This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If you have already decided ChatGPT is useful for your business, you are now trying to work out where the Privacy Act draws the line. The answer is not a blanket yes or no. It depends on what customer data you are using, whether that data identifies an individual, and what controls you have in place before it leaves your system.
In short: You can use ChatGPT with customer data in some circumstances, but not without safeguards. The Privacy Act 1988 and Australian Privacy Principles apply whenever you handle personal information. Sending identifiable customer data to ChatGPT without the right controls is likely an APP breach. Anonymised or de-identified data is a different situation. The sections below spell out exactly where the line sits. For the full Privacy Act background, see our Australian Privacy Act guide for AI users.
This article is general information, not legal advice. Whether a specific use of ChatGPT with customer data complies with the Privacy Act depends on your specific facts. Consult a qualified privacy professional for advice on your situation.
What the Privacy Act Actually Covers Here
The Privacy Act 1988 applies to any organisation with an annual turnover above $3 million, as well as certain smaller businesses in health, financial services, and other regulated sectors. If your business collects, holds, or uses personal information about individuals, the Act and its 13 Australian Privacy Principles (APPs) apply to what you do with that data.
When you type customer information into ChatGPT, you are disclosing that data to a third party: OpenAI, a US-based company. That triggers two APPs immediately. APP 6 governs secondary use of personal information (using data for a purpose beyond what it was collected for). APP 8 governs cross-border disclosure of personal information to overseas recipients.
Your customers almost certainly did not consent to their data being sent to an AI model hosted on US servers when they gave you their contact details, order history, or health records. That gap between original collection purpose and new use is where compliance risk lives.
Here is what that looks like day to day. Your property manager needs to send a lease renewal reminder to a tenant whose lease expires next month. Instead of checking whether this was actually compliant, she would paste the tenant's name, address, and phone number straight into ChatGPT so it could draft a personalised email. That is a cross-border disclosure of personal information under APP 8, done in seconds without anyone deciding to take that risk. After the fix, she drafts the same email using placeholders (Tenant A, the property address) and swaps the real details back in herself before sending. Same five minutes saved, no personal information ever left your system.
When YES: You Can Use Customer Data with ChatGPT
There are circumstances where using customer data with ChatGPT is compliant. These are not loopholes; they are the conditions the Privacy Act already provides for.
The data is de-identified. If you remove all direct identifiers (name, email, phone, address, account number) and there is no realistic way to re-identify the individual from the remaining data, it is no longer personal information under the Act. You can use genuinely de-identified data with ChatGPT without Privacy Act constraints. This covers things like aggregate sales trends, anonymised support ticket categories, or templated scenarios that contain no real individual's details.
You have explicit, informed consent for this specific use. If your privacy policy or a specific consent form tells customers their data may be processed using third-party AI tools, and they have agreed to that, you have a basis to proceed. The consent must be specific enough to cover AI processing and cross-border disclosure, not just a generic "we may share your data with service providers" clause. Most existing privacy policies do not meet this standard.
You are using ChatGPT Enterprise or an API deployment with data processing controls in place. OpenAI's standard consumer ChatGPT and ChatGPT Plus plans have used conversation data for model training by default (you can opt out, but this requires action). ChatGPT Enterprise and API access with the right contract terms can provide data processing agreements that make the cross-border disclosure more manageable from a compliance standpoint. This does not eliminate APP 8 obligations, but it provides a documented basis for the disclosure.
The safest default: strip any data to the minimum needed, remove all identifiers before it goes into ChatGPT, and keep a note of what you sent and why. That habit covers most SMB use cases without requiring a legal review for every prompt.
When NO: You Cannot Use Customer Data with ChatGPT
The following scenarios may create compliance risk under current Privacy Act settings. These are not edge cases. They are the common ways Australian SMBs currently use ChatGPT without realising the exposure.
Pasting customer records, emails, or contact details into a standard ChatGPT chat session. This is a direct cross-border disclosure of personal information to a US-based third party. Without an APP 8 compliant basis (written consent or a reasonably enforceable equivalent), this breaches the Privacy Act. It does not matter if your intention was innocent, such as drafting a reply email. The disclosure itself is the issue.
Uploading documents that contain personal information. ChatGPT's document upload feature (available on Plus and above) sends file contents to OpenAI's servers. If those files contain names, contact details, health records, financial information, or any other personal data, the same APP 8 issue applies.
Using ChatGPT to process sensitive information. Sensitive information has a higher protection threshold under the Act. Health information, racial or ethnic origin, religious beliefs, sexual orientation, criminal records, and similar categories require explicit consent for almost any secondary use or disclosure. Using ChatGPT to summarise a patient's history, or to draft a letter referencing an employee's medical situation, creates significant exposure.
Assuming your privacy policy covers it. A standard SMB privacy policy written before 2022 almost certainly does not contemplate AI processing of personal data. Do not assume existing consent covers new uses. The OAIC's guidance indicates that consent relied upon for AI-based processing of personal information should explicitly cover AI tools. The OAIC has flagged this directly in its AI guidance for Australian organisations.
The APP 8 Cross-Border Disclosure Problem
APP 8 is the principle that catches most businesses off-guard. It requires that before you disclose personal information to an overseas recipient, you take reasonable steps to ensure the recipient does not breach the APPs in relation to that information, or you have the individual's consent to the disclosure.
