top of page

OAIC releases new guidance on Automated-Decision Making transparency

1 day ago
3 min read
Clear as crystal
Clear as crystal

The guidance supports the new requirement in APP 1.7–1.9, which sits alongside APP 1.3's duty to maintain a clear and up-to-date privacy policy.


From 10 December 2026, APP entities must disclose in their privacy policies where a "computer program" makes, or is substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.


More than just "AI"


A "computer program" includes AI and machine learning, generative AI, rule-based automation, or even a spreadsheet formula or macro. The mere inclusion of 'human-in-the-loop' review doesn't take a decision out of scope, and the OAIC generally expects ML and generative AI outputs used in significant decisions to be covered unless human oversight is extensive. If in doubt, the OAIC's guidance is to disclose.


What's in scope

A few decision categories that the OAIC considers would generally be considered in scope caught our eye:

  • "facial recognition technology use in a retail store or stadium for watchlist matching"

  • "recruitment software used to sort through candidate profiles and make hiring decisions"

  • "differential and/or personalised pricing practices used by online retailers in the sale of significant goods"

  • "programmatic advertising relating to the decision to sell significant goods or services"


The list also covers credit and loan decisions, insurance eligibility, prioritisation of health and disability services, and AI-generated reports ranking employee performance or setting bonuses.


Many pixels have been spilled on facial recognition - but recruitment software and programmatic advertising have to date flown somewhat under the radar. The example of personalised pricing in the OAIC's guidance shows that even small per-item differences can add up to a "significant" impact requiring disclosure. This doesn't mean that these techniques can't be used, but APP entities will need to be open that they are using them.


A balancing act


APP entities must help individuals understand how their personal information is handled without overwhelming them with granular technical detail.


In practice, the OAIC expects you to:

  • tailor the disclosure to your own activities

  • group categories of decisions and kinds of personal information, provided the result is meaningful to a reasonable person

  • make clear when sensitive information, such as health or biometric data, is used

  • enable people to ask for more information.


Trade secrets and commercially sensitive detail are excluded, so you are not required to disclose how a proprietary model works. Automated decisions that would be embarrassing or cause customer anger do not fall within that exclusion.


Enforcement


The OAIC has already reviewed privacy policies in 2026, and the Privacy Commissioner has previously suggested that the OAIC could conduct a ‘sweep’ of privacy policies regarding AI transparency in 2027. The OAIC can issue infringement notices for non-compliance with APP 1.3 without court action, of up to 200 penalty units ($72,800).


So what?


  1. Build an inventory of your automated decisions. Include the system (vendor tools and informal ones like spreadsheets), the decision, the personal information used, and whether a human reviews the output. Keep it current.

  2. Review and update your privacy policy. Describe the kinds of personal information used and the kinds of decisions made or substantially informed by computer programs. The OAIC's fact sheet includes model wording (Examples 6 and 7).

  3. Get it approved and published before 10 December 2026, and set up a process to keep it current as new tools are adopted.


And, of course, if you need help, don't hesitate to reach out to Sabirus Advisory.

bottom of page