This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If you have already read up on the December 2026 Privacy Act deadline and now want to know exactly how to update your privacy policy, this guide covers the full process. The APP 1.7 automated decision-making disclosure is not a separate document you file with the OAIC. It has to sit inside your organisation's privacy policy, which most businesses already have published on their website. The practical question is: what do you add, where do you put it, and how do you word it?
In short: There are six steps. Audit which AI tools make decisions using personal information. Classify whether those decisions significantly affect someone's rights or interests. Write a plain-English disclosure section in your privacy policy. Have legal review it if your AI use is complex. Publish the updated policy before 10 December 2026. Document your process for accountability. For most small businesses using one or two AI tools, this takes around two hours.
Step 1: Audit which AI tools you use for decisions
Start by listing every AI system your business currently uses. Include AI features built into tools you already pay for, not just standalone AI products. Microsoft Copilot in your CRM, an AI shortlisting feature in your HR platform, and a credit-scoring add-on in your accounting software all count.
For each tool, ask two questions: Does it process personal information? And does it produce an output that influences a decision? If the answer to both is yes, that tool is in scope. If an AI tool only processes anonymised or aggregate data, it sits outside the disclosure requirement.
Write down the tool name, what personal information it receives, and what kind of output it produces. This list becomes the foundation for your disclosure. If you find you cannot answer these questions clearly, that is a signal to contact the vendor and ask directly.
Take a recruitment agency owner who has been running candidate applications through an AI shortlisting tool for a year without a second thought. Instead of guessing whether it counts, she applies the two-question test above: the tool receives applicant names, work history and contact details, and its output decides who gets forwarded to interview. That is a yes on both counts. Now she has one AI tool confirmed in scope, and the audit for the rest of her software stack takes about twenty minutes.
Step 2: Classify: does this decision significantly affect someone?
Not every AI output that touches personal information requires disclosure. The APP 1.7 obligation applies to automated decisions that significantly affect a person's rights or interests. A spelling checker is not in scope. An AI system that scores job applicants and determines who moves forward for interview is in scope.
Use this as your practical test: could the AI's output reasonably result in someone being denied a job, refused credit, excluded from a service, charged a different price, or treated differently in a way that matters to them? If yes, that decision is significant and must be disclosed. Employment screening, insurance risk assessment, credit eligibility, eligibility for healthcare services, and pricing algorithms that vary by individual all fall into this category.
Content recommendations, document summaries, spelling and grammar tools, and scheduling assistants generally do not meet the threshold. When you are uncertain, the safer position is to include the disclosure rather than leave it out. Over-disclosing carries no penalty; under-disclosing creates compliance risk.
Step 3: Write the disclosure in plain English
The Privacy Act does not prescribe exact wording. The OAIC expects businesses to write a disclosure that is clear, accurate, and understandable to the people whose information is being used. Plain English is both required and sufficient.
Your disclosure must cover three things for each relevant AI system: whether you use personal information to make automated decisions, what types of decisions those are, and what kinds of personal information are involved. You do not need to name the specific vendor or tool unless you choose to.
Automated decision-making We use automated systems, including AI-assisted tools, to help make certain decisions that may affect you. These include decisions about job applications, where an AI tool reviews application information such as your name, contact details, employment history, and responses to screening questions, and produces a shortlist recommendation. Human review occurs before any final decision is made. If you have questions about how automated systems are used in decisions that affect you, please contact us at [email address].
-- Sample APP 1.7 disclosure: adapt to your actual AI use
If your business uses more than one AI system for significant decisions, include a separate paragraph for each type of decision. Keep each paragraph focused: state the decision type, name the personal information involved, and note any human oversight in the process. The goal is that someone reading your policy can understand what happens to their information without needing a law degree.
Step 4: Where to put the disclosure in your privacy policy
The APP 1.7 disclosure must sit inside your organisation's privacy policy. It cannot satisfy the requirement if it only appears in a terms of service document, a staff handbook, or a separate AI ethics statement. If someone reads your website privacy policy, they must find this disclosure there.
Add a dedicated section headed something like "Automated decision-making" or "How we use AI in decisions." Place it logically within your existing policy structure, typically alongside sections that explain how you use personal information. Do not bury it in a definitions appendix or a general catch-all clause at the end of the document.
If your privacy policy is overdue for a general refresh, this is a reasonable time to do both. A privacy policy that was last updated in 2019 and uses language about "third-party processors" without naming any specific practices is unlikely to pass scrutiny even before the ADM requirements are considered.
