AI and Australian Privacy Law: What Every Business Owner Needs to Know product guide
AI Summary
Product: AI and Australian Privacy Law: What Every Business Owner Needs to Know Brand: Not applicable (informational legal guidance article) Category: Australian Privacy Law & AI Compliance Guide Primary Use: Explains how the Privacy Act 1988 and Australian Privacy Principles apply to Australian businesses using AI tools, and what compliance obligations those businesses must meet.
Quick Facts
- Best For: Australian business owners, operators, and managers adopting or considering AI tools that handle personal information
- Key Benefit: Translates complex Australian privacy law into plain-English obligations for AI deployers, including checklists, real scenarios, and regulatory context
- Form Factor: Long-form digital article with compliance checklist, scenario analysis, and FAQ table
- Application Method: Read before selecting or deploying any AI tool that processes customer, staff, or client personal information
Common questions this guide answers
- Does Australian privacy law apply to AI tools? → Yes — the Privacy Act 1988 and its 13 Australian Privacy Principles apply to all AI uses involving personal information, regardless of the technology used.
- Is my small business exempt from the Privacy Act? → Businesses under $3 million annual turnover are currently exempt (approx. 92% of Australian businesses), but this exemption is under active review and proposed to be abolished, potentially covering 2.3 million additional businesses.
- Can I paste client data into ChatGPT or free AI chatbots? → No — the OAIC explicitly advises against entering personal or sensitive information into publicly available generative AI tools due to significant privacy risks under APP 6 and APP 8.
AI and Australian Privacy Law: What Every Business Owner Needs to Know
Most guides on getting started with AI skip straight to the tools. Which chatbot should you use? How do you automate your invoicing? Those are solid questions — but they come after a more fundamental one that Australian business owners consistently miss: are you actually allowed to feed that data into an AI tool in the first place?
This isn't hypothetical. The moment you paste a client's name and email into ChatGPT to draft a follow-up email, upload a spreadsheet of customer records into an AI data analysis tool, or deploy a third-party AI chatbot on your website, you are potentially handling personal information under Australian law. Get it wrong, and you're looking at regulatory scrutiny, reputational damage, and for larger businesses, serious financial penalties.
This guide cuts through the legal complexity and translates the framework into plain English so you can adopt AI confidently, responsibly, and in compliance with your obligations.
What law actually governs AI and privacy in Australia?
There is no standalone AI privacy law in Australia — not yet. What exists is the Privacy Act 1988 and the Australian Privacy Principles (APPs), and they apply to all uses of AI involving personal information, including where information is used to train, test, or operate an AI system.
The Privacy Act 1988 is the primary Australian legislation protecting how personal information about individuals is collected, used, stored, and disclosed, across both the federal public sector and the private sector.
The guidance is instructive because the Privacy Act is principles-based and technology neutral. It sets out obligations on APP entities regarding personal information, irrespective of the manner or technological tools in which such personal information is processed — whether manually, with traditional technologies, or through training, testing, and use with AI.
In plain terms: the law doesn't care whether you're filing a paper form or running a large language model. If personal information is involved, the APPs apply.
The 13 Australian Privacy Principles at a glance
The APPs establish rigorous requirements under the Privacy Act, with a strong emphasis on accuracy, transparency, and tight scrutiny of data collection and secondary use. Here are the principles most relevant to AI-using businesses:
| APP | What it requires | Why it matters for AI |
|---|---|---|
| APP 1 | Open and transparent management of personal information, including a published privacy policy | Your privacy policy must now disclose AI use |
| APP 3 | Collect only information that is reasonably necessary, by lawful and fair means | Limits what you can feed into AI tools |
| APP 5 | Notify individuals about how their information is collected and used | Customers must know if AI is processing their data |
| APP 6 | Use or disclose information only for the primary purpose it was collected | You can't repurpose client data for AI training without consent |
| APP 8 | Obligations when disclosing personal information to overseas recipients | Most AI tools are hosted overseas |
| APP 10 | Take reasonable steps to ensure personal information is accurate | Applies to AI-generated outputs that contain personal information |
| APP 11 | Protect personal information from misuse, interference, and loss | Covers data security when using cloud AI tools |
Does the Privacy Act apply to your business?
