Practical AI and SaaS for Business
Compliance · Privacy & Law

Australian Privacy Act and AI

What Australian businesses need to know about the Privacy Act, OAIC guidance, and using AI tools without breaching your obligations.

46 guides Updated June 2026 Verified against primary sources

This section covers Australian compliance obligations. If you're outside Australia, see Global & Regional Governance instead.

The Privacy Act 1988 and the Australian Privacy Principles, or APPs, provide a national framework for how covered organisations handle personal information. For an overview of related topics, start at the Compliance hub.

When a business adopts an AI tool, the privacy question is not simply whether the product uses AI. What matters is the information placed into it, how the provider handles that information, what the tool produces and whether its outputs influence decisions about identifiable people.

Customer messages, job applications, support transcripts, contact records and staff documents can all raise privacy questions. The practical starting point is to identify what information enters the tool, where it may be processed and who can access or reuse it.

In short: The Privacy Act may apply to your use of an AI tool if your business is an APP entity handling personal information. Coverage depends on the business and its activities, not merely the tool being used. Some businesses with annual turnover below $3 million may qualify for the small business exemption, although exceptions can apply. The OAIC's privacy guidance or an appropriately qualified adviser can help you assess your circumstances.

Find the guide for your situation

If staff are putting customer details, messages or documents into a general-purpose chatbot, read our guide to using customer data in ChatGPT and similar tools. It focuses on the checks to make before personal information is entered into an external service.

If an AI system screens applicants, ranks candidates or supports employment decisions, continue to AI hiring and Privacy Act considerations. That guide examines recruitment information and decisions affecting individuals.

If you are comparing suppliers or reviewing terms before purchase, use the guide to AI vendor contracts and the Privacy Act. It explains which privacy, security and data handling clauses deserve closer attention.

If you want to begin with material from Australia's privacy regulator, visit our guide to OAIC guidance on AI and privacy, which helps readers navigate the regulator's own resources and statements.

If terms such as APP 1, APP 6 or APP 8 are unfamiliar, the plain-English APP-by-APP walkthrough for AI tools is the better next step. It covers the principles individually without turning this hub into a second full explainer.

If your organisation uses AI-supported automated decisions and is reviewing what its public privacy policy says, see updating a privacy policy for AI-driven automated decisions.

If your concern is specifically the reported December 2026 commencement of new automated decision-making disclosure requirements, go directly to the December automated decision-making deadline guide. It covers the timing and mechanics in more detail.

If you work in a legal practice, client confidentiality and professional duties add another layer beyond general privacy questions. The guide to ChatGPT for Australian lawyers addresses that setting.

If you would prefer one longer introduction before choosing a narrower topic, read the broader guide to AI and the Australian Privacy Act.

The small business exemption

The OAIC explains that many private-sector businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but it also describes exceptions. Turnover alone therefore does not settle the question. Business activities, such as providing a health service or trading in personal information, can affect coverage. Check the OAIC's small business information and seek advice where the answer is unclear.

An exemption for your business also does not make the vendor relationship irrelevant. The provider may have its own privacy policy and contractual terms governing uploaded information. Customers and business partners may also expect sensible privacy controls regardless of statutory coverage. Following privacy-conscious practices voluntarily can reduce commercial and reputational risk, but it should not be treated as proof of legal compliance.

What the Privacy Act does not tell you

The Privacy Act is not a certification system for AI products, and it does not automatically label a particular tool as safe or unsafe. A familiar brand, an Australian data centre or a vendor's security claim does not answer every privacy question. The information, purpose, settings, contract and business context still need to be considered.

This hub does not determine your legal obligations or certify that a workflow is compliant. It helps you find the relevant regulator material and the right practical guide. Advice about a specific situation should come from the OAIC or an appropriately qualified professional.

Frequently asked questions

Is my business definitely covered by the Privacy Act?

Not necessarily. The OAIC says coverage can depend on annual turnover and the activities a business undertakes, with exceptions to the small business exemption. Use the OAIC's information as a starting point and obtain advice if your structure or activities make the answer uncertain.

What counts as personal information when using an AI tool?

Under the Privacy Act, personal information can include information or an opinion about an identified individual, or an individual who is reasonably identifiable. Names and contact details are obvious examples, but free-text prompts, case notes and combined datasets can also reveal identity depending on context.

What happens if an AI vendor exposes customer data?

The response depends on who is covered, what information was involved and the likelihood of harm. The OAIC's guidance on data breaches and the Notifiable Data Breaches scheme can help a business assess the regulatory pathway. Promptly preserving records, activating the incident response process and obtaining appropriate advice can support that assessment.

Does removing names make information safe to upload?

Removing direct identifiers can reduce risk, but it may not make a person unidentifiable. Details can sometimes be combined to identify someone, and the vendor's retention or reuse practices still matter. Consider the complete dataset and context rather than relying on name removal alone.

Do I need a lawyer before using an AI tool?

There is no single answer for every tool or business. Many routine assessments can begin with a data inventory, vendor review and OAIC guidance. Professional advice may be worthwhile when sensitive information, unclear Privacy Act coverage, high-impact decisions or complex contracts are involved.

