This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your business uses AI to screen job applicants, score customers, or help decide who gets approved for something, a new Privacy Act requirement means your privacy policy needs to change before December 2026. This is not a major operational overhaul, but the disclosure deadline is real, and ignoring it puts you in breach of Australia’s privacy law. This article explains what the rule covers, whether it applies to your business, and exactly what you need to do before 10 December 2026.
This is general information only, not legal advice. For specific obligations, consult a qualified privacy professional.
In short: From 10 December 2026, the Privacy Act requires covered businesses that use AI to make or heavily inform decisions that significantly affect people to disclose this in their privacy policy. The disclosure must name the types of decisions and the kinds of personal information used. The rule does not require stopping AI use, changing how it works, or obtaining individual consent. It is a transparency and disclosure obligation. The first step is auditing which AI tools you use and whether any of them influence significant decisions about people. See APP 1.7 guidance at oaic.gov.au.
What is the December 2026 deadline?
On 10 December 2024, the Privacy and Other Legislation Amendment Act 2024 received Royal Assent. That legislation introduced a new requirement into the Privacy Act 1988, known as APP 1.7. The change gives businesses a 24-month transition period to update their privacy practices before the rule takes effect on 10 December 2026.
APP 1.7 sits within Australian Privacy Principle 1, which outlines what businesses are expected to include in their privacy policy. The December 2026 deadline is when compliance becomes mandatory, not optional. Businesses that have not updated their privacy policy by that date may be in breach of the Privacy Act.
The Office of the Australian Information Commissioner (OAIC) oversees compliance with the Privacy Act and can investigate complaints, conduct audits, and seek civil penalties for serious or repeated breaches. The December 2026 deadline is not a soft guidance date. It is the commencement date written into the legislation.
What counts as automated decision-making under the Privacy Act?
Not every use of AI in your business triggers this requirement. The rule applies when a business uses personal information to make decisions by automated means, and where those decisions significantly affect the rights or interests of an individual.
The threshold phrase is “significantly affects rights or interests.” The legislation and explanatory materials point to categories such as: decisions about employment or contractor screening, decisions about credit or loan eligibility, insurance assessments, decisions about access to services or benefits, and tenancy assessments. These are decisions where the outcome materially changes what a person can access, earn, or be offered.
A few examples make the boundary clearer. If your HR software uses AI to rank or filter job applicants before a human reviews them, that is likely within scope. If your lending or credit management software scores customers and those scores feed into approval or rejection decisions, that is within scope. If AI helps decide whether someone qualifies for a service tier, a discount, or continued access to something important to them, that is within scope.
Routine business uses of AI are not within scope. Using an AI writing tool to draft marketing emails does not involve personal information in a way that significantly affects someone’s rights. Using an AI meeting transcription tool does not trigger this rule. Using AI to summarise internal documents, generate content, or help with accounting tasks is outside the scope of APP 1.7. The rule is targeted at AI that influences outcomes for specific individuals, not AI that assists with general business tasks.
Does the Privacy Act apply to my business?
The Privacy Act 1988 applies to businesses with an annual turnover above $3 million AUD. It also applies to certain businesses regardless of turnover, including those that handle health information, trade in personal information as part of their business model, or provide services to the Commonwealth government. From 1 July 2026, it also applies to businesses providing AML/CTF "designated services" (real estate, legal, accounting, and conveyancing work covered by anti-money-laundering rules), for the personal information handled as part of that AML/CTF work specifically, regardless of turnover.
If your business sits below the $3 million threshold and does not fall into one of those special categories, the Privacy Act does not currently apply to you, and APP 1.7 does not create a direct obligation. That said, the Australian government has flagged broader reforms to extend Privacy Act coverage to smaller businesses generally. That change has not yet passed into law or been introduced as a Bill as at July 2026, but it is worth monitoring.
If you are unsure whether your business is covered, the OAIC provides guidance on its website at oaic.gov.au. A qualified privacy professional can also confirm your obligations based on your specific circumstances and revenue.
What the rule actually requires you to disclose
APP 1.7 requires covered businesses to include three specific things in their privacy policy if they use personal information to make decisions by automated means that significantly affect individuals.
First, the policy must state whether the business uses personal information to make decisions by automated means. A plain yes or no, written into the policy, is the starting point.
Second, it must describe the types of decisions made using automated means. The OAIC's guidance does not require exhaustive technical documentation. A plain-English description of the decision categories is what APP 1.7 calls for. For example: "We use automated tools to assist in assessing loan applications" or "Our recruitment platform uses automated ranking to sort job applicants."
Third, the policy must identify the kinds of personal information used in those automated decisions. Again, this is categories of information rather than a complete data inventory. Examples include name and contact details, financial history, employment history, or health status.
What APP 1.7 does not require is also worth noting. The OAIC's guidance confirms the rule does not require explaining the technical workings of your AI system, giving individuals a right to opt out, or providing human review of every automated decision. Those are separate policy questions that may develop over time. See the full text of APP 1.7 at legislation.gov.au and the OAIC's guidance at oaic.gov.au.
What to do before 10 December 2026
There are four practical steps to take before the deadline. First, audit the AI tools your business currently uses. Go through every software platform, plugin, or AI-assisted feature your team uses and ask whether it uses personal information about individuals to produce outputs that influence decisions with significant effects. Pay close attention to HR and recruitment tools, credit or financial assessment tools, customer scoring or segmentation tools, and any platform that produces an automated recommendation about whether to approve, reject, or prioritise an individual.
Second, for any tool that sits within scope, document what personal information it uses and what category of decision it informs. You do not need a legal brief for each one, but you do need enough detail to write an accurate description in your privacy policy. A simple internal register noting the tool name, the decision type, and the data inputs is enough to support the policy update.
