On 10 December Your Privacy Policy Has to Describe Your Automated Decisions. The Excel Formula Counts.

Abstract illustration of a spreadsheet grid resolving into a decision gate that sorts individual figures down separate paths

On 10 December Your Privacy Policy Has to Describe Your Automated Decisions. The Excel Formula Counts.

The new transparency obligation is not an AI rule. It reaches every place a program shapes a decision about a real person — which for most finance functions means a spreadsheet nobody thinks of as a system.

From 10 December 2026, APP entities that use personal information in automated decision-making have to say so in their privacy policy. The obligation comes from subclauses 1.7, 1.8 and 1.9 of the Australian Privacy Principles, inserted by the Privacy and Other Legislation Amendment Act 2024, and it has been on a long runway that is now thirteen weeks from ending.

Almost every piece written about this treats it as an AI compliance item. It is worth reading the regulator's own scoping material before accepting that framing, because the OAIC's Issues Paper is explicit that the trigger is a computer program, and a computer program includes pre-programmed rule-based processes. Not just models. Not just anything anyone would call AI.

The worked example the regulator reaches for is a pre-programmed Microsoft Excel formula used to score and triage people calling a domestic violence hotline. Where that score is a key factor in a human deciding what order to attend calls, the Issues Paper treats it as substantially and directly related to the decision. Where the same spreadsheet only works out someone's age from a date of birth, it isn't. Same software; what matters is what the output does to a person.

The line the regulator drew

A spreadsheet that adds up numbers is not in scope. A spreadsheet that takes personal information, applies a rule, and produces a score or a category that sorts people into different treatment is a different thing entirely.

Think about what that captures inside an ordinary finance function:

  • A hardship or fee-waiver sheet that scores an applicant against income and arrears criteria and returns approve, decline or refer.
  • A debtor model that assigns a risk band and drives whether someone goes to a payment plan or to collections.
  • A waitlist or intake prioritisation tool that ranks people on weighted criteria.
  • Anything with a lookup table and a threshold that produces a different outcome for a named individual.

None of those are AI. Several are older than the person maintaining them. All are computer programs using personal information to make or substantially shape a decision, which is the statutory test.

10 Dec 2026
Commencement of the ADM transparency obligation in APP 1.7–1.9. There is no transitional period attached to it.
18 May 2026
Date of the OAIC Issues Paper that sets out the scoping questions. Submissions closed 15 June. The OAIC said it intends to publish guidance by September 2026.

What you actually have to disclose

The obligation is narrower than the anxiety around it. It is a privacy policy disclosure, not an individual notification duty and not a right of explanation. Three things go in:

The kinds of personal information used by the computer program in making those decisions. Kinds, not fields — you are describing categories, not publishing a data dictionary.

The kinds of decisions made solely by the program — where no person intervenes between the input and the outcome.

The kinds of decisions where the program does something substantially and directly related to making the decision — the human-in-the-loop case, where a person signs but the program produced the thing they signed. This is the limb most organisations will actually be caught by, and the one most likely to be missed, because it feels like a person made the decision.

Commercially sensitive detail does not have to be published. You are not being asked to expose your model, your weightings or your thresholds — only to be able to say, in ordinary language, that this happens and roughly on what basis.

The threshold question, and why smaller providers should not relax

The obligation applies to APP entities. There is a general small business exemption under the Privacy Act for organisations under $3 million in annual turnover, and a lot of organisations in this sector will read that number and stop reading.

They shouldn't, because the exemption has carve-outs, and one of them is decisive here: a private sector organisation that provides a health service and holds health information is an APP entity regardless of turnover. Both limbs have to be met, though in practice they travel together. The definition of health service is wider than "a doctor" — it reaches activities intended to assess, maintain or improve a person's health — and the regulator's own guidance names disability service providers handling health information as an example, alongside allied health and non-government health services.

