Which of your systems are caught by 10 December?
From 10 December 2026, Australian Privacy Principle 1 requires APP entities to describe their automated decision-making in their privacy policy. You cannot disclose what you have not found. This worksheet is the finding part — the three-limb test, a way to inventory your systems, and a model policy section to adapt. Free, no sign-up.
The three-limb test
All three limbs must be met for the obligation to apply to a system. Run them on each system separately, and record the answer and the reason — including for the systems you decide are out of scope.
Does a computer program make the decision, or do something substantially and directly related to making it?
The trigger is arranging for the program, not operating it. A tool a vendor runs on your behalf still counts. So does a system where a person approves an outcome the software has already shaped.
Write down what the program does, and what the person who signs off actually changes.
Could the decision reasonably be expected to significantly affect the rights or interests of an individual?
This is the limb that decides how much of your organisation is in scope, and it is a judgement call. It applies whether the effect is beneficial or adverse. Refusing or failing to decide counts as a decision.
Name the person affected and what they gain or lose. If you cannot, it is probably out of scope — record why.
Is personal information about that individual used in the operation of the program?
Personal information includes information the system infers or generates about someone, not only what they gave you.
List the kinds of personal information the program reads, in the words a customer would use.
The second limb is where reasonable people disagree, and it is the one to put in front of your privacy adviser. Keep the record of how you decided. It is what you will want when the OAIC guidance lands, and when a supplier changes a feature.
What to inventory first
Most organisations can name their AI tools. The systems that get missed are the rule-based ones nobody calls AI, and the features a vendor switched on without saying so. Start here.
A model privacy policy section
APP 1.8 asks for three things: the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to making the decision. Adapt the wording below — do not publish it as it stands.
Automated decision-making We use computer programs, including artificial intelligence, to make some decisions about individuals and to do things that are substantially and directly related to making those decisions. Personal information is used in the operation of those programs. Decisions made solely by a computer program: [for example: whether a refund request meets our returns policy] Decisions where a computer program does something substantially and directly related to the decision, with a person deciding: [for example: whether to shortlist an applicant for interview] Kinds of personal information used: [for example: identity and contact details; transaction history; employment history, qualifications and references] Human review: [how a person asks for review, and how long it takes]
This is general information, not legal advice, and it is not a compliance certificate. Have your privacy adviser review the wording before you publish it.
Where this came from
Arcus is an AI-compliance platform built and hosted in Australia. It maps AI systems against the Australian Privacy Act, the EU AI Act and 13 more live jurisdictions, and generates the assessment and documentation that follows. This worksheet is free and stays free, whether or not you ever use the product.
Sources: Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1 Part 15. Wording of the obligation follows the OAIC's own summary on its APP 1 guidance page. Checked 29 September 2026, when the OAIC's detailed guidance on these obligations had not yet been published.