From December 2026, must a conveyancer's privacy policy disclose automated decision-making?
Only if you are an APP entity and your software crosses the line. From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to disclose automated decision-making where three conditions are all met: a computer program has been arranged to make, or do a thing substantially and directly related to making, a decision; that decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program's operation. A human signing off at the end does not put you outside it: that case is APP 1.8(c).
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What is the new rule?
The Privacy and Other Legislation Amendment Act 2024 (No. 128 of 2024), Schedule 1 Part 15, inserts APP 1.7, 1.8 and 1.9, requiring an APP entity's privacy policy to disclose automated decision-making (ADM). Its commencement table, s 2 table item 7, states the date for that Part as 10 December 2026. APP 1.7 binds APP entities, so it reaches a practice with turnover over A$3m in a completed financial year (s 6D(4)(a)) across everything it does, and a smaller practice through s 6E(1A), which applies the Act "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act. That reach follows the AML activity, not merely the AML data.
Note the key point up front: this is a privacy-policy disclosure obligation. It doesn't ban automated decision-making or require you to change your tools; it requires you to tell people about qualifying automated decisions in your policy.
When is APP 1.7 triggered?
APP 1.7 is triggered where an APP entity has arranged for a computer program, using an individual's personal information, to make a decision, or to do a thing that is substantially and directly related to making a decision, that could reasonably be expected to significantly affect the individual's rights or interests.
Three conditions do the work, not two, and all three must be met: (a) a computer program has been arranged to make, or do a thing substantially and directly related to making, a decision; (b) that decision could reasonably be expected to significantly affect an individual's rights or interests; and (c) personal information about that individual is used in the program's operation. "Substantially and directly related" describes what the program does; "significantly affect" describes the effect on the person.
What would the policy need to say?
Where APP 1.7 applies, APP 1.8 fixes the three things the privacy policy must contain:
- the kinds of personal information used in the operation of those computer programs (APP 1.8(a));
- the kinds of those decisions made solely by the operation of those programs (APP 1.8(b)); and
- the kinds of those decisions for which the program does a thing that is substantially and directly related to making the decision (APP 1.8(c)), which is the limb that catches a part-automated process where a human still makes the final call.
What's the conveyancer angle, and why does it stay conditional?
Conveyancers use electronic VOI, identity-verification (IDV) and PEP or sanctions-screening software. Whether a given tool is caught turns on APP 1.7(b): could the decision it feeds reasonably be expected to significantly affect the individual's rights or interests. A human reviewer at the end does not answer that question. APP 1.8 splits the disclosure: a decision made solely by the program falls under (b), one the program does a substantially and directly related thing towards falls under (c). So a screening result a human then acts on sits in (c), not outside the rule. APP 1.9 adds that a beneficial effect counts as much as an adverse one. The OAIC's guidance is still in development: its ADM Issues Paper was published 18 May 2026 and submissions closed 15 June 2026.
So the position is conditional, and you can test it in four questions. Are you an APP entity at all, by turnover under s 6D(4)(a), by AML activity under s 6E(1A), or otherwise? Has a computer program been arranged to make, or do a thing substantially and directly related to making, a decision? Could that decision reasonably be expected to significantly affect an individual's rights or interests? Is personal information about that individual used in the program's operation? Four yeses and the disclosure is owed from 10 December 2026. A no at the first and APP 1.7 does not reach you, whatever software you run, and we would rather tell you that.
| Question | Where it lands |
|---|---|
| Does APP 1.7 apply to every conveyancer? | No. Only to an APP entity, and only where all three conditions in APP 1.7(a) to (c) are met |
| What triggers it? | A program that makes, or does a thing substantially and directly related to making, a qualifying decision, using the individual's personal information |
| What's the obligation? | Disclose the ADM in your privacy policy; it's transparency, not a ban |
| When? | From 10 December 2026 |
Why does it belong on your radar now?
Because item 87 of the same Part also adds APP 1.7 to the list in s 13K(1)(b), and s 80UB(1)(a) makes s 13K(1) subject to an infringement notice under Part 5 of the Regulatory Powers (Standard Provisions) Act 2014. Item 89 applies the rule to decisions made after 10 December 2026 even where the software was arranged years earlier, so a privacy policy written for the 1 July 2026 AML obligations may need updating again. For the policy itself, see Do conveyancers need a privacy policy in 2026?; for how the Privacy Act reaches you at all, see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?.
Common questions
Does APP 1.7 mean I can't use VOI software?
No. It's a transparency rule about your privacy policy, not a ban on automated tools. Where it applies, you disclose the automated decision-making; you don't have to stop using the software.
Does every VOI or identity-check tool trigger it?
Not automatically, and two gates have to be passed. You have to be an APP entity, and the tool has to satisfy all three conditions in APP 1.7(a) to (c). A human making the final call is not a third gate: that case is disclosed under APP 1.8(c) rather than APP 1.8(b).
When does it start?
10 December 2026. That is the date stated for Schedule 1 Part 15 in the commencement table at s 2 of the Privacy and Other Legislation Amendment Act 2024, and item 89 applies it to decisions made after that day, even where the software was arranged earlier.
What do I actually have to write in my policy?
APP 1.8 lists three: the kinds of personal information used in the operation of those programs, the kinds of decisions made solely by the operation of those programs, and the kinds of decisions for which the programs do a thing substantially and directly related to making the decision.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy and Other Legislation Amendment Act 2024 (Cth), Sch 1 Pt 15 items 87 to 89; Privacy Act 1988 (Cth), ss 6D, 6E, 13K, 80UB; OAIC, consultation on transparency in automated decision-making.