APP 1.7 · Privacy Act · Melbourne
Automated decision-making and the Privacy Act: are you ready for 10 December?
AI that does the paperwork and leaves the decisions with your team. Lumeio finds every system in your business that touches decisions about people, so your privacy lawyer can tell you what to disclose before 10 December 2026.
Find out what you need to disclose before 10 December
Already know you’re covered? Book a Pain Point Audit
Lumeio maps the systems. A privacy lawyer writes the policy. This page is general information, not legal advice.
From 10 December 2026, Australian businesses covered by the Privacy Act must describe in their privacy policy when they use personal information in automated decisions that could significantly affect people, including software that only does part of the work. Lumeio lists every system that touches those decisions, rates each one for risk and gives your privacy lawyer a brief to update your policy from.
What is changing
What APP 1.7 changes on 10 December 2026
From 10 December 2026, a new Australian Privacy Principle, APP 1.7, requires Privacy Act entities that use personal information in automated decisions that could significantly affect people to describe this in that policy.
What counts as a decision about people
Think of anything that decides, or helps decide, what happens to a particular person: whether they get a shift, a job interview, a service, a payment, an approval or a place in the queue.
Why “substantially and directly related” catches more than you’d expect
The rule is not limited to decisions a computer makes on its own. It also covers software that does something substantially and directly related to a decision. So a tool that scores, ranks, filters or flags people can be in scope even when a person makes the final call. Most owners, asked about “automated decisions”, think of nothing. Asked about their rostering tool, they think again.
- Rostering software that suggests who works which shift, based on availability, skills or past hours.
- Recruitment screening that ranks applicants or filters out CVs before anyone reads them.
- Eligibility, credit or claims checks that approve, decline or flag an application for review.
- Triage or intake tools that score urgency and decide whose request is handled first.
None of these are unusual. That’s the point. Whether each one is caught is a question for your lawyer, and they can only answer it if someone has written the list.

Scope
Does this apply to you?
It is worth checking if all three of these are true:
- Your annual turnover is above $3M. Businesses with turnover of $3M or less are generally exempt from the Privacy Act.
- You use personal information about customers, clients, residents, staff or job applicants.
- Software contributes to decisions that could significantly affect those people, even if a person signs off at the end.
Near the $3M line, recently over it, or unsure whether the general exemption covers you? Confirm with your lawyer before assuming you’re out of scope.
The ADM readiness review
What Lumeio does
We map how decisions about people actually get made in your business, system by system. You get five things.
A list of every system
Every system that touches decisions about people, including the spreadsheet, the add-on and the vendor tool nobody thinks of as software.
A risk rating for each
A plain rating of how closely each system is tied to decisions that could significantly affect someone, so your lawyer knows where to look first.
A brief for your lawyer
A privacy policy brief your lawyer can work from: the personal information each system uses and the kind of decision it touches.
Where the data lives
Where each system’s data is stored and which models, AI or otherwise, touch it.
Where a person steps in
The point where a person reviews or overrides each decision, or a clear note that nobody currently does.
The split
What Lumeio does not do
- Write your privacy policy
- Give legal advice
- Certify that you comply
We’re not lawyers. We work out what your systems actually do. Your lawyer decides what that means and what goes in the policy.
How it works
How the automated decision making Privacy Act review works
- 5 minutes
Short exposure check
Answer six questions below. You’ll see whether the rule is likely to be relevant to you.
- Inside the audit
ADM readiness review
We map your systems during the Pain Point Audit, alongside the rest of your processes, and include the findings in your written report.
- Your lawyer
Brief handed to your lawyer
Your privacy lawyer gets a clear brief to update your policy from, instead of starting with a blank page and a lot of questions.
Price
What it costs
A$750 + GST
A fixed-price add-on to the Pain Point Audit.
Included free in Pain Point Audits booked before 10 December 2026.
One fixed price, agreed before we start. No hourly extras.
Self-check
Check your ADM exposure
Six questions, about five minutes. Nothing you select here is sent to us or stored.
Please answer all six questions.
This result is indicative only and is not legal advice. It doesn’t tell you whether you comply. Your privacy lawyer can.
Prefer to work through it yourself first? Use our Privacy Act ADM checklist: 12 steps, tickable and printable.
