APP 1.7 · Privacy Act · Melbourne

Automated decision-making and the Privacy Act: are you ready for 10 December?

AI that does the paperwork and leaves the decisions with your team. Lumeio finds every system in your business that touches decisions about people, so your privacy lawyer can tell you what to disclose before 10 December 2026.

Check your ADM exposure

Find out what you need to disclose before 10 December

Already know you’re covered? Book a Pain Point Audit

Lumeio maps the systems. A privacy lawyer writes the policy. This page is general information, not legal advice.

From 10 December 2026, Australian businesses covered by the Privacy Act must describe in their privacy policy when they use personal information in automated decisions that could significantly affect people, including software that only does part of the work. Lumeio lists every system that touches those decisions, rates each one for risk and gives your privacy lawyer a brief to update your policy from.

What is changing

What APP 1.7 changes on 10 December 2026

From 10 December 2026, a new Australian Privacy Principle, APP 1.7, requires Privacy Act entities that use personal information in automated decisions that could significantly affect people to describe this in that policy.

What counts as a decision about people

Think of anything that decides, or helps decide, what happens to a particular person: whether they get a shift, a job interview, a service, a payment, an approval or a place in the queue.

Why “substantially and directly related” catches more than you’d expect

The rule is not limited to decisions a computer makes on its own. It also covers software that does something substantially and directly related to a decision. So a tool that scores, ranks, filters or flags people can be in scope even when a person makes the final call. Most owners, asked about “automated decisions”, think of nothing. Asked about their rostering tool, they think again.

  • Rostering software that suggests who works which shift, based on availability, skills or past hours.
  • Recruitment screening that ranks applicants or filters out CVs before anyone reads them.
  • Eligibility, credit or claims checks that approve, decline or flag an application for review.
  • Triage or intake tools that score urgency and decide whose request is handled first.

None of these are unusual. That’s the point. Whether each one is caught is a question for your lawyer, and they can only answer it if someone has written the list.

A person flipping through a printed application beside a laptop, the kind of file an automated decision-making review traces
The review starts with the paperwork: which systems touch decisions about people, and how.

Scope

Does this apply to you?

It is worth checking if all three of these are true:

  • Your annual turnover is above $3M. Businesses with turnover of $3M or less are generally exempt from the Privacy Act.
  • You use personal information about customers, clients, residents, staff or job applicants.
  • Software contributes to decisions that could significantly affect those people, even if a person signs off at the end.

Near the $3M line, recently over it, or unsure whether the general exemption covers you? Confirm with your lawyer before assuming you’re out of scope.

The ADM readiness review

What Lumeio does

We map how decisions about people actually get made in your business, system by system. You get five things.

01

A list of every system

Every system that touches decisions about people, including the spreadsheet, the add-on and the vendor tool nobody thinks of as software.

02

A risk rating for each

A plain rating of how closely each system is tied to decisions that could significantly affect someone, so your lawyer knows where to look first.

03

A brief for your lawyer

A privacy policy brief your lawyer can work from: the personal information each system uses and the kind of decision it touches.

04

Where the data lives

Where each system’s data is stored and which models, AI or otherwise, touch it.

05

Where a person steps in

The point where a person reviews or overrides each decision, or a clear note that nobody currently does.

The split

What Lumeio does not do

  • Write your privacy policy
  • Give legal advice
  • Certify that you comply

We’re not lawyers. We work out what your systems actually do. Your lawyer decides what that means and what goes in the policy.

How it works

How the automated decision making Privacy Act review works

  1. 5 minutes

    Short exposure check

    Answer six questions below. You’ll see whether the rule is likely to be relevant to you.

  2. Inside the audit

    ADM readiness review

    We map your systems during the Pain Point Audit, alongside the rest of your processes, and include the findings in your written report.

  3. Your lawyer

    Brief handed to your lawyer

    Your privacy lawyer gets a clear brief to update your policy from, instead of starting with a blank page and a lot of questions.

Price

What it costs

A$750 + GST

A fixed-price add-on to the Pain Point Audit.

Included free in Pain Point Audits booked before 10 December 2026.

One fixed price, agreed before we start. No hourly extras.

Self-check

Check your ADM exposure

Six questions, about five minutes. Nothing you select here is sent to us or stored.

1. What is your business’s annual turnover?
2. Do you collect or use personal information about customers, clients, residents, staff or job applicants?
3. Does any software decide something about a person on its own? For example, automatically declining an application or assigning a shift.
4. Does any software score, rank, filter or flag people, even if a person makes the final call? For example, ranking job applicants, scoring urgency or flagging a claim for review.
5. Could those decisions significantly affect someone? For example, their work, income, access to a service, care or money.
6. Do you have a written list of which systems do this and where their data goes?

