All insights
AI security & compliance2 min read

Privacy Act reform and AI: preparing for automated decision transparency

What tightening Australian privacy expectations around automated decision-making mean for organisations already running AI in customer-facing processes.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory27 July 2026

The direction of travel

Australian privacy reform has moved steadily toward greater transparency about how personal information is used in automated decisions, alongside stronger expectations on fairness, retention and security.

For organisations running AI in customer or employee processes, the practical consequence is documentation. You need to be able to say which decisions involve automation, what information feeds them, and what a person can do about the outcome.

Start with the decisions, not the models

Work backwards from decisions that affect people: eligibility, pricing, prioritisation, screening, escalation, service refusal. For each one, establish whether an automated system contributes to the outcome and how heavily.

Many organisations discover automation in places they never classified as AI — scoring rules inside a CRM, a triage model inside a vendor platform, a ranking feature switched on by default.

Notice that actually informs

A privacy notice that mentions automation in a clause nobody reads will not satisfy a regulator or a complainant. Say plainly which kinds of decisions involve automated processing and what information is used.

Keep the notice consistent with the inventory. Divergence between what your policy claims and what your systems do is the failure mode that turns a complaint into a finding.

Make human oversight defensible

Human oversight only counts when the reviewer has the information, the authority and the time to reach a different conclusion. A queue of two hundred approvals per hour is not oversight.

Record what the reviewer saw, what they decided and how often they diverged from the automated recommendation. A divergence rate of zero over months is itself a finding.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

Data minimisation and retention

AI programmes tend to accumulate data because more data feels safer. Privacy obligations push the other way. Define what the system genuinely needs, exclude the rest, and set retention for prompts, outputs and logs the way you would for any other record.

Prompt and output logs frequently contain personal information nobody planned for. Classify and retain them accordingly.

What to do in the next quarter

Identify automated decisions affecting people, confirm the notice matches reality, evidence human oversight for the highest-impact ones, set retention on AI logs, and record vendor data-use and residency positions.

General information only — not legal advice. Confirm your specific obligations with your legal adviser and current OAIC guidance.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.