At a glance: An ADM transparency statement is the new section of your privacy policy that discloses how your organisation uses computer programs — including AI — to make decisions that use personal information and could significantly affect people. Australia’s Privacy and Other Legislation Amendment Act 2024 added this obligation to the Privacy Act, and it applies to APP entities from 10 December 2026. Sales and marketing teams that automate lead scoring, eligibility screening or offer decisions should start their inventory now.
This article is general information for business teams, not legal advice. Before you publish or rely on a privacy policy update, have it reviewed by a qualified privacy lawyer.
What the new obligation actually says
The Privacy and Other Legislation Amendment Act 2024 (No. 128 of 2024) received Royal Assent on 10 December 2024. Schedule 1, Part 15 — “Automated decisions and privacy policies” — amends Australian Privacy Principle 1 (APP 1), the principle covering open and transparent management of personal information. The automated decision-making (ADM) amendments commence on 10 December 2026, two years after assent.
According to the OAIC’s ADM Issues Paper (May 2026), the obligation is triggered when three criteria are all met:
- the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; and
- the decision could reasonably be expected to significantly affect the rights or interests of an individual; and
- personal information about the individual is used in the operation of the computer program.
Where those criteria are met, the privacy policy must disclose three things: the kinds of personal information used in the operation of such computer programs, the kinds of decisions made solely by those programs, and the kinds of decisions where the program does a thing substantially and directly related to making the decision. The OAIC also notes that “making a decision” includes refusing or failing to make one, and that a decision is captured whether the individual is affected adversely or beneficially.
Two points worth stressing. First, this is a transparency obligation, not a prohibition — the Act requires you to describe automated decisions, not stop making them. Second, “computer program” is broad: law firm Norton Rose Fulbright notes in its client update on the consultation that the OAIC reads the term expansively to cover pre-programmed rule-based processes as well as artificial intelligence and machine learning — so a hard-coded scoring formula can be captured just as an LLM can.
Where OAIC guidance stands (as at late July 2026)
The OAIC has not yet published final guidance. On 18 May 2026 it opened a public consultation with an Issues Paper; submissions closed on 15 June 2026, and the OAIC states in its Issues Paper that it intends to release guidance by September 2026, ahead of commencement. The Issues Paper openly asks how key phrases should be interpreted — “substantially and directly related”, “significantly affect the rights or interests”, even “arranged for” — and works through fictional edge cases such as differential pricing, discriminatory targeted job ads and generative AI with human oversight.
The honest position, then, is that the core mechanics are settled in the Act, but the boundary lines are not. Build your programme so that a September course-correction is cheap: keep your inventory in a living document, and draft disclosures you can amend without a full legal review cycle.
Why sales and marketing teams are in scope
Most commentary on the ADM obligation focuses on credit, insurance and government services. But revenue teams run plenty of automated decisions over personal information: lead scoring decides who gets a call and who never hears back; eligibility rules decide who is offered a discount or payment plan; AI agents decide how and when to contact someone. Whether each of these “significantly affects rights or interests” is exactly what the OAIC’s consultation examined and its forthcoming guidance is expected to settle — so the sensible move is to inventory them all and assess each one, rather than assume marketing automation is out of scope. This sits alongside the obligations you already manage; our guide to AI outreach compliance covers the spam and telemarketing side of the same coin.
| Automated decision common in sales/marketing | Personal information typically used | Disclosure question to assess |
|---|---|---|
| Lead scoring and qualification (who gets contacted, who is dropped) | Contact details, job title, company, behavioural and engagement data | Does being deprioritised significantly affect the individual’s interests? Often arguable — assess and document. |
| Automated pricing, discount or payment-plan offers | Purchase history, location, inferred willingness to pay | Differential pricing is an edge case the OAIC itself examines — treat as likely in scope pending guidance. |
| Eligibility or credit-style screening before an offer | Financial details, identity data, third-party enrichment data | Decisions affecting access to significant services or contractual rights are squarely the target — likely in scope. |
| AI agent conversation routing and follow-up cadence | Contact details, conversation history, stated preferences | Usually operational rather than “significant” — but document the reasoning, especially where an agent can decline service. |
| Audience selection and ad targeting | Demographics, interests, lookalike model outputs | Targeting that gates access to opportunities (e.g. job ads) is an OAIC edge case — assess for exclusionary effects. |
A practical four-step process
Step 1: Inventory your automated decisions
List every point in your funnel where software makes or substantially shapes a decision about a person. For each entry, capture: the decision, which system makes it (including third-party tools — Johnson Winter Slattery’s practical guide recommends mapping technology and data flows first for exactly this reason), what personal information feeds it, whether a human reviews the output, and what happens to the person on each branch. Do not forget embedded AI inside your CRM, ad platforms and enrichment tools: the obligation covers programs you have “arranged for”, not just software you built.
Step 2: Assess significance
For each inventoried decision, ask whether it could reasonably be expected to significantly affect a person’s rights or interests. The Act provides examples of captured decisions — JWS highlights decisions affecting contractual rights, access to significant services, and benefits under legislation. A follow-up email cadence probably is not significant; refusing someone a payment plan, declining to serve them, or pricing them differently very well might be. Record your reasoning either way, and remember both limbs: decisions made solely by a program, and decisions where a program does something substantially and directly related — a model that shortlists people for a human still counts under the second limb if the other criteria are met.
Step 3: Draft the disclosure in plain English
The statute asks for “kinds” of information and “kinds” of decisions — categories, not a system-by-system technical annex. JWS suggests a clear, succinct approach that avoids over-disclosure. As an illustrative outline (not legal drafting), an ADM section of a privacy policy typically covers:
- What we automate: the kinds of decisions made solely by computer programs, in plain terms (e.g. “whether to offer particular pricing or payment options”).
- Where automation assists: the kinds of decisions where a program does something substantially and directly related to a decision a person finalises.
- What information is used: the kinds of personal information those programs use (e.g. contact details, transaction history, engagement data).
- Human oversight and contact: not strictly required by APP 1, but stating how a person can reach a human or query an outcome is widely regarded as good practice.
Write it the way you would explain it to a customer on the phone. The OAIC’s research, reported in its Issues Paper, found 89% of Australians believe they should have the right to know when their personal information is used in ADM that could affect them — disclosure only builds trust if a reader can understand it.
Step 4: Set a review cadence
Your automation stack changes faster than your privacy policy. Put a standing quarterly review in the calendar: new tools, changed models, newly automated decisions, and whether the disclosure still matches reality. Assign an owner — usually whoever owns the privacy policy, with a named counterpart in revenue operations who knows what the stack actually does. When the OAIC’s final guidance lands, schedule an immediate gap review against it.
A sensible timeline before 10 December 2026
August 2026: complete the inventory and significance assessment; chase vendors for details of embedded AI. September–October 2026: review the OAIC’s final guidance when released, adjust scope calls, and draft the disclosure. November 2026: legal review, sign-off and publication, leaving buffer before commencement. Non-compliance is not theoretical: JWS notes that a privacy policy which fails the new requirements can attract the OAIC’s compliance-notice and infringement-notice powers, available since December 2024.
Teams evaluating AI sales platforms can make this easier at procurement time. Knowing where models run and what data they touch is half the inventory work — the reasoning in our companion piece on AI data sovereignty for Australian businesses applies directly, since a privately deployed model on your own infrastructure gives you a much cleaner answer to “what personal information is used in the operation of the program”. Likewise, keeping a person in the approval loop for consequential outcomes — the pattern we describe in human-in-the-loop AI sales agents — does not remove the disclosure obligation on its own, but it changes which limb of the obligation applies and makes your statement easier to write honestly.
Frequently asked questions
What is an ADM transparency statement?
It is the section of an organisation’s privacy policy that discloses its use of automated decision-making: the kinds of personal information used by the relevant computer programs, the kinds of decisions those programs make solely, and the kinds of decisions where a program does something substantially and directly related to the decision. The requirement was added to Australian Privacy Principle 1 by the Privacy and Other Legislation Amendment Act 2024.
When does the ADM transparency obligation start?
10 December 2026. The OAIC states on its consultation page that from 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.
Is the OAIC’s guidance on the ADM obligation final?
No. As at late July 2026, the OAIC has published an Issues Paper and run a public consultation (18 May to 15 June 2026), and it intends to release guidance by September 2026, before commencement. Key terms such as “significantly affect the rights or interests” are still being worked through, so scope judgements made now should be revisited when the final guidance is published.
Does lead scoring or marketing automation trigger the disclosure requirement?
It depends on whether the decision could reasonably be expected to significantly affect a person’s rights or interests — a threshold the OAIC is still settling in guidance due by September 2026. Routine cadence and routing decisions are unlikely to qualify; automated decisions about pricing, eligibility or access to a significant service are much more likely to. The prudent approach is to inventory every automated decision, assess each against the three statutory criteria, and document the reasoning.
Do we need consent for automated decisions, or just disclosure?
The new Part 15 obligation is a transparency requirement: it requires disclosure in your privacy policy, not a new consent step and not a right to opt out of automated processing. Your existing Privacy Act obligations around collection, use and direct marketing continue to apply alongside it, as do spam and telemarketing rules.
If you are choosing an AI sales platform with the December 2026 deadline in view, it helps to work with one built for auditability — private model deployment on your own infrastructure, CRM integrations that keep data flows mappable, and human-in-the-loop guardrails through a structured Discover/Deploy/Scale process. Zian AI partners with a limited number of teams at a time; if that is the kind of foundation you want under your ADM statement, Apply For Partnership and tell us about your funnel.
Reminder: this is general information, not legal advice. The Act and OAIC materials linked above are authoritative.