The automated decisions you forgot you were making
From 10 December 2026, Australian privacy policies must disclose automated decision-making. The hard part is not the wording. It is finding out where it is already happening.
What the obligation is
From 10 December 2026, entities covered by the Australian Privacy Principles must include information in their privacy policy about their use of automated decision-making. Specifically, where personal information is used in automated decisions that could significantly affect an individual's rights or interests, the policy must describe the kinds of personal information used and the kinds of decisions being made.
It is a transparency obligation rather than a prohibition. Nobody is telling you to stop using automated tools. You are being told to say that you use them, and roughly what for.
Which sounds straightforward, and is — right up until someone asks you to produce the list.
What counts as automated
The obligation is drafted more broadly than most people assume. It reaches a computer program that makes a decision, and also one that does something substantially and directly related to making a decision. The second limb is the one that catches people. A system that does not make the final call, but produces the score, ranking or filter the human relies on, is squarely in scope.
The threshold is that the decision could reasonably be expected to significantly affect an individual's rights or interests. Commentary ahead of the deadline suggests the OAIC is reading the scope broadly, with examples including CV filtering, lead scoring, dynamic pricing, risk scoring and algorithmic recommendation.
Note also that "automated" is not a synonym for "AI". A rules engine written in 2014 that declines applications below a threshold is automated decision-making. So is a spreadsheet-driven scoring model, if the output substantially drives a decision about a person.
Where it is hiding
In the environments we assess, automated decision-making is rarely in the place the organisation first looks. It is almost never a single obvious "AI system". It is spread across tools that were bought to do something else and quietly acquired a scoring feature in a product update.
- Recruitment. Applicant tracking systems that rank, screen or knock out candidates on keywords, screening questions or assessment scores. This is the highest-risk category for most organisations and frequently owned by HR rather than IT.
- CRM and marketing automation. Lead scoring, segmentation and propensity models that determine who gets contacted, who gets an offer and who is quietly deprioritised.
- Credit, onboarding and eligibility. Automated credit checks, identity verification, fraud scoring and eligibility rules that gate access to a service.
- Pricing. Dynamic or segmented pricing that varies what an individual is offered based on attributes held about them.
- Workforce tools. Rostering, performance scoring and productivity monitoring that feed into decisions about people's hours, pay or progression.
- Features you did not switch on deliberately. The SaaS platform that added an AI scoring or recommendation feature in a release, enabled by default. Nobody procured it. It is running.
That last category is the reason this is an IT problem and not only a legal one. Finding it means going application by application through what you actually run, including the things bought on a departmental credit card.
The timing problem
The OAIC has indicated its guidance on this obligation is expected around September 2026. The obligation commences on 10 December 2026.
That leaves roughly three months between authoritative guidance and the deadline — over Christmas, in a country that effectively stops for much of January. Waiting for the guidance before starting is a plan that runs out of calendar.
The sequencing that works: do the discovery now, because the inventory of where automated decision-making exists in your environment is required under any reading of the rules. Draft the disclosure language later, once the guidance lands. The expensive, slow, cross-departmental part is the discovery. The wording is an afternoon.
A four-step approach
- Inventory your systems that touch personal information. Start from your actual application list — including shadow IT and departmental SaaS — not from the systems the IT team formally manages. If you do not have that list, this obligation is the second-best reason to build one. The first is security.
- For each system, ask one question: does this produce a score, ranking, flag, filter or recommendation about a person that someone then acts on? If yes, it is a candidate. Do not try to resolve the legal threshold at this stage — capture it and move on.
- Ask each vendor directly, in writing, whether their product performs automated decision-making as defined by the Australian Privacy Act amendments, and request their position ahead of December. Their answer, or their silence, is useful either way — and it is evidence you asked.
- Take the shortlist to whoever owns privacy and let them apply the significance threshold and draft the policy language once OAIC guidance is available.
The bigger question underneath
Most organisations that go through this exercise discover something more uncomfortable than a privacy policy gap. They find automated decisions being made about people by systems nobody has reviewed, using data nobody has audited, with no record of who approved it or how to challenge an outcome.
The December deadline only asks you to describe that in a policy. The better use of the work is deciding whether you are comfortable with what you found — which is a governance question, and one your board is increasingly likely to ask about regardless of the statutory date.
A useful test: ask your HR and marketing leads whether any system they use scores, ranks or filters people automatically. If the answer is "not really, but the platform does suggest things", you have found automated decision-making — and you have found it in a department that does not know the December deadline exists.
This is general information about a regulatory change, not legal advice. Whether a particular system meets the significance threshold is a question for your privacy adviser or legal counsel, ideally against the OAIC guidance when it is released.
You cannot disclose what nobody has counted
Our assessment starts by counting what you actually run — including the departmental SaaS nobody told IT about. That inventory is where this obligation begins.