Build a defensible inventory of governed automated actions, decision context, human intervention, outcomes, and evidence before the APP Privacy Policy amendments commence.
APP 1.7 to 1.9 are scheduled law commencing 10 December 2026. This is a technical readiness guide, not legal advice, OAIC approval, certification, or a determination that the amendments apply to a particular system.
IssuerAustralian Parliament and Office of the Australian Information Commissioner
Act registered13 December 2024
Commencement10 December 2026
Last verified27 July 2026
Law and guidance boundary
Start with the enacted APP 1 text; keep developing guidance separate.
From 10 December 2026, APP 1.7 to 1.9 require covered APP entities to add specified information about certain automated decisions and the personal information used to their APP Privacy Policy. The OAIC consultation concerns developing guidance and does not alter the statutory text.
The OAIC is developing more detailed automated-decision transparency guidance. Its consultation is an official source for that process, but the consultation does not create additional statutory requirements.
APP 1.7 scope logic
Three conditions define the automated-decision disclosure trigger.
An APP entity needs its own legal and data assessment. HaltState records can support an inventory only for actions that the customer actually integrates.
01Program involvement
A computer program makes a decision, or does a thing that is substantially and directly related to making it.
02Significant effect
The decision could reasonably be expected to significantly affect an individual's rights or interests.
03Personal information
The condition applies when personal information about the individual is used in the program's operation.
APP 1.8 policy information
The APP Privacy Policy must describe specified categories, not dump runtime logs.
For covered arrangements, the policy must include information about the following kinds. Legal advisers and privacy owners must determine the final wording and level of detail.
Personal informationThe kinds of personal information used in the operation of the computer program.
Solely automated decisionsThe kinds of decisions made solely by a computer program.
Substantially related stepsThe kinds of decisions for which the operation of a computer program does a thing that is substantially and directly related to making the decision.
Decision effectInclude refusals, failures to grant a benefit, and decisions that may be beneficial or adverse where the statutory conditions are met.
Scheduled-law crosswalk
Technical evidence can support the assessment; it cannot replace it.
Each row preserves the APP entity responsibility and the verified limit behind the mapped control. Privacy-policy drafting and disclosure remain an explicit product gap.
Supports evidence
APP 1.7 scope evidence for programs, decisions, and personal information
Record caller-supplied agent attribution and declared action labels for business actions that the customer has routed through an active HaltState integration.
The APP entity owns its system inventory, personal-information data map, decision-impact assessment, legal scope analysis, and proof that every relevant program and action is covered.
Verified limitation
Agent attribution is caller supplied. HaltState sees only customer-integrated actions, does not discover personal information use, and does not determine whether APP 1.7 applies.
Supports evidence
APP 1.8 kinds of decisions and automated steps
Return a policy decision for a declared action and preserve action and decision labels that can support an APP entity's workflow inventory.
The APP entity owns classification of the kinds of decisions, automated steps, personal information, affected individuals, and significant effects that must appear in its APP Privacy Policy.
Verified limitation
Action names and parameters are supplied by the customer. Expired-trial, policy-load, and no-matching-rule paths can default to ALLOW, so HaltState records do not establish a complete statutory decision inventory.
Supports evidence
Human checkpoints and final outcomes as operational context
Record approval-required decisions and best-effort execution outcomes that can help an APP entity explain how an integrated automated workflow operates.
The APP entity owns approval persistence, reviewer authority, reconsideration and correction processes, final outcome reconciliation, and any explanation provided to individuals.
Verified limitation
Human approval is not itself an APP 1.7 to 1.9 statutory requirement. Pending operation persistence is customer owned and execution reporting is best-effort rather than guaranteed durable linkage.
Verified product gap
Privacy-policy content, legal assessment, and disclosure
Expose a reviewed product gap between limited technical evidence and the legal, data-governance, drafting, publication, and individual-rights work required of an APP entity.
The APP entity and its advisers own legal assessment, privacy-policy drafting and validation, notices, data accuracy, access and correction, complaints, redaction, retention, and publication.
Verified limitation
Current Proof Pack evidence is refund-specific, the verifier does not recompute the embedded action-evidence hash, and public redaction covers a bounded refund projection. HaltState does not draft or validate an APP Privacy Policy.
