Automated decision-making (ADM) transparency is the single biggest change in the 2026 Privacy Act amendments, and it's also the requirement most existing privacy policies quietly fail. Here's what it actually requires.

What is ADM transparency?

If your business uses an automated system, an algorithm, scoring model, eligibility engine, or any software that makes or materially contributes to a decision affecting a customer, you're required to disclose it. This covers more than obvious cases like loan approvals or insurance pricing. It can include automated fraud checks, dynamic pricing, tenant or employee screening tools, and eligibility filters on a signup form.

What the new disclosure requires

A compliant privacy policy needs to plainly state, in language an ordinary customer can understand, not legal boilerplate:

  • That an automated system is used in the decision
  • What kind of decision it affects
  • What personal information feeds into it
  • How a customer can seek more information or contest the outcome

Vague, generic statements like "we may use technology to assist our processes" don't meet this bar. The disclosure has to be specific enough that a customer actually understands what's happening to their information and why.

Common gaps

The most frequent problem isn't that businesses hide their ADM use, it's that their privacy policy was written before they adopted the automated tool, and nobody circled back to update the policy when the tool went live. A second common gap: policies that mention "automated processing" in one vague line, with no detail on what decisions it affects or how to contest them, which reads as a disclosure but doesn't function as one under the new standard.

How to fix it

Start by listing every automated or algorithmic tool your business actually uses that touches customer outcomes, not just the obvious ones. For each, write a plain-English sentence describing what it does and how a customer can query or contest a decision. This isn't a rewrite of your whole privacy policy, usually it's adding a clearly labelled section addressing exactly this. If you're not sure whether something counts as ADM, a Deep Scan checks your current policy against the specific requirement and flags exactly what's missing.

This is general information, not legal advice. For advice on your specific obligations, speak with a qualified privacy lawyer.