Automated decisions in Australia series – Part 3: Shifting from compliance to defensible decision-making
Key insights to help you prepare for the consequences of ADM transparency:
We dive deeper into each of these insights below.
Automated decision-making (ADM) transparency will bring aspects of internal decision-making processes into clearer view for customers, regulators, activists, and competitors. Increased transparency brings the potential for increased trust, but also the risk of reputational harm and regulatory or private legal action.
The new laws are intended to give consumers the information they need to take further action, not just under privacy laws. In a recent consultation, the OAIC highlighted avenues including anti-discrimination law, administrative law and the General Insurance Code of Practice, as well as administrative and freedom of information laws for government. New privacy laws in Western Australia also require government entities to provide automated decision transparency, alongside additional, more comprehensive, requirements.
This is by no means a complete list. Business processes underlying automated decisions will have a range of technology neutral laws and legal risks to manage, as well as reputational and social licence risks, which become more significant once those processes are disclosed or challenged.
Activities that significantly impact people's lives will naturally attract the greatest scrutiny – access to essential services, financial outcomes, employment opportunities, and services affecting vulnerable groups.
ADM transparency is an opportunity to ask not only "what are we doing", but "can we explain and defend what we are doing?" That question should bring together legal, operational, data, customer, complaints and reputational risk perspectives.
While many organisations are focused on getting ready for the new ADM transparency requirements, there is value in looking beyond minimum compliance. Transparency done well can strengthen trust and make business practices more defensible. It also helps set organisations up for additional automated decision requirements that arise in future reforms to the Privacy Act.
First, transparency supports meaningful privacy choices. When people understand how their personal information contributes to automated decisions, they can make genuinely informed decisions about whether to share that data. Transparency done well means consent frameworks stand up to regulatory scrutiny and build customer trust.
Second, transparency can expose poor design choices and push back against dark patterns or manipulative design. It is very difficult to provide genuine transparency while also using interface design that nudges individuals toward outcomes that may not align with their preferences. Regulators are increasingly focused on this intersection. The recent InspectRealEstate / 2Apply determination demonstrates that the Privacy Commissioner is already scrutinising so-called ‘dark patterns’ and online choice architecture, when assessing whether personal information has been collected by unfair means.
Third, transparency strengthens governance. At its core, you cannot clearly explain a system that you do not fully understand. Before you can offer meaningful transparency to others, you need to have a firm grasp of how automated systems and associated business processes operate. Not just technically, but in terms of outcomes and impacts, and how decisions affect individuals.
Understanding and risk managing automated decisions requires each process be mapped, documented, risk rated, and understood. You need to consider a wide set of risks, including privacy law, competition law, intellectual property law, sector-specific regulations, contractual obligations, and stakeholder expectations.
A comprehensive bottom-up inventory may be desirable over time, but it may not be the most effective starting point where organisations are working to a fixed commencement date. A risk-based approach should begin with the ADM use cases most likely to affect individuals in a significant way, then work through the data, systems, controls and disclosures that support those use cases.
As APRA observed when developing guidance for entities to comply with Operational Risk Management prudential regulation CPS 230, a "bottom-up" approach has its merits, but is often slower. Adopting a "top-down" approach that starts by identifying your biggest risks can deliver greater insight and implementation progress.
To discover higher-risk uses of AI and ADM, organisations must understand:
the external landscape: watch regulator guidance, media and public sentiment, and domestic and international regulatory focus and enforcement action for "hot button" industries or practices;
the customer impact: identify business processes that are likely to have a bigger impact on your customers, including where your decisions are acted on by others (for example, a credit score will have consequences beyond your organisation);
the business context: prioritise higher-value or business-critical processes to understand how they have been or will be automated; and
the data that business processes are accessing: look at access to (and requests to access) sensitive, higher-value or higher-risk data sets (including those containing sensitive information).
Pay particular attention to business processes that use sensitive information (such as certain biometric information, health information, and information about race, ethnicity, political beliefs). Sensitive information is likely to raise greater community concerns and is subject to more stringent privacy requirements. Recent regulatory activity involving sensitive information include facial recognition, and website tracking pixels in health services.
