Privacy Act
Automated decision-making and the Privacy Act.
From 10 December 2026 an Australian privacy policy must name the automated decisions your software makes and the personal information they use. A phone agent makes some of those decisions without a person, and the OAIC counts a decision it declines to make as one of them.
The clause
What APP 1.7 asks for
APP 1.7 reaches you when three things are true at once. You have arranged for a computer program to make a decision, or to do something substantially and directly related to making one. The decision could reasonably be expected to significantly affect a person's rights or interests. And personal information about that person is used in the operation of the program. The clause and the guidance under it are on the OAIC's APP 1 chapter. We run the voice and text agents this page is written about, so every claim below about a call is one our own documentation already carries.
| APP 1.8 asks you to name | On a voice agent that is |
|---|---|
| The kinds of personal information the programs use | The caller's number, what they say, the transcript, details a tool collects, and the recording where recording is on |
| The kinds of decisions made solely by those programs | Whatever you let the agent finish without a person: ending a call, declining a booking, choosing not to escalate |
| The kinds of decisions they do part of the work for | Classifying the call, screening who reaches a person, scoring the outcome, writing the summary a person then acts on |
APP 1.9 is the part page one leaves out. Making a decision includes refusing or failing to make it, and doing a thing includes refusing or failing to do it. An effect counts whether it helps the person or harms them. An agent that hangs up without taking the booking has done something the clause covers.
On the call
Which parts of an agent make a decision
An agent answers, works out what the caller wants, reads from a knowledge base, and calls the tools you switched on. Our privacy policy states the position in one line: agents use models and your instructions to respond, classify conversations, route contacts, and take configured actions, and you decide the purpose, the rules, the tools and the human review. The four cells below are where that becomes a disclosure you have to write.
Routing
Who reaches a person
Transfer is a tool the agent calls when your rule says to. The rule is yours, so the kinds of call it will and will not put through is a kind of decision your policy can name.
Booking
What it commits you to
A booking tool writes into your own system. Taking a slot, or declining because the tool returned nothing, is a decision made without a person in the loop.
Ending
When it hangs up
Call-handling limits end a call on a maximum duration, or on a caller who has gone silent. Each one is a decision under APP 1.9, because failing to continue counts.
Scoring
What a person reads after
Every call is stored with its timings and its scores. Where a person then acts on that summary, the scoring is work substantially related to their decision rather than a decision of its own.
The data
Where each part of a call is processed
APP 1.8 asks which personal information the program uses, and a voice agent is not one program. It is a speech recogniser, a language model, a speech synthesiser and a database, and they sit in different places. The component-by-component list is on data residency, and the counts below come from it. No other page returned for this query names a provider, a model or a region.
| Component | Where it runs | What it sees |
|---|---|---|
| Speech recognition | Australian endpoint, every environment that serves calls | The caller's words as audio |
| Language model, default | Amazon Bedrock, Sydney and Melbourne inference profile | The transcript and your prompt |
| Language model, selectable | Four of the thirty-two models are Australian-resident; the rest are routed by their provider | The same, wherever that provider serves it |
| Speech synthesis | One of the four providers has an Australian endpoint and three are in the United States | The agent's reply text, including any detail it reads aloud |
| Database and file storage | Sydney | Transcripts after redaction, recordings, caller profiles |
| Content moderation | Sydney | The live turn it checks |
Two of those rows are a choice you make rather than a fact about the platform. Pick a model labelled Australian in the picker and the transcript stays onshore. Pick a Deepgram voice and the reply text never leaves Australia, which matters most when the agent reads a caller's own details back to them. APP 8 governs the components that are processed overseas, and our compliance page lists them individually. The security page carries the stage-by-stage version for a reviewer.
Before the date
What to write in the policy
Name the kinds, not the mechanism. The obligation excludes commercially sensitive information and trade secrets, and the OAIC warns that excessive detail works against the transparency the clause is for. Four lines answer it for a phone agent.
One
The information
Say that an automated phone service uses the caller's number, what they say on the call, and the details they give it. Name the recording where you record.
Two
The decisions it finishes
List the ones you actually let it finish. Booking, declining, ending the call, choosing not to escalate. If a person signs off everything, say that instead.
Three
The decisions it contributes to
Classification, screening and scoring, where a person then decides. This is the row most policies miss, and it is the third APP 1.8 disclosure.
Four
Where it is processed
Your readers ask this whatever the clause says. Name the country for each component, or link a page that does, and keep it current when you change a model or a voice.
The obligation sits on the business whose customers are being decided about. Our compliance page puts it as the customer holding the obligations under the Privacy Act, with Meddle as the service provider, at compliance. Our own disclosure is at privacy, under automated decisions.
Last updated 6 October 2026
Questions
What the clause does and does not ask
Does APP 1.7 apply to an AI phone agent?
What are the three things the policy has to say?
Does a decision the agent declines to make count?
Is a chatbot a computer program for this obligation?
Do I have to publish how the model works?
What personal information does one call use?
Where is that information processed?
Can I keep transcripts out of the database?
Who holds the obligation, you or me?
Read a call and see what it decided.
Build an agent, place a test call, and read the transcript with the tools it reached for. That is the list your privacy policy has to describe.