This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your business is using AI tools that touch customer data, employee records, or any personal information, the OAIC has published clear guidance on what it expects from you. The Office of the Australian Information Commissioner is not waiting for a new AI law to pass before acting. It is applying the existing Privacy Act 1988 to AI use right now, and it has told businesses what that looks like in practice.
Most small and medium businesses using AI tools have not mapped their obligations against this guidance. That is not a sign you are behind or reckless. It is simply that the guidance has not been translated into a plain business checklist until now. This article does exactly that.
The checklist below is based on the OAIC's published AI guidance, the Australian Privacy Principles (APPs), and the practical steps the OAIC has said businesses should take. You can use it to audit what you have in place, identify gaps, and understand what to fix first. For a full overview of what the OAIC's AI guidance covers, see our companion article on OAIC AI guidance for Australian businesses.
In short: The OAIC applies the Privacy Act 1988 to AI tools that handle personal information. Businesses must be able to show they have assessed the privacy risks of the AI tools they use, documented what data those tools access, and put staff policies and governance structures in place. This checklist maps the eight areas the OAIC has signalled it will scrutinise.
Why This Checklist Exists Now
The OAIC does not have a standalone AI law to enforce yet. The Australian Government's AI regulation framework is still being developed. But the OAIC has made it clear that the Privacy Act 1988 already applies when AI tools collect, use, store, or disclose personal information, and it has published detailed guidance on what that means for businesses.
The key OAIC documents are the Privacy and AI Guidance for Organisations (released 2024, updated 2025) and the Guidance on Privacy and Generative AI. Together, they set out what the OAIC considers responsible AI use under existing law. These documents form the basis of every item on this checklist.
The Privacy Act applies to businesses with an annual turnover above $3 million, as well as health service providers, credit reporting bodies, and certain other entities regardless of turnover. If your business falls outside that threshold, the checklist is still useful, because several states have their own privacy obligations, and because being on the right side of OAIC expectations is increasingly a client and tender requirement.
AU compliance flag: The Privacy Act 1988 threshold review is ongoing. The Australian Government has proposed lowering the $3 million turnover threshold or removing it entirely. If this passes, the Privacy Act would apply to almost all Australian businesses. Check the current status at oaic.gov.au and assume the direction of travel is toward broader coverage.
How to Use This Checklist
Work through the eight sections below. Each section maps to a compliance area the OAIC has specifically addressed in its AI guidance. For each item, you are either able to document what you have done, or you have identified a gap to close.
A printable version of the checklist table is included below the section explanations. Use your browser's print or save-as-PDF function to keep a copy for your files, share it with your team, or attach it to a board or management meeting agenda.
This checklist covers the Privacy Act and OAIC obligations. It does not replace legal advice if your business operates in a regulated industry such as financial services (ASIC/APRA), health (TGA, AHPRA), or law. If that applies to you, treat this as a foundation and layer your sector-specific obligations on top.
The Eight Compliance Areas: Plain-English Breakdown
1. Know Which AI Tools Your Business Is Using
The OAIC cannot assess your compliance if you do not know which tools you are using. More importantly, you cannot protect your customers' personal information if you do not know which systems are processing it. The first obligation is simply to maintain a register of AI tools in use across the business.
This includes tools used by individual staff members on their own initiative, not just tools purchased at the business level. A staff member pasting client data into ChatGPT to summarise a report is an AI tool in use, even if the business never bought a ChatGPT licence. Your AI register needs to capture shadow use, not just sanctioned tools.
The OAIC expects businesses to know what AI tools are active, what data each tool accesses, who approved the use, and what the data handling terms are. Use this AI register template to build your register if you do not have one.
Picture the office manager at that mid-size logistics firm working through this exact step. Instead of guessing, she pulls together a list: the dispatch software, a route-planning AI tool the ops team started using six months ago, and a chatbot the customer service desk added last quarter. She used to have no idea two of those tools were even active until she asked around. Now she has a single register document showing what each tool touches, who approved it, and when it was last reviewed. That's an afternoon of admin, but it's the one document the OAIC will ask to see first.
2. Conduct a Privacy Impact Assessment Before Deploying New AI Tools
A Privacy Impact Assessment (PIA) is a structured review of the privacy risks of a new system or process before it goes live. The OAIC recommends a PIA for any AI tool that will handle personal information. For tools handling sensitive information (health data, financial records, identification documents), a PIA is not optional from an OAIC perspective.
