What you need to know
- New automated decision-making (ADM) transparency requirements come into effect in Australia in December 2026, impacting your use of AI and other computer-assisted systems.
- The regulator is likely to issue guidance in September, but you can apply lessons from recent consultations in your privacy program today.
- In this Part 2 of our Automated decisions in Australia series, we highlight "hot button" issues and areas of regulatory focus from the consultation.
- For an overview of the new transparency rules, see Automated decisions in Australia series – Part 1: a quick guide to Australia's new privacy rules.
What you need to do
- Use our key insights from the regulator's recent consultation to refine, risk-assess and improve, focusing on how computer assisted processes operate in practice and impact people.
- Assess your processes through the eyes of your customers, particularly those more likely to experience vulnerability, such as children, seniors, or people subject to coercive control.
- Prepare for targeted advertising and algorithmic pricing to come under scrutiny – “gating” steps that affect who sees job ads or what prices customers pay may be considered decisions requiring transparency.
- Close the loop on governance – ensure you can trace what your systems are actually doing in practice and keep disclosures aligned with reality.
Insights from the ADM guidance consultation in a nutshell
While final guidance has not been released, the OAIC's consultation Issues Paper highlights areas of regulatory interest that help refine your automated decision risk assessments today.
- Example factors: Use the OAIC’s example factors to refine your scoping and risk assessments today – they signal likely areas of regulatory focus and can support reasoning in future determinations. Expect the final factors to act as baseline, not a complete list.
- Computer-supported decisions: Focus on practical operation and experience, not theoretical capability. The OAIC emphasises the “ability and likelihood” of human override – whether a human is likely to challenge or alter a decision in practice matters more than whether they theoretically can.
- What decisions are covered: Decisions involving sensitive information, vulnerable persons, intrusive practices, or financial outcomes are more likely to affect rights and interests. The inclusion of “intrusive practices” indicates that preserving privacy is an “interest” in its own right.
- Significant service or support: Financial services, healthcare, telecommunications, essential utilities, and education are clearly target industries. While they illustrate areas more likely to significantly affect rights and interests, always examine risk in your specific organisational context.
- Vulnerability: The Issues Paper does not engage with the fact that vulnerability is fluid and context dependent. Even standardised business processes can inadvertently exclude or harm people experiencing vulnerability. Assess processes through the eyes of your more vulnerable stakeholders. Organisations operating online should also factor in the proposed Children's Online Privacy Code, which raises the bar on handling children's data.
- Can targeted advertising be a decision? “Gating” or “filtering” steps (such as deciding who sees a job ad) might be considered decisions in their own right that require transparency, particularly steps that act as an “off-ramp” potentially blocking individuals from being considered in later decisions. Recent privacy determinations on pixel tracking may expand the types of personal information to be disclosed. This will be a controversial area.
- Algorithmic pricing: Price differences from algorithmic decisions may significantly affect a person's interests, depending on the product’s significance and the consumer’s circumstances. While the OAIC has asked for views on whether a percentage change in price could be set that would "significantly" affect customers, setting a global set percentage might be difficult given the variable impact of pricing across different products and consumers.
- Service providers: Transparency rules apply to the entity that "arranges" for automated decisions, not necessarily the entity operating the system. The distinction won't always be clear and could extend beyond contracted service providers. Put in place the governance and contracts to bridge the gap between the party who needs to be transparent and the party who can practically provide the information.
- What good transparency looks like: The OAIC suggests disclosures should be clear, tailored, structured to enable further enquiry, and framed to allow decisions to be challenged. However, expect the line between minimum mandatory legal requirements and desirable best practice to blur.
New transparency rules apply from December 2026
Under new automated decision transparency rules privacy policies will need to identify types of automated decisions that significantly affect the rights or interests of an individual, and the types of personal information used to make them. The rules go beyond AI, and beyond automation. They can apply where a computer system does not make a decision itself but does a thing substantially and directly related to the decision.
The new rules apply from December 2026, and guidance from the Office of the Australian Information Commissioner (OAIC) is not expected until later in the year, potentially September 2026.
However, the OAIC's recent consultation to inform the guidance provides clear indications of regulatory focus areas or concerns that can help you refine your compliance program and risk-assess your business processes. Even though this consultation only provides indicative positions on the OAIC’s interpretation of the requirements, it can be used as a reference point for organisations undertaking assessments now.
