ADM Register (APP 1.7 to 1.9)
Draft for review by your privacy or legal adviser. AgentValet does not provide legal advice.
From 10 December 2026, Australian Privacy Principles 1.7 to 1.9 (inserted by the Privacy and Other Legislation Amendment Act 2024) require an APP entity’s privacy policy to describe automated decision-making when all three of these are true:
- The entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision.
- The program uses personal information to do so.
- The decision could reasonably be expected to significantly affect the rights or interests of an individual.
When triggered, APP 1.8 requires the privacy policy to set out:
- 1.8(a) the kinds of personal information used in the operation of those programs,
- 1.8(b) the kinds of decisions made solely by the operation of those programs, and
- 1.8(c) the kinds of decisions for which a thing substantially and directly related to making the decision is done by those programs.
APP 1.9: making a decision includes refusing or failing to make one.
The OAIC’s guidance is in the APP Guidelines, chapter 1 (version 2.0, 30 September 2026, paragraphs 1.35 to 1.73). Two points shape the register:
- A human making the final call does not take a program out of scope. “Substantially” means the program’s output is a key factor in the human’s decision; “directly” means it is directly connected to making it (paragraph 1.54).
- The obligation is transparency. It does not create a new right to object or to request human review.
What the register does
The ADM Register lists every agent in your organisation with:
| Column | Where it comes from |
|---|---|
| Agent, owner and status | Your AgentValet agents |
| Platforms and scopes | The agent’s active grants |
| Personal information the agent can reach (inferred from access) | The scope mapping applied to those grants |
| Actions in the window, first and last seen | The audit log, per agent and platform |
| Approval requests, approved, denied, expired | Approval records |
| Decision, decision role, significant effect, affected people, vulnerability | Your assessment, recorded with who made it and when |
| APP 1.7 status | Derived from the above (rules below) |
It also drafts privacy policy wording grouped as 1.8(a), (b) and (c), and lets you save snapshots: a frozen copy of the register and draft with a SHA-256 fingerprint, which you can download again as CSV, printable HTML or JSON and get the same bytes every time.
What it does not do
- It does not scan your data. Personal information is inferred from which platforms an agent is connected to and which scopes it holds. An agent that can read a mailbox can reach email content, whether or not it has read any.
- It does not decide for you. Whether an agent makes or substantially assists a decision, and whether that decision could significantly affect someone, is a judgement your organisation records.
- It does not see systems AgentValet does not govern. Programs that never call through AgentValet are not in the register.
- It is not legal advice. The draft wording is a starting point for your privacy or legal adviser.
How personal information is inferred
Each platform and scope maps to zero or more kinds of personal information, using the category language in the table on the scope mapping page. Three outcomes are possible for each scope:
- Kinds listed: the scope can reach those kinds of personal information.
- None: the scope was reviewed and reaches no personal information about the people affected (for example DNS settings, or the sign-in scopes that only identify the person who connected the account).
- Unclassified, needs review: nobody has mapped the scope yet. This includes every MCP server tool, because a tool’s name is not evidence of what it reaches. Unclassified scopes are counted at the top of the register; they are never dropped.
How the APP 1.7 status is worked out
Rules are applied in order:
- If you assessed the agent as not making or assisting decisions, or the decisions as not significantly affecting people, the status is Likely out of scope. Your answer is respected, with a warning if the agent can reach sensitive information.
- If the agent reaches no personal information and nothing is unclassified: Likely out of scope.
- If the agent makes or substantially assists decisions, the effect is significant, and it reaches at least one kind of personal information: Likely in scope.
- Anything else (not assessed, unsure, or only unclassified access): Review needed.
Approvals are never an input to the status. They are shown beside it as evidence of the human’s role.
Separate badges flag Review overdue (past the next review date, 12 months by default) and agents that affect children or people experiencing vulnerability (OAIC paragraph 1.65).
Plans
The register view and assessments are on every paid plan; snapshots, exports and draft wording are on Team and above. Only organisation admins can view or assess.
Related regimes
The register can support, but is not designed around, the WA Privacy and Responsible Information Sharing Act 2024 (IPP 10, which expects a register of automated decision-making in the WA public sector) and APRA’s expectation that regulated entities keep an inventory of AI tools and use cases.