This result is indicative only and is not legal advice. It doesn’t tell you whether you comply. Your privacy lawyer can.

Human in the loop

A person signs off every decision that matters

When Lumeio builds a system, the software reads, sorts and drafts. A named person approves, rejects or overrides anything that affects someone, and the system records who did it and when. Anything the system can’t validate goes to a person instead of being guessed.

That design makes disclosure simpler. Your privacy policy can say exactly what the software does and where a person takes over, and your customers, staff and residents can see that a person is accountable. Here’s what proper human oversight looks like.

What you get

What an ADM register looks like

An illustrative extract, with made-up systems. Your register lists your own systems and goes into the brief for your lawyer.

Sample ADM register, dummy data for illustration only
SystemDecision it touchesPersonal informationWhere a person steps inRisk
Rostering appSuggests who is offered each shiftAvailability, qualifications, hours workedRoster manager approves the weekly rosterMedium
Job board screening add-onRanks applicants and hides low scorersCVs, answers to screening questionsNone for hidden applicantsHigh
Intake spreadsheet with formulasScores urgency of new service requestsContact details, needs, notesCoordinator reviews top of queue dailyMedium
Accounting software remindersSends automatic overdue noticesName, invoice historyAccounts team handles repliesLow

About the author

Ju-mei Lin

Founder, Lumeio

Ju-mei Lin founded Lumeio after a career in engineering and the building industry, including a role as Engineering Manager at a building surveying firm. That background is why Lumeio maps how work is actually done before recommending anything, and why every system it builds leaves accountable decisions with a person.

FAQ

Questions about automated decision-making and APP 1.7

Does the new automated decision-making rule apply to my business?

It applies to organisations covered by the Privacy Act that use personal information in automated decisions that could significantly affect people. Businesses with annual turnover of $3M or less are generally exempt. If your turnover is above $3M and software helps decide things like shifts, job applications, eligibility, claims or priority, it is worth checking. If you are near the threshold or unsure whether you are covered, confirm with your lawyer.

What counts as an automated decision under APP 1.7?

It is not limited to decisions a computer makes on its own. From 10 December 2026 it also covers software that does something substantially and directly related to a decision, such as scoring, ranking, filtering or flagging people, where that decision could significantly affect them. A person making the final call does not by itself take the system out of scope. Your lawyer decides how the definition applies to each of your systems.

We only use off-the-shelf software. Are we covered?

Using off-the-shelf software doesn’t take you out of scope on its own. The rule is about how your business uses personal information in decisions, whoever built the software, so a rostering, recruitment or triage tool you subscribe to can still be part of a decision about a person. Your lawyer can confirm how it applies to your setup. The review lists these tools alongside anything built in-house, so your lawyer sees the whole picture.

What happens if we do nothing?

From 10 December 2026, the rule requires covered businesses to describe this use of automated decisions in their privacy policy, so a policy that leaves it out would not meet it. Lumeio does not advise on enforcement or penalties. Ask your privacy lawyer what it would mean for your business.

Do you write our privacy policy?

No. Lumeio maps the systems and a privacy lawyer writes the policy. We give your lawyer a brief listing each system, the personal information it uses, the decision it touches, where a person reviews it and where the data lives. We do not give legal advice or certify compliance.

How long does the ADM readiness review take?

It runs inside the Pain Point Audit. We cover your systems in the same half-day session, and the findings arrive in the same written report, within 5 business days. The exposure check on this page takes about 5 minutes.

What does the ADM readiness review cost?

It is a fixed-price add-on to the Pain Point Audit at A$750 + GST. It is included free in Pain Point Audits booked before 10 December 2026.

How is this different from a general AI audit?

A general AI audit looks for places to use AI. The ADM readiness review looks at software you already use, AI or not, and asks one question of each system: does it touch decisions about people? The output is a register and a brief for your lawyer, not a list of new tools to buy.

Book

Book your review

The ADM readiness review is booked as part of a Pain Point Audit. Tell us about your business and the systems you use that affect people, and we’ll come back to you with times.

Book a Pain Point Audit

Mention ADM in the form and we’ll include the review.

Know what your systems decide before 10 December

Five minutes to check your exposure. One review to map your systems. A brief your lawyer can work from.

Sources and further reading

This page is general information, not legal advice. Lumeio maps systems and does not give legal advice or certify compliance. Speak to a privacy lawyer about your obligations.