Here's where many small business owners assume they're off the hook — and where the ground is shifting fast.
Currently, most businesses with a turnover under $3 million, approximately 92% of businesses in Australia, are exempt from Privacy Act compliance.
But the exemption does not apply if your business:
- Provides a health service — the Privacy Act provides added protections for health information, and all businesses that provide a health service are covered by the Act.
- Trades in personal information for a benefit, service, or advantage
- Is a credit reporting body or handles tax file number information
- Has contracted with a larger business to handle their personal information — if a small business is dealing contractually with a bigger business in a way that will likely include the exchange of personal information, the bigger business will often want assurances that the small business will handle that personal information in accordance with the Privacy Act, and this is generally included in a contract.
The exemption is on borrowed time
Even if you're currently exempt, start preparing now. The Privacy Act's small business exemption is under serious reconsideration. The February 2023 Privacy Act Review Report proposed abolishing this exemption entirely, a move that would bring approximately 2.3 million additional businesses into the scope of privacy regulation.
It is predicted that the second tranche of reforms may contain crucial changes including removing the small business exemption from the Privacy Act and introducing a 'fair and reasonable' test to be applied in handling personal information.
The practical implication is clear: even if you're exempt today, building privacy-compliant habits now protects you from a disruptive compliance scramble when the law changes. It also signals trustworthiness to the clients, suppliers, and enterprise customers who are already bound by the Act.
The OAIC's specific AI guidance: what deployers must know
In October 2024, Australia's privacy regulator made a significant move. The Office of the Australian Information Commissioner (OAIC) published two new guidelines on privacy and artificial intelligence: Guidance on privacy and the use of commercially available AI products, which explains organisations' obligations when using personal information in commercially available AI products such as chatbots, content-generation tools, productivity assistants, note-taking, and transcription tools.
This was a clear shift in the OAIC's regulatory approach, from enforcement-focused oversight to proactive guidance. That shift matters for every business using AI tools right now.
If you are using any AI tool in your business, even internally, you are a deployer under this framework. A 'deployer' is any individual or organisation that supplies or uses an AI system to provide a product or service. Deployment can be used for internal purposes or used externally, impacting others such as customers or individuals who are not deployers of the system. If your organisation is using AI to provide a product or service, including internally within your organisation, then you will be a deployer.
Key obligations for AI deployers
APP entities developing or using AI systems should take the following steps to ensure privacy law compliance: review and update external privacy policies and collection notices to ensure clear and transparent information about how and when AI will use and generate personal information.
Conduct due diligence to ensure the AI system or product is suitable for the intended use and does not pose any material security risks to the business. Entities should consider how the AI system has been trained, the quality of data sets used to train the system, and steps taken to mitigate any bias or discrimination.
When looking to adopt a commercially available product, organisations should conduct due diligence to ensure the product is suitable to its intended uses. This should include considering whether the product has been tested for such uses, how human oversight can be embedded into processes, the potential privacy and security risks, as well as who will have access to personal information input or generated by the entity when using the product.
These aren't aspirational guidelines — they're the baseline the regulator expects.
Real scenarios: where Australian businesses get it wrong
Scenario 1: Uploading client records into ChatGPT
A bookkeeper pastes a client's full name, ABN, bank account details, and transaction history into ChatGPT to draft a financial summary. It's a common shortcut — and a serious compliance risk.
APP entities are advised not to enter personal information, particularly sensitive information, into publicly available generative AI tools such as chatbots, because of the significant and complex privacy risks involved.
The problem is twofold. First, you may be disclosing that information to an overseas operator (most AI tools are US-based), triggering APP 8 obligations around cross-border disclosure. Second, you may not have collected that information for the purpose of feeding it into a third-party AI system, which creates an APP 6 breach.
