OAIC's new privacy guidance puts human-reviewed AI decisions in view
New OAIC guidance explains when software-assisted decisions belong in a privacy policy. Covered businesses should check their systems before 10 December.

A human approval button is no reason to skip a privacy review.
That is the useful warning in the Office of the Australian Information Commissioner’s updated guidance, published on 30 September. The regulator has released practical resources for an obligation that starts on 10 December 2026: certain businesses must explain significant software-made or software-assisted decisions in their privacy policies.
This is a follow-up to our 25 September privacy reforms explainer, which noted that final guidance had not been found at that point. The deadline is unchanged. What is new is the OAIC’s updated APP 1 guidance, fact sheets and decision flowchart, giving covered businesses a more useful starting point than a generic promise to use AI responsibly.
Start with whether the Act covers you
The small-business exemption has not disappeared. The OAIC’s small-business guidance says most businesses with annual turnover of A$3 million or less are not covered by the Privacy Act.
There are exceptions. Health service providers are one important example for small clinics and allied-health practices: size alone does not take them out of the Act. Businesses that trade in personal information and some Commonwealth contractors can also be covered. Check the regulator’s full list rather than treating turnover as the only test.
If your business is covered, the next question is what the software actually does with personal information. Owning an AI subscription is not the test. A useful review starts with decisions about people, then works backwards to the tools involved.
A human in the process is not an automatic exemption
The updated APP 1 guidelines explain that software can be in scope when it uses personal information to substantially and directly support a decision with a reasonably expected significant effect on someone’s rights or interests. It need not make the final call.
Rule-based software can qualify too. Merely recording a human decision in a word processor is different. The entity arranging the decision can retain responsibility when it uses an outside supplier.
Our recommendation is to avoid an inventory headed simply “AI tools”. It can miss the software nobody calls AI. Instead, ask the person responsible for each service: what decisions are made about customers or patients, which systems contribute, and how much does the team rely on the output?
Write down the answer before asking somebody to update the website. A polished privacy-policy paragraph cannot fix an organisation’s uncertainty about its own workflow.
The spreadsheet example is the point
The OAIC’s new fact sheet includes a fictional health and aged-care provider using spreadsheet formulas to rank people for services. Staff then use those rankings to decide whom to contact. The example shows why this is not just a chatbot issue: the significance of the decision and the software’s role matter.
For decisions in scope, policies must describe the kinds of personal information used, the kinds of decisions made entirely by software, and the kinds of decisions substantially and directly supported by it. The fact sheet distinguishes extensive human oversight from simply accepting an output. Assess what the review actually involves.
For a covered business, we suggest preparing a short working record for each relevant process: its purpose, the personal-information categories, the software’s contribution and who can explain the human review. Use that record to brief the person responsible for privacy compliance. It is a preparation aid, not a substitute for assessing the legal test.
Give the supplier a specific question
The regulator’s flowchart offers a way to work through the relevant conditions. Use it alongside the guidance, rather than assuming every automated process belongs in the policy.
A practical supplier enquiry is: which personal-information categories does this feature use, what decision or recommendation does it produce, and what can our staff review or override? Ask for an answer about the feature your business uses, not a sales statement about the supplier’s approach to AI.
Then give the policy update an owner and a review date before 10 December. Our website privacy-policy guide covers the broader document; today’s guidance is about making the automated-decision part specific enough to describe the business behind it.
Checklist
- Check coverage. Have the owner compare the business with the OAIC’s small-business exemption and exceptions.
- Map significant decisions. Ask the service manager which software uses personal information to make or materially support decisions about people.
- Question the supplier. Request feature-specific information about data categories, outputs and human review for the processes being assessed.
- Prepare the policy update. Have the privacy lead assess those processes against the OAIC guidance and complete required disclosures before 10 December 2026.
Tick items as you go. Your ticks stay in this browser.