A PIA for an SMB does not need to be a lengthy document. It needs to answer four questions: What personal information will the tool access? How will that information be used and stored? What are the risks if there is a breach or the tool makes an error? What controls are in place to manage those risks?
The OAIC publishes a PIA guide on its website. Documenting that you completed a PIA, even a short one, is evidence of a privacy-by-design approach, which is explicitly what the OAIC says it expects.
3. Understand Where Your Data Goes (Cross-Border Disclosure)
Almost every major AI tool processes data on overseas servers. ChatGPT, Microsoft Copilot, Google Gemini, and most AI writing, transcription, and analysis tools run on US or EU infrastructure. When personal information about Australian individuals crosses a national border, Australian Privacy Principle 8 (APP 8) applies.
The OAIC's guidance on APP 8 outlines that organisations are expected to take reasonable steps to ensure any overseas recipient handles the information consistently with the Australian Privacy Principles. Or to make clear to individuals that their information may be sent overseas before collection. In practice, this means reviewing the vendor's data processing terms and confirming what data actually leaves Australia. See the OAIC's full APP 8 guidance at oaic.gov.au.
This is a common gap. Many businesses using AI tools have not checked the vendor's data residency terms. The OAIC has flagged cross-border data flows as a specific AI risk area. See our Privacy Act and AI article for a detailed breakdown.
4. Update Your Privacy Policy
The OAIC's guidance states that where organisations use AI tools to process personal information, their privacy policy should accurately describe how that information is collected, used, and disclosed. If your current privacy policy does not mention AI processing, it may not reflect current practice. A gap the OAIC has identified as a compliance risk area. See the OAIC's AI guidance at oaic.gov.au.
The OAIC has indicated that the policy should describe that AI-assisted processing may occur, what kinds of data may be involved, and how individuals can ask questions or request their data. This does not mean listing every tool by name. Categories and purposes are sufficient.
Most SMB privacy policies were written before AI tools became a standard part of business operations. A review and update is strongly recommended. The changes are usually small, but the gap between an outdated policy and current practice is something the OAIC treats as a compliance concern.
5. Put an AI Staff Policy in Place
The OAIC's guidance specifically notes that organisations should have governance structures, including policies governing staff use of AI tools. Without a staff policy, you cannot consistently enforce appropriate use, and you cannot demonstrate to the OAIC that you have taken reasonable steps to comply.
A staff AI policy does not need to be complex. It needs to cover: which AI tools are approved for use, what types of information staff may and may not enter into AI tools, what staff must do before using a new AI tool, and what to do if something goes wrong (an accidental disclosure or a tool generating incorrect output that gets used).
A free staff AI policy template is available at this link. It is structured for Australian SMBs and references the OAIC guidance and Privacy Act directly.
6. Do Not Rely on AI Outputs Without Human Review
The OAIC has explicitly addressed automated decision-making: where AI tools make or significantly influence decisions that affect individuals, businesses must maintain meaningful human oversight. This is particularly relevant if your business uses AI for credit assessments, hiring screening, performance management, or any process that results in a consequential outcome for a person.
Meaningful oversight means a human with the authority and context to override the AI output reviews it before the decision is made. Rubber-stamping an AI recommendation without genuine review does not satisfy this standard. The OAIC has said it considers this a core element of responsible AI governance under the existing APPs.
For most SMBs, this is less about complex automated decisions and more about ensuring staff know they are responsible for the accuracy and appropriateness of AI-assisted work, including checking AI-generated summaries, recommendations, and correspondence before acting on them.
7. Have a Data Breach Response Plan That Covers AI Tools
The Notifiable Data Breaches (NDB) scheme requires businesses covered by the Privacy Act to notify the OAIC and affected individuals if there is a breach likely to result in serious harm. AI tools create new breach scenarios: a staff member entering client data into an unauthorised tool, an AI vendor suffering a breach, or a model producing output that inadvertently discloses one customer's information to another.
Your existing data breach response plan (if you have one) may not account for these scenarios. Review it to ensure it covers AI-specific breach types, that staff know to report them, and that your escalation path to the OAIC is current. If you do not have a plan, this is a gap to close before you go further with AI adoption.