In accordance with Australian Privacy Principle (APP) 6, an individual's personal information should only be used or disclosed for AI for the primary purpose for which it was collected or otherwise with consent where used for a secondary purpose; or where the individual would reasonably expect the entity to use or disclose their information for the secondary purpose.
The fix: Use enterprise-grade AI tools with data processing agreements that confirm your data is not used for model training (see our guide on ChatGPT vs. Google Gemini vs. Microsoft Copilot: Which AI Assistant Is Right for Your Australian Business? for a comparison of privacy settings across the major platforms). De-identify data wherever possible before it enters any AI tool.
Scenario 2: Deploying a third-party AI chatbot on your website
A retail business installs a third-party AI chatbot to handle customer enquiries. The chatbot collects names, email addresses, and purchase queries. The business owner assumes the chatbot provider handles all the privacy obligations.
That assumption is wrong — and it's a costly one to discover after the fact.
If your organisation is covered by the Privacy Act, you will need to understand your obligations under the APPs when using AI. This includes being aware of the different ways that your organisation may be collecting, using, and disclosing personal information when interacting with an AI product.
You remain the data controller. You must ensure your privacy policy discloses the chatbot's data collection, that customers are notified at the point of collection, and that the third-party provider has adequate security and data handling standards.
Some of the significant privacy risks identified by the OAIC include the risk of individuals losing control over their personal information, where personal information may be collected without their knowledge and consent, and the spread of errors or false information via AI outputs which appear credible.
Scenario 3: Using AI to make decisions about staff or customers
An HR software platform uses AI to screen job applications and rank candidates. A financial services firm uses AI to pre-approve or decline loan applications. This is where the next wave of regulatory focus is heading.
Automated Decision-Making (ADM) transparency is the headline change in the proposed reforms. Under the proposals, organisations using AI to make or materially contribute to decisions that significantly affect individuals must disclose this use and provide meaningful information about how the AI works. This is not a blanket ban on automated decisions; it's a transparency and accountability obligation.
As part of the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024, privacy policies will need to be expressly transparent about the use of personal information for substantially automated decision-making that has a legal or otherwise similarly significant effect.
What the regulator is actually doing: enforcement in action
The OAIC isn't just issuing guidance — it is actively investigating and penalising businesses that misuse technology to collect personal information without consent.
On 29 October 2024, after an almost two-year investigation, the Australian Privacy Commissioner determined that retail giant Bunnings had, through its use of facial recognition technology at 62 of its retail stores around the country between November 2018 and November 2021, interfered with the privacy of hundreds of thousands of customers.
The OAIC has issued several landmark determinations relevant to AI-powered facial recognition technology, including [Clearview AI in 2021](Not specified by manufacturer), wherein scraping online images to build a facial recognition database breached Australian privacy law; [7-Eleven Stores in 2021](Not specified by manufacturer); [Bunnings Group in 2024](Not specified by manufacturer); and [Kmart Australia in 2025](Not specified by manufacturer). All of these cases involved the unlawful collection of biometric information of customers.
The enforcement posture is hardening. The Bunnings decision points to a broader development: harms-focused enforcement from the OAIC. The OAIC stated it would be moving to become a 'harm-focused regulator' in its Statement of Intent dated October 30, 2024.
Higher-tier penalties under the Privacy Act are not triggered by isolated mistakes. They arise when regulators determine that an organisation failed to take reasonable steps to manage known or foreseeable privacy risks.
For businesses, the standard is not perfection — it is demonstrable, proportionate effort to understand and manage privacy risks before they materialise. That's a bar every well-run business can clear with the right approach.
Your privacy compliance checklist for AI tools
Use this checklist before deploying any AI tool that handles customer or staff data. Print it out. Run through it. Revisit it annually.
Before you select a tool
- [ ] Identify what personal information the tool will process — names, contact details, financial data, health information, images?