The regulator has already drawn attention to certain higher risk factors, including the use of sensitive information, intrusive practices, financial outcomes, and decisions impacting vulnerable people (discussed in Automated decisions in Australia series – Part 2: Learnings from the regulator’s consultation paper).
Because transparency requirements are intended to shine light on underlying business practices, make sure those business practices are up to scratch.
Rather than treating ADM disclosures as a standalone privacy policy exercise, organisations should use them as a lens to stress-test how personal information flows through the business and how automated or computer-assisted decisions are made.
This is underpinned by Australian Privacy Principle 1.2, which requires reasonable steps to implement practices, procedures and systems to ensure compliance and deal with inquiries and complaints. The measures that you put in place to identify automated decisions, to stress-test personal information flows, and to ensure that automated decisions are understandable, do more than ensure your privacy policy meets the new automated decision requirements. The measures support your broader privacy management plan and compliance with Australian Privacy Principle 1.2.
1. Make sure the data lifecycle is defensible
Do you have a legitimate need to collect the data in the first place, is it retained for an appropriate period, and destroyed or de-identified at the right time?
2. Think about all the data contributing to a decision
Do not focus only on information you collect directly from individuals:
Ensure your ADM disclosures describe all the types of personal information used and ensure the collection and management of that data is defensible.
3. Keep your privacy disclosures consistent and up to date
Where automated decisions and supporting personal information are disclosed in privacy policies, close the loop and confirm that other Privacy Act requirements have been met – for example related collection notices, purposes of collection, and consents.
Make sure your marketing materials, customer promises, customer terms and other documents all sing from the same hymn sheet.
Have the processes and governance in place to rapidly notice changes in business practices and flow changes through to customer transparency.
Make sure you are ready to explain the basis for using automated decisions in your business process, should individuals make a request or complaint based on the changes to your privacy policy.
4. Do not collect more data than you need
It can be tempting to use as many data points as possible to drive better decision-making. However, more transparency around automated or computer-assisted decisions may draw attention to over-collection of personal information.
Organisations should be able to explain why the personal information used in ADM is reasonably necessary for their functions or activities (Australian Privacy Principle 3.2). As the Privacy Commissioner recently said in the InspectRealEstate / 2Apply determination, "data collected should be relevant, minimal, and not excessive".
5. Document underlying practices, systems and processes
Like other Privacy Act obligations, new transparency requirements are supported by a broader underlying obligation under Australian Privacy Principle 1.2 to take reasonable steps to implement practices, procedures, and systems to comply with privacy laws. Privacy enforcement actions regularly examine not only privacy failures, but the underlying practices, procedures and systems that allowed the failures to occur.
6. Get your privacy impact assessments in order
Recent privacy determinations and decisions make it clear that privacy impact assessments are an essential part of practices, procedures and systems required under Privacy Act, and will likely be a key area of scrutiny if the regulator investigates the use of automated decisions in the future.
Although proposed reforms to introduce mandatory privacy impact assessments have not yet arrived, privacy impact assessments should be treated as a fundamental part of compliance practices, procedures, and systems required under Australian Privacy Principle 1.2. Privacy impact assessments remain one of the clearest ways to evidence organisational discipline (particularly for higher risk ADM use cases) and to ensure new ADM transparency requirements are met.
Decision points to conduct, update, or review privacy impact assessments should be well understood and built into governance arrangements. Subsuming the assessment into a broader artificial intelligence review procedure potentially results in missed business processes, given the automated decision requirements are broader than just artificial intelligence.
7. Make sure the practice is fair
Greater transparency around automated or computer-assisted decisions can draw attention to business practices, including industry standard business practices, that can be challenged as either unfair collection of personal information, or under new unfair trading practices laws (read more in our article Australia bans unfair trading practices, strengthens laws against drip pricing and subscription traps).
As the Privacy Commissioner demonstrated in the recent IRE / 2Apply determination, the Privacy Act already requires data collection to be "fair" – with factors indicating "unfair" collection in that case including power imbalance, market dynamics, limited choice of service provider, excessive collection of information, security risks, and design choices or "dark patterns".