Separate voluntary guidance
Guidance for AI Adoption adds a broader operating checklist.
The voluntary official guidance presents six essential practices for safe and responsible AI adoption, including accountability, risk management, data governance, testing and monitoring, human control, and stakeholder transparency.
Published 21 October 2025, this is voluntary official guidance built around six essential practices. It is not law and does not change APP 1.7 to 1.9.
Supports integration
AI register, records, monitoring, and human control
Provide selected pre-execution decisions, approval checkpoints, action records, outcome reports, and an external stop integration for actions routed through active governance.
The organisation owns its complete AI register, accountability structure, risk assessment, data governance, testing, monitoring, human oversight, stakeholder communication, incident response, and decommissioning processes.
Verified limitation
The Guidance for AI Adoption is voluntary official guidance, not law. HaltState does not provide a complete AI register, organisation-wide risk-management system, redress process, monitoring programme, or decommissioning workflow.
Reviewed control detail
Inspect the exact capability boundary behind every Australia mapping.
These catalogue records are reused without broadening their enforcement point, evidence, capability status, customer responsibility, or limitation.
Treat the returned decision as authority, execute only an allowed or later-approved action, and monitor trial state and policy availability.
Control limitation
Expired trials bypass governance and return allowed with governance inactive. A policy-load failure returns an empty policy set, and no matching policy defaults to ALLOW. Customers must not treat this control as fail-closed.
Report the final execution result accurately, retain the operation-to-report binding in the customer ledger, and verify durable receipt when that matters.
Control limitation
This is report receipt and best-effort recording, not proof that a guarded action was durably linked. Immediate ALLOW can have no approval row; the endpoint does not check whether its UPDATE matched a row; the idempotency key is not written to the action log; and event emission failures are ignored.
Hash a redacted refund evidence document before proof storage
The refund worker computes SHA-256 over the canonicalized redacted in-memory evidence document and stores that digest beside a logical haltstate:// artifact URI in a Proof Pack.
Enforcement point
After the governed workflow has a final decision and before the demonstrated refund execution is recorded.
Supply accurate redacted evidence, independently verify exported evidence when integrity assurance is required, and retain records according to policy.
Control limitation
The artifact URI is logical and the verifier does not recompute the embedded action-evidence hash. The live page demonstrates Proof Pack integration only, not evidence integrity. This is not a digital signature, external timestamp, immutable store, or legal certification.
Use controlled non-sensitive action labels and review access control and redaction for private exports and customer-specific fields.
Control limitation
The refund params and result fields use a bounded allowlist, but action and last_action are passed through from caller-controlled event and status data. Integrators must use controlled non-sensitive action labels. This does not establish redaction for private exports or arbitrary non-refund fields.
Poll with tenant credentials, obey kill or pause status, and operate a tested pause, rollback, or recovery procedure appropriate to the protected system.
Control limitation
Kill-switch activation uses a 3,600-second (one-hour) TTL. The heartbeat protocol returns OK, PAUSE, or KILL, returns OK on backend-check failure, and gives unauthenticated legacy polling only a status-only OK. The customer agent must poll and obey it; HaltState does not force termination, roll back completed actions, or return customer systems to a safe state.
Public evidence and implementation detail
Inspect one governed business workflow and the integration contract.
HaltState does not determine whether APP 1.7 applies and does not discover personal information use, unintegrated programs, or unguarded actions.
Agent identity is caller-supplied agent attribution, not cryptographic workload identity or proof of the accountable human principal.
Expired trials, policy-load failures, and no matching rule include paths that can default to ALLOW.
Human approval is not itself an APP 1.7 to 1.9 statutory requirement; it is optional operational context where a workflow uses it.
Outcome reporting is best-effort. The demonstrated proof evidence is refund-specific, not a complete automated-decision record or immutable audit store.
HaltState does not draft or validate an APP Privacy Policy, provide privacy notices, or operate access, correction, complaint, retention, and regulator-response processes.
Readiness engagement
Australia ADM Evidence Readiness Sprint
Map one automated-decision workflow across program scope, personal-information use, decision categories, significant effects, guarded actions, human intervention, outcomes, disclosure ownership, and verified evidence gaps.