Third, update your privacy policy before 10 December 2026. The update needs to add the APP 1.7 disclosures in plain language. If your privacy policy is currently a generic template, this is also a good time to make sure the rest of it accurately reflects how your business actually handles personal information. A free AI Staff Policy Template (T-01) is available at needtoknowai.com to help you document how your business uses AI tools more broadly.
Fourth, set a review reminder. AI tools change. If your business adopts new AI capabilities after December 2026 that bring additional decision-making into scope, your privacy policy needs to be updated accordingly. Building a six-monthly review of your AI tool register into your compliance calendar is a low-effort way to stay current. For a step-by-step guide to writing the actual policy language, see How to Update Your Privacy Policy for AI Automated Decisions: Australian Guide.
Common SMB scenarios: does this affect me?
A recruitment or HR platform that uses AI to rank, score, or filter candidates before a human sees the shortlist is within scope. The AI is using personal information (resume content, work history, skills data) to influence a decision that significantly affects the individual’s employment prospects. You would need to disclose in your privacy policy that you use automated tools in your recruitment process and identify the types of personal information involved.
A finance broker or lender using AI-assisted credit assessment software is within scope. If the tool scores an applicant and that score feeds into a decision about whether to offer finance, at what rate, or at what limit, the automated decision-making threshold is met. The disclosure requirement applies to the business using the tool, not just the software vendor.
A general practice or allied health clinic using an AI admin tool to schedule appointments or summarise clinical notes is not automatically within scope. The key question is whether the AI output significantly affects the patient’s rights or access to something important. Appointment scheduling does not meet that threshold. An AI tool that flags patients for treatment prioritisation or triages access to specialist referrals would sit closer to the boundary and would warrant a closer look with a privacy professional.
A retailer using AI to personalise product recommendations on an ecommerce site is unlikely to be within scope for APP 1.7, provided the personalisation does not significantly affect the individual’s access to services, pricing, or rights in a material way. Product recommendations are commercial, not consequential in the sense the legislation targets. That said, if AI-powered pricing decisions result in materially different prices for different individuals based on profiling, that is worth examining more closely.
What this rule does not require
APP 1.7 is a transparency requirement, not an operational restriction. It does not prohibit automated decision-making. It does not require businesses to obtain consent before using AI in decisions. It does not create a right for individuals to demand human review of an automated decision. None of those obligations exist in the current version of the legislation.
The rule also does not require you to disclose the specific AI vendor or product you use, the technical model behind the tool, or the precise weighting it applies to different inputs. Plain-English categories are what the legislation asks for, not technical documentation.
It is worth noting that the broader Privacy Act reform agenda includes proposals that go further than APP 1.7, including a potential right to explanation for automated decisions. Those proposals have not yet become law as at June 2026. APP 1.7 as it currently stands is narrower and more achievable than some commentary has suggested.
Last verified: June 2026 | Next review: September 2026
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools and our AI and the Privacy Act guide.
Related reading: our Claude AI review for Australian business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our AI governance by region.
What is APP 1.7 and when does it come into effect?
APP 1.7 is a new requirement under Australian Privacy Principle 1, introduced by the Privacy and Other Legislation Amendment Act 2024. It requires businesses covered by the Privacy Act to disclose in their privacy policy whether they use personal information to make decisions by automated means, what types of decisions those are, and what kinds of personal information are involved. It comes into effect on 10 December 2026, giving businesses a 24-month transition period from the date the legislation received Royal Assent.
Does APP 1.7 apply to every business that uses AI?
No. Two filters apply. First, your business must be covered by the Privacy Act, which generally means annual turnover above $3 million AUD, or your business handles health information or trades in personal information. Second, your use of AI must involve making or heavily informing decisions that significantly affect an individual’s rights or interests. Routine AI use for content creation, admin support, or internal tasks does not trigger the requirement.
Do I need to stop using AI tools or get consent from individuals before December 2026?
No. APP 1.7 does not require stopping AI use, changing how AI tools work, or obtaining individual consent for automated decisions. It is a disclosure rule only. The requirement is to update your privacy policy to be transparent about automated decision-making that is already happening. The rule does not introduce a right to opt out or a right to human review under current legislation. See the OAIC's guidance at oaic.gov.au.
What happens if my business does not update its privacy policy by 10 December 2026?
Under the Privacy Act, a business that has not updated its privacy policy to meet the APP 1.7 requirement by 10 December 2026 may be in breach of the Act. The OAIC can investigate complaints, conduct audits, and seek civil penalties for non-compliance. Serious or repeated breaches of the Australian Privacy Principles can result in significant financial penalties. The OAIC has signalled it will take an education-first approach to new requirements, but that does not eliminate the legal exposure. See the OAIC's enforcement approach at oaic.gov.au. Consult a qualified privacy or legal advisor to confirm your obligations and timeline.
How much detail does my privacy policy need to include about automated decision-making?
Plain-English categories are sufficient. You do not need to name the specific AI vendors you use, describe the technical model, or document every data input. A statement that your business uses automated tools in recruitment and identifies the types of personal information used (such as employment history and skills data) meets the requirement. The goal is transparency for individuals, not a technical audit trail.
Where can I find a template to help update my privacy policy and AI practices?
Need to Know AI provides a free AI Staff Policy Template (T-01) covering how businesses should govern staff use of AI tools, available at needtoknowai.com. For a step-by-step guide to writing the automated decision-making disclosures specifically required by APP 1.7, see How to Update Your Privacy Policy for AI Automated Decisions: Australian Guide. For your specific legal obligations, consult a qualified privacy professional.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Ready to update your privacy policy for the December 2026 deadline? Our step-by-step Australian guide walks you through exactly what to write and where to put it.
How to Update Your Privacy Policy for AI