With increased transparency, organisations may need to prepare for regulatory interventions, and potentially an increase in privacy complaints.
Individual privacy complaints have skyrocketed. It is unlikely that the regulator will be able to investigate and take enforcement action in relation to many individual complaints. Despite finalising 38 per cent more cases in less than a year, the OAIC has seen a 73 per cent increase in complaints over that period.
The Privacy Commissioner has made it clear that not all individual privacy complaints will be taken through to investigation, and the OAIC is working hard to increase expectations that organisations deal with privacy complaints at the first instance.
The OAIC has shifted its enforcement strategy, recognising the "considerable deterrent and educative benefits of proportionate regulatory action."
Expect targeted information gathering and enforcement activity aiming to have a leveraged, industry-wide impact in areas of social concern using three key methods:
Monitoring and surveillance: use of information gathering exercises and regulatory intelligence to identify priority issues, industries, or areas for targeted intervention.
Rapid smaller scale intervention: The Privacy Commissioner has made it clear that pairing the automated decision-making requirement with her new power to issue infringement notices for administrative failures (such as not including information in a privacy policy), the OAIC may be able to bring quick action.
Strategic enforcement action to drive broader industry change. An example of the Commissioner's approach to having a leveraged impact, in the recent IRE Pty Limited / 2Apply determination, the Commissioner targeted the rental sector as a regulatory priority, informed by a recognition of the power imbalance in that market. She then provided copies of her determination to real estate peak bodies to ensure the decision is taken on board by real estate agents, property managers and landlords.
Organisations should expect ADM transparency to increase the volume and sophistication of questions, complaints and requests for explanation. As the OAIC places greater emphasis on strategic enforcement and expects organisations to resolve privacy concerns at first instance, internal complaint handling, escalation and evidence management processes will become increasingly important.
Social licence is now a material risk issue
"This is about building Australians' confidence and trust in AI and our nation's capacity to manage it"
- Australian Prime Minister, Anthony Albanese
The Australian Government's new regulatory approach is to build the social licence for AI adoption and AI infrastructure by building public trust that Australia's regulatory settings will protect Australians' interests. This is accompanied by a renewed focus on AI consumer safety.
This policy direction continues to emphasise trust, safety and confidence. The Government has linked AI adoption to public confidence in how AI is managed, and the OAIC’s recent work shows that community expectations about fairness, choice and data minimisation are becoming increasingly important in privacy regulation.
The message is clear – the social risks of today are rapidly becoming the regulatory and operational risks of tomorrow (a theme we recognised as emerging in 2022).
A recent OAIC survey found Australians remain cautious about AI in decision-making:
These findings don't mean consumers will reject all automated services – Australians still expect seamless, efficient, frictionless, and personalised services.
The findings do show the importance of clear limits, meaningful choice and defensible data practices, principles that remain relevant throughout your use of automated decisions, and handling of personal information more generally.
Authors: Geoff McGrath, Partner; Sonia Haque-Vatcher, Partner; Andrew Hilton, Expertise Counsel; Olivia Carmody, Lawyer and Noah Steinman, Graduate
This publication is a joint publication from Ashurst Perkins Coie Australia, Ashurst Perkins Coie Risk Advisory LLP and Ashurst Perkins Coie Risk Advisory Pty Ltd, which are all part of the Ashurst Perkins Coie Group.
Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.
Ashurst Perkins Coie Risk Advisory LLP is a limited liability partnership registered in England and Wales under number OC442883. A list of members of Ashurst Perkins Coie Risk Advisory LLP and their professional qualifications is open to inspection at its registered office, London Fruit & Wool Exchange, 1 Duval Square, London E1 6PW.
Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.
The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.
The services provided by Ashurst Perkins Coie Risk Advisory LLP and Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. Ashurst Perkins Coie Risk Advisory LLP is not regulated by the Solicitors Regulation Authority of England and Wales. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.
This material is current as at 24 August 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.