Automated decisions in Australia series
In this Part 2 of our dedicated series, we take a deeper dive into practical lessons you can take from the OAIC's recent consultation. Future articles will explore how to move beyond compliance and prepare for increased scrutiny.
For a reminder of the new automated decision transparency rules, read Automated decisions in Australia series – Part 1: a quick guide to Australia's new privacy rules.
1. The OAIC's example factors can help refine your strategy today
In its consultation to inform automated decision guidance, the OAIC asked 10 questions, many supported by "edge case" examples to help illustrate practical challenges.
Several questions asked submitters to identify and rank factors that indicate a decision will be captured by the new transparency rules, providing "example factors”.
Why it matters
- The example factors give an insight into likely future areas of focus. Organisations currently scoping and risk assessing their activities should take these factors into account, as strong indications of what the OAIC considers relevant and important.
- In recent determinations, the Privacy Commissioner has clearly articulated factors she considered relevant to her determination, and in some cases these factors have been supported on appeal. A lot of these factors are sourced in existing guidance or guidelines. By consistently voicing relevant factors in determinations, guidance, and guidelines, the Commissioner is setting behavioural expectations within industry and identifying higher risk practices or industries.
- Expect general factors to act as baseline considerations, not a complete list. Factors applied in determinations can be a combination of circumstance-specific factors, and factors that would be more generally applicable.
- Submission responses may support reasoning in future determinations – in particular, if there are factors that submissions consistently rank as extremely important.
We take a closer look at some of these examples below.
2. Computer-supported decisions
In asking submitters to identify and rank the factors that indicate that a computer does a thing "substantially and directly related to" a decision, the Issues Paper lists some example factors.
These factors indicate that the regulator is thinking about how computer processes fit in with and influence business processes in practice:
- the degree of reliance on ADM output;
- the ability and likelihood of human override;
- the nature of the output (advisory vs determinative);
- transparency and explainability of outputs; and
- integration of ADM into decision-making workflow.
Why it matters
- Many of these factors reflect well-understood best practice governance tools for automated decisions or the use of AI tools.
- It is worth focussing on the words "ability and likelihood" of a human override. The theoretical ability to alter a decision or not accept a recommendation may be less meaningful than whether, in practice, a human is likely to do it. Understanding organisational context, and how processes operate in practice, is an essential part of any risk assessment.
- Transparency and explainability, on its surface, might not appear to go to whether a program is "substantially and directly related to a decision". However, they do go to the practical ability of a human to override a decision, and the likelihood it will happen.
- The Issues Paper discusses how the term "substantial" has been applied in other legal frameworks, meaning real or of substance and not insubstantial ephemeral or nominal. This is not particularly helpful, as it sets a much lower bar than that intended by Parliament, with explanatory materials describing "substantial" as meaning a "key factor".
3. What kinds of decision are covered?
The Issues Paper asks what factors increase the likelihood that a decision could affect an individual's rights or interests. Example factors are:
- sensitive information
- vulnerable persons
- intrusive practices
- financial outcomes
Why it matters
- The example factors should already form part of most organisations' scoping and risk management activities. They are not by any means comprehensive.
- The inclusion of "intrusive practices" indicates that preserving privacy is an "interest" of a person in its own right. 2024's reforms to the Privacy Act emphasised the public interest in protecting privacy. We may see this factor used as a lever to create more transparency in automated decisions processes that use more information than reasonably necessary, or than employ unfair collection practices (particularly when read in the context of the recent IRE Pty Limited / 2Apply determination).
- Explanatory materials make it clear that vulnerability is an important factor – we explore what this means in more detail below.
4. Significant service or support
The concept of a "significant service or support" is one of three examples in APP 1.9 of the kinds of decision that significantly affects rights or interests. (The other two are decisions under legislation to grant a benefit, and decisions that affect rights under contracts, agreements or arrangements.)
The Issues Paper asked submitters to identify and rank significant services and support, and provides as examples:
- physical assistance/support
- financial assistance
- access to educational services
- in home services
- access to essential banking and credit services
- access to telecommunications
- access to essential utilities
In other locations, the Issues Paper identifies restricting access to financial products or healthcare as clearly a decision that significantly affects the interest of an individual.
Why it matters
- Providing specific examples in guidance for a "significant service or support" makes a lot of sense, but remember this list is a non-exhaustive list of factors for one element in a non-exhaustive list of examples. They are illustrative of higher risk areas. Always examine risk in the specific context of your organisation and its customers, even if your organisation is not listed in the higher risk areas.
