This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your business uses AI tools and handles any information about clients, customers, or employees, Australia's Privacy Act 1988 applies to you. That's not a maybe. It's a legal reality that most small and medium businesses haven't fully come to terms with yet, largely because the conversation around AI and privacy has been dominated by enterprise compliance teams and law firms writing for other lawyers.
This article is not that. It's a plain-English guide to what the Privacy Act actually requires from a business using AI tools, written for a business owner who needs to know what to do, not what to cite in a legal submission. We'll cover the four Australian Privacy Principles most directly relevant to AI use, what they mean in practice, and what steps your business should take.
A note on timing: the Privacy Act is currently undergoing its most significant reform in decades. New rules around automated decision-making are scheduled to take effect in December 2026. That deadline and what it means for your business is covered separately here. This article focuses on obligations that already apply today.
In short: If your business has an annual turnover above $3 million, or handles health information, or provides services to government, the Privacy Act applies to you right now. Using AI tools that process personal information counts as handling that information under the Act. You have obligations around collection, storage, disclosure, and security. Failing to meet them carries civil penalties of up to $50 million for serious or repeated breaches.
This article is general information, not legal advice. Whether the Privacy Act applies to your business, and what it requires, depends on your specific circumstances. Consult a qualified privacy professional for advice on your situation.
Does the Privacy Act Apply to Your Business?
The Privacy Act 1988 applies to most Australian businesses, but not all. The key threshold is annual turnover: businesses with a turnover above $3 million per year are covered automatically. Below that threshold, coverage depends on the type of data you handle or the nature of your business activities.
Your business is covered regardless of turnover if it: handles health information, operates as a private health service provider, discloses personal information for benefit, trades in personal information, provides services under a government contract, or operates as a credit reporting body. It also applies if you are a related body corporate to a covered entity.
If you're unsure whether you're covered, the safe working assumption for any business using AI tools in a professional context is that you are. The risk of assuming you're exempt and being wrong is significantly higher than the cost of treating the obligations as real and building basic practices around them.
The Four APPs That Matter Most for AI Use
The Privacy Act contains 13 Australian Privacy Principles (APPs). They cover everything from how you collect data to how you handle requests for access and correction. For businesses using AI tools, four of them are directly and immediately relevant: APP 1, APP 3, APP 8, and APP 11. Understanding these four is where most businesses need to start.
APP 1: Having a Privacy Policy That Reflects What You Actually Do
APP 1 requires covered entities to have an up-to-date privacy policy that accurately describes how personal information is managed. That includes disclosing whether personal information may be sent overseas, and if so, to which countries.
Here's why that matters for AI use: when you paste a client's name, email address, or case notes into ChatGPT, that information is transmitted to OpenAI's servers in the United States. When your team uploads a document to a cloud-based AI writing tool, that document and any personal information it contains is processed by a third-party platform, often in a US or EU data centre.
If your current privacy policy says nothing about overseas disclosure or AI processing, it is almost certainly out of date. APP 1 doesn't require you to stop using AI tools. It requires you to be honest with your clients about how their information is handled. How to update your privacy policy to reflect AI use is covered in detail here.
APP 3: Only Collecting What You Actually Need
APP 3 covers the collection of personal information. It requires that you only collect information that is reasonably necessary for your business functions, and that you collect it by lawful and fair means.
For AI users, APP 3 has a specific practical implication: the way staff use AI tools often results in more personal information being shared than is actually needed. When someone copies a client email thread into an AI tool to get a summary or a draft reply, they may be including contact details, account numbers, medical references, or sensitive business information that the AI tool doesn't need to perform the task.
APP 3 compliance here is a drafting and training discipline. It means establishing a clear practice of stripping or anonymising personal information from prompts before they're submitted to AI tools, wherever the task can be done without it. Not every task allows for full anonymisation, but where it does, it should be the default.
APP 8: Cross-Border Disclosure and What It Means When You Use Cloud AI Tools
APP 8 is the most significant APP for Australian businesses using AI tools, and the one most businesses haven't thought through. It governs the disclosure of personal information to overseas recipients, which is precisely what happens when you use any major AI platform.
APP 8 requires that before disclosing personal information to an overseas recipient, you take reasonable steps to ensure that recipient will handle the information in a way that meets Australian Privacy Principle standards. The obligation here is on your business, not on the overseas provider.
There are two common ways businesses meet this obligation. The first is through contractual arrangements: a data processing agreement or similar contract with the overseas provider that commits them to handling data in compliance with Australian standards. The second is an exception that applies in limited circumstances: where the individual has been informed of the overseas disclosure and expressly consented to it.
For most AI tool use in a business context, the practical answer is vendor contracts. Check whether the AI tools your business uses offer a Data Processing Agreement (DPA) and review what it actually says about data handling and storage locations. OpenAI, Microsoft, Google, and most major enterprise AI vendors provide DPAs for business customers. Free consumer-tier accounts typically do not carry the same contractual protections.