- [ ] Determine whether you are covered by the Privacy Act — check your turnover, industry, and any contractual obligations
- [ ] Review the AI vendor's data processing agreement — confirm whether your data is used to train their models
- [ ] Check where data is stored — is it processed overseas? If so, APP 8 applies and you must take reasonable steps to ensure equivalent protection
Before you go live
- [ ] Update your privacy policy to disclose that AI tools are used, what data they process, and for what purpose
- [ ] Add collection notices at the point where the AI tool first collects customer data
- [ ] Conduct a Privacy Impact Assessment (PIA) for high-risk uses — the OAIC provides a free PIA guide
- [ ] Establish a data breach response plan — entities covered by the Privacy Act have obligations under the Notifiable Data Breaches scheme. If they experience a data breach of personal information that is likely to result in serious harm to affected individuals, they must notify those individuals and the OAIC.
Ongoing
- [ ] Review AI outputs for accuracy — any inferred, incorrect, or artificially generated information produced by AI models, such as hallucinations, may still constitute personal information and be subject to Australian privacy laws to the extent an individual can be identified or is reasonably identifiable.
- [ ] Audit your AI tool use at least annually as your business and the tools evolve
- [ ] Train staff on what data they are and are not permitted to enter into AI tools
What's coming: privacy reforms that will affect AI use
The regulatory picture is moving fast — faster than most business owners realise. The first tranche of reforms, passed in 2024, introduced new transparency obligations around automated decision-making that will take effect in December 2026.
Further reforms remain on the agenda, including stronger consent rules, potential rights to explanation for high-impact automated decisions, direct rights of action, and higher penalties. These reforms will significantly shape compliant AI data practices.
Australia's privacy regulator, the OAIC, has been proactive in interpreting the Act in AI contexts and is actively regulating AI through interpretation and enforcement rather than waiting for dedicated legislation.
The trajectory is clear: more obligations, broader coverage, higher stakes. The businesses that start building good habits now won't just be compliant — they'll be ahead.
For a broader view of how Australia's AI governance framework is evolving, including the October 2025 Guidance for AI Adoption and its six key practices, see our companion guide: Responsible AI for Australian SMEs: Understanding the Government's Guidance for AI Adoption.
Key takeaways
- The Privacy Act 1988 already applies to AI. There is no separate AI privacy law — the existing APPs govern every use of personal information in AI systems, regardless of the technology involved.
- Most small businesses are currently exempt from the Privacy Act if their annual turnover is under $3 million, but this exemption is under active review and is expected to be removed, potentially bringing 2.3 million additional businesses into scope.
- You are a "deployer" the moment you use any AI tool that handles personal information, even internally, and the OAIC's October 2024 guidance sets out specific obligations for deployers around transparency, due diligence, and data minimisation.
- Do not paste personal information into public AI tools. The OAIC explicitly advises against entering personal or sensitive information into publicly available generative AI tools such as free-tier chatbots.
- Update your privacy policy now. The Privacy and Other Legislation Amendment Act 2024 requires transparency about automated decision-making, and the OAIC expects all AI-using businesses to update their privacy policies and collection notices to reflect how AI processes personal information.
Conclusion
Privacy compliance isn't a bureaucratic afterthought to AI adoption — it's the foundation on which responsible AI use is built. The OAIC has made clear that the Privacy Act applies to every business that handles personal information through AI tools, and its enforcement posture is becoming more active, not less. The Bunnings determination, the Clearview AI finding, and the October 2024 AI guidance all point in the same direction: Australian regulators are watching how businesses use technology to collect and process personal data, and they are prepared to act.
The good news? Compliance doesn't require a legal team or an IT department. It requires clear thinking about what data you're using, why you're using it, and whether the people it belongs to would reasonably expect it to be processed that way.
