This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If you've started using AI tools in your business and you're not sure whether you're doing it correctly under Australian privacy law, you're in good company. Most SMB owners using tools like ChatGPT, Microsoft Copilot, or AI-powered customer service platforms haven't had a formal privacy briefing on what that use actually requires. They've just started using the tools, because the tools are useful.
The problem is that Australian privacy law, specifically the Privacy Act 1988 and the Australian Privacy Principles that sit inside it, does apply to how you collect, use, store, and share personal information, including when an AI tool is doing the collecting and sharing on your behalf. Understanding which principles apply to AI use, and what they actually ask of you, is the first step to using these tools with confidence rather than anxiety.
For a broader overview of how the Privacy Act applies to AI use in general, see our Privacy Act and AI guide. This article goes one level deeper, working through the specific Australian Privacy Principles that matter most for AI tool use, one at a time.
In short: Six Australian Privacy Principles are directly relevant to how most SMBs use AI tools: APP 1 (transparency about how you manage personal information), APP 3 (rules on what you can collect), APP 5 (telling people what you're collecting and why), APP 6 (limits on how you use and share data), APP 8 (cross-border disclosure rules when data goes to overseas AI servers), and APP 11 (keeping data secure). Each one has a practical checklist below.
What Are the Australian Privacy Principles?
The Australian Privacy Principles are 13 legally binding rules that sit inside the Privacy Act 1988. They govern how organisations collect, hold, use, and disclose personal information about individuals. Personal information means anything that could identify a specific person, including a name, email address, phone number, health record, or financial detail.
Not every business in Australia is covered. If your business has an annual turnover of more than $3 million, you are covered by the Privacy Act regardless of your industry. Some smaller businesses are also covered depending on their activities, including businesses that handle health information, operate as credit providers, or are contracted service providers to government agencies. If you're unsure whether the Act applies to your business, the OAIC guidance on AI is a useful starting point, and a privacy lawyer can confirm your status in one short consultation.
Once the Privacy Act applies to your business, all 13 APPs apply. This guide focuses on the six that are most directly triggered by ordinary AI tool use.
Note on upcoming changes: The Privacy Act is currently being updated. Key changes affecting automated decision-making are expected to come into force by December 2026. These changes are most relevant to APP 1. See our ADM deadline guide for what's coming and what to do before it arrives.
APP 1: Open and Transparent Management of Personal Information
APP 1 requires organisations to manage personal information in an open and transparent way. The OAIC's full APP 1 guidance is at oaic.gov.au. In practice, this means having a Privacy Policy that accurately describes how you handle personal information, and keeping that policy current. It also means that if you ask someone for their personal information, you're not doing anything with it that would surprise them or that they haven't been told about.
Where AI tools come in: if your business is using an AI tool that processes customer data, staff data, or any other personal information, the OAIC's guidance indicates your Privacy Policy should reflect that. A policy written before your business used any AI tools is likely out of date. You should also be aware that the upcoming amendments to the Privacy Act will introduce new transparency requirements specifically for automated decision-making, which includes many AI functions. The December 2026 ADM deadline is the most immediate compliance pressure for businesses using AI in ways that affect individuals.
APP 1 Checklist for AI Tool Use
- Review your Privacy Policy and confirm it mentions the use of AI tools that process personal information.
- Check that your policy names the categories of data the AI tool handles (for example, customer contact details, support queries, financial records).
- If your AI tool makes decisions about individuals (for example, routing support tickets, scoring leads, or filtering applications), note this in your policy.
- Set a review date for your Privacy Policy at least annually, or whenever you adopt a new AI tool.
- Read the ADM December deadline guide to confirm what additional disclosures you'll need before the new rules apply.
APP 3: Collection of Solicited Personal Information
APP 3 sets out the rules for what personal information you can collect. The core rule is that you should only collect personal information that is reasonably necessary for your functions or activities. You should not collect more than you need, and you should collect it by lawful and fair means.
AI tools create a specific risk here because they are very good at collecting and processing large volumes of data, often more than you'd consciously choose to collect by hand. An AI customer service chatbot, for example, might log full conversation transcripts including sensitive disclosures that a customer makes incidentally. An AI note-taking tool in a meeting might capture everything said, including information about third parties who weren't expecting to be recorded.
