Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

From 10 December, Your Privacy Policy Has to Name the Decisions Your Software Makes

On 10 December 2026, three new subclauses of Australian Privacy Principle 1 take effect. If you have arranged for a computer program to make, or to materially shape, a decision that significantly affects someone, and personal information goes into that program, your privacy policy has to say so.

That is less than four months away. In the conversations we are having, most businesses have not started, and a good number have decided it does not apply to them because they do not use AI. That assumption is the single biggest exposure in this reform, and it is wrong for a reason that is easy to miss.

Tilt-shift miniature of application forms being sorted into two trays by a machine, with a single figure watching
From 10 December 2026, APP 1.7 applies where a computer program makes or substantially shapes a decision affecting someone’s rights or interests. The OAIC reads “computer program” to include ordinary spreadsheets.

What the new rules require

The obligation comes from the Privacy and Other Legislation Amendment Act 2024 (Cth), which inserts new APP 1.7, 1.8 and 1.9 into the Privacy Act 1988. Every other amendment in that Act commenced on 10 December 2024. The automated decision making provisions were given a two year runway, and that runway ends this December.

APP 1.7 sets three tests, and all three have to be met:

  1. You have arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision;
  2. The decision could reasonably be expected to significantly affect the rights or interests of an individual; and
  3. Personal information about that individual is used in the operation of the program.

APP 1.8 then tells you what has to appear in the privacy policy: the kinds of personal information used in those programs, the kinds of decisions made solely by them, and the kinds of decisions where the program does something substantially and directly related to the decision.

APP 1.9 widens it further. Rights or interests can be affected beneficially as well as adversely, so an approval counts alongside a refusal. Refusing or failing to make a decision is itself a decision. The examples given are a decision under legislation to grant or refuse a benefit, a decision affecting someone’s rights under a contract or arrangement, and a decision affecting access to a significant service or support.

The first thing most businesses get wrong: this is not an AI rule

The phrase in the legislation is “computer program”, not “artificial intelligence”, and the OAIC has signalled that it will read those words broadly. Its Automated Decision-Making Issues Paper, released on 18 May 2026, treats the term as covering pre-programmed rule based processes, machine learning, everyday business software, apps, word processing tools and generative AI chatbots. The Explanatory Memorandum to the Bill made the same point, and used a spreadsheet as its example.

Read that again with your own systems in mind. The scoring spreadsheet your credit team has run since 2014 is potentially in scope. So is the rules engine in your CRM that decides which enquiries get a callback, the applicant tracking system that ranks CVs before a human sees them, and the eligibility calculator on your website. None of it is AI. All of it can be caught.

An organisation that scopes this exercise by asking “where do we use AI” will map the wrong set of systems and produce a disclosure that is confidently incomplete.

The second thing: a human in the loop does not discharge the obligation

The most common answer we hear is “a person always reviews it before it goes out”. That is a good control. It is not an exemption.

The test is not whether a human made the final call. It is whether the program did something substantially and directly related to making the decision. The Explanatory Memorandum reads “substantially” as the program’s output being a key factor in facilitating the human decision, and “directly” as the output having a direct connection with the decision. On the OAIC’s commentary, a program that recommends an outcome, guides a decision maker, or categorises a person using their personal information can meet that test even though a human signs the decision off.

The boundary is genuinely unsettled. The OAIC has asked for views on how much weight to give factors such as the degree of reliance on the output, how likely a human override is in practice, and whether the output is advisory or determinative. Until guidance lands, the safe working assumption is that human review narrows the obligation rather than removing it.

If you already comply with the GDPR, you are not automatically compliant here

Article 22 of the GDPR bites on decisions “based solely on automated processing”. The Australian test is deliberately wider, because it reaches decisions where the program contributes substantially rather than decides outright.

The practical consequence for any business operating in both jurisdictions is that the mapping work done for Europe does not transfer. A system that sits comfortably outside Article 22 because a human decides can still require disclosure under APP 1.8.

What the rules do not do

It is worth being precise about the scope, because overstating it leads to wasted effort. This is a transparency measure only. It does not give individuals a right to contest an automated decision, a right to an explanation of the logic, or a right to human intervention, and it does not require you to notify anyone directly. It requires a privacy policy that tells the truth about what your systems do.

Western Australia has gone further. The Privacy and Responsible Information Sharing Act 2024 (WA) commenced on 1 July 2026 and does require notification, information on request, and the ability to ask for human intervention. If you are captured by both, the WA obligations are the more demanding of the two.

None of which makes the federal obligation soft. The OAIC’s powers to issue infringement notices and compliance notices have been live since 11 December 2024, and civil penalties apply to a privacy policy that does not meet the requirement.

