Guide

How to write an ADM transparency statement

A practical guide to writing the automated decision-making disclosure your privacy policy needs under APP 1.7 to 1.9, with worked examples of adequate and inadequate wording.

How do you write an automated decision-making disclosure for your privacy policy?

You write it by setting out, for each automated decision that significantly affects a person, the kinds of decisions involved, the kinds of personal information used and how the system is used to make or substantially shape the decision. The wording itself is the easy half. The hard half is knowing which decisions to disclose and keeping that list current as your systems change, because a statement that is true today goes wrong the moment a new system ships or an old one is retired.

You write an ADM transparency statement by setting out, for each automated decision that significantly affects a person, the kinds of decisions involved, the kinds of personal information used and how the system is used to make or substantially shape the decision. That is what Australian Privacy Principle 1.7 to 1.9 ask for. The wording is the part most people get stuck on, and it is the easier half. This guide gives you the structure and three worked passages so you can see adequate and inadequate disclosure side by side. The harder half, which the worked examples point back to, is knowing which decisions to disclose and keeping that current as your systems change.

What APP 1.7 to 1.9 actually require

From 10 December 2026, an organisation that uses a computer program to make, or substantially and directly assist in making, a decision that significantly affects the rights or interests of a person has to set this out in its privacy policy. The obligation has three parts.

APP 1.7 names the trigger. It applies where a decision is made wholly or substantially by automated means and the decision significantly affects a person. APP 1.8 says the privacy policy must include information about the kinds of personal information used in connection with those decisions. APP 1.9 says the policy must include information about the kinds of decisions made wholly or substantially by the automated process.

Read together, the practical effect is that for each in-scope system your privacy policy has to make three things clear. The kinds of decisions the system is used to make. The kinds of personal information it uses to reach them. And enough about how the system is used that a reader understands its role in the decision. You are not required to publish the model, the source code or a technical specification. You are required to be clear about what is decided, on what information and how automation is involved.

Fully-automated and substantially-assisted are both in scope

One distinction does more work than any other when you write this statement, and getting it wrong is the most common way a disclosure goes thin.

A fully-automated decision is one a system reaches and applies with no person in the loop. An application is scored and declined, and the outcome takes effect, without anyone reviewing it. A substantially-assisted decision is one where a system does the substantive work and a person signs off on the result. A model ranks, scores or recommends, and a person approves what the model produced rather than reaching the decision independently.

Both are in scope. The test in APP 1.7 is decisions made “wholly or substantially” by automated means. A person clicking approve at the end does not move a decision out of scope if the system did the deciding. The line that matters is whether the human adds independent judgment or rubber-stamps the output. If the system substantially shapes the outcome, it is disclosable, even with a person at the end. The worked examples below show how this changes the wording.

How to structure the disclosure in your privacy policy

Put the statement inside the privacy policy as a clearly headed section, not a separate page or a downloadable annex. APP 1 governs the privacy policy, so the disclosure has to live there to do its job.

Organise it system by system, or by kind of decision where several systems make the same kind. For each one, cover the three required elements in plain order. What kind of decision is made. What kinds of personal information are used. How the system is used to reach the decision, including whether it is fully automated or a person reviews the result. Keep each passage short and specific. A reader should be able to tell what your organisation decides about them by automation, and you should be able to point to the system behind every sentence.

Worked example one: a fully-automated decision

The first example is a lending decision made with no person in the loop. Compare the two passages.

Inadequate:

We use advanced technology and data analytics to deliver fast, accurate outcomes and to improve our services. Automated tools may be used as part of our processes.

This says nothing a reader can use. It names no decision, no information and no effect. It describes a stance toward technology rather than disclosing an automated decision, and it would leave a person no wiser about whether a decision about them was automated.

Adequate:

We use an automated system to decide whether to approve or decline applications for a personal loan. The decision is made by the system without a person reviewing it. The system uses the personal information you provide in your application, your stated income and the information in your credit report. Where your application is declined by this system, you can ask us to review the decision.

This passage names the decision, states that it is fully automated, lists the kinds of personal information used and gives the reader a route to a person. It maps directly onto APP 1.8 and 1.9.

Worked example two: a substantially-assisted decision

The second example is the case people most often get wrong. A model does the substantive work and a staff member approves the result. The temptation is to describe this as a human decision and leave it out. If the system substantially shapes the outcome, it is in scope.

