Binding law — not yet in force or stayed AI-adjacent law
State in the APP privacy policy the personal information computer programs use and the decisions they make or substantially help make (Australia, APP 1.7-1.9)
From 2026-12-10, Australian Privacy Principle 1.7 (inserted by the Privacy and Other Legislation Amendment Act 2024, Sch. 1 Pt 15) requires an APP entity that has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using their personal information, to state in its APP privacy policy the kinds of personal information used, the kinds of decisions made solely by such programs, and the kinds of decisions they substantially and directly help make (APP 1.8). Decisions include refusals and failures to decide, and adverse or beneficial effects; examples are benefits under legislation, contractual rights and access to a significant service or support (APP 1.9). It applies to decisions made after commencement, and APP 1.7 is an infringement-notice provision. Detect a privacy policy with no automated-decisions statement.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — not yet in force or stayed Enacted, not yet applying: applies from 10 Dec 2026
- Official source
- POLA Act 2024, Sch. 1 item 88 (APP 1.7-1.9, automated decisions) · captured 2 Oct 2026 · anchor hash (SHA-256)
76bb672fcedf…· 7 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Policies outside the repository
- Statements using other words (for example 'algorithmic assessment')
- Only meaningful where the system makes or assists significant decisions with personal information; the policy may be hosted outside the repository.
Who it applies to
- Duty falls on: organization, controller
- Systems covered: automated decision, consequential decision
- APP entities (agencies and organisations; small business operators excluded unless s 6D(4) applies) that have arranged for a computer program, including an AI model, to make, or do a thing substantially and directly related to making, decisions that could reasonably be expected to significantly affect individuals' rights or interests, using their personal information: the APP privacy policy states the kinds of personal information used and the kinds of decisions made solely by, or substantially assisted by, such programs. Applies from 2026-12-10 to decisions made after that date. What 'substantially and directly related to making' a decision covers for AI recommendations a person then acts on is a question for counsel (review flag).
- Not covered:
- Decisions made before 10 December 2026 (item 89 applies the APPs to decisions made after commencement)
- Small business operators (annual turnover of $3,000,000 or less) are not organisations and so not APP entities, unless s 6D(4) applies (health service providers holding health information, traders in personal information, Commonwealth contracted service providers, credit reporting bodies) (ss 6C(1), 6D)
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Keep an automated-decisions section in the privacy policy, generated or checked against the decision paths in code.
A section of the privacy policy that lists the kinds of decisions computer programs make solely, the kinds they substantially and directly help make (scores, rankings, recommendations a person then decides on), and the kinds of personal information each uses. Keep a small inventory in the repository (decision name, model or rule, inputs, solely automated or assisted) and a CI check that every decision service calling a model or scoring rule appears in the inventory and in the policy, so a new decision path cannot ship without its policy entry.
Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 14 user-facing text.
What this provision adds:
- List in the APP privacy policy the kinds of personal information computer programs use, the kinds of decisions made solely by them, and the kinds of decisions they substantially and directly help make.
- Include refusals and failures to decide, and decisions with beneficial as well as adverse effects.
Example (APP privacy policy), before:
# Privacy policy
We collect your name, contact details and transaction history to provide our services.After:
# Privacy policy
We collect your name, contact details and transaction history to provide our services.
## Automated decisions
Decisions made solely by a computer program: instant approval or decline of credit limit increases
(uses your income, repayment history and current balances).
Decisions a computer program substantially helps us make: fraud reviews, where a model scores each
transaction (uses transaction amount, merchant, device and location) before a staff member decides.Control: The privacy policy does not describe the decisions computer programs make or help make with personal information. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Rule id au-privacy-app-1-7.privacy-policy-automated-decisions · review status: primary source derived