Applying APP 3 to AI tool use means thinking about what the tool is actually collecting, not just what you intended it to collect, and confirming that collection is limited to what your business genuinely needs.
APP 3 Checklist for AI Tool Use
- Identify every AI tool your business uses that collects or processes personal information, even incidentally.
- For each tool, confirm what data it actually collects versus what you intended it to collect. Read the vendor's data documentation, not just the marketing page.
- Check whether the tool collects sensitive information (health details, financial records, political opinions). Sensitive information has a higher collection threshold under the Privacy Act.
- If the tool collects more data than you need, check whether you can configure it to limit collection, or consider whether a different tool is more appropriate.
- Do not use AI tools to collect personal information through deceptive or unfair means. For example, do not use an AI chat tool that presents itself as a human agent without disclosure.
APP 5: Notification of the Collection of Personal Information
Under APP 5, the OAIC's guidance outlines that businesses are expected to take reasonable steps to notify individuals of certain things: who you are, what you'll use the information for, whether you'll disclose it to third parties, and whether you're likely to disclose it overseas. The OAIC's guidance indicates this notification should happen at the time of collection, or as soon as practicable afterwards. See APP 5 guidance at oaic.gov.au.
For AI tools, this is frequently a gap. If your business website has an AI chatbot and a customer types their name and complaint into it, does your website make it clear that information is being collected, who holds it, and where it goes? Many SMBs have deployed AI chat tools without updating their website's privacy notice or collection statement to account for the new data flows.
APP 5 Checklist for AI Tool Use
- For each customer-facing AI tool (chatbot, form, voice assistant), confirm there is a visible notice at the point of collection explaining what information is being collected and why.
- Check that your privacy notice or collection statement mentions that data may be processed by a third-party AI platform.
- If personal information collected by an AI tool is sent to overseas servers (which is the case for most major AI platforms), this must be disclosed. See APP 8 below.
- For AI tools used internally with staff data, confirm staff have been notified of how AI tools process their work-related information.
- Review website footers and terms of service to confirm they reference AI tool data collection where relevant.
APP 6: Use or Disclosure of Personal Information
APP 6 sets out when you can use or disclose personal information that you've already collected. The primary rule is that personal information should only be used or disclosed for the primary purpose for which it was collected, or for a secondary purpose that the individual would reasonably expect, or where they've consented to the secondary use.
AI tools regularly create APP 6 tension because they tend to do things with data beyond what a customer originally expected when they handed over their details. For example, a customer who gave you their email address to receive an invoice would not necessarily expect that email to be processed by an AI tool that analyses customer sentiment or categorises support cases. Whether that constitutes a breach of APP 6 depends on the specific circumstances, but the question is worth asking.
If you're also sharing customer data with an AI vendor, it's worth checking whether that vendor uses your data to train their models. Some vendors do, and some don't. This matters under APP 6 because model training is a use of the personal information beyond the immediate transaction, and it's not something most customers would expect. See the customer data and ChatGPT guide for a specific look at how this plays out with one of the most commonly used tools.
APP 6 Checklist for AI Tool Use
- For each AI tool that handles customer data, identify the original purpose for which that data was collected. Confirm the AI tool's use of the data is consistent with that purpose.
- Check whether your AI vendor uses your data to train their AI models. Look for this in the vendor's terms of service or data processing agreement, not just their marketing materials.
- If training data use is opt-in, confirm whether you've opted in or out and document that decision.
- Do not use personal information collected for one purpose (for example, sales inquiries) to feed an AI tool doing a different function (for example, HR screening) without fresh consent or a clear secondary purpose basis.
- If you intend to use personal data for AI-assisted profiling or segmentation, check whether this is a use your customers would reasonably expect.
APP 8: Cross-Border Disclosure of Personal Information
APP 8 is the Australian Privacy Principle most directly triggered by using cloud-based AI tools, and it's the one Australian SMBs most often overlook. APP 8 requires that before you disclose personal information to someone overseas, you take reasonable steps to ensure that the overseas recipient will handle the information in a way that is at least as protective as the Australian Privacy Principles require.
