In short
Executive Summary
- Privacy counsel should sign the APP 1.7 wording; operations should sign the workflow list that wording describes
- A vendor cannot review your privacy policy into compliance, because the customer reads your policy, not theirs
- An operational review can map decisions, test likely gaps and draft disclosure support; it is not legal advice
- The executive who owns publication is the third reviewer, or the approved text never leaves the folder
Detail
Overview
The search query is usually “who can review an APP 1.7 privacy policy in Australia”. People want a single professional. There isn’t one who can do the whole job alone.
Start with the facts. Someone who runs hiring, claims, credit, fraud, rostering or customer operations has to confirm which computer programs influence outcomes about people, and which kinds of personal information those programs use. If that person is not in the review, counsel is drafting against a story.
Then privacy lawyers. Internal counsel, a panel firm, or a specialist privacy practice: the title matters less than whether they will own the APP 1.7 analysis and the final sentences in the policy. Ask them to work from the workflow map, not from a generic AI addendum. Ask them to say, in writing, what they have not verified.
An operational adviser, including a Rapid Review, sits between those two. The job is to find the workflows, test whether the current policy mentions the relevant decision kinds, and hand legal a map they can use. It is decision mapping and governance analysis. It is not a determination that you are or are not covered, and it is not a substitute for counsel approving the public wording.
Who should not be the only reviewer: the vendor whose software runs the workflow; the agency that rewrote the website; the AI steering committee that has never opened the privacy policy. Each can contribute facts. None of them is the APP entity the customer will look at.
Commercial impact
Why It Matters for Organisations
A privacy policy is a public statement about how the organisation handles personal information. After 10 December 2026 it may also have to describe certain automated decisions. If the wrong people review it, you get fluent prose that names AI in general and misses the collections scorer, or you get a legal opinion with no inventory behind it.
Regulators and affected people will not parse your internal RACI. They will read the policy and compare it with what happened to them. The review structure exists so that comparison is not a surprise.
There is a time problem as well. Counsel booked in November cannot invent a workflow map. Operations briefed in November cannot get a thoughtful legal review. The reviewers have to be named while there are still weeks on the clock, not days.
Podcast
Listen to how Australian executives are applying AI
Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
In practice
Examples or Practical Context
A company sent its privacy policy to the marketing agency because “they own the website”. The agency added a paragraph about using AI to improve services. None of the live decision kinds were in it. The website owner was the wrong reviewer for APP 1.7.
Another company asked the HR-tech vendor to certify that the hiring tool was “compliant”. The vendor sent a white paper. The organisation’s own policy still said nothing about automated ranking of candidates. The customer, and the candidate, read the organisation’s policy.
A general counsel asked for an operational map before they would touch the draft. That is the right sequence. The Rapid Review produced the workflow list and the likely-gap calls. Counsel then wrote and approved the disclosure sentences. Two signatures, two jobs.
Where no executive would own publication, the approved text sat in a legal folder. Review without an owner is not a review that reaches the public.
What to do
Key Takeaways
- Split the review: operations signs the map, privacy counsel signs the wording, an executive signs publication
- Do not treat the vendor or the website agency as the APP 1.7 reviewer
- Use an operational Rapid Review to prepare the map and draft support, then hand it to legal
- Name the reviewers while there is still time before 10 December 2026
- If counsel has not seen the workflow list, they have not reviewed the policy that matters
Newsletter
Get the Executive Brief each week
Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Assessment
Run the AI Readiness Assessment
Check whether policy, accountability, and compliance are keeping pace with deployment. The assessment scores governance and decision control alongside four other dimensions.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Read next
Where this sits
Explore This Pillar
Next step