Home Insights Transparency in automated decision-making: What the OAIC guidance means for your business
Share

Transparency in automated decision-making: What the OAIC guidance means for your business

New guidance from the Office of the Australian Information Commissioner (OAIC) will assist businesses to identify the immediate steps they should take to prepare for the upcoming transparency obligation concerning automated decision making (ADM).

From 10 December 2026, organisations that use computer programs (including software, algorithms or artificial intelligence) to make or inform significant decisions about individuals’ rights or interests must explain that use in their privacy policies. That obligation is set out in the new Australian Privacy Principles (APPs) 1.7 – 1.9. 

Recently, the OAIC issued its final guidance on the new transparency obligation, which follows an issues paper released by the OAIC in May 2026. The guidance confirms the broad scope of the transparency obligation, with the OAIC urging organisations to treat borderline use cases as in scope. As a result, the compliance burden on organisations is likely to be greater than many expect, particularly where computer programs are integrated across multiple business functions. Organisations should therefore begin mapping potentially in-scope systems, evaluating how those systems inform decision-making, and working with third-party technology providers to gather the information needed to support compliance. Doing so will ensure they are well-placed to update their privacy policies ahead of the 10 December deadline.

We explore the key takeaways from the finalised guidance, and the practical steps businesses should take before 10 December 2026.

What is the transparency obligation?

Under the new APP 1.7, the automated decision making (ADM) transparency obligation applies where three conditions are met: 

  1. the entity has arranged for a computer program to make or do a thing that is substantially and directly related to making a decision;
     
  2. the decision could reasonably be expected to significantly affect the rights or interests of an individual; and
     
  3. personal information about the individual is used in the operation of the computer program to make the decision, or to do the thing that is substantially and directly related to making the decision.

Where these conditions are satisfied, APP 1.8 requires entities to disclose the following details of their use of ADM in their privacy policy:

  • the kinds of personal information used in the operation of such computer programs; 
     
  • the kinds of such decisions made solely by the operation of such computer programs; and 
     
  • the kinds of decisions for which something substantially and directly related to the decision is done by a computer program.

Key takeaways from the OAIC guidance

The OAIC's new resources, including fact sheets for businesses and government agencies, a scope-assessment flowchart and updated APP 1 guidance, provide practical guidance for organisations applying the new APPs to their activities.

Scope of 'computer program'

The term ‘computer program’ is defined broadly and includes rule-based processes, machine learning and generative AI tools, chatbots, and everyday software such as apps, word-processing tools and spreadsheets. The examples of in-scope programs provided in the OAIC guidance include a spreadsheet formula used to rank clients for access to health services. Businesses should avoid interpreting the term narrowly and consider how the transparency obligation may apply to all programs used across their operations, including everyday software.

'Arranged for' 

The OAIC guidance provides examples of when organisations may have ‘arranged for’ a computer program to inform or make a decision. Those examples include:

  • using in-house or proprietary software, 
     
  • procuring a third-party program, 
     
  • configuring or customising off-the-shelf software, 
     
  • authorising a program to make a determinative decision, or 
     
  • relying on a program’s recommendations or other advisory outputs.

Importantly, using third-party software to facilitate a decision does not transfer the disclosure obligation to the third-party vendor, even if the organisation has no control over the software’s parameters. The OAIC expects organisations’ contractual arrangements with their third-party software providers to clarify which entity retains responsibility for, and control over, the relevant decision. Organisations should also consider whether they have appropriate contractual rights (or other mechanisms) to obtain any information from their vendors where required to make the ADM disclosures in their policies.

‘Decisions’ that are in scope

The concept of a ‘decision’ is broad. It includes choosing to take, or not to take, an action, and deliberately doing or refusing to do something, where the outcome could reasonably be expected to benefit or disadvantage an individual. The OAIC guidance includes a non-exhaustive list of decisions that would generally be in scope of the transparency obligation:

  • recruitment software that sorts candidates and informs hiring decisions;
     
  • approving or rejecting loan or credit applications;
     
  • AI reports used to rank employee performance or set pay and promotions;
     
  • differential or personalised pricing by online retailers selling significant goods;
     
  • programmatic advertising relating to the decision to sell significant goods or services; and
     
  • facial recognition technology used in retail stores or stadiums for watchlist matching.

Programs that are 'substantially and directly related to making a decision' 

To be captured by the new transparency obligation, a program must be substantially and directly related to making a decision. The OAIC guidance defines ‘substantially’ as meaning the program is a ‘key factor in facilitating’ the decision.

Programs can still be captured where the output is either advisory or determinative. Human involvement in a decision will not itself exclude a program from scope (e.g. a decision may be captured even where the output is reviewed or contributes only partially to the decision-making process). The OAIC's view is that machine learning or generative AI outputs used for significant decisions will generally be captured ‘unless subject to extensive human oversight and control’. The OAIC does not define ‘extensive human oversight and control’. However, it indicates that relevant measures may include interrogating outputs, reviewing the underlying inputs, narrowing the program's parameters, relying on additional evidence and documenting why a decision departs from the output.

Ultimately, a computer program may be substantially and directly related to a decision where it:

  • advises of an appropriate outcome of a process;
     
  • determines the outcome of a process; or
     
  • influences the outcome of a process.

Given this breadth, organisations that have already mapped automated decisions for the purposes of Article 22 of the European Union’s General Data Protection Regulation (GDPR) should not rely solely on that work. Article 22 governs decisions based solely on automated processing. Unlike the new Australian obligation, meaningful human involvement will generally take decisions outside the scope of the Article 22 requirements. 

Does the decision significantly affect the rights or interests of an individual?