Human in the loop
A person signs off every decision that matters
When Lumeio builds a system, the software reads, sorts and drafts. A named person approves, rejects or overrides anything that affects someone, and the system records who did it and when. Anything the system can’t validate goes to a person instead of being guessed.
That design makes disclosure simpler. Your privacy policy can say exactly what the software does and where a person takes over, and your customers, staff and residents can see that a person is accountable. Here’s what proper human oversight looks like.
What you get
What an ADM register looks like
An illustrative extract, with made-up systems. Your register lists your own systems and goes into the brief for your lawyer.
| System | Decision it touches | Personal information | Where a person steps in | Risk |
|---|---|---|---|---|
| Rostering app | Suggests who is offered each shift | Availability, qualifications, hours worked | Roster manager approves the weekly roster | Medium |
| Job board screening add-on | Ranks applicants and hides low scorers | CVs, answers to screening questions | None for hidden applicants | High |
| Intake spreadsheet with formulas | Scores urgency of new service requests | Contact details, needs, notes | Coordinator reviews top of queue daily | Medium |
| Accounting software reminders | Sends automatic overdue notices | Name, invoice history | Accounts team handles replies | Low |
About the author
FAQ
Questions about automated decision-making and APP 1.7
Does the new automated decision-making rule apply to my business?
It applies to organisations covered by the Privacy Act that use personal information in automated decisions that could significantly affect people. Businesses with annual turnover of $3M or less are generally exempt. If your turnover is above $3M and software helps decide things like shifts, job applications, eligibility, claims or priority, it is worth checking. If you are near the threshold or unsure whether you are covered, confirm with your lawyer.
What counts as an automated decision under APP 1.7?
It is not limited to decisions a computer makes on its own. From 10 December 2026 it also covers software that does something substantially and directly related to a decision, such as scoring, ranking, filtering or flagging people, where that decision could significantly affect them. A person making the final call does not by itself take the system out of scope. Your lawyer decides how the definition applies to each of your systems.
We only use off-the-shelf software. Are we covered?
Using off-the-shelf software doesn’t take you out of scope on its own. The rule is about how your business uses personal information in decisions, whoever built the software, so a rostering, recruitment or triage tool you subscribe to can still be part of a decision about a person. Your lawyer can confirm how it applies to your setup. The review lists these tools alongside anything built in-house, so your lawyer sees the whole picture.
What happens if we do nothing?
From 10 December 2026, the rule requires covered businesses to describe this use of automated decisions in their privacy policy, so a policy that leaves it out would not meet it. Lumeio does not advise on enforcement or penalties. Ask your privacy lawyer what it would mean for your business.
Do you write our privacy policy?
No. Lumeio maps the systems and a privacy lawyer writes the policy. We give your lawyer a brief listing each system, the personal information it uses, the decision it touches, where a person reviews it and where the data lives. We do not give legal advice or certify compliance.
How long does the ADM readiness review take?
It runs inside the Pain Point Audit. We cover your systems in the same half-day session, and the findings arrive in the same written report, within 5 business days. The exposure check on this page takes about 5 minutes.
What does the ADM readiness review cost?
It is a fixed-price add-on to the Pain Point Audit at A$750 + GST. It is included free in Pain Point Audits booked before 10 December 2026.
How is this different from a general AI audit?
A general AI audit looks for places to use AI. The ADM readiness review looks at software you already use, AI or not, and asks one question of each system: does it touch decisions about people? The output is a register and a brief for your lawyer, not a list of new tools to buy.
Book
Book your review
The ADM readiness review is booked as part of a Pain Point Audit. Tell us about your business and the systems you use that affect people, and we’ll come back to you with times.
Mention ADM in the form and we’ll include the review.
Know what your systems decide before 10 December
Five minutes to check your exposure. One review to map your systems. A brief your lawyer can work from.
Sources and further reading
- OAIC: new resources on transparency for AI and automated decision-making
- Cowell Clarke: what the new obligations surrounding automated decision-making mean for APP entities
- Sprintlaw: automated decision-making privacy rules
This page is general information, not legal advice. Lumeio maps systems and does not give legal advice or certify compliance. Speak to a privacy lawyer about your obligations.