All guides

Showing all 46 guides

Guide APPs

Cybersecurity for an Accounting App Stack

How to review identity, MFA, shared logins, permissions, integration tokens, backups and incident readiness across a connected accounting app stack today.

Read guide
Guide Vendors

AI Vendor Contract Red Flags for Ecommerce

Check AI vendor contract clauses that expose ecommerce stores to customer data misuse, payment risk, catalogue loss and costly platform lock-in today.

Read guide
Guide Guide

Bill C-36: Canada's Next Federal Privacy Law

Bill C-36 would replace PIPEDA with a new federal privacy law. Here's what it proposes for AI and data, and why businesses should watch, not act, yet.

Read guide
Guide Hiring

AI Hiring Tools and the Equality Act in the UK

AI CV-screening tools can create indirect discrimination under the UK Equality Act, even with no protected characteristic as input. What employers check.

Read guide
Guide Hiring

AI in Canadian Hiring

AI hiring tools trigger different rules depending on where candidates live. A practical map of Quebec Law 25, PIPEDA, and Ontario's new AI disclosure rule.

Read guide
Guide Vendors

AI Vendor Contracts Canada PIPEDA

Does your AI vendor's terms of service actually meet PIPEDA's accountability requirements? What to check in the contract before you sign.

Read guide
Guide Guide

Privacy Impact Assessments Canada AI

Does a small business need a privacy impact assessment for a new AI tool? What Quebec's Law 25 actually requires, and what a proportionate PIA looks like.

Read guide
Guide Guide

Which Canadian Privacy Law Applies to AI

PIPEDA, Quebec's Law 25, Alberta and BC's own privacy statutes. Which Canadian privacy law applies to your AI tool, based on where your customers live.

Read guide
Guide Hiring

EEOC AI Hiring Adverse Impact

Does a vendor's bias-testing assurance for an AI hiring tool protect your business under Title VII? The EEOC's guidance, and a test you can run yourself.

Read guide
Guide ADM

California CPRA ADMT Requirements

California's CPRA has specific rules for AI-driven automated decision-making. What counts as ADMT, what it requires, and the compliance deadlines in force.

Read guide
Guide Hiring

NYC Local Law 144 AI Hiring Bias Audit

NYC Local Law 144 requires a bias audit before using AI to screen job applicants, and it applies wherever your business is based. What the law requires.

Read guide
Guide Vendors

GDPR AI Vendor Processor Agreements

What does a GDPR-compliant AI vendor contract actually need to cover? A plain-English guide to Article 28 processor agreements for AI tools.

Read guide
Guide ChatGPT

ChatGPT for Allied Health UK

What UK allied health practitioners need to know about UK GDPR before using ChatGPT to draft patient letters, referrals, or treatment notes.

Read guide
Guide Hiring

AI Recruitment Candidate Data Privacy UK

Screening applicants with AI? Here's what UK GDPR and the ICO expect around candidate data collection, retention, and deletion for recruitment tools.

Read guide
Guide Guide

Privacy-First Cloud Storage: Honest Options for Small Business

Comparing privacy-focused cloud storage providers on real region choice and vendor data access, not just marketing claims about encryption and security.

Read guide
Guide Vendors

The Data Sovereignty Questions to Ask Any AI Vendor

Specific questions to ask any AI vendor about data location, subprocessors, and cross-border transfer before signing, and how to spot a vague answer.

Read guide
Guide ChatGPT

ChatGPT for Lawyers: What to Know Before You Use It With Client Work

A practical guide to ChatGPT for lawyers, covering confidentiality, accuracy, supervision, client disclosure and safer legal workflows for small firms.

Read guide
Guide Vendors

AI Vendor Contracts: The Clauses to Check Before You Sign

Review key AI vendor contract clauses covering data use, security, ownership, liability, service changes, exit rights and regulatory support before signing

Read guide
Guide Hiring

HR and AI in the EU: Compliance Obligations for Hiring, Screening, and Performance

Understand EU HR AI compliance for recruitment, screening and performance management, including high-risk uses, GDPR issues and practical review steps.

Read guide
Guide Vendors

AI Vendor Breach Response Plan Template

Use this AI vendor breach response plan template to assign roles, assess exposed data, manage notifications, document decisions and improve controls now.

Read guide
Guide Vendors

AI Data Residency Comparison: What Six Major Vendors Actually Offer

Compare where major business AI tools store and process prompts, files and transcripts, and what to verify before selecting a regional data setting safely.

Read guide
Guide Vendors

AI Vendor Due Diligence Checklist for Business

Use this AI vendor due diligence checklist to assess data handling, security, contract terms, oversight and warning signs before signing with a provider.

Read guide
Guide ADM

How to Update Your Privacy Policy for AI Automated Decisions Under GDPR

Learn how to update a GDPR privacy policy for AI-assisted decisions, identify Article 22 cases, explain the logic and document your review clearly today.

Read guide
Guide ChatGPT

Can I Put Customer Data Into ChatGPT? The GDPR Answer

Can customer data go into ChatGPT under GDPR? Learn how lawful basis, data minimisation, processor contracts and overseas transfers affect the answer.