Step 5: Publish and document before 10 December 2026
The deadline for compliance with APP 1.7 is 10 December 2026. Your updated privacy policy must be live on your website by that date. If you have a separate app privacy policy or a policy linked from a customer portal, update those too. The obligation applies wherever your privacy policy is published.
After publishing, record what you did and when. Save a dated copy of the updated policy, note the date it was published, and keep a record of the audit you completed in Step 1. This documentation supports accountability if the OAIC ever requests evidence of your compliance process. A simple dated email to yourself or a shared folder with a filename like "privacy-policy-ADM-update-2026-11.pdf" is sufficient for most small businesses.
For organisations with complex AI use: If your business uses AI for credit assessment, health-related decisions, or large-scale employment screening, have a lawyer review your disclosure wording before you publish. The plain-English standard still applies, but the stakes of getting the scope wrong are higher when significant decisions affect large numbers of people.
Common mistakes to avoid
Disclosing too vaguely. A statement like "we may use AI in some of our processes" does not satisfy APP 1.7. The disclosure must name the types of decisions made and the kinds of personal information used. Vague language that could apply to any business in any industry is not a disclosure. It is a placeholder.
Not listing which decisions are automated. Some businesses draft a general "we use AI" statement and consider the obligation met. The requirement is to identify the specific decision types, not just acknowledge that AI exists in the business. A hiring tool and an insurance pricing tool are two different decisions that require two separate descriptions.
Waiting until November to start. Updating a privacy policy sounds simple, but it typically involves a legal review, a website update, approval from a director or principal, and time to confirm the audit in Step 1 is complete. Starting in October leaves no buffer for any of those steps to take longer than expected. Starting now means you have time to get it right.
Forgetting to update all versions. If your business has a privacy policy on your main website, a separate one in your mobile app, and another linked from your booking system, all three need the APP 1.7 disclosure. Publishing it on one and missing the others leaves gaps.
Last verified: June 2026 | Next review: September 2026
This is general information, not legal advice. For advice on your specific privacy policy wording and obligations, consult a qualified privacy professional.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools and our AI and the Privacy Act guide.
See also: our OAIC AI guidance summary.
Related reading: our Claude AI review for Australian business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI vs Human Cost Comparison to compare the cost of AI tools against equivalent human time.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Try our free AI Policy Generator to generate a customised AI policy for your business.
Related reading: our free AI acceptable use policy template and our AI governance by region.
Does the APP 1.7 disclosure have to go in my existing privacy policy, or can it be a separate document?
The OAIC's guidance and the APP 1.7 requirement are clear that the disclosure should sit inside your privacy policy itself. Not in a separate AI policy, ethics statement, or terms document. The OAIC expects the disclosure to be findable by someone reading your privacy policy directly. A separate document that most readers will never encounter does not meet the intent of the transparency requirement. See the OAIC's APP 1.7 guidance at oaic.gov.au.
What if the AI tool I use is run by a third party: does my business still need to disclose?
Yes. If a third-party AI tool processes your customers' or employees' personal information to make or influence a significant decision, your business is the entity collecting and using that information. The disclosure obligation sits with you, not the vendor. Name the type of decision and the personal information involved in your policy. You do not need to name the vendor unless you choose to.
What counts as a 'significant' decision for APP 1.7 purposes?
Decisions that could materially affect a person's rights, opportunities, or access to services. Employment screening, credit assessment, insurance underwriting, health service eligibility, and individual pricing decisions are clear examples. Content recommendations, document drafting tools, and productivity features like spelling checkers generally do not meet the threshold. If you are unsure, the OAIC's guidance on APP 1.7 provides further examples, and the safer default is to include the disclosure.
Does 'automated decision' mean the AI makes the final call, or does it include AI-assisted decisions where a human signs off?
APP 1.7 covers both fully automated decisions and decisions where an automated system substantially assists a human decision-maker. If an AI shortlists candidates and a human chooses from that shortlist, the AI component still needs to be disclosed. The presence of a human at the final step does not remove the disclosure requirement for the automated step that preceded it.
Is there a fine for not updating the privacy policy before the deadline?
Non-compliance with the Australian Privacy Principles, including APP 1.7, can result in OAIC investigations and enforceable undertakings. Serious or repeated breaches can attract civil penalties. For most small businesses, the practical risk in the short term is reputational and regulatory rather than immediate financial penalties. That said, the December 2026 deadline is not advisory. Compliance is required.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Need a starting point for your AI governance documentation? The free AI staff policy template covers acceptable use, data handling rules, and oversight requirements: a practical companion to your privacy policy update.
Get the Free AI Staff Policy Template