So the population most likely to assume it is out of scope — a $2m allied health practice, a small SIL provider, a home care operator — is disproportionately likely to be in it. That is the sting of this obligation, and it is worth ten minutes with your adviser rather than reading your status off the turnover line.

Confirm your own entity status; don't infer it. Whether the small business exemption applies to you turns on turnover, on whether you provide a health service, and on other carve-outs including being a Commonwealth contracted service provider. Get that answered specifically. Everything below assumes you are, or may be, an APP entity.

The task is an inventory, not a policy rewrite

Here is the part worth internalising. You cannot write the disclosure until you know what to disclose, and almost no organisation holds a list of the places where a rule, a score or a model shapes a decision about a person.

Rewriting the privacy policy is an afternoon. Finding out what belongs in it is the work — and it is finance work more than legal work, because finance is where most of these tools live and finance is the function that can read a spreadsheet and say what it does.

A workable register has one row per decision point and five columns:

What decision is being made, about whom. Written as an outcome a person experiences — "whether a client's fee is waived," not "hardship assessment process."

What personal information goes in. Categories: income, health status, service history, arrears.

What the program does. Scores, ranks, filters, flags, calculates, allocates. Be specific — this is the column that determines whether you are in scope at all.

Whether a person intervenes, and what they actually do. "Approves" is not an answer. Does the reviewer see the inputs, can they override, do they in practice, and how often? A sign-off that never departs from the recommendation is a rubber stamp — the "substantially and directly related" limb, not the human-decision one.

Who owns it. Named person. Undocumented spreadsheets outlive their authors, and an orphaned decision tool is the one you will not be able to describe in December.

Where AI helps build the register, carefully

Finding the tools is a discovery problem across a shared drive, and that is a reasonable use of an AI-assisted pass: scanning workbooks for the structural signature of a decision tool — nested conditional logic, lookup tables against person-level records, a column whose output is a band or a verdict — and shortlisting them for a human to walk through.

The shortlist is the deliverable. The model should not decide whether a given tool is in scope; that is a legal characterisation with a regulator attached to it. Use the pass to find the candidates, and settle each one with a person who has read the Issues Paper.

On the data itself: the workbooks you would be scanning are full of client, participant and payroll records. Before any of that goes near an AI tool, confirm whether the vendor trains its models on customer inputs. The safest posture is a tool where your data isn't retained for training. And de-identify first: strip names, tax file numbers and participant identifiers before upload. A no-training contract governs what the vendor does with your data; APP 11 still governs whether you should have sent it in that form. There is a certain irony in creating a privacy exposure while building a privacy register.

What to do between now and December

Settle your entity status. Build the register — a fortnight of someone's attention, not a project. Take the register to whoever owns your privacy policy and let them draft from a factual list rather than from imagination. Then watch for the OAIC guidance: the Issues Paper says the OAIC intends to release it by September 2026, ahead of commencement, so check whether it has landed before you finalise anything. When it does, the register is what lets you read it in an hour instead of a month.

The organisations that will struggle in December are not the ones running sophisticated models. They are the ones who spend the first three weeks trying to find out what they have.

Could you list every place a rule decides something about a client?

Most finance functions can name the obvious two or three, then find several more during a structured walk-through. PFL provides senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations — including finding the decision tools that have quietly accumulated in your spreadsheets.

Talk to PFL →
This post is general commentary based on publicly available information and does not constitute legal advice. The OAIC's guidance on the ADM transparency obligation had not been published at the time of writing, and the scope questions in the Issues Paper remain open. Always seek independent professional advice before acting.
Timothy, CPA is Managing Director of Professional Financelink (PFL), providing senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations. 20+ years in finance leadership across NFP, NDIS and SME.

Comments

Popular posts from this blog

Google Gemma 4 Just Launched — And It Might Solve Finance's Biggest AI Privacy Problem

Claude vs Gemini for Australian Finance: An Honest Comparison After 12 Months of Using Both

Why NFP Boards Are Finally Talking About AI — And What the Finance Team Should Do Before They Ask