Framework

Privacy Act: ADM transparency

The amendments to Australian Privacy Principle 1 that take effect on 10 December 2026. Every APP entity must disclose how personal information is used in automated decisions and what kinds of decisions are being made.

What it is

The Privacy and Other Legislation Amendment Act 2024, passed on 29 November 2024 and given Royal Assent on 10 December 2024, amended the Privacy Act 1988 to insert three new subclauses into Australian Privacy Principle 1. Those subclauses, APP 1.7, 1.8 and 1.9, commence on 10 December 2026 and introduce a transparency regime for automated decision-making.

What it requires

Every APP entity, which means essentially every Australian organisation with turnover above the small business threshold, plus all Commonwealth agencies, must update its privacy policy to disclose, for decisions made or substantially assisted by a computer program using personal information:

  • The kinds of personal information used in making those decisions
  • The kinds of decisions that are made solely by a computer program
  • The kinds of decisions where a computer program plays a substantial and direct role in making the decision, meaning decisions where a human technically makes the call, but the computer program does the analytical work the human relies on

The threshold for disclosure is that the decision "could reasonably be expected to significantly affect" the rights or interests of an individual. This is a broader threshold than the GDPR's Article 22, which applies only to decisions based solely on automated processing with legal or similarly significant effect.

"Computer program" is deliberately broad

The definition of "computer program" in the amendments is intentionally wide. It covers AI and machine learning systems, rule-based systems, decision trees, workflow automation, and even scoring models running in spreadsheets. If a piece of software is using personal information to produce or materially influence a decision, it's in scope. Organisations that think of themselves as "not really using AI" are likely to be caught by this anyway.

Who it applies to

All APP entities. The small business exemption, which currently excludes organisations with under A$3 million in annual turnover, is expected to be removed in the Tranche 2 reforms, although those reforms have only been agreed in principle and are not yet legislated. If the small business exemption is removed before December 2026, an estimated 100,000+ additional entities will become APP entities and will need to meet the ADM transparency requirements from the start.

Penalties

The Privacy Act's penalty regime was strengthened in the 2024 amendments and is now severe:

  • Serious or repeated interference with privacy: for bodies corporate, the greater of A$50 million, three times the benefit obtained from the interference, or 30% of adjusted domestic turnover during the relevant breach period
  • Mid-tier civil penalty for less serious contraventions, up to 10,000 penalty units (approximately A$3.3 million for a body corporate)
  • Infringement notices for non-compliant privacy policies, up to 1,000 penalty units (approximately A$330,000)

The OAIC has signalled that it is preparing a proactive compliance scan of privacy policies against the ADM requirements around the commencement date.

Common misreadings

"It only applies to fully automated decisions." No. It applies to both fully automated decisions and decisions where a computer program plays a substantial and direct role. This is much broader than GDPR Article 22.

"We don't use AI, so we're not affected." Possibly not. The definition of "computer program" covers rule-based systems and scoring models, not just machine learning. Most organisations using any software to support decisions about individuals will be in scope.

"Updating the privacy policy is enough." Updating the policy is the specific legal obligation, but the policy update has to be accurate, which means you need to know what computer programs are actually being used and what decisions they're actually making. The documentation work is larger than the drafting work.

How Aicura supports work against it

Aicura's Privacy Policy module specifically targets this framework. You upload your current privacy policy, Aicura reviews it against rules extracted from the legislation and cross-references it with your AI Register, and produces recommendations against specific findings plus a draft transparency statement. The AI Register captures the metadata you need to make the disclosures, meaning which systems affect individuals, what kinds of personal information they use and whether decisions are solely automated or substantially assisted. The register and the review work together.


A note on this page

This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.

For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.

Get started with Aicura.

Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.