- Financial services and healthcare are clearly target industries – as are telecommunications, essential utilities, and education.
- The use of "essential" in some, but not other, examples may indicate not all services of that type are significant – that there are "essential" and "non-essential" banking and credit services.
5. Vulnerability
The Issues Paper requests feedback on what classes of person are considered vulnerable. Unlike similar questions, the OAIC did not include examples as part of the question.
People more likely to experience vulnerability
Modern safeguarding frameworks recognise that people can experience vulnerability at different points in their life, on a short or longer term basis. Vulnerability can be hard to identify, including for the individuals experiencing vulnerability.
Some frameworks explicitly identify examples of persons who may experience vulnerability – for example, children and seniors, people with impaired intellectual or physical functioning, people from low socio-economic background, people who are Aboriginal or Torres Strait Islanders, people who are not native speakers, people with low levels of literacy or education, and people subject to modern slavery or similar exploitation or control.
These are not "categories of vulnerable persons" (a phrase used in the Issues Paper). They are factors that indicate that a person may be more likely to experience vulnerability, factors which are non-exclusive and can intersect to compound vulnerability.
Understanding the fluid nature of vulnerability helps keep risk management and control frameworks impactful.
Children
Decisions affecting children are a particularly complex and developing area, with the proposed Children's Online Privacy Code expected to introduce a new high bar on how we handle children's data – with specific obligations around being transparent, fair, and acting in the best interests of the child.
Why it matters
- Consistency across regimes and practices matters: Many organisations already focus on persons experiencing vulnerability within mandatory or voluntary frameworks. Measures for people experiencing vulnerability are also a key part of safeguarding frameworks to prevent abuse, neglect, and exploitation. Aligning risk factors between regimes where appropriate will be important to keep risk control frameworks simple and effective, and to avoid additional complexity for organisations and people experiencing vulnerability.
- Standard business processes can exacerbate harm: Essential controls designed to manage risks can actively exacerbate risks to persons experiencing vulnerability – for example, identity verification requirements can exclude people who may be less likely to have (or have possession of) standard forms of identification, as can be the case in some Aboriginal or Torres Strait Islander communities, or people subject to modern slavery or domestic and family violence including coercive control. Many of these controls will be embedded in automated or computer-assisted processes.
- A shift in expectations: The focus on how automated decisions can impact persons experiencing vulnerability reflects a growing expectation that organisations manage not only risks to their business, but also the harms that they may produce. This expectation can extend to a broader look at how actions may exacerbate or ameliorate the challenges already faced by their customers.
6. Can targeted advertising be a decision?
In a fictional example, the Issues Paper looks at algorithmic bias in job advertising, resulting in a female engineer not seeing a job ad. In the example, gender is a metric used by the algorithm.
Submitters are asked whether this targeted advertising should be considered a "decision".
Explanatory materials for the ADM transparency laws already clarified Parliament's intent that targeted advertising may have a significant effect if (for example) it results in differential access to employment opportunities. However, not all targeted advertising is likely to be captured by the requirements; a specific instance will still need to meet all the requirements of an automated decision in order to be captured.
Why it matters
- Identifying a "decision" is essential before you can determine which internal or external automated or computer-assisted steps make that decision or do things that are "directly and substantially related" to that decision. If an automated step like serving a job ad is considered a decision, then there may be further things done by computers that are directly and substantially related to that decision that will also be captured.
- "Gating" or "filtering" steps in important customer or applicant journeys may very well be considered a decision in their own right, particularly steps that act as an "off-ramp" on that journey (ie where individuals aren't considered for subsequent decisions).
- No expectation to disclose commercial-in-confidence information. This example may raise concerns about disclosing commercially sensitive information about algorithms. Explanatory material released with the legislation clarifies that information to be disclosed in privacy policies is "not expected to include commercial-in-confidence information". For example, in some circumstances, the "type" of information used would likely need to be disclosed, but not necessarily commercial-in-confidence information about how it is weighted or used.
The pixels problem and not-so-personal information
- In recent determinations about tracking pixels used to target online advertising, the Privacy Commissioner has advanced a "novel" view that information can be regulated as "personal information" if it can be used to affect someone's rights and interests, even if the person cannot be individually distinguished from all others.