8. Keep Records of Your Compliance Steps
The OAIC cannot verify your compliance based on what you intend to do or what you believe you are doing. It can only assess what you have documented. Accountability, under the Privacy Act, means being able to demonstrate the steps you have taken, not just assert that they have been taken.
For AI compliance specifically, this means keeping records of: PIAs completed, AI tools assessed and approved, staff policy versions and acknowledgement dates, cross-border data flow assessments, and any incidents or near-misses. These records do not need to be elaborate, but they need to exist and be retrievable.
A simple AI register, a dated copy of your staff policy, and a PIA document for each major AI tool in use will put you in a materially stronger position than most SMBs of your size if the OAIC ever asks.
OAIC AI Compliance Checklist: Printable Table
The table below consolidates all eight compliance areas into a single checklist you can print, save, or share with your team. Each row maps to the OAIC guidance area and the corresponding action required.
| No. | Compliance Area | What You Need to Have in Place | OAIC Basis | Status |
|---|---|---|---|---|
| 1 | AI Tool Register | A documented list of all AI tools in use, including shadow/unofficial use. Records what data each tool accesses, who approved it, and the vendor's data handling terms. | OAIC AI Guidance; APP 1 (open and transparent management) | ☐ Done ☐ Gap |
| 2 | Privacy Impact Assessments | Completed PIA for each AI tool handling personal information. Documented answers to: what data is processed, how, what the risks are, and what controls are in place. | OAIC PIA Guide | ☐ Done ☐ Gap |
| 3 | Cross-Border Data Flow Assessment | Confirmation of where each AI tool stores and processes data. Vendor data processing agreement reviewed for overseas data flows. APP 8 obligations assessed per tool. | APP 8 (cross-border disclosure) | ☐ Done ☐ Gap |
| 4 | Privacy Policy Updated for AI | Privacy policy reviewed and updated to reflect AI-assisted processing of personal information. Policy indicates what types of data may be processed by AI, and how individuals can make enquiries. | APP 1 (privacy policy); OAIC AI Guidance | ☐ Done ☐ Gap |
| 5 | Staff AI Policy | Written policy covering approved AI tools, what information staff may and may not enter into AI tools, the process for requesting approval to use new tools, and incident reporting steps. | OAIC AI Guidance (governance); APP 11 (security) | ☐ Done ☐ Gap |
| 6 | Human Oversight of AI Decisions | Documented process for human review of AI outputs that affect individuals (hiring, assessments, customer communications, financial recommendations). Staff understand they are accountable for AI-assisted decisions. | OAIC AI Guidance (accountability); APP 10 (quality) | ☐ Done ☐ Gap |
| 7 | Data Breach Plan Updated for AI | Existing data breach response plan reviewed to include AI-specific scenarios. Staff know how to report an AI-related incident. NDB reporting obligations understood and escalation path to OAIC is current. | Privacy Act NDB scheme; APP 11 | ☐ Done ☐ Gap |
| 8 | Compliance Records Maintained | Records kept of PIAs, approved AI tools, staff policy version history and sign-offs, cross-border assessments, and any AI-related incidents. Records are retrievable and dated. | APP 1 (accountability); OAIC AI Guidance | ☐ Done ☐ Gap |
What to Do If You Have Gaps
Most SMBs working through this checklist for the first time will find gaps in multiple areas. That is the normal starting point, not a sign of serious non-compliance. The OAIC's own guidance acknowledges that businesses are at different stages of AI maturity. What matters is that you have a plan to close the gaps and that you are making genuine progress.
Start with the highest-risk gap first. In most cases, that is either the staff policy (because it governs everything else) or the cross-border data flow assessment (because APP 8 is one of the clearest existing obligations). Build the AI register next, because it is the foundation for everything else. Then work through the remaining items in order.
The tools you need are mostly free or low cost. A staff policy template is available at this link. An AI register template is available at this link. The OAIC publishes a free PIA guide at oaic.gov.au. What is not free is the time it takes to do this properly, so set a realistic timeline and assign ownership within the business.
Industry-Specific Considerations
Several sectors carry obligations beyond the base Privacy Act requirements. If your business operates in any of these areas, layer the following on top of the eight checklist items above.
Health and allied health: The Privacy Act's health information provisions are stricter than the general APPs. AI tools handling patient records, clinical notes, or health assessments trigger heightened obligations under APP 3 (sensitive information) and APP 6 (use and disclosure). The OAIC has specifically noted health as a high-risk area for AI use.