Read guide
Guide Vendors

AI Vendor Due Diligence Checklist for Australian Business

What to check before signing up with any AI vendor: data retention, security certifications, breach notification, and contract terms for Australian firms.

Read guide
Guide Vendors

AI Data Sovereignty: What to Ask Before You Buy

Ten specific questions to ask an AI vendor about data location before signing up, for Australian businesses that care about data sovereignty.

Read guide
Guide Guide

Privacy-First Cloud Storage for Australian Business: Honest Options

pCloud and Backblaze B2 compared for Australian businesses wanting data sovereignty, with the honest limitation neither is actually Australia-hosted.

Read guide
Guide Vendors

Microsoft Copilot Data Residency Australia: What Stays Local and What Doesn't

Does Microsoft 365 Copilot keep Australian business data in Australia? What Microsoft's data residency commitments actually cover, and where the gaps are.

Read guide
Guide ChatGPT

ChatGPT for Allied Health Practitioners in Australia

ChatGPT for allied health in Australia: what's safe, what risks patient data, and how AHPRA obligations affect AI tool use for registered practitioners.

Read guide
Guide ChatGPT

ChatGPT for Australian Lawyers: What the Privacy Act Means for Your Practice

Using ChatGPT as an Australian lawyer: Privacy Act APP 8 implications, where your data goes, training defaults, and safer configurations for client work.

Read guide
Guide Guide

What to Do When AI Goes Wrong

What to do when AI goes wrong in your business. Covers wrong outputs, data breaches, hallucinations, and bias incidents. 5-step incident response protocol.

Read guide
Guide Hiring

HR and AI in Australia: Compliance Obligations for Hiring, Screening, and Performance

Using AI in hiring raises privacy, discrimination and workplace risks. See what OAIC, Fair Work Ombudsman and AHRC guidance says HR teams should check.

Read guide
Guide Vendors

AI Vendor Breach Response Plan Template for Australian Businesses

Free AI vendor breach response plan template for Australian businesses. Copy it, fill in your contacts, and know exactly who does what in the first hour.

Read guide
Guide Guide

What Happens if Your AI Tool Gets Breached? Australian SMB Guide

AI vendor breaches can trigger NDB scheme notifications. Three common scenarios for Australian SMBs, what counts as serious harm, and the steps to take.

Read guide
Guide Guide

AI Data Breaches and the NDB Scheme: What Australian Businesses Must Do

An AI incident may become a notifiable data breach. See what OAIC guidance says about NDB timeframes and response steps Australian SMBs can prepare now.

Read guide
Guide Vendors

AI Tool Data Residency Comparison: Where Your Data Actually Goes

AI tool data residency compared for Australian businesses: AU data centres, training opt-out options, and what APP 8 means for your Privacy Act compliance.

Read guide
Guide OAIC

OAIC AI Compliance Checklist: What Australian Businesses Must Have in Place

A practical checklist based on OAIC AI privacy guidance, covering Privacy Act checks, AI registers, staff policies and records Australian SMBs should keep.

Read guide
Guide APPs

AI Vendor Contracts and the Privacy Act: What Australian Businesses Should Check

Six vendor contract clauses to review before signing, including APP 8, data residency, training opt-outs and breach notification for Australian businesses.

Read guide
Guide APPs

Australian Privacy Principles and AI Tools: A Plain-English Guide for SMBs

Which Australian Privacy Principles apply to AI tool use? APPs 1, 3, 5, 6, 8, and 11 explained for Australian SMBs, with a practical checklist for each.

Read guide
Guide ChatGPT

Can I Put Customer Data into ChatGPT? The Australian Privacy Act Answer

OAIC guidance highlights purpose, consent, security and overseas disclosure when Australian SMBs assess whether customer data can go into ChatGPT at work.

Read guide
Guide OAIC

OAIC AI Guidance for Australian Business: What the Privacy Regulator Expects

The OAIC has issued guidance on AI and privacy for Australian businesses. Here is what it means for an SMB using commercial AI tools, in plain English.

Read guide
Guide APPs

AI and the Australian Privacy Act: What Every Business Owner Needs to Know

What OAIC guidance says about using AI tools under Australia's Privacy Act, with plain-English checks for APPs 1, 3, 8 and 11 for business owners today.

Read guide
Guide APPs

Privacy Act December 2026 Deadline. AI Automated Decision-Making Rules for Australian SMBs

The OAIC says privacy policies must explain certain automated decisions from 10 December 2026. A plain-English guide with steps for Australian SMB owners.

Read guide
Guide APPs

AI Hiring and Recruitment. Privacy Act Obligations for Australian Businesses

OAIC guidance for Australian businesses using AI in recruitment, covering candidate notices, data handling and the privacy checks to make before rollout.

Read guide
Guide ADM

How to Update Your Privacy Policy for AI Automated Decisions. Australian Guide

OAIC guidance on updating privacy policies for automated decisions, with APP 1.7 context, plain-English sample wording and six practical steps for SMBs.

Read guide