What the Obligation Actually Is
The Privacy and Other Legislation Amendment Act 2024 inserted three new subclauses into Australian Privacy Principle 1 — APP 1.7, 1.8 and 1.9. They commence on 10 December 2026.
Stripped to its working parts, the requirement is this. If you are an APP entity, and you have a computer program that makes a decision, or does something substantially and directly related to making a decision, and personal information is used in that program, and the decision could reasonably be expected to significantly affect the rights or interests of an individual — then your privacy policy must set out:
| What must be disclosed | What that means in practice |
|---|---|
| The kinds of personal information used in the decisions | Categories, not a data dictionary. “Contact details, account identifiers, service history and call records” is the register this is pitched at |
| The kinds of decisions made by the program | Again categories. “Prioritisation of service requests” rather than a description of the algorithm |
Read the shape of it before the detail
This is a disclosure obligation attached to your privacy policy. It does not ban automated decisions. It does not require human review. It does not create an individual right to an explanation of a specific decision, and it does not require you to publish how the system works. Several 2026 commentaries have drifted toward describing something closer to the European position. That is not what commences in December. What commences is: say, in categories, in your policy, that this happens.
Two further points on scope, because they are where most of the confusion sits.
“Computer program” is not a synonym for AI. A deterministic rule written in 2014 is a computer program. A decision tree in your phone system is a computer program. A spreadsheet formula is a computer program. If a business assumes this obligation only reaches machine learning, it will audit the wrong half of its estate. Conversely, plenty of AI does not touch this obligation at all, because the decisions it makes are trivial.
“Substantially and directly related to making a decision” extends past the final call. A program that does not itself decide, but produces the score, ranking or classification that the decision then rests on, is caught. This is the limb that reaches a surprising amount of phone-system behaviour, because phone systems rarely make final decisions — they classify, route and prioritise, and a human at the end of the queue makes the decision. The drafting anticipated exactly that pattern.
The OAIC ran an issues paper consultation in the first half of 2026 to inform its guidance, and has signalled it intends to publish before the commencement date. Commentary on that consultation has consistently read the regulator as leaning toward a broad interpretation of the threshold rather than a narrow one. The practical consequence is not to wait. If guidance lands in the last quarter before commencement, a business that starts its inventory then is starting too late.
The Two Tests That Decide Everything
Everything below turns on two questions, applied to each automated step you can find.
Is personal information involved?
Information about an identified individual, or one reasonably identifiable. A phone number attached to a customer record is personal information. An anonymous count of calls per hour is not.
Could the decision significantly affect rights or interests?
The word doing the work is significantly. Inconvenience is not significance. Access to a service, money, a benefit, a legal position or an employment outcome generally is.
The second test is the one you will actually argue about internally, so it is worth setting a working standard before you start rather than deciding case by case, which produces inconsistency you cannot defend later.
A defensible working standard: the decision is significant if a reasonable person, told what happened, would want to know it had been automated. That is not a legal test and it does not appear in the Act. It is a triage heuristic, and it sorts the phone-system list below quickly and in roughly the right direction.
Where the heuristic will mislead you
It under-calls cumulative effects. One deprioritised call is trivial. A rule that systematically routes a class of customer to the longest queue every time they ring, for a year, is not trivial — it is differential access to your service, applied by a program, using personal information. Ask the question of the rule, not of the single call. That reframing changes the answer on at least one item for most businesses.
The Nine Decisions Your Phone System Makes
Here is what a modern cloud phone platform decides, without anyone thinking of it as decision-making. Most businesses recognise seven of the nine within a minute of reading the list, and are surprised by two.
| # | The automated step | What it uses |
|---|---|---|
| 1 | Identity-based routing — the caller's number is matched against your CRM and the call is sent to a specific team, owner or queue | Phone number, customer record, account history |
| 2 | Priority queueing — recognised customers, high-value accounts or particular segments are placed higher in the queue | Customer tier, spend, contract status |
| 3 | AI qualification — a voice agent asks why the caller is ringing and classifies the intent before a human is involved | What the caller says, plus whatever context the record supplies |
| 4 | Callback eligibility — the system offers a callback to some callers and not others, or estimates a wait and applies a threshold | Queue position, segment, sometimes account status |
| 5 | Screening and blocking — numbers are blocked, sent to a different path, or challenged | Number, prior call behaviour, risk flags |
| 6 | Out-of-hours and overflow logic — after a threshold, calls divert to voicemail, an AI agent, or an external service | Time, volume, sometimes caller attributes |
| 7 | Automated identity verification — the caller is authenticated by data or by voice before reaching an agent | Account data, and in some deployments voice characteristics |
| 8 | Sentiment and escalation flags — a model detects frustration and escalates, tags, or changes the routing | Audio and transcript of the individual's own words |
| 9 | AI scoring of the agent — calls are automatically scored for quality, compliance or performance | Employee identity, call content, performance history |
Nobody built any of these as an “automated decision-making system”. They were built as call routing, which is why they are missing from the inventories being compiled right now. The relevant question is not what the feature was called when it was purchased.