Almost every major AI platform, including ChatGPT (OpenAI, US), Microsoft Copilot (US), Google Gemini (US), and Anthropic's Claude (US), processes data on servers outside Australia. When you input personal information about a customer, employee, or any individual into these tools, that constitutes a cross-border disclosure under Australian law. APP 8 applies.
There is an exception under APP 8.2(b): if the individual has consented to the overseas disclosure after being informed that APP protections may not apply, the obligation on your business is reduced. This is why some businesses are updating their privacy notices to include a cross-border disclosure consent clause specifically for AI tool use. It's a practical workaround, but it requires that the consent is genuinely informed and freely given, not buried in a terms-of-service click-through.
APP 8 Checklist for AI Tool Use
- For every AI tool you use, confirm where the vendor's servers are located. Look in the vendor's data processing agreement or privacy documentation. Do not assume Australian data residency without checking.
- If the AI tool processes personal information and the servers are overseas, APP 8 obligations apply under the Privacy Act. Review the OAIC's guidance at oaic.gov.au.
- Review whether the vendor has contractual commitments to handle data consistent with Australian Privacy Principles. Many major vendors do offer data processing agreements that include these commitments, but you need to review and sign them.
- Consider updating your Privacy Policy and collection notices to include disclosure that personal information may be transferred to and processed by overseas AI services.
- If you rely on the APP 8.2(b) consent exception, ensure the consent is genuinely informed: the individual must be told that the overseas country's protections may differ from Australia's, and they must agree to this before the data transfer occurs.
- For highly sensitive data (health information, financial records), consider whether an Australian-hosted or Australian-compliant AI option exists before relying on an overseas service.
APP 11: Security of Personal Information
APP 11 requires that you take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. It also requires you to destroy or de-identify personal information when you no longer need it, and when you are no longer required by law to retain it.
AI tools introduce specific security considerations. If staff are copying and pasting customer data into a public AI chatbot interface, that data is being transmitted to and potentially retained by a third party. If your business uses an AI tool with weak access controls, an employee or contractor could access personal information they shouldn't be able to reach. If the AI vendor experiences a data breach, your customers' data may be at risk even though you did nothing wrong on your own systems.
APP 11 doesn't require perfection, it requires reasonable steps. For most SMBs, reasonable steps include choosing AI vendors with credible security certifications, configuring tools to avoid unnecessary data retention, and training staff on what personal information should and shouldn't be entered into AI tools.
APP 11 Checklist for AI Tool Use
- Confirm that each AI vendor you use has credible security certifications (SOC 2 Type II and ISO 27001 are the most common to look for).
- Review the vendor's data retention policy: how long do they keep data entered into their platform? Is there an option to reduce the retention period?
- Set an internal policy on what types of personal information staff are permitted to enter into external AI tools. At minimum, exclude full names combined with sensitive information (health, financial, identity documents) unless a specific compliant process is in place.
- Check whether your AI tool accounts are protected by multi-factor authentication and that access is restricted to staff who need it.
- Confirm you have a process for responding to an AI vendor data breach. Under the Notifiable Data Breaches scheme, you may have obligations to notify the OAIC and affected individuals if a breach involving personal information occurs.
- When you stop using an AI tool or a vendor, request deletion of your data from their systems and confirm it in writing where possible.
Which Industries Face Extra Scrutiny
Every business covered by the Privacy Act is expected to apply the APPs described above. But some industries face additional obligations or higher-stakes consequences when AI tools are involved.
Healthcare and allied health. Health information is sensitive information under the Privacy Act, and it has a higher collection threshold and stricter use limits. Using AI tools that process patient notes, clinical records, or health-related communications requires careful attention to APPs 3, 6, and 11 in particular. Medicare and private health data stored in overseas AI systems is a specific concern.
Accounting, bookkeeping, and financial services. AI tools used for bookkeeping, financial reporting, or client advisory functions often process detailed financial information. ASIC and the Tax Practitioners Board have their own obligations around client confidentiality that overlay the Privacy Act requirements. Sending client financial records to an overseas AI platform without appropriate contractual protections is a risk in this context.
