Australian Privacy Act and AI
What Australian businesses need to know about the Privacy Act, OAIC guidance, and using AI tools without breaching your obligations.
This section covers Australian compliance obligations. If you're outside Australia, see Global & Regional Governance instead.
Australian Government AI Policy Roundup: OAIC, DISR, ASIC and ACSC Guidance in One Place
Australian government AI guidance in one place. What OAIC, DISR, ASIC and ACSC say, what it means for SMBs, and primary source links. Verified June 2026.
The Privacy Act 1988 and the Australian Privacy Principles, or APPs, provide a national framework for how covered organisations handle personal information. For an overview of related topics, start at the Compliance hub.
When a business adopts an AI tool, the privacy question is not simply whether the product uses AI. What matters is the information placed into it, how the provider handles that information, what the tool produces and whether its outputs influence decisions about identifiable people.
Customer messages, job applications, support transcripts, contact records and staff documents can all raise privacy questions. The practical starting point is to identify what information enters the tool, where it may be processed and who can access or reuse it.
In short: The Privacy Act may apply to your use of an AI tool if your business is an APP entity handling personal information. Coverage depends on the business and its activities, not merely the tool being used. Some businesses with annual turnover below $3 million may qualify for the small business exemption, although exceptions can apply. The OAIC's privacy guidance or an appropriately qualified adviser can help you assess your circumstances.
Find the guide for your situation
If staff are putting customer details, messages or documents into a general-purpose chatbot, read our guide to using customer data in ChatGPT and similar tools. It focuses on the checks to make before personal information is entered into an external service.
If an AI system screens applicants, ranks candidates or supports employment decisions, continue to AI hiring and Privacy Act considerations. That guide examines recruitment information and decisions affecting individuals.
If you are comparing suppliers or reviewing terms before purchase, use the guide to AI vendor contracts and the Privacy Act. It explains which privacy, security and data handling clauses deserve closer attention.
If you want to begin with material from Australia's privacy regulator, visit our guide to OAIC guidance on AI and privacy, which helps readers navigate the regulator's own resources and statements.
If terms such as APP 1, APP 6 or APP 8 are unfamiliar, the plain-English APP-by-APP walkthrough for AI tools is the better next step. It covers the principles individually without turning this hub into a second full explainer.
If your organisation uses AI-supported automated decisions and is reviewing what its public privacy policy says, see updating a privacy policy for AI-driven automated decisions.
If your concern is specifically the reported December 2026 commencement of new automated decision-making disclosure requirements, go directly to the December automated decision-making deadline guide. It covers the timing and mechanics in more detail.
If you work in a legal practice, client confidentiality and professional duties add another layer beyond general privacy questions. The guide to ChatGPT for Australian lawyers addresses that setting.
If you would prefer one longer introduction before choosing a narrower topic, read the broader guide to AI and the Australian Privacy Act.
The small business exemption
The OAIC explains that many private-sector businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but it also describes exceptions. Turnover alone therefore does not settle the question. Business activities, such as providing a health service or trading in personal information, can affect coverage. Check the OAIC's small business information and seek advice where the answer is unclear.
An exemption for your business also does not make the vendor relationship irrelevant. The provider may have its own privacy policy and contractual terms governing uploaded information. Customers and business partners may also expect sensible privacy controls regardless of statutory coverage. Following privacy-conscious practices voluntarily can reduce commercial and reputational risk, but it should not be treated as proof of legal compliance.
What the Privacy Act does not tell you
The Privacy Act is not a certification system for AI products, and it does not automatically label a particular tool as safe or unsafe. A familiar brand, an Australian data centre or a vendor's security claim does not answer every privacy question. The information, purpose, settings, contract and business context still need to be considered.
This hub does not determine your legal obligations or certify that a workflow is compliant. It helps you find the relevant regulator material and the right practical guide. Advice about a specific situation should come from the OAIC or an appropriately qualified professional.
Frequently asked questions
Is my business definitely covered by the Privacy Act?
Not necessarily. The OAIC says coverage can depend on annual turnover and the activities a business undertakes, with exceptions to the small business exemption. Use the OAIC's information as a starting point and obtain advice if your structure or activities make the answer uncertain.
What counts as personal information when using an AI tool?
Under the Privacy Act, personal information can include information or an opinion about an identified individual, or an individual who is reasonably identifiable. Names and contact details are obvious examples, but free-text prompts, case notes and combined datasets can also reveal identity depending on context.
What happens if an AI vendor exposes customer data?
The response depends on who is covered, what information was involved and the likelihood of harm. The OAIC's guidance on data breaches and the Notifiable Data Breaches scheme can help a business assess the regulatory pathway. Promptly preserving records, activating the incident response process and obtaining appropriate advice can support that assessment.
Does removing names make information safe to upload?
Removing direct identifiers can reduce risk, but it may not make a person unidentifiable. Details can sometimes be combined to identify someone, and the vendor's retention or reuse practices still matter. Consider the complete dataset and context rather than relying on name removal alone.
Do I need a lawyer before using an AI tool?
There is no single answer for every tool or business. Many routine assessments can begin with a data inventory, vendor review and OAIC guidance. Professional advice may be worthwhile when sensitive information, unclear Privacy Act coverage, high-impact decisions or complex contracts are involved.