If you want the underlying picture of how much of this a current platform does by default, our guide to AI business phone systems covers the capability set, and which calls to automate covers where the line usually sits operationally. This article is about where the line sits legally, which is drawn in a different place.
Which of Them Are Actually in Scope
Now apply the two tests. The following is an assessment framework, not advice about your business, and the answer for any specific deployment depends on what the program actually does and who it does it to. But the pattern is stable enough to be useful.
| Step | Usual assessment | Why |
|---|---|---|
| Identity-based routing to the right team | ✗ Usually out | Sending a caller to the department that handles their product is administrative convenience. Nothing about their rights or interests turns on it |
| Priority queueing by customer value | ~ Borderline — assess it properly | One shorter wait is trivial. A standing rule that gives one class of customer materially faster access to a service they pay for, every time, is differential treatment produced by a program using personal information |
| AI qualification of intent | ~ Depends entirely on what follows | If it routes, out. If the classification determines whether the person gets an appointment, a hardship path, a quote or an escalation, it is substantially and directly related to a decision that matters |
| Callback eligibility | ✗ Usually out | A convenience feature, unless eligibility is tied to account standing in a way that withholds access from a class of people |
| Screening and blocking | ✓ Usually in | Automatically preventing an identified individual from reaching your business is close to the clearest example available. If a program decides someone cannot contact you, that affects their interests |
| Out-of-hours and overflow logic | ✗ Out | Time-of-day rules generally use no personal information at all. They fail the first test before you reach the second |
| Automated identity verification | ✓ Usually in | Passing or failing verification determines whether someone can access their own account and their own information. That is a rights-and-interests decision by any reading |
| Sentiment and escalation flags | ~ Borderline | Out if it only prompts a supervisor. Closer to in if the flag feeds a customer record, a risk register or a retention decision |
| AI scoring of the agent | ✓ In, and it is about your staff — see below | Automated performance assessment of an identified employee, where the output feeds coaching, ranking, remuneration or discipline |
The realistic outcome for most businesses
Six of the nine are out. Two or three are in, and they are almost always automated verification, automated blocking, and AI scoring of staff. That is a small enough set that the disclosure is a paragraph, not a project — provided you do the inventory rather than guessing. Businesses that guess tend to make one of two errors: disclosing nothing because “the phone system doesn't make decisions”, or disclosing everything in a defensive blanket statement that is uninformative and therefore does not do what the obligation asks.
The One About Your Own Staff
This is the finding that changes the meeting, so it is worth putting plainly.
AI call scoring assesses an identified employee, automatically, using personal information, and produces an output that affects their employment interests. If those scores inform coaching priority, performance review, ranking, roster allocation, incentive payments or termination, the decision is significant on any reasonable reading — considerably more significant than most of the customer-facing items above.
There is a genuine complication here, and it should be stated rather than smoothed over. The Privacy Act contains an employee records exemption for private sector employers in relation to acts and practices directly related to a current or former employment relationship and an employee record. Whether, and how far, that exemption reaches automated assessment of employees is not settled, and it has been squarely on the reform agenda for years without being resolved in the 2024 tranche.
What to do with an unsettled question
Do not build a compliance position that only works if the exemption is read broadly and stays that way. The cost of disclosing that you use automated call scoring is close to zero. The cost of being found not to have disclosed it — or of your staff discovering it in a way that feels concealed — is not. Tell your team what is scored, how, and what the score is used for. That is defensible under every reading of the exemption, it is what a fair-work-conscious employer would do anyway, and it is the position that survives if the exemption narrows later.
Worth separating two things that get conflated. Whether you may record the call is a different question with a different answer, governed principally by state and territory surveillance devices law — our call recording guide covers the jurisdictional detail. Whether you may automatically assess a person using that recording is this question. A business can be entirely correct on the first and have never considered the second. On the operational side, AI call scoring and quality assurance covers what scoring every call actually changes in a team, including the trust dynamics that make disclosure the practical choice as well as the safe one.
How to Write the Disclosure
Two failure modes dominate, and they are opposites.
Too vague to be information
“We may use automated systems to process personal information.” This tells a reader nothing about the kinds of information or the kinds of decisions, which is precisely what the subclauses ask for.
So detailed it becomes a liability
A four-page technical annex describing models and thresholds. It is not required, it is read by nobody, and it is now a document you must keep accurate through every vendor change.
The obligation asks for kinds. Categories of information, categories of decision. Here is the shape of a disclosure that meets it for a business whose in-scope items are the usual three — written as an illustration of structure, not as wording to copy without reviewing it against your own systems and your own advice.
Illustrative structure only — not legal advice
“Automated decisions. Some of our systems use personal information to make, or to help make, decisions about people. In our contact channels this includes: verifying your identity before we discuss your account, using information such as your contact details and account information; restricting contact from numbers we have identified as abusive or fraudulent, using call records and prior contact history; and assessing the quality and compliance of calls handled by our team members, using call recordings and transcripts together with employee information. You can ask us about any decision that affects you by contacting [privacy contact].”
Three properties make that work. It names the kinds of decisions in language a customer recognises. It names the kinds of information without becoming a schema. And it gives a contact point — not required by these subclauses, but it converts a legal disclosure into something a person can act on, which is the entire point of a transparency obligation and costs you nothing.