- This expanded concept of "personal information" could dramatically expand the types of information that might need to be disclosed under new ADM transparency rules. If a particular targeted ad is considered a decision covered by the regime, then the "types" of personal information used as criteria to target that ad might need to be disclosed.
- It is worth noting that the Commissioner has recognised parts of her determination as "novel", and the expanded concept of "personal information" has not been tested in a court or tribunal.
7. Differential or algorithmic pricing
The Issues Paper asks if inflation of prices for a consumer product (using the example of a book) would "significantly" affect interests, and if so, what amount of price difference would have a significant effect (eg 5% or 20%).
Submitters are also asked to rate the importance of the price difference and the significance of the product being purchased.
Why it matters
- Explanatory materials for the ADM transparency laws already make it clear that targeted advertising may have a significant effect if, for example, it results in differential pricing or access to significant goods or services.
- Guidance on the percentage price difference might create some regulatory certainty. However, it will be difficult for the OAIC to settle on a global figure given the impact of price can be variable. For example:
- there may be alternative suppliers of products;
- products may have different levels of significance;
- the regime takes into account vulnerability of individuals (including income levels);
- a small percentage difference in an expensive product price may have a bigger impact than a big percentage difference in a cheaper product; and
- frequently purchased products may have a bigger impact than others.
8. Service providers and supply chains
The Issues Paper brings focus to the distinction between entities that "arrange for" computer assisted decisions (covered under the new rules), and those that simply operate systems (eg develops and hosts software or maintains infrastructure).
Submitters are asked for scenarios that may require guidance.
Why it matters
- The distinction is similar to the distinction between data processors and data controllers in overseas jurisdictions, recognising that privacy responsibilities are best managed by the party controlling data and tools, not necessarily the party holding the data or providing the tools.
- This might extend beyond contracted service providers. The Issues Paper refers to an entity "permitting" or "directing" its employees to use an AI chat tool. Understanding how automation makes or assists decisions on the ground requires a combination of review and audit processes, and ongoing behavioural and system controls.
- A firm understanding of both who is legally responsible for transparency and who can practically provide the information to achieve it needs to be embedded in governance and contract arrangements.
9. What good transparency looks like
The new transparency laws require organisations to disclose the kinds of decisions, and kinds of personal information used. Under existing privacy laws, entities already need to identify in privacy policies the "kinds" of personal information collected and held.
On its face, this may mean organisations should apply the same level of granularity in describing their automated decisions as they apply to their current privacy policies.
However, we can expect automated decision transparency, particularly in higher regulatory risk areas, to come under specific and targeted scrutiny, and higher expectations.
The Issues Paper indicates the OAIC has high transparency expectations, saying that entities should strike an appropriate balance to ensure disclosures are (among other things):
- clearly articulated in plain language and easy to understand;
- structured to enable consumers to request further information, where required;
- appropriately tailored – sufficiently specific to be meaningful, while avoiding overwhelming levels of detail;
- organised so that similar information is grouped in a logical manner; and
- framed in a way that allows the information and the decision to be challenged or contested.
The Issues Paper also pointed to a 2024 audit of privacy practices of AI recruitment tools by the UK Information Commissioner's Office, which suggested organisations:
- supplement text-based privacy information with bite-sized informative pop-up messages or visual aids;
- confirm people actually understand how their information is processed; and
- avoid overly complex explanations, or technical or legalistic language.
Why it matters
- Best and better practices: As with other guidance, expect a blurring of the line between mandatory legal requirements and best practice.
- Child-friendly transparency: For many businesses operating online, transparency will need to be age-appropriate under the coming Children's Online Privacy Code – see The kids are online – what Australia's Children's Online Privacy Code means for you.
- Good governance can close the loop: A key challenge in maintaining high quality disclosure is having the governance in place to close the loop. A closed loop process requires you to:
- understand what processes are actually doing in practice (and where that differs from what was intended);
- notice when processes change or new processes emerge – risk reviews can help set appropriate review cycles or monitoring;
- align business process and system changes with privacy policies and other customer-facing materials – differences between documents and reality can mislead customers; and
- ensure consistency across privacy policies, collection notices, and other statements – for example marketing materials or corporate documents might discuss how important systems work.
Authors: Geoff McGrath, Partner; Sonia Haque-Vatcher, Partner; Andrew Hilton, Expertise Counsel; Olivia Carmody, Lawyer; Cindy Nguyen, Graduate and Joanne Lee, Paralegal.
Want to know more?