For practical next steps, explore our related guides: Step-by-Step: How to Implement Your First AI Tool in an Australian Small Business walks you through a privacy-conscious implementation process, while AI Cybersecurity Risks for Australian Small Businesses covers the operational security dimension that sits alongside your legal obligations. Together, they give you the complete picture of what responsible AI adoption looks like in practice.
References
Office of the Australian Information Commissioner (OAIC). "Guidance on privacy and the use of commercially available AI products." OAIC, 21 October 2024. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
Office of the Australian Information Commissioner (OAIC). "Guidance on privacy and developing and training generative AI models." OAIC, 21 October 2024. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-developing-and-training-generative-ai-models
Attorney-General's Department. "Privacy." Australian Government, 2025. https://www.ag.gov.au/rights-and-protections/privacy
Office of the Australian Information Commissioner (OAIC). "Part 4: Exemptions — Privacy Act Review Issues Paper Submission." OAIC, 2021. https://www.oaic.gov.au/engage-with-us/submissions/privacy-act-review-issues-paper-submission/part-4-exemptions
Future of Privacy Forum. "OAIC's Dual AI Guidelines Set New Standards for Privacy Protection in Australia." FPF, December 2024. https://fpf.org/blog/oaics-dual-ai-guidelines-set-new-standards-for-privacy-protection-in-australia/
International Association of Privacy Professionals (IAPP). "Global AI Governance Law and Policy: Australia." IAPP, 2025. https://iapp.org/resources/article/global-ai-governance-australia
Gilbert + Tobin. "OAIC AI Guidance — regulating AI to maintain privacy." Gilbert + Tobin Insights, 2025. https://www.gtlaw.com.au/insights/oaic-ai-guidance-regulating-ai-to-maintain-privacy
A&O Shearman. "Australian Information Commissioner publishes new guidance on privacy considerations when using AI." A&O Shearman on Data, January 2026. https://www.aoshearman.com/en/insights/ao-shearman-on-data/australian-information-commissioner-publishes-new-guidance-on-privacy-considerations-when-using-ai
Bird & Bird. "Australia's Privacy Regulator releases new guidance on artificial intelligence (AI)." Bird & Bird Insights, February 2025. https://www.twobirds.com/en/insights/2025/australia/australias-privacy-regulator-releases-new-guidance-on-artificial-intelligence
SafeAI-Aus. "Current Legal Landscape for AI in Australia." SafeAI-Aus, January 2026. https://safeaiaus.org/safety-standards/ai-australian-legislation/
Spruson & Ferguson. "Privacy and AI Regulations: 2024 review & 2025 outlook." Spruson & Ferguson, January 2025. https://www.spruson.com/privacy-and-ai-regulations-2024-review-2025-outlook/
ValiDATA. "AI and Australia's Privacy Act Reforms: What's Changing and Why It Matters." ValiDATA, April 2026. https://www.validata.ai/post/ai-and-australia-s-privacy-act-reforms-what-s-changing-and-why-it-matters
Frequently Asked Questions
| Question | Answer |
|---|---|
| Does Australia have a specific AI privacy law? | No, there is no standalone AI privacy law yet |
| What law governs AI and privacy in Australia? | The Privacy Act 1988 |
| What principles govern personal information handling in Australia? | The Australian Privacy Principles (APPs) |
| How many Australian Privacy Principles are there? | 13 |
| Does the Privacy Act apply to AI tools? | Yes, it applies to all AI uses involving personal information |
| Does the Privacy Act care what technology is used? | No, it is technology neutral |
| What is the Privacy Act 1988? | Australia's primary legislation protecting personal information |
| Does the Privacy Act cover only government agencies? | No, it covers both public sector and private sector |
| What turnover threshold currently exempts small businesses from the Privacy Act? | Under $3 million annual turnover |
| What percentage of Australian businesses currently fall under the small business exemption? | Approximately 92% |
| Are health service providers exempt from the Privacy Act? | No, all health service businesses are covered regardless of turnover |
| Are businesses that trade in personal information exempt? | No, they are covered by the Privacy Act |
| Can a small business be covered by the Privacy Act through a contract? | Yes, if contracted to handle a larger business's personal information |
