Automated Decision-Making Transparency: What APP 1.7 Means for Your Vendor Contracts

From 10 December 2026, Australian Privacy Principle 1.7 requires organisations to disclose how computer programs use personal information to make decisions that significantly affect people. The duty stays with the buyer, not the software vendor, which makes it a contract and tender problem.
CYBORIUM AI governance article header for automated decision-making transparency under APP 1.7

From 10 December 2026, Australian organisations must disclose in their privacy policies how computer programs use personal information to make decisions that significantly affect people. The obligation sits with the organisation that arranged for the program to run. It does not sit with the vendor who built it.

That single point of law turns automated decision-making transparency into a procurement problem. Most of the qualifying decisions in a mid-size Australian business are made inside purchased software: a fraud engine in the payments platform, a ranking model in the recruitment suite, an eligibility rule set in the claims system. The disclosure duty lands on the decision owner, and the facts needed to write the disclosure sit with the seller.

What the automated decision-making transparency obligation requires

The obligation comes from Schedule 1 of the Privacy and Other Legislation Amendment Act 2024, which received assent on 10 December 2024 and gave entities a 24 month lead time. It adds three new subclauses to Australian Privacy Principle 1.

APP 1.7 sets the trigger. It applies where an APP entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision, where personal information is used and the decision could reasonably be expected to significantly affect the rights or interests of an individual.

APP 1.8 sets the disclosure. Where APP 1.7 is triggered, the privacy policy must set out:

  • the kinds of personal information used in the operation of those computer programs;
  • the kinds of decisions made solely by the operation of those computer programs; and
  • the kinds of decisions for which a thing substantially and directly related to making the decision is done by the operation of those computer programs.

APP 1.9 confirms that an effect on rights or interests can be beneficial as well as adverse. The examples given cover decisions about statutory entitlements, decisions affecting contractual rights, and decisions that determine access to a significant service.

Which decisions are captured

The test is not whether the system is artificial intelligence. A deterministic rules engine that declines an application is captured. A scorecard implemented in a spreadsheet and wired into a workflow is captured. A large language model that drafts a recommendation a human then signs is captured if the draft is a key factor in the human decision.

The Explanatory Memorandum reads “substantially” as meaning the program is a key factor in facilitating the human decision, and “directly” as requiring a direct connection with making the decision. That second limb is what pulls partly automated processes into scope. A screening step that removes two thirds of applicants before a person looks at the shortlist is doing something substantially and directly related to the hiring decision, even though a human makes the call.

Working examples that commonly qualify in Australian businesses:

  • Credit, lending and payment terms decisions, including automated declines.
  • Insurance pricing, underwriting triage and claims routing.
  • Resume screening, candidate ranking and interview scheduling gates.
  • Fraud and risk scoring that suspends an account or blocks a transaction.
  • Eligibility assessment for a benefit, concession, tariff or program.
  • Tenancy, membership and onboarding checks that gate access to a service.
  • Automated content or account enforcement that removes access.

The amendments apply to decisions made on or after 10 December 2026. The date the model was trained, the data collected or the contract signed does not change that.

Why automated decision-making transparency is a procurement obligation

APP 1.7 uses the words “arranged for”. An organisation that licenses a platform, configures it and points it at its own customers has arranged for that program to operate. Outsourcing the build does not outsource the disclosure.

To write a compliant privacy policy the decision owner needs three facts from each supplier: which categories of personal information the program consumes, which decisions it makes on its own, and which decisions it materially shapes for a human. Vendors do not publish that detail in product documentation, and support desks are rarely able to answer it. It has to be asked for, and the reliable place to ask is the tender.

There is a second problem that contracts have to solve. Automated features now arrive by product update rather than by purchase order. A recruitment platform adds candidate ranking in a quarterly release. A service desk tool switches on priority prediction by default. The privacy policy that was accurate in January is wrong by March, and nobody in the buying organisation was told.

Contract terms that make the disclosure maintainable

A written statement of automated decisions

Require the supplier to state, per module, which decisions the software makes without a human and which it substantially supports, and to describe the categories of personal information each uses. Ask for it as a schedule to the agreement, not as a sales answer, so it can be updated under a change process.

Notice before behaviour changes

Set a notice period for any release that introduces automated decisioning, expands the personal information used, or shifts a decision from human to automated. Thirty days lets a privacy policy be revised before the change reaches production. Notice after the fact is a compliance report, not a control.

The right to switch a feature off

Some automated features will not be worth the disclosure and the review effort behind it. Negotiate the ability to disable them at tenant level without losing the rest of the product, and confirm it is a real configuration option rather than a support request.

Assistance with complaints and regulator inquiries

If an individual complains about an automated outcome, or the Commissioner asks how a decision was reached, the decision owner answers. Bind the supplier to provide the logic description, the input categories and the decision records within a defined period, and set the cost basis in advance.

Subprocessor and model provenance disclosure

Many vendors call a third party model behind their own interface. Require disclosure of which subprocessors and foundation models are involved, where inference runs, and whether customer personal information is used for training. Each of those affects what the privacy policy has to say and what other APP obligations apply.

Evidence rather than assurance

Ask for the artefacts: a data flow description, the decision inventory, testing records for accuracy and bias, and the change log for the decisioning components. A statement that the product is compliant with Australian privacy law tells the decision owner nothing they can put in a policy.

