recommendation is a key factor in the final decision, the obligation can still apply - a human "signing off" on what the system produced doesn't change that. This point comes up across every source covering this requirement, which suggests it's the single most common wrong assumption businesses are making about it.

What you actually have to disclose

Three things, and only three things, under APP 1.8: the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions the program substantially supports. "Kinds," not specifics - this is a category-level disclosure, not a line-by-line audit trail of every decision made.

Do you have to reveal how your system actually works?

No. This is worth stating plainly because it's the fear most likely to stop a business owner from taking this seriously: the Explanatory Memorandum to the amending Act specifically notes the disclosure isn't expected to include commercial-in-confidence detail about how a system works internally. The obligation covers the kind of decision and the kind of data - not a scoring formula, model weights, or a vendor's proprietary logic.

Which of your tools actually count?

A short checklist, since "automated decision-making" sounds more exotic than it usually is in practice:

If personal information feeds into any of these and the outcome could meaningfully affect someone, APP 1.7 may be relevant.

What happens if a business doesn't comply

The penalties that apply are the same general Privacy Act regime that already covers privacy policies - there's no separate, higher figure specifically for missing ADM disclosure. Infringement notices for a privacy policy missing required content run to 200 penalty units - around $72,800 at current rates, indexed annually (the OAIC quoted $66,000 in late 2025, before the July 2026 indexation). Civil penalties for serious or repeated breaches can scale much higher under the 2024 amendments - but that's the general serious-breach maximum, not a number specific to this requirement.

There's also no separate grace period after 10 December 2026. The roughly two years since the amending Act passed in 2024 is the lead-in time businesses have had - Commissioner Carly Kind has described it publicly as "a small change but really important for businesses." Once the date arrives, it arrives.

Separately, and worth not confusing with this requirement: the OAIC's first privacy compliance sweep started in January 2026, checking around 60 businesses across sectors like real estate, pharmacies and car dealerships for basic privacy policy adequacy under APP 1.4. That sweep isn't checking automated decision-making disclosure - it can't yet, since the obligation doesn't commence until December. But it's a real, current sign the regulator is actively checking privacy policies.

If you want the full picture of what applies to your specific business beyond this one requirement, AI Framework maps it against the Commonwealth and state instruments that apply to your industry in one pass.

FAQ

Does a chatbot or lead-scoring tool count as automated decision-making? It can, if personal information feeds into it and the outcome could significantly affect someone - regardless of whether the tool uses AI or simple rules. Check it against the three-part APP 1.7 test above.

If a human reviews the automated output, are we exempt? Not automatically. If the automated system's output is a key factor in the final decision, disclosure can still be required even with a human making the final call.

Do we have to disclose how our algorithm or scoring system works? No. The disclosure covers the kinds of personal information used and the kinds of decisions made - not the internal logic, model, or vendor's proprietary system.

If we already comply with the GDPR or the EU AI Act, are we covered? No - APP 1.7 is a separate Australian test with its own three-part definition. Compliance with an overseas framework doesn't automatically satisfy it.

Is there a grace period after 10 December 2026? No. The roughly two years since the 2024 amending Act passed is the only lead-in time - there's no further leniency window once the requirement commences.

For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.

This page covers one requirement. If your business handles personal information and uses AI, address it today with AI Framework.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights