Privacy
Automated decision making privacy changes start with your suppliers
Oct 11, 20265 min read
Trent Smith Co-Founder, Contract Cloud In-house lawyer with more than 11 years' experience across commercial contracts, procurement, privacy and governance.
If your December privacy policy update depends on a supplier explaining what its software actually does, send the questions now.
For in-house Legal and Procurement teams, the difficult part will often be finding the facts. A supplier describes its product as a workflow tool. The business calls it decision support. Nobody has recorded which personal information it uses, what it recommends, or how much weight staff give the output.
Those gaps need attention before 10 December 2026.
What changes in December
The 2024 privacy amendments introduce additional privacy policy disclosures from 10 December 2026. Broadly, the new APP 1.7 applies where an entity covered by the Australian Privacy Principles (APPs) arranges computer-based decision-making or assistance substantially and directly connected to a decision, uses personal information about the affected individual in that process, and the decision could reasonably be expected to significantly affect that person's rights or interests.
APP 1.8 requires disclosure of the categories of personal information involved, the types of qualifying decisions made entirely by the program, and the types of qualifying decisions involving the relevant computer assistance. Existing arrangements are included for decisions made after commencement. Signing the supplier agreement years ago does not remove it from the review. See the amending Act, section 2 and Schedule 1, Part 15.
The existing obligation to maintain an understandable, current privacy policy already applies under APP 1.3. December adds specific disclosure requirements; it does not postpone today's privacy responsibilities.
Published guidance is now available
The OAIC released updated APP 1 Guidelines and supporting resources on 30 September 2026. Its earlier consultation opened in May and closed on 15 June. Teams working from the consultation paper should now review the published guidance. The guidance explains the regulator's approach; the legislation establishes the obligation. See the September announcement and consultation record.
Two points matter immediately. The OAIC interprets computer programs broadly, including rules-based processes. It also explains that human involvement does not automatically take a process outside scope. Outsourcing the software does not, by itself, remove the customer's disclosure responsibility. The updated APP 1 Guidelines address these issues at paragraphs 1.40–1.54.
Start with decisions the business makes
Asking every supplier whether it uses AI will produce an inconsistent collection of answers. Start internally with decisions affecting people, then identify the systems supporting them.
For each process, record:
- The decision and the people affected
- The business owner and relevant supplier
- The personal information used, including scores or other information generated about a person
- What the system produces and what staff actually do with it
- The potential consequences for the individual
- Where the supporting explanation and contract are kept
Ask the business to demonstrate one real workflow. A screen recording or walkthrough can reveal more than a completed questionnaire, particularly where the contracted service description predates the current configuration.
A shortlist can matter before anyone makes an offer
Consider a hypothetical employer covered by the APPs. Its recruitment platform processes 600 applications, scores experience and qualifications, and presents 40 candidates for interview. Recruiters usually work from that list. A manager still makes every hiring decision.
The supplier answers the questionnaire by saying that its software never makes an employment offer. That answer leaves the important question unresolved: what role did the ranking play in determining who progressed?
Legal should assess the actual screening process against the statutory test. Procurement should obtain a description of the scoring inputs, outputs and configured screening steps. The business should explain whether recruiters review excluded applicants and how they use the ranking.
Keep the supplier's technical explanation and the organisation's legal assessment separate. The supplier can explain its service. Your team needs to decide what your use of that service means.
Negotiate information rights you can use
A general promise to comply with privacy law may provide little help when the policy owner needs facts by Friday. For relevant services, consider negotiating these practical obligations:
- Service information. Require an accurate description of the deployed functionality, personal information categories, outputs and decision-related uses. Include relevant subcontracted components.
- Response times. Agree when the supplier must answer reasonable compliance questions, who receives them and how urgent requests are escalated. Avoid an open-ended assistance obligation with no delivery date.
- Change notices. Require advance notice of material changes affecting the information supplied, including new inputs, decision functions or subcontracted processing. Allow time to assess the change before deployment where commercially achievable.
- Publication permissions. Permit the customer to use appropriate high-level descriptions in privacy disclosures. Resolve confidentiality restrictions before the supplier labels the entire response confidential.
- Verification and remedies. Agree proportionate supporting evidence and a correction process. Consider suspension of the affected function or termination rights for material, unresolved failures where justified by the service risk.
These are suggested contract protections, not a statutory clause checklist. The OAIC's September fact sheet expects software providers to supply useful high-level information. Turn that expectation into a workable arrangement rather than assuming a broad warranty will produce it.
Give the next eight weeks named owners
Use October to identify relevant processes, request supplier information and locate gaps in existing agreements. Prioritise decisions with potentially significant consequences rather than the largest software invoices.
During November, assess scope, resolve missing information and draft descriptions that match actual operations. Privacy should own the disclosure assessment, Procurement the supplier response, and the business owner the accuracy of the workflow description.
Before 10 December, complete review and publication arrangements, retain the evidence supporting each assessment, and record unresolved issues with a decision owner. Where a supplier cannot explain a relevant function, escalate whether that function should continue operating in its current form.
Then make changes to these processes a trigger for further review. A policy based on October's configuration can become inaccurate after January's product update.
For a conversation with Contract Cloud about your team's contract management priorities, Book a Demo.
Sources
- Privacy and Other Legislation Amendment Act 2024 (Cth), assented to 10 December 2024. Section 2 and Schedule 1, Part 15. Amending Act.
- Privacy Act 1988 (Cth), compilation dated 4 June 2026. Schedule 1, APP 1.3. Current privacy policy obligation.
- OAIC, New resources on transparency for use of AI and automated decision-making, 30 September 2026. Publication announcement.
- OAIC, Consultation on Guidance for Transparency in Automated Decision Making, 18 May 2026; closed 15 June 2026. Consultation record.
- OAIC, Chapter 1 APP 1 Open and transparent management of personal information, updated 30 September 2026, paragraphs 1.35 to 1.54. APP 1 Guidelines.
- OAIC, APP 1.7 to 1.9 Transparency Obligation Fact Sheet, September 2026. Fact sheet.