One drafting note. Write it so it survives a vendor change. “Voice characteristics analysed by our AI provider” obliges you to revisit the policy every time procurement moves. “Information you provide during the call, including recordings” does not, and is equally accurate.
Four Things This Obligation Is Not
Enough advisory content is circulating that it is worth clearing four misconceptions directly, because each one causes real wasted effort.
| The claim | The position |
|---|---|
| “You will need human review of every automated decision” | No. Human-in-the-loop is good practice and is often a sensible control. It is not what these subclauses require, and building a review workflow you do not need is the most expensive way to over-comply |
| “Individuals will be able to demand an explanation of a specific decision” | Not from this obligation. It requires policy-level disclosure of kinds. A separate access request may reach related personal information, but that is a different mechanism with different rules |
| “It only applies to AI” | No. It applies to computer programs. Deterministic rules count, and most businesses have far more rules than models |
| “Small businesses are exempt, so this is irrelevant to us” | Be careful. The small business exemption still exists as at writing, but it does not apply to a range of businesses regardless of turnover — including those providing a health service and holding health information, those trading in personal information, and those related to a larger entity. Many businesses that assume they are exempt are APP entities |
That last row deserves emphasis because it is where the largest number of businesses will get it wrong. A medical or allied health practice is an APP entity regardless of size — the practice phone systems guide covers what that means for a clinic's phones more generally. An aged care or NDIS provider holding health information is in the same position. If you are in one of those sectors and have been treating privacy obligations as something that applies to bigger organisations, this deadline is a good prompt to correct that assumption.
The Two-Hour Audit
You do not need a consultant to produce a defensible inventory of your phone system. You need your call flow diagram, whoever administers the platform, and two hours.
| Step | What to do | Time |
|---|---|---|
| 1 | Print or export every call flow, IVR menu and routing rule. Include the ones nobody has looked at since setup — those are where the surprising rules live | 20 min |
| 2 | Mark every point where the system branches based on who the caller is, as opposed to what they pressed or what time it is. Only the first category can be in scope | 30 min |
| 3 | For each marked branch, write one sentence: what information it uses, and what happens differently to the caller as a result | 30 min |
| 4 | Apply the second test to each — could this reasonably be expected to significantly affect their rights or interests? Ask it of the rule, not the single call | 20 min |
| 5 | Separately, list every automated assessment applied to staff: scoring, ranking, adherence, sentiment. These are usually invisible in a call flow diagram | 10 min |
| 6 | Hand the marked list to whoever owns your privacy policy, with the one-sentence descriptions. They do not need to understand telephony, and now they do not have to | 10 min |
The step people skip, and shouldn't
Step 5. Customer-facing automation is visible and gets audited. Automated assessment of employees is configured once, in a supervisor console, and then never appears in any diagram anyone reviews. If your audit finds nothing about staff, that is a sign the audit missed something rather than evidence there is nothing there — ask the person who runs quality assurance directly.
Keep the output. Not because you must file it anywhere, but because the first question anyone asks in eighteen months is “how did we reach that position?” A one-page table with a date on it answers that. Reconstructing the reasoning from memory does not.
A Plan That Finishes Before December
There are roughly four months between now and commencement, and the OAIC guidance is expected inside that window. The sequence below is ordered so that guidance, whenever it arrives, refines your position rather than starting it.
| When | What | Who |
|---|---|---|
| August | Run the two-hour audit on the phone system. Run the equivalent on your CRM, website forms and any scoring or segmentation tool. Confirm whether you are actually an APP entity rather than assuming | Ops + whoever administers each system |
| September | Draft the disclosure from the inventory. Review the OAIC guidance if it has published; adjust rather than rewrite. Decide your position on the employee scoring question and write it down | Privacy owner + legal |
| October | Tell your staff what is automatically assessed and what it is used for, before the policy says it publicly. Hearing it first from a website is a bad way for a team to learn it | Managers |
| November | Publish the updated privacy policy. Brief the people who answer the phone so they can respond to a question about it rather than transferring the caller | Marketing + team leads |
| December | Commencement on the 10th. Diarise a review for each material change to your call flows or AI features thereafter | Privacy owner |
The October row is the one that gets dropped under time pressure and is the one most likely to cause an actual problem. A team that learns from a customer that their calls are being scored by a model draws conclusions about what else they have not been told, and that is far more expensive to repair than it would have been to say in the first place.
10 Dec
2026 commencement
1.7–1.9
The new APP 1 subclauses
2 hrs
To inventory a phone system
~2–3
Items typically in scope
One closing thought about why this is worth doing properly rather than minimally. The businesses that will handle this deadline well are the ones that already know what their systems do. The audit is the valuable part; the paragraph in the privacy policy is a by-product. A great many organisations are about to discover routing rules written years ago by someone who has left, doing things nobody currently intends. That is worth finding for its own sake — and this is a good excuse to go looking.
This is general information, not legal advice, and it does not account for your circumstances. For how the automation itself should be designed once you know what it does, AI voice agents: cost and ROI and can a small business use AI are the practical companions to this piece.