AI Governance7 min read

The OAIC's Automated Decision Making Guidance Is Landing. Here Is Your Countdown to 10 December

The Privacy Act's ADM transparency obligation commences 10 December. Here is your practical countdown as OAIC guidance lands this month.

Shane CoetserBy Shane Coetser
Automated Decision Making Privacy Act Countdown: What OAIC Guidance Means Before 10 December

Ten December is now less than three months away, and it is the date the Privacy Act's new automated decision making transparency obligation actually commences. The Office of the Australian Information Commissioner has been consulting on guidance since May, that consultation closed in June, and formal guidance is expected this month. For any organisation using personal information in automated decisions that could affect a person's rights or interests, this is no longer a future compliance project to plan for eventually. It is a countdown with a fixed, legislated end date.

The obligation itself is not new news, it has been on the books since the amendment passed. What changes now is that the vague part, exactly what the guidance will actually require organisations to disclose, is about to become concrete. Organisations that have been waiting for the guidance before starting preparation have a considerably shorter runway than those who started building their ADM documentation against the underlying legislative requirement months ago.

What the Obligation Actually Requires

From 10 December, APP entities using personal information in automated decision making that could affect a person's rights or interests must include specific information in their privacy policies, covering the kinds of personal information used in that automated decision making and the kinds of decisions actually made using it. This is a transparency obligation, not a substantive restriction on automated decision making itself. Organisations are not being told to stop making automated decisions. They are being told they must be specific and honest, in a document already legally required to exist, about how those decisions are made.

Why "Which Decisions Count" Is the Practical Problem

The genuinely difficult part of compliance is rarely the disclosure itself, it is identifying, accurately and completely, which of an organisation's actual systems and processes constitute automated decision making that affects rights or interests in the first place. Credit scoring and loan approval are obvious candidates. Automated content moderation, algorithmic pricing, automated eligibility screening for services, and AI-assisted triage in customer service are less obviously captured but plausibly within scope depending on how directly the automated output determines the outcome for the person involved. Organisations that have not yet mapped their systems against this question are the ones most likely to be caught short in December.

What the OAIC's Guidance Should Clarify

The Issues Paper process suggests the OAIC is aware that "kinds of personal information" and "kinds of decisions" are open to interpretation, and the guidance expected this month should narrow that ambiguity considerably. Organisations should treat the guidance's arrival as the trigger to finalise, not begin, their ADM mapping and privacy policy updates. Waiting for the guidance to start the underlying identification work leaves a genuinely tight window between guidance publication and the 10 December commencement date.

The Practical Countdown Checklist

With roughly eleven weeks between now and commencement, the realistic sequence is: identify every system or process that could plausibly constitute automated decision making affecting rights or interests, document what personal information feeds into each one and what kind of decision it produces, draft the specific privacy policy language once the OAIC's guidance clarifies expected detail and format, and confirm the updated privacy policy is published and accessible before 10 December. Organisations starting this sequence now have a comfortable runway. Organisations waiting for the guidance to begin do not.

What This Means for Your Organisation

What we see across the organisations we work with is that the identification step, working out which systems actually constitute automated decision making under the Act, consistently takes longer than the actual privacy policy drafting once that mapping is done. Organisations that have not started this work yet should treat the OAIC's guidance landing this month as the last reasonable trigger to begin, not a reason to keep waiting for more certainty before starting.

Key Takeaways

  • The Privacy Act's automated decision making transparency obligation commences 10 December, requiring APP entities to disclose in their privacy policies the kinds of personal information used and kinds of decisions made through ADM affecting rights or interests.
  • The OAIC's guidance, following a consultation that closed in June, is expected this month and should clarify the ambiguity around exactly what counts as ADM under the obligation.
  • Identifying which of an organisation's actual systems constitute in-scope automated decision making is typically the hardest and longest part of compliance, not the privacy policy drafting itself.
  • With roughly eleven weeks remaining, organisations that have not started mapping their ADM systems against the obligation have a genuinely tight window to be ready by 10 December.

How Trusenta Can Help

AI Governance Foundations maps an organisation's systems against the automated decision making obligation and identifies which processes are actually in scope before the OAIC's guidance narrows the remaining ambiguity.

Compliance Management tracks the practical countdown to 10 December against an organisation's actual privacy policy update and documentation progress.

Risk Management flags where existing automated systems, credit scoring, eligibility screening, algorithmic pricing, may fall inside the ADM obligation's scope without having been assessed for it previously.

Conclusion

Ten December is a fixed date, not a moving target, and the OAIC's guidance landing this month removes the last major source of genuine ambiguity about what compliance actually requires. Organisations that treat this month's guidance as the starting gun rather than the finish line will have a comfortable runway. Organisations that have been waiting for certainty before doing any preparation are about to find out how little time that certainty actually leaves them.

Shane Coetser

Written by

Shane Coetser

With over 30 years of experience delivering real technology outcomes, he combines strategic insight with deep technical expertise across enterprise, cloud and AI. At Trusenta, he helps organisations move beyond AI hype to accountable, sustainable impact.

Connect on LinkedIn

Ready to transform your AI strategy?

Partner with Australia's AI strategy and governance specialists. From adoption roadmaps to ISO 42001 audit readiness.