OpenAI is a US company. Its servers are primarily in the US. There is no Australia-US adequacy arrangement comparable to the EU framework. This means that sending personal information to ChatGPT is a cross-border disclosure to a country without equivalent privacy protections, and APP 8 puts the compliance obligation squarely on your business, not OpenAI.
The practical consequence: if OpenAI misuses or mishandles personal information you sent to ChatGPT, your business can be held accountable by the OAIC as if you had mishandled it yourself. This is not a theoretical risk. The OAIC's updated AI guidance, issued in 2024, explicitly named AI model inputs as a cross-border disclosure scenario requiring APP 8 compliance. See the Privacy Act amendment deadline guide for what the December changes mean for how this is enforced.
Practical Safeguards That Change the Answer
Compliance here is not all-or-nothing. These safeguards move you from the NO column to the YES column for specific use cases.
De-identify before you paste. Create a habit of replacing real names with placeholders (Customer A, Client 1), removing contact details, and replacing any identifying reference numbers before sending data to ChatGPT. This takes ten seconds and removes the personal information from the equation entirely.
Update your privacy policy to name AI tools. If using ChatGPT with customer data on a consent basis, the OAIC's guidance indicates the privacy policy should describe that use. Naming the category of tool (AI language models), the cross-border disclosure, and providing customers a genuine opt-out. This is a policy update, not a legal retainer. If you need a starting point, the free AI staff policy template covers the internal governance side and includes a privacy policy update checklist.
Use the API or ChatGPT Enterprise if you need to process real customer data. The standard ChatGPT consumer product is not built for business data handling. OpenAI's API and Enterprise plans include data processing agreements that provide better contractual protections and clearer data handling terms. These are not perfect solutions to APP 8, but they give you a documented basis for the disclosure and, importantly, turn off training data use by default.
Train staff on what not to paste. Most Privacy Act breaches involving AI tools in SMBs are not deliberate; they are staff doing something efficient without realising the compliance implication. A simple one-page internal guideline covering what can and cannot go into ChatGPT is a proportionate control for a business of 5 to 50 people. This is basic governance, not complexity.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: AI data residency in Australia, AI tools with Australian data centres, HR AI compliance in Australia, AI vendor contracts and Privacy Act, AI data breaches and the NDB scheme, Claude AI review for Australian business, Notion AI review for Australian business, and Microsoft Copilot pricing in Australia.
Related reading: our what shadow AI is and why it matters for your business, our how to audit shadow AI use in your organisation, and our shadow AI audit checklist.
Related reading: our how Australian Privacy Principles apply to AI tools.
Related reading: our best AI password manager for business, our AI password management for remote teams in Australia, and our how Australian lawyers can use ChatGPT safely.
Related reading: our AI hallucinations and Australian Consumer Law, our AI tools for Australian healthcare practices, and our ChatGPT for allied health practitioners in Australia.
Related reading: our the best AI productivity tools for Australian business and our best AI tools for saving time in your business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Related reading: our AI for GP clinics in Australia and our how healthcare businesses are using AI.
For the broader Privacy Act picture beyond ChatGPT specifically, see our Australian Privacy Act hub.
Does the Privacy Act apply to my business if I am small?
The $3 million annual turnover threshold means many small businesses are technically exempt from the Privacy Act's main obligations. However, health service providers, businesses that trade in personal information, and businesses that opt in to the Act are covered regardless of size. If you handle health information, work with financial data, or operate in a regulated sector, assume the Act applies. Even if you are exempt, state-based privacy laws and sector-specific regulations may still apply to how you handle customer data.
Is ChatGPT's data training opt-out enough to make it compliant?
No. Opting out of model training (available in ChatGPT settings) removes your data from OpenAI's training pipeline, but it does not address the APP 8 cross-border disclosure issue. Your customer's personal information has still been sent to a US-based third party. The opt-out reduces one risk but does not resolve the fundamental compliance question under the Privacy Act.
What is the penalty for breaching APP 8 by sending customer data to ChatGPT?
Serious or repeated interferences with privacy can attract penalties of up to $50 million for companies, or three times the benefit obtained, or 30 percent of adjusted turnover, whichever is greater, following the December 2022 penalty increases. Individual serious breaches can result in significant fines as well. The OAIC can also require remediation, audit your practices, and publish findings. The risk is real for SMBs handling customer data carelessly with AI tools.
Can I use ChatGPT to write emails to customers if I include their name?
If you type a customer's name, email address, or account details into ChatGPT to draft an email, that is a disclosure of personal information to an overseas recipient. Without consent or a compliant APP 8 basis, this may create compliance risk under the Privacy Act. The simple alternative: draft the email as a template using placeholder names, then fill in the real details in your email client after the fact. You get the efficiency of AI-drafted copy without the privacy exposure. See the OAIC's APP 8 guidance at oaic.gov.au.
Does using ChatGPT through Microsoft Copilot change the compliance situation?
Microsoft 365 Copilot operates under Microsoft's data processing terms, which include explicit commitments about data not being used for model training and data processing within agreed regions. This is a meaningfully different compliance position than standard consumer ChatGPT. It does not eliminate APP 8 obligations, but it provides a documented, contractual basis for the cross-border disclosure that most SMBs using consumer ChatGPT do not have. If your business runs on Microsoft 365, Copilot is worth assessing as a more compliance-ready alternative for tasks involving real customer data.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Get a free AI staff policy template covering what staff can and cannot send to ChatGPT, with a built-in privacy policy update checklist for Australian SMBs.
Get the Free Policy Template