The auditor’s point: this is an inventory problem before it is a drafting problem

Almost everything written about these reforms treats them as a privacy policy rewrite. It is not, or at least not yet. You cannot draft a word of the disclosure until you can answer four questions:

  • What programs do we actually run?
  • Which of them make or materially shape decisions about people?
  • Whose personal information goes into them?
  • Who supplied them, and what did the supplier change last quarter?

Most organisations can answer the first two with some effort. Very few can answer the fourth, and that is where this gets uncomfortable. The OAIC has acknowledged that the line between arranging for automated decision making and merely operating it is unclear in complex supply chains, and has invited submissions on exactly that point.

Consider the realistic version. Your HR platform adds candidate ranking in a routine product update. Nobody in your business decided to arrange for automated decision making, nobody was asked, and the release notes ran to eleven pages. The decision it shapes affects access to employment. You may well have a disclosure obligation you do not know about, created by a supplier’s roadmap.

That is not a legal problem. It is a records problem, and it is the same records problem we see behind most privacy findings: the organisation knows what it bought, but not what it now runs.

Where ISO 27001 and ISO 42001 carry the load

If you hold either certification, most of the machinery you need already exists. It has simply never been pointed at this question.

  • ISO 27001, control A.5.9, inventory of information and other associated assets. You already maintain the register. Add a field recording whether the asset makes or shapes decisions about people, and whose personal information it consumes. That single column turns an existing artefact into your APP 1.8 evidence base.
  • Controls A.5.19 and A.5.21, supplier relationships and the ICT supply chain. This is where the embedded feature question gets asked, at procurement and at contract review, rather than discovered eighteen months later.
  • Control A.5.34, privacy and protection of personally identifiable information. The natural home for tracking this as a standing legal requirement rather than a one off project that closes in December.
  • ISO 42001’s AI system impact assessment. It is designed to ask what a system does to the people it touches. That is very close to the question APP 1.7 asks, and an assessment already on file will do a lot of the scoping work.
  • Clause 9.2, internal audit. A published disclosure is a claim about your systems, and claims drift. Systems get replaced, suppliers ship features, and the policy quietly stops being true. Sampling the disclosure against what the systems actually do is a straightforward audit and nobody is doing it yet.

If you are working through how the two standards sit together, we have covered that in ISO 42001 and ISO 27001: how they fit together. The related question of what “reasonable steps” looks like for personal information is dealt with in our piece on APP 11.3 and where ISO 27001 and ISO 42001 fit. And if the honest answer to “what programs do we run” is “more than we can list”, shadow AI in the workplace is the place to start.

What to do between now and 10 December

  1. Map the programs, not the AI. Walk each process that produces an outcome for a person, and record every piece of software involved, including spreadsheets and calculators.
  2. Put the question to your suppliers in writing. Ask whether their product makes, recommends, ranks or scores anything about an individual, and ask to be told when that changes. Get it into the contract at the next renewal.
  3. Decide your threshold, and record the reasoning. “Significantly affect” is not defined, and the OAIC has noted that impact can be greater for a child or a vulnerable person. Whatever line you draw, the defensible position is a documented line, not a generous one.
  4. Draft with restraint. The OAIC wants disclosures in plain language, specific enough to be meaningful and short enough to be read. Hedging by publishing everything is self defeating: the more you include, the less anyone understands, which is the opposite of what APP 1 is for.
  5. Watch for the guidance. The OAIC has said it intends to publish before commencement, with September 2026 the stated target. Submissions on the Issues Paper closed on 15 June 2026.
  6. Diarise the review. Whatever you publish in December will be out of date within a year unless something owns it.

Businesses that hold personal information belonging to someone else’s customers, which in our experience means business process outsourcers, debt collectors, medical and allied health practices, and software and managed service providers, should treat this as a priority rather than a December task. The systems that make decisions about those individuals are usually the ones running highest volume and lowest visibility.

Not sure which of your systems are caught?

Tell us what your business decides about people and what software sits behind it, and we will tell you honestly which programs are likely in scope and what your privacy policy needs to say. You will be working directly with a qualified Lead Auditor who does this scoping for a living, and who will point you at the shortest route that holds up.

Book a free consultation →

We work with organisations across Australia on ISO 42001 AI management systems and ISO 27001 information security management systems, whether you want the system built end to end, an independent internal audit of something you have built yourself, or mentoring that keeps the work in your own team’s hands.

Sources

  • Office of the Australian Information Commissioner, Consultation on guidance for transparency in automated decision-making, and the Automated Decision-Making Issues Paper, 18 May 2026
  • Office of the Australian Information Commissioner, APP Guidelines, Chapter 1: APP 1
  • Allens, Automated decision-making transparency: what APP entities need to know about the APP 1 amendments, 10 June 2026
  • Johnson Winter Slattery, Practical implications of the new transparency requirements for automated decision making, 14 January 2025
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring

Filed Under: Articles Tagged With: #informationsecurity, #iso27001, #iso42001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire