From 10 December 2026, if a computer program helps decide things about people and your organisation falls under Australia’s Privacy Act, your privacy policy must say so [1]. Not the code. Not the weightings. Just an honest account of the kinds of personal information the program uses and the kinds of decisions it touches [1][2]. That sounds modest. For a membership organisation or university running registration platforms, submission systems and eligibility checks, it is rather less modest than it sounds, because the first job is working out which of your systems count.
What the law actually says
Australia’s Privacy and Other Legislation Amendment Act 2024 added new transparency requirements to Australian Privacy Principle 1, in what practitioners refer to as APP 1.7 to 1.9, commencing 10 December 2026 [1][2]. The trigger has three parts: a computer program makes a decision, or does something “substantially and directly related” to making it; the decision “could reasonably be expected to significantly affect the rights or interests of an individual”; and personal information is used in the program’s operation [2][3].
Where that trigger is met, your privacy policy must set out three things: the kinds of personal information used in the operation of such programs, the kinds of decisions made solely by them, and the kinds of decisions they substantially and directly contribute to [2][3].
Three details deserve more attention than they tend to get.
There is no grandfathering. The obligation applies to decisions made after 10 December 2026 even where the system was built, and the personal information collected, years earlier [2][7].
A human in the loop is not an exemption. Where a program’s output is a key factor in a person’s decision, it can still be “substantially and directly related” to making that decision, and therefore disclosable [3][7]. The likelihood of a human actually overriding the system is one of the factors the regulator says it will weigh [7].
“Computer program” means almost anything. The Office of the Australian Information Commissioner’s issues paper covers pre-programmed rule-based processes as well as AI and machine learning, and offers a scoring formula in a spreadsheet as an example of a system that can qualify [3][7]. A decision also includes refusing or failing to make one, and the effect on the individual can be beneficial rather than adverse [3][7].
Does this reach an organisation outside Australia?
Possibly, and that is the point of asking now rather than in December. The Privacy Act covers Australian government agencies and organisations with annual turnover above AUD 3 million, with exceptions that pull some smaller organisations in [4][5]. It also reaches entities based elsewhere that “carry on business in Australia” under section 5B [5][6]. The indicators include personnel in Australia, a website offering goods or services to Australian customers, and orders processed there; a website that is merely accessible from Australia is not, by itself, enough [5][6]. Not-for-profits are not automatically outside the net either: the OAIC’s guidance notes an organisation can carry on business through commercial acts repeated on a systematic basis [6].
So an association headquartered in London or Toronto that sells memberships to Australians, runs a congress in Melbourne, or employs a secretariat in Sydney has a genuine question to put to its advisers. Whether the answer is yes will turn on the facts. The mistake is assuming the answer is no because the head office is elsewhere.
Where this lands in a membership operation
The examples advisers give for decisions that significantly affect rights or interests include eligibility for significant services, insurance terms, employment screening and differential pricing based on profiling [2][7][8]. Map those onto the systems we build and care for, and the questions become concrete. Does your platform automatically decide who qualifies for a concessional membership rate? Does your abstract system score or triage submissions before a human reads them? Does registration software screen payments for fraud and decline some automatically? Is a waitlist or bursary ranked by formula?
Not all of these will cross the threshold. The effect must be more than trivial, and reasonable people will disagree about, say, waitlist ordering [2]. But that judgment is exactly what the exercise requires: a short inventory of every place software decides or ranks something about a person, and an honest note of which ones matter. One spreadsheet, one named owner, an afternoon of work. If you built an AI inventory for the EU AI Act in January, it will do double duty here — the same document, one more column.
What a compliant paragraph might look like
The OAIC consulted on draft guidance over May and June 2026, and final guidance is expected before commencement, so the safe course is to write plainly now and refine against the guidance when it lands [1][3][8]. In our view a serviceable disclosure, for a society whose platform auto-assesses concession eligibility, reads something like: “We use automated processes to assess eligibility for concessional membership rates. These processes use the membership category, career stage and country information you provide. Eligibility decisions are made by this process without human review; you may ask us to review any decision.” Ours is a suggestion, not the regulator’s words. The regulator has said only that disclosures should be clear, in plain language, and not buried in detail that obscures the point [3].