| Is the small business exemption permanent? | No, it is under active review |
| What proposed change could affect the small business exemption? | The February 2023 Privacy Act Review Report proposed abolishing it |
| How many additional businesses would be affected if the exemption is removed? | Approximately 2.3 million |
| When did the OAIC publish its AI guidance? | October 2024 |
| What is the name of the OAIC's AI guidance document? | "Guidance on privacy and the use of commercially available AI products" |
| What is a "deployer" under the OAIC framework? | Any individual or organisation that uses an AI system to provide a product or service |
| Am I a deployer if I use AI only internally? | Yes, internal use still makes you a deployer |
| Must deployers update their privacy policies for AI use? | Yes, privacy policies must disclose AI use |
| What is APP 1? | Requirement for open and transparent management of personal information |
| What does APP 3 require? | Collect only information that is reasonably necessary |
| What does APP 5 require? | Notify individuals about how their information is collected and used |
| What does APP 6 require? | Use or disclose information only for the primary purpose it was collected |
| What does APP 8 concern? | Obligations when disclosing personal information to overseas recipients |
| What does APP 10 require? | Take reasonable steps to ensure personal information is accurate |
| What does APP 11 require? | Protect personal information from misuse, interference, and loss |
| Does uploading client data to ChatGPT create a compliance risk? | Yes, it is a serious compliance risk |
| Why does pasting client data into ChatGPT breach APP 8? | Most AI tools are US-based, triggering cross-border disclosure obligations |
| Why does pasting client data into ChatGPT breach APP 6? | Data was not collected for the purpose of feeding into a third-party AI |
| Does the OAIC advise against entering personal information into public AI chatbots? | Yes, explicitly |
| What is the recommended fix for using AI with client data? | Use enterprise-grade tools with data processing agreements |
| Should data be de-identified before entering AI tools? | Yes, wherever possible |
| If I deploy a third-party chatbot, who remains the data controller? | Your organisation remains the data controller |
| Must my privacy policy disclose a chatbot's data collection? | Yes |
| What is Automated Decision-Making (ADM)? | AI making or materially contributing to decisions affecting individuals |
| When must ADM transparency be disclosed? | When decisions have legal or similarly significant effects on individuals |
| What legislation introduced ADM transparency obligations? | The Privacy and Other Legislation Amendment Act 2024 |
| When did the Privacy and Other Legislation Amendment Act 2024 receive Royal Assent? | 10 December 2024 |
| When do ADM transparency obligations take effect? | December 2026 |
| Can AI hallucinations constitute personal information under Australian law? | Yes, if an individual is reasonably identifiable |
| What was the Bunnings OAIC determination about? | Unlawful use of facial recognition technology in 62 stores |
| When was the Bunnings determination issued? | 29 October 2024 |
| What did the Clearview AI determination find? | Scraping online images for facial recognition breached Australian privacy law |
| When was the Clearview AI determination? | 2021 |
| What other businesses received OAIC determinations on facial recognition? | 7-Eleven (2021) and Kmart Australia (2025) |
| What type of information was unlawfully collected in the Bunnings case? | Biometric information of customers |
| What is the OAIC's stated enforcement approach? | Harm-focused regulation |
| What triggers higher-tier penalties under the Privacy Act? | Failure to take reasonable steps to manage known privacy risks |
| Is perfection required for Privacy Act compliance? | No, demonstrable proportionate effort is the standard |
| What is a Privacy Impact Assessment (PIA)? | A tool for assessing privacy risks before deploying AI |
| Does the OAIC provide a free PIA guide? | Yes |
| What is the Notifiable Data Breaches scheme? | Obligation to notify individuals and OAIC of breaches likely to cause serious harm |
| Who must comply with the Notifiable Data Breaches scheme? | Entities covered by the