Legal professionals. Legal professional privilege and confidentiality obligations are separate from the Privacy Act but interact with it. Solicitors and barristers in particular need to consider whether inputting client matter information into a cloud-based AI tool is consistent with their professional obligations, regardless of what the Privacy Act requires.
Businesses contracting to government. If your business provides services to Commonwealth or state government agencies, you may be subject to additional privacy obligations under government procurement requirements, including requirements about where data is stored and processed.
What to Actually Do Next
The APPs are not a reason to stop using AI tools. They are a framework for using those tools responsibly, and most of what they require is practical and achievable for a business without a dedicated legal team.
A reasonable starting point for most SMBs is this: list every AI tool your business currently uses, identify which ones process personal information, and work through the six checklists above for each one. That audit will surface your actual gaps, as distinct from the theoretical ones, and give you a prioritised list of things to address.
Our free AI Compliance Checker tool walks through many of the same questions covered in the six checklists above and gives you a quick read on where your gaps are.
For a deeper read on the OAIC's own guidance on AI and privacy, including how the regulator expects businesses to interpret the APPs in the context of AI adoption, see our OAIC AI guidance breakdown. For the specific question of whether it is safe to enter customer data into ChatGPT, the customer data and ChatGPT article works through the details.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our Claude AI review for Australian business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our AI governance by region.
Do the Australian Privacy Principles apply to my small business if I use AI tools?
The Privacy Act 1988 and the APPs apply to your business if your annual turnover exceeds $3 million, or if you operate in certain industries regardless of turnover (including health services, credit providers, and government contractors). If you meet those thresholds, the APPs apply to everything you do with personal information, including when an AI tool is doing the processing on your behalf. If you're below the threshold and not in a covered industry, the Act may not apply, but you may still face contractual or reputational obligations to handle customer data responsibly.
What counts as personal information under the Privacy Act?
Personal information is any information or opinion about an identified individual, or an individual who is reasonably identifiable. This includes names, email addresses, phone numbers, home addresses, health information, financial details, and in many cases IP addresses and device identifiers. It does not need to be sensitive or secret to count as personal information. If it can identify a specific person, it is personal information for the purposes of the Act.
Can I use overseas AI tools like ChatGPT without breaching APP 8?
Yes, but you need to address APP 8 rather than ignore it. The most common approaches are: signing a data processing agreement with the vendor that includes APP-equivalent protections, relying on the individual's informed consent to the overseas transfer, or verifying that the overseas country has comparable privacy protections. Simply using an overseas AI tool without taking any of these steps is the gap most SMBs currently have. The customer data and ChatGPT guide works through this specifically for OpenAI's platform.
What is the difference between APP 5 and APP 1, and do I need to address both?
APP 1 requires your business to have a Privacy Policy that accurately reflects how you manage personal information overall. APP 5 requires you to notify individuals at the point of collection about specific things: who you are, what you'll use their information for, and whether you'll disclose it overseas. Both apply when you use AI tools. APP 1 is the policy-level obligation; APP 5 is the point-of-contact notification. You need both: a current Privacy Policy that mentions AI tool use, and a collection notice or disclosure that appears when you actually collect personal information through an AI tool.
Does it matter if an AI tool uses my customer data to train its models?
Yes, it matters under APP 6. APP 6 limits how you can use or disclose personal information beyond the purpose for which it was collected. If an AI vendor uses data you provide to train their AI models, that constitutes a further use of the personal information. Whether this is permitted depends on the vendor's terms and whether your customers were notified and consented. Many major AI vendors now offer options to opt out of training data use, or provide enterprise tiers where training is excluded. Check your vendor's current terms rather than assuming a default position either way.
What happens if I don't comply with the Australian Privacy Principles?
The OAIC can investigate complaints and, for serious or repeated breaches, can take enforcement action including civil penalty proceedings. Fines for serious breaches can reach $50 million for corporations (or a formula based on turnover or benefit obtained if higher). Beyond regulatory penalties, a privacy breach can damage client relationships in industries where confidentiality is a core part of the service offering, such as accounting, legal, and health. Most SMBs face the compliance risk as a reputational one first and a regulatory one second, but both are real.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Try our free AI Compliance Checker to work through your obligations across the APPs covered in this article, and see where your gaps are.
Try the Free Compliance Checker