Article

Look What You Made Me Disclose: AI decision-making and your new privacy policy obligations

WRITTEN BY Katie Innes


On 10 December 2026, two significant changes to Australia’s privacy framework take effect.

Organisations that use computer programs, including AI, to make decisions about individuals need to say so in their privacy policies. And the Office of the Australian Information Commissioner (OAIC) must register the Children’s Online Privacy Code (the Code) adding new rules for online services that children are likely to use.

Both changes were introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) which we outlined in our Essential Guide: Privacy Act Reforms in May 2025 . This article sets out what is changing, who is caught, and what to do before December.

Automated decision-making: what is changing

New Australian Privacy Principles (APPs) 1.7 and 1.8 will require privacy policies to contain information about how you use computer programs to make decisions where:

  • you arrange for computer programs to make a decision, or do something to substantially and directly assist make decisions;
  • those decisions could significantly affect the rights or interests of an individual; and
  • personal information is used in the operation of the program.

If this applies to you, in your privacy policy you will need to disclose:

  • the kinds of personal information used;
  • the kinds of decisions made solely by the operation of these programs; and
  • the kinds of decisions which might be substantially and directly assisted by these programs.

APP 1.9 confirms that making a decision extends to refusing or failing to make a decision.

These obligations are not limited to AI. Any computer program can be caught, including rules-based systems that have been running for year. Common examples include tools that screen job applications, assess eligibility for a service, set prices or credit terms or flag accounts for fraud review.

It is not just a privacy policy update

The new APPs are transparency obligations. They do not prohibit automated decision-making and they do not change your obligations to take reasonable steps (active technical and organisational measures) to comply with privacy laws.

What changes is that you must:

  • be able to describe, publicly and accurately, how these programs use personal information; and
  • have updated measures within your organisation as to how you are going to protect the personal information you do use.

You need to know what you are using across your organisation and how. You need to build the internal systems and protocols to ensure you are properly managing personal information in these computer programs and you train your staff on these protocols. Updating the privacy policy is almost the last step (not the first).

Where to start

On 30 September 2026 the OAIC released new resources on transparency for the use of AI and automated decision-making which includes flowcharts and fact sheets. They are a practical starting point for reviewing how your organisation operates.

Earlier this year Australia’s National AI Centre also released guidance for AI adoption and implementation . It is also a useful framework for any organisation trying to implement a system for the safe adoption and use of AI, particularly in the context of this upcoming privacy reform.

You should already be asking yourselves: where is AI already being used in my business, by whom, and with what data and permissions.

Children’s Online Privacy Code

The other significant change is that the OAIC must register a “Children’s Online Privacy Code” by 10 December 2026. The Code is an APP Code which specifies how online services must comply with the APPs and additional requirements in relation to the handling of children’s personal information. A breach of the Code will be an interference with the privacy of an individual and therefore a breach of the Privacy Act.

More businesses may be affected than you might think.

Who will the Code apply to?

The Code will apply to:

  • social media services – essentially platforms where people can connect, share content and interact with others. This includes social networks public media-sharing sites, discussion forums and review platforms;
  • relevant electronic services – online services that let people communicate with each other. This includes messaging apps, email services, video calling platforms and online games where players can chat; and
  • designated internet services – this covers online services that allows users to access or receive material over the internet. (e.g. cloud storage, websites that let users receive/access content, streaming platforms, consumer IoT devices)

where there is an “online service” that is likely to be accessed by children or primarily connected with the activities of children.

Examples of these kinds of services include apps that track early childhood development, family photo sharing applications, online school management systems that monitor student performance and internet-connected baby monitors. Industries potentially captured include advertising, online retail, education, early childhood, EdTech, gaming and media.

Schools and other education providers, sporting bodies and not-for-profits that work with young people should also consider whether their member portals, booking systems, apps or online communities fall within these categories.

Entities providing health services are not bound by the Code. However, the OAIC can also “include” and “exclude” entities so stay tuned.

What the draft Code proposes

The key obligations in the draft Code are:

  • Collection, use and disclosure of personal information must be consistent with the best interests of the child
  • Direct marketing is only permissible with consent, when in the child’s best interests and when the personal information is collected directly from the child (rather than third parties)
  • More rights and controls for children including introducing a right to request destruction of their personal information
  • Privacy notices and policies must be written in clear, accessible language that is age appropriate
  • Stronger consent mechanisms, including telling a child when a parent consents on their behalf

The final iteration of the Code is yet to be published but the consultation papers around the draft code are available on the OAIC’s website. 

Five steps to take before 10 December

  1. Confirm your position. Check whether your organisation is an APP entity, and whether any of your online services are likely to be accessed by children.
  2. Map your AI and automated tools. Find out where AI and other computer programs are used across the organisation, including tools staff have adopted on their own initiative. Ask where, by whom, and with what data and permissions.
  3. Identify the decisions. Work out which of those uses make, or substantially and directly contribute to, decisions that could significantly affect individuals, and what personal information they use.
  4. Update your privacy policy. Make the disclosures required by APPs 1.7 and 1.8, in language your customers, clients or community will understand. We can help.
  5. Govern your AI use. Put a policy for the responsible use of AI in place, supported by internal protocols and staff training.

AI is already being used inside most organisations, often more widely than leaders realise. Now is the time to really understand how you and your staff are using AI, assess the privacy impacts of that use, and update your internal systems and privacy policy.

And if you don’t have a Policy for the responsible use of AI … you should.


Please note that the information in this article is current as at 1 October 2026. It is not legal advice, and readers should contact us for specific advice on their particular situation. If you need advice on the reforms, assistance updating your privacy policy, or help implementing a policy for the responsible use of AI, please get in touch with the Business & Commercial team on 02 6274 0999.

Katie Innes is a Legal Director at BAL Lawyers, practising in corporate governance, privacy, intellectual property and commercial contracts.


Join our mailing list

Get in touch