Financial services: ASIC and APRA both have published positions on AI governance for entities they regulate. If your business holds an AFS licence or operates under APRA prudential standards, your AI governance framework must also satisfy those requirements. The OAIC obligations are a floor, not a ceiling, in this sector.
Legal services: Confidentiality obligations mean that the data-sharing question for AI tools is also a professional conduct question, not just a privacy question. Check your state bar's guidance before using AI tools that process client files or communications.
Accounting and bookkeeping: Client financial records are personal information and, depending on their nature, may also be sensitive information. The cross-border data flow issue is particularly relevant here, as many bookkeeping AI tools process data on US servers.
What the OAIC Actually Checks
The OAIC investigates complaints and conducts own-motion investigations. In an AI context, the scenarios most likely to trigger OAIC attention are: a complaint from an individual whose data was processed by an AI tool without adequate notice, a data breach involving an AI tool, or a business whose AI use causes serious harm to an identifiable person.
The OAIC does not routinely audit every SMB in Australia. But when it does investigate, it will ask for documentation. Businesses that can produce a PIA, a staff policy, an AI register, and records of their compliance steps are in a materially different position to those that cannot. The difference between the two positions is not technical sophistication. It is paperwork.
The OAIC has also flagged that it may take a more proactive regulatory posture on AI as adoption grows. Investing a few hours in the eight checklist items above is significantly less expensive than responding to an OAIC investigation or a notifiable data breach.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our free AI acceptable use policy template and our AI governance by region.
For the plain-English overview this checklist is based on, see our OAIC guidance hub.
Related reading: Claude AI Review for Australian Business and Notion AI Review for Australian Small Business.
Does the Privacy Act apply to my small business if I use AI tools?
The Privacy Act 1988 currently applies to businesses with an annual turnover above $3 million, health service providers, and certain other entity types regardless of turnover. If your business is below the threshold, the Act may not apply directly, but an amendment to lower or remove the threshold is under active consideration. Even below the threshold, state-based privacy obligations may apply, and clients or government contracts may require Privacy Act compliance regardless. Using the checklist now puts you ahead of any threshold change.
What is the OAIC's position on using tools like ChatGPT with client data?
The OAIC has not banned the use of any specific tool, but it has said that before using any AI tool with personal information, businesses must assess the privacy risks, understand where the data goes, and ensure they have authority under the APPs to disclose that information to the tool's vendor. For ChatGPT specifically, personal data entered into the standard interface may be used by OpenAI for model training unless you have an enterprise agreement that restricts this. The OAIC expects businesses to check these terms and make an informed decision, not assume the tool is safe by default. See our OAIC guidance overview for more detail.
Do I need a formal Privacy Impact Assessment for every AI tool I use?
The OAIC recommends a PIA for any new project or system that involves personal information, and specifically for AI tools. For low-risk tools that access no personal information (such as an AI tool you use only for drafting internal documents that never mention individuals), the case for a full PIA is weaker. For tools that access customer data, employee records, health information, or financial information, a documented PIA is the OAIC's expectation. It does not need to be lengthy. A one-page document that answers the four core questions is sufficient for most SMB use cases.
What happens if one of my staff uses an AI tool I did not approve?
From the OAIC's perspective, your business is responsible for how personal information is handled by your staff, whether or not you approved the tool they used. If a staff member pastes client records into an unapproved AI tool and a breach results, that is your business's breach under the Privacy Act, not just the employee's error. This is why a staff AI policy, combined with clear guidance on approved tools, is one of the first gaps to close. The policy does not need to be complex, but it needs to exist and staff need to have acknowledged it.
Is there a free checklist I can download and print?
Yes. The full eight-area checklist is built directly into this page as a printable table (see the table above). Use your browser's print or save-as-PDF function to keep a copy for your files or share it with your team. No separate download, account, or payment is required.
How often should I review this checklist?
Review your AI compliance position at least once every 12 months, and any time you add a significant new AI tool to the business. The OAIC guidance is updated periodically as new AI developments emerge, and the Privacy Act itself may be amended. Treat this checklist as a living document rather than a one-time exercise. Keeping a dated record of each review is itself a compliance record the OAIC may ask for.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Want a faster way to check where you stand? Try our free AI Compliance Checker to score your current AI tool setup against these obligations.
Check Your Compliance