APP 8 liability reminder: If an overseas AI provider mishandles personal information you disclosed to them, and they do not meet Australian Privacy Principle standards, your business remains accountable under Australian law. The APP 8 exception for relying on a provider's assurances does not fully transfer liability. This is why reviewing vendor contracts matters, not just trusting their marketing language about privacy.
APP 11: Keeping Personal Information Secure
APP 11 requires that you take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. It also requires that you destroy or de-identify personal information when it is no longer needed for the purpose it was collected.
AI tool use creates new APP 11 exposure in two main ways. The first is prompt history and data retention: many AI tools store conversation history by default, which means personal information submitted in a prompt may persist on a vendor's servers after the task is complete. Understanding each vendor's data retention settings and turning off retention where possible is a basic APP 11 step.
The second is file upload risk. If your team uploads documents to AI tools for analysis, processing, or summarisation, those documents may include personal information that is then retained by the vendor, indexed, or used in model training (depending on the platform and account tier). Enterprise or business accounts typically offer data handling terms that prevent training data use. Consumer accounts typically do not.
For businesses storing documents that contain personal information, using a compliant, encrypted storage solution as the source of truth, rather than relying on AI tool storage, is good practice. pCloud is one option worth considering for businesses that need encrypted, audit-ready file storage. It offers zero-knowledge encryption and European data residency options (affiliate disclosure: this is an affiliate link). The critical point is that wherever personal information is stored, the storage arrangement needs to meet APP 11 standards, and many default AI tool environments do not.
What This Looks Like in a Real Business
Consider a 20-person accounting practice. Staff use ChatGPT regularly to draft client emails and summarise meeting notes. A team member uploads a spreadsheet with client names, contact details, and account balances to an AI tool to speed up a reconciliation task.
Under the current Privacy Act, that practice has at minimum the following obligations: a privacy policy that discloses overseas processing (APP 1), practices that limit what personal information enters AI prompts to what's necessary (APP 3), a vendor contract with OpenAI that meets APP 8 requirements for cross-border disclosure, and controls over how long that information is retained on OpenAI's servers (APP 11).
Most practices don't have all four in place. That gap is not unusual, and it doesn't mean the practice is acting in bad faith. It means the compliance work is catching up to the speed of AI adoption. The OAIC has published guidance specifically addressing AI and privacy obligations. That guidance is covered in full here.
What About Shadow AI?
Shadow AI refers to AI tool use by staff that the business hasn't sanctioned, tracked, or reviewed. It's extremely common. A staff member who uses a personal ChatGPT account to help with work tasks, or who connects a third-party AI plugin to a business platform, is engaging in shadow AI use.
The problem with shadow AI from a Privacy Act perspective is that the business typically has no visibility into what personal information is being shared with which platforms, under what terms. This creates real APP 8 and APP 11 exposure without the business even knowing it exists.
Addressing shadow AI risk starts with a staff AI policy and a basic audit of what tools your team is actually using. How to conduct a shadow AI audit for an Australian SMB is covered in this guide.
What Your Business Should Actually Do
The following steps address the most common Privacy Act gaps for businesses using AI tools. They are ordered by priority: the first two should be done immediately, the rest within 30 to 60 days.
1. Audit which AI tools your business is using. Include tools used by staff on personal accounts for work purposes. List the vendor, the account type (free vs business), and what types of information staff are putting into those tools. This is the foundation for everything else. It does not need to be a large project. A simple spreadsheet will do.
2. Review or obtain vendor data processing agreements. For any AI tool handling personal information, check whether you have a DPA in place. For OpenAI, this is available under their business terms. For Microsoft Copilot under a Microsoft 365 Business subscription, it's part of the standard Microsoft Customer Agreement. For Google Workspace AI features, it's covered by Google's data processing terms. Free consumer accounts generally do not include DPAs.
3. Update your privacy policy. Add a clause that discloses the use of AI tools, the categories of personal information that may be processed through them, and the countries where that processing occurs. This does not need to be long. It needs to be accurate. A template for updating your privacy policy is available here.
4. Establish a staff AI policy. A written policy that sets out which AI tools are approved for business use, what categories of information can and cannot be included in prompts, and how staff should handle AI outputs that contain personal information. This doesn't need to be a 30-page document. A one-page policy that your team actually reads is worth more than a comprehensive one they don't. A free template for an Australian SMB AI staff policy is available here.
5. Review data retention settings on AI tools. For each approved tool, confirm whether conversation history and uploaded files are stored, for how long, and how to turn off retention or request deletion. This is the APP 11 control. It takes 15 minutes per tool to check and configure, and it closes a real gap.
Industry-Specific Considerations
Some industries carry additional obligations on top of the Privacy Act that affect how AI tools can be used with client information.
Accounting and bookkeeping practices handle tax file numbers, financial records, and sometimes health information (for salary packaging). TFNs carry specific protections under the Tax Administration Act and are among the most sensitive identifiers in the Privacy Act framework. They should not enter AI tool prompts under any circumstances.
Healthcare providers and allied health businesses handle health information, which is a sensitive category under the Privacy Act and carries heightened obligations. OAIC guidance specifically cautions against using AI tools that lack enterprise data handling terms for health information processing.