Inadequate:

All decisions about claims are made by our trained assessors. We may use tools to help our staff work efficiently.

This passage uses the human sign-off to imply the decision is not automated. If the model produces the assessment and the assessor approves it, the decision is made substantially by automated means and this wording understates the system’s role. It discloses nothing about the personal information used or the kind of decision reached.

Adequate:

We use an automated system to assess claims and recommend whether a claim is accepted, declined or referred. A claims assessor reviews each recommendation before it takes effect and can change the outcome. The system uses the information in your claim, your policy details and your claims history to produce its recommendation. You can ask us how a decision about your claim was reached.

This passage is accurate about the division of work. It states that the system does the assessment and a person reviews the result, which is the substantially-assisted case, and it covers the kinds of decisions and the kinds of personal information as APP 1.8 and 1.9 require.

Worked example three: scope of personal information

The third example shows a passage that is clear about automation but thin on the information used. Adequate disclosure has to cover the kinds of personal information, not just the existence of the system.

Inadequate:

We use an automated system to prioritise applications for housing assistance. The system uses your personal information to do this.

This names the decision and the automation, which is a start, but “your personal information” tells a reader nothing about the kinds of information involved. APP 1.8 asks for the kinds of personal information used, so a single catch-all phrase does not meet it.

Adequate:

We use an automated system to prioritise applications for housing assistance and to decide the order in which applications are assessed. This prioritisation significantly affects how quickly you are assisted. The system uses the information in your application, your stated circumstances, your household composition and information we hold about your prior contact with us. A person can adjust the priority where your circumstances are not captured by the system.

This passage gives the reader the kinds of information used and is specific about the effect of the decision, which is what carries it from describing a tool to disclosing an automated decision.

The statement is not write-once

The deadline is why you write the statement now. Keeping it true is the work that continues after. A transparency statement reflects the systems your organisation runs at the moment it is written. Organisations add automated-decision systems, change how existing ones work and retire others. Each of those events can make the statement wrong in a way that is quiet and easy to miss. The policy can keep claiming to disclose a decision that has changed, or it can fall silent on a new system that should now be named.

This is why the prose is the easy half. Once you can see the three worked patterns above, writing an adequate passage is mostly mechanical. The hard half is knowing which decisions are in scope today and noticing when that set changes, because that is what keeps the statement accurate rather than just well written. A statement that was correct in December and wrong by March is the failure mode to design against.

Where the work stays current

Knowing which decisions to disclose comes from reconciling your privacy policy against a current record of your systems. Aicura is your AI Register. It identifies which registered systems make decisions that fall within APP 1.7 to 1.9 and can draft a transparency statement from the register. Because the register and the policy are kept reconciled, when a system is added or changed Aicura surfaces the decisions that are no longer disclosed, so the statement stays true as the organisation changes rather than going stale between reviews. This work is generated, not analyst-built. It is offered as the practical way to keep the statement accurate over time, which is the part the wording alone cannot solve.

Where to go next

Read the companion guide on which systems make automated decisions to work out what belongs in scope before you write a word, since that is the input every passage above depends on. The framework page on automated decision-making sets out how APP 1.7 to 1.9 define a decision that significantly affects a person, and the December 2026 scenario covers what changes on the day and who it reaches.

One caution on the worked examples. They are illustrative passages rather than legal templates, written to show the difference between adequate and inadequate wording, and using one does not make an organisation compliant with anything. Where a decision is finely balanced, or the stakes are high, take your own advice against your specific facts.


Related frameworks

Related scenarios


A note on this page

This guide explains what the rules require and how to do the work. It is general information, not legal advice. How the obligations apply turns on your own circumstances, so read the primary source and take your own advice before you rely on it.

Aicura does not certify, audit or issue a compliance verdict, and it does not produce a score. That decision belongs to your organisation and its people.

Primary source: Privacy Act 1988 (Cth), Australian Privacy Principle 1.7 to 1.9, and the OAIC's APP guidelines

Keep your disclosure true as your systems change

Aicura is your AI Register. It scans your privacy policy against the ADM rules and surfaces which automated-decision systems are not yet disclosed, and the scanning keeps pace as your systems change.