The regulator is not waiting politely
If the December date feels distant, the enforcement climate around it should not. The OAIC ran its first-ever compliance sweep in the first week of January 2026, checking privacy policies across six sectors against APP 1’s transparency requirements [9][14]. In October 2025 the Federal Court ordered Australian Clinical Labs to pay AUD 5.8 million in the first civil penalties under the Privacy Act [10][11]. The top penalty tier for serious interference with privacy now stands at the greater of AUD 50 million, three times the benefit obtained, or 30 per cent of adjusted turnover [11][12]. And since 10 June 2025 individuals have been able to sue directly under a statutory tort for serious invasions of privacy, which has already produced its first cases [13][14]. A regulator that sweeps privacy policies for transparency failures is unlikely to ignore a brand-new transparency obligation with a fixed start date.
This month, not this quarter
Four things, in order. Establish whether the Privacy Act plausibly reaches you, and write the answer down. Inventory where software decides or ranks anything about a person, including inside third-party platforms, and ask those vendors directly what their systems automate — their answer belongs in your file. Draft the paragraph. Then watch for the OAIC’s final guidance and adjust once, rather than guessing twice [1].
None of this requires a consultant or a committee. It requires an afternoon, a spreadsheet and a willingness to describe honestly what your own systems do — which, as with most transparency obligations, turns out to be the useful part regardless of where your members live.
References
- Office of the Australian Information Commissioner. Consultation on Guidance for Transparency in Automated Decision Making. OAIC, 2026. https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making. Accessed 21 September 2026.
- Gilbert + Tobin. Automated decision-making transparency under the Privacy Act: are you prepared for 10 December 2026? Gilbert + Tobin, 2026. https://www.gtlaw.com.au/insights/automated-decision-making-transparency-under-the-privacy-act. Accessed 21 September 2026.
- Allens. Automated decision-making transparency: what APP entities need to know about the APP 1 amendments. Allens, June 2026. https://www.allens.com.au/insights-news/insights/2026/06/automated-decision-making-transparency-what-app-entities-need-to-know-about-the-app-1-amendments/. Accessed 21 September 2026.
- Office of the Australian Information Commissioner. The Privacy Act. OAIC, n.d. https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act. Accessed 21 September 2026.
- Spruson & Ferguson. Do Australian privacy laws apply to me? Spruson & Ferguson, n.d. https://www.spruson.com/do-australian-privacy-laws-apply-to-me/. Accessed 21 September 2026.
- Office of the Australian Information Commissioner. Australian Privacy Principles guidelines, Chapter B: Key concepts. OAIC, n.d. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-b-key-concepts. Accessed 21 September 2026.
- MinterEllison. Preparing for the new ADM Obligation: OAIC consultation. MinterEllison, 2026. https://www.minterellison.com/articles/oaic-seeks-feedback-on-automated-decision-making. Accessed 21 September 2026.
- White & Case. Australian Privacy Update: Automated decision making transparency requirement. White & Case, 2026. https://www.whitecase.com/insight-alert/australian-privacy-update-automated-decision-making-transparency-requirement. Accessed 21 September 2026.
- Office of the Australian Information Commissioner. Privacy compliance sweep to put privacy policies under the spotlight. OAIC, 2025. https://www.oaic.gov.au/news/media-centre/privacy-compliance-sweep-to-put-privacy-policies-under-the-spotlight. Accessed 21 September 2026.
- Office of the Australian Information Commissioner. Australian Clinical Labs ordered to pay penalties in relation to Medlab Pathology data breach in first for Privacy Act. OAIC, 2025. https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act. Accessed 21 September 2026.
- Clyde & Co. Cyber and privacy law update: accountability gets real. Clyde & Co, October 2025. https://www.clydeco.com/en/insights/2025/10/cyber-and-privacy-law-update-accountability-gets-r. Accessed 21 September 2026.
- Office of the Australian Information Commissioner. Guide to privacy regulatory action, Chapter 7: Civil penalties — serious or repeated interference with privacy and other penalty provisions. OAIC, n.d. https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action/chapter-7-privacy-assessments. Accessed 21 September 2026.
- Office of the Australian Information Commissioner. Statutory tort for serious invasions of privacy. OAIC, n.d. https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/statutory-tort-for-serious-invasions-of-privacy. Accessed 21 September 2026.
- LK Law. Privacy in the Courts: privacy litigation and enforcement ramps up. LK Law, December 2025. https://www.lk.law/2025/12/privacy-in-the-courts-privacy-litigation-and-enforcement-ramps-up/. Accessed 21 September 2026.



