Urgent.News

What's breaking now, across thousands of outlets.

AI

Your privacy policy now has to describe your AI

From 10 December 2026, Australian Privacy Principles 1.7 to 1.9 require APP entities to disclose automated decision-making in their privacy policy. If a computer program uses personal information to make, or substantially and directly contribute to, decisions that could significantly affect someone's rights or interests, the policy must state the kinds of information and decisions involved.…

Beginning on 10 December 2026, Australian privacy policies must explicitly outline the use of automated decision-making processes. This requirement stems from the amendments to the Privacy Act, introduced through the Privacy and Other Legislation Amendment Act 2024. These changes affect all organizations classified as APP entities.

To ensure compliance, the Office of the Australian Information Commissioner (OAIC) released guidance material, including a fact sheet and flowchart, in response to 90 submissions from various stakeholders.

A computer program falls under the scope of these regulations if it utilizes personal information to make decisions, or contribute significantly to decision-making, about an individual. The decision may either be solely generated by the program or substantially influenced by a human. Regardless of whether the outcome positively or negatively impacts the individual, it is considered a decision that must be disclosed in the privacy policy.

This rule applies not only to artificial intelligence and machine learning but also to pre-programmed rule-based processes, as long as they meet the criteria.

The privacy policy must provide information on the types of personal data the programs utilize and the categories of decisions they are involved in. The guidelines differentiate between decisions made exclusively by the program and those where the program contributes to the decision-making process alongside human input. For instance, if a model ranks rental applicants and a property manager selects from the top five, the ranking algorithm must be disclosed.

Organizations must maintain accurate disclosures over time as AI systems evolve. This requires implementing a governed context layer that manages connections and rules dynamically. By centralizing the rules and approved connections in a shared layer, organizations can ensure their privacy policies remain current even after updates or swaps, such as model replacements or the introduction of new tools.

This approach helps prevent discrepancies between the documented system capabilities and actual operations, thereby maintaining compliance with the new regulatory requirements.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

Paul Graham Versus the Pope

Pope Leo XIV recently tweeted that there is “an ontological difference, even before an aesthetic one, between art and what a machine can generate through statistical calculation based on millions of…

More from Tuesday 6 October →