What non-compliance now costs

The same 2024 Act rebuilt enforcement into three tiers, and the lower tiers are the ones a privacy policy defect will meet.

  • Section 13G remains the high tier, for serious interferences with privacy.
  • Section 13H adds a mid tier for interferences that warrant action without meeting the serious threshold, with a maximum of 2,000 penalty units for a person and five times that for a body corporate.
  • Section 13K lists specified contraventions, including privacy policy requirements under APP 1, for which the Commissioner can issue an infringement notice or a compliance notice without going to court.

An out of date privacy policy used to be a housekeeping item. Under section 13K it is an administratively enforceable contravention, and from 10 December 2026 the policy has more to be wrong about.

The statutory tort raises the stakes on automated outcomes

A statutory tort for serious invasions of privacy commenced on 10 June 2025 under Schedule 2 of the Privacy Act. An individual can sue for intrusion upon seclusion or misuse of information where they had a reasonable expectation of privacy, the invasion was intentional or reckless, and the public interest in privacy outweighs any countervailing public interest. Proof of damage is not required.

Negligence is not enough to found the claim, which is the important qualifier. The exposure comes from continuing to run a system after being told it mishandles personal information. That is a records question, and the records are procurement records: what the vendor disclosed, what the decision owner asked, and what was done about the answer.

The pressure is not theoretical. The OAIC recorded 1,205 data breach notifications in 2025, an increase of 8 per cent on the 1,112 received in 2024 and the highest annual figure since the scheme began, with 716 attributed to malicious or criminal attack.

A twelve week plan to 10 December 2026

  1. Inventory the decisions, not the tools. Walk the customer, employee and supplier journeys and list every point where an outcome is produced or shaped by software using personal information.
  2. Apply the significance test to each one. Record why a decision is in or out, because that reasoning is what a regulator will ask for.
  3. Ask every in-scope supplier the three questions: what personal information, what decided alone, what materially supported. Set a response date.
  4. Check whether existing contracts give you any right to that answer. Most will not, which tells you where the gaps are.
  5. Triage renewals falling before December 2026. Those are the negotiations where the clauses cost nothing to add.
  6. Draft the privacy policy text early and keep it readable. Volume of detail is not the goal, and dense disclosure defeats the purpose of the obligation.
  7. Assign an owner for the register and tie it to release notes, so a vendor feature update triggers a policy review rather than a surprise.

The OAIC consulted on guidance for the transparency obligation with submissions closing on 15 June 2026 and has indicated guidance will be published ahead of commencement. Waiting for it before starting the inventory is a poor trade, because the inventory takes longer than the drafting.

How CYBORIUM supports automated decision-making procurement

CYBORIUM helps Australian organisations define requirements, test the market, compare providers and produce a decision record that stands up to scrutiny. The approach is independent and vendor-neutral. The client pays no fee to CYBORIUM and contracts directly with the selected provider.

For automated decision-making readiness that can include supplier disclosure requirements, decision inventory schedules, change notice and opt-out terms, complaint and regulator assistance obligations, evidence rights, and commercial benchmarking. CYBORIUM does not sell, deliver, operate, manage or invoice the selected technology.

Related guidance: Vendor and Supplier Risk Management for Enterprise Procurement, enhanced CIRMP supply chain obligations, APRA CPS 230 third party due diligence and the Cybersecurity Vendor Evaluation Framework.

Also relevant: how these obligations translate into AI procurement guardrails.

Buying software that decides something about people? Use CYBORIUM’s evaluation previews to test scope, evidence, pricing and contract terms before you commit.

Frequently asked questions

When does the automated decision-making transparency obligation start?

10 December 2026. It applies to decisions made on or after that date, regardless of when the system was built or deployed.

Does it only apply to artificial intelligence?

No. APP 1.7 refers to a computer program. A rules engine, a scoring model or a workflow automation is captured on the same terms as a machine learning system, provided personal information is used and the decision could significantly affect an individual.

Does the obligation move to the vendor if we license their platform?

No. The APP entity that arranged for the program to operate carries the disclosure obligation. Suppliers are reached through contract terms and evidence requests rather than directly by APP 1.8.

What if a human reviews the automated output?

Human review does not remove the obligation on its own. APP 1.8 separately covers decisions where the program does something substantially and directly related to making the decision, which captures scoring, ranking and shortlisting that a person then acts on.

What happens if the privacy policy is wrong or out of date?

Privacy policy requirements under APP 1 are among the contraventions listed in section 13K, so the Commissioner can issue an infringement notice or a compliance notice without court proceedings. More serious or repeated conduct can be pursued under section 13H or section 13G.

Do we need to give individuals an explanation of each decision?

The December 2026 change is a privacy policy transparency obligation about kinds of information and kinds of decisions, not an individual right to an explanation of a specific outcome. Existing rights of access and correction, and the Privacy Commissioner’s complaint powers, continue to apply.

Official sources and update status

Information status: reviewed against publicly available Commonwealth sources on 7 August 2026. Section and APP references were read from the Act as made and the OAIC APP Guidelines. Confirm them against the legislation as in force before relying on them. This is general information, not legal advice.

Preparing a tender or a renewal for software that makes decisions about people? Speak with CYBORIUM about an independent, evidence-led pathway.

Share this analysis