Legal practices have professional obligations around client confidentiality that operate alongside (and in some respects above) the Privacy Act. The Law Society and state law councils have issued guidance on AI tool use. Client information should not be submitted to AI tools without explicit client consent and appropriate confidentiality controls in the vendor contract.
Real estate agencies handle significant volumes of personal information, including identity documents, financial records, and tenancy histories. The same APP 8 and APP 11 obligations apply, and the volume of personal information moving through typical real estate workflows makes the risk higher than many principals realise.
What the December 2026 Deadline Adds
The Privacy Act reform package includes new rules for automated decision-making (ADM) that are scheduled to commence in December 2026. These rules will require businesses to disclose when significant decisions affecting individuals are made using automated means, and in some cases to provide individuals with access to information about how those decisions were made.
For most SMBs, the December deadline is not the most urgent priority right now. Getting the foundational APPs covered (especially APP 1, APP 3, APP 8, and APP 11) comes first. But if your business uses AI tools to assist with decisions about customers, employees, or loan applicants, you need to understand what the ADM rules will require. The full breakdown of the ADM deadline and what it means for Australian businesses is here.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: can staff upload customer data to AI tools, AI data residency in Australia, AI tools with Australian data centres, HR AI compliance in Australia, AI vendor contracts and Privacy Act, AI data breaches and the NDB scheme, Claude AI review for Australian business, Notion AI review for Australian business, and Microsoft Copilot pricing in Australia.
Related reading: our how Australian Privacy Principles apply to AI tools.
Related reading: our using AI for tax preparation in Australia, our how Australian accountants are using AI, and our using AI for legal research.
Related reading: our legal liability for AI-generated content in Australia.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our AI content verification checklist and our AI scheduling software for healthcare practices.
Related reading: our Microsoft Copilot data residency in Australia.
For the full Australian Privacy Act compliance hub, with links to every related guide, see our Australian Privacy Act hub.
Does the Privacy Act apply to my small business if I'm under the $3 million turnover threshold?
It may. The $3 million threshold is the most common exemption, but it has exceptions. If your business handles health information, provides services under a government contract, or operates as a related entity to a larger covered business, you're covered regardless of turnover. If you're below the threshold and none of the exceptions apply, you're technically exempt from the Act, but state-level privacy legislation and professional obligations (in legal, health, and financial services) may still impose similar requirements. When in doubt, treating the obligations as real is the lower-risk position.
Is it legal to put client information into ChatGPT?
It depends on the account type and what your privacy policy discloses. Using a free consumer ChatGPT account to process personal client information creates APP 8 risk, because there is typically no Data Processing Agreement in place and data may be used for model training. A ChatGPT Team or Enterprise account includes a DPA with data handling commitments and turns off training data use. The short answer: consumer tier, risky; business tier with a DPA in place, manageable with appropriate disclosure in your privacy policy. The OAIC has published guidance on this point that is worth reading directly.
What is APP 8 and why does it matter for AI tools?
APP 8 governs the disclosure of personal information to overseas recipients. Almost every major AI tool processes data on servers outside Australia, which means using them with personal information constitutes an overseas disclosure under Australian law. APP 8 requires that before making such a disclosure, you take reasonable steps to ensure the overseas recipient will handle the information in compliance with Australian Privacy Principle standards. In practice, this means having a Data Processing Agreement with your AI vendor that commits them to those standards. Without one, your business bears the compliance risk if something goes wrong.
What penalties can a business face for Privacy Act breaches?
For serious or repeated breaches, civil penalties can reach up to $50 million, or three times the benefit gained from the breach, or 30% of adjusted turnover, whichever is higher. These are the post-2022 reform figures. Less severe breaches can result in enforceable undertakings, compliance notices, or determinations by the OAIC. For most SMBs, the more immediate risks are reputational damage and the cost of responding to a complaint investigation, rather than a maximum penalty. But the direction of travel under Privacy Act reform is toward stronger enforcement, not weaker.
Do I need to tell my clients I'm using AI tools to handle their information?
Yes, under APP 1. Your privacy policy must accurately describe how personal information is managed, including whether it may be disclosed to overseas recipients and for what purposes. If your business uses AI tools that process client information, that should be disclosed in your privacy policy. The disclosure does not need to name specific tools or version numbers, but it should describe the category of processing and the countries involved. Some professional service contexts, particularly legal and health, may require more specific disclosure or explicit consent before AI processing of client files.
What is the simplest thing I can do today to start addressing Privacy Act obligations?
Two steps that take under an hour: first, list every AI tool your business or your team uses, including tools on personal accounts used for work. Second, check whether you have a Data Processing Agreement in place with each vendor. If you don't, contact the vendor or check their business plan terms. A business account with a DPA for your most-used AI tool closes the most immediate APP 8 gap and is a concrete, auditable step. From there, updating your privacy policy and establishing a staff AI policy are the next priorities.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Once you understand your Privacy Act obligations, the next step is putting a staff AI policy in place. A written policy that tells your team what's approved, what's not, and how to handle personal information in AI tools closes the gap between knowing the rules and actually following them.
Get the Free AI Staff Policy Template