The new transparency obligation applies only where a decision significantly affects an individual's rights or interests. An impact is ‘significant’ if it is more than trivial and has the potential to materially influence the individual's circumstances or outcomes. A ‘right’ is a moral or legal entitlement to have or do something, while an ‘interest’ is a relevant concern, benefit, stake or claim. 

The OAIC lists access to essential food, healthcare and aged care, financial assistance, education, banking and credit, telecommunications, utilities, employment and housing as interests that would generally be in scope.

The guidance includes two illustrative scenarios, which demonstrate the range of potential rights and interests organisations will need to consider:

  • Pricing: An e-commerce platform uses subscribers' postcodes to vary prices for essential goods. Although the price differences between two subscribers are small per item, they add up to $132 on baby formula over a year, and the same car seat is advertised to them at prices $102 apart. The OAIC considered the pricing decisions significant because even modest differences could compound and affect access to essential goods, including food and medication. The platform would therefore be required to disclose how it uses personal information to set prices. 
     
  • Recruitment: A recruitment platform uses age and gender to determine who sees an engineering firm's job advertisement, preventing a 45-year-old female graduate from seeing it. An AI screening tool then uses biometric inputs to score video interviews and rank candidates. Both tools would be caught by the obligation: the targeting tool affects access to employment opportunities, while the screening tool determines which candidates progressed.

The assessment must also account for the circumstances of vulnerable individuals, as the same decision may have a greater impact on people experiencing vulnerability than on the broader population. Businesses should not assume that routine pricing, marketing or recruitment tools fall outside the regime. These tools warrant particular scrutiny, especially where they influence access to essential goods, employment or services.

What technical information must be disclosed in a privacy policy?

The guidance provides practical direction on how organisations can satisfy the disclosure requirement in APP 1.8 and determine the appropriate level of detail for their privacy policy disclosures. In particular, disclosures:

  • should be tailored, meaningful and readily understandable, without unnecessary technical detail;
     
  • may group categories of decisions and types of personal information where appropriate, provided the disclosure remains meaningful and logically structured. Particular care is required when grouping disclosures involving sensitive information, such as health information or biometric templates;
     
  • should be structured to facilitate requests for further information, although the APPs do not expressly require an entity to provide that information; and
     
  • should present the relevant information and decision-making process in a manner that supports review, although the APPs do not expressly require an entity to review a decision at an individual's request.

Generic, high-level transparency statements will not be sufficient to satisfy the obligation.

What is the commercial-in-confidence exclusion? 

Businesses have been concerned that the new disclosure requirements could expose the confidentiality of proprietary models or algorithms to competitors. While the legislation addresses this directly by excluding commercially sensitive information and trade secrets from the transparency obligation, the exclusion is narrower than it might first appear. It covers only information whose release could harm the entity's commercial interests, not all information with commercial value. Information that would expose a business to ridicule, embarrassment or public criticism is not exempt from disclosure. In deciding whether information qualifies, the OAIC suggests asking:

  • whether it is unique to the business and whether disclosure would detract from its intrinsic commercial value;
     
  • whether it gives the business a competitive advantage; and 
     
  • whether a genuine ‘arm's-length’ buyer would pay to obtain it. 

In practice, the distinction is generally between how a tool works (which may be protected) and the fact that it is used (which must be disclosed). For instance, in the OAIC's banking example, the way a proprietary fraud model weights its data points could be kept confidential, but the bank would still have to disclose that personal information is used to detect fraud and to decide loan and credit applications. 

Key and immediate actions for compliance

In light of the OAIC’s final guidance, APP entities should now:

  1. Conduct an ADM audit. Map where computer programs are used in their business (whether sourced in-house or from third-party providers) to make decisions about individuals, or to do things substantially and directly related to making those decisions, using their personal information. This will define the scope of the broader compliance exercise. Some organisations may benefit from first identifying decisions made within their business that significantly impact an individual’s rights or interests and then tracing programs that feed into those decisions. 
     
  2. Engage third-party providers. Where relevant, request clear explanations from vendors on how their tools use personal information in decision-making. Existing contracts should also be reviewed to ensure they include adequate information-sharing obligations and, where appropriate, warranties to support your compliance position.
     
  3. Update privacy policies by 10 December 2026. Draft updated disclosures that are clear, meaningful and proportionate. Grouping of decisions and personal information is permitted, but any use of sensitive information should be called out separately. When preparing the disclosures, organisations should carefully assess any proposed exclusions of commercially sensitive information to ensure they do not under-disclose. 
     
  4. Review internal IT policies. Consider updating acceptable-use and other internal IT policies so that unapproved programs are not used in significant decisions about people, such as in HR, credit, pricing or account suspensions. Otherwise, staff use could unintentionally bring a decision within scope. 
     
  5. Consider how these obligations fit with Tranche 2. The Tranche 2 privacy reforms will broaden the scope of information treated as ‘personal information’, which may bring more programs within scope of the transparency obligation. Organisations could consider those changes as part of any ADM audit. 

Authors

Stephanie Tones

Associate (Admitted in England & Wales, not admitted in Australia)

Rachael Rozengurt

Law Graduate


Tags

Technology, Media and Telecommunications Employment and Labour Regulatory

This publication is introductory in nature. Its content is current at the date of publication. It does not constitute legal advice and should not be relied upon as such. You should always obtain legal advice based on your specific circumstances before taking any action relating to matters covered by this publication. Some information may have been obtained from external sources, and we cannot guarantee the accuracy or currency of any such information.

Share
  • Print article

Contacts

NORTH-james-highres_SMALL

James North

Head of Technology, Media and Telecommunications

DIXIT arvin SMALL

Arvind Dixit

Partner

KOLIVOS-eugenia-highres_SMALL

Eugenia Kolivos

Head of Intellectual Property

BURGER Jodie SMALL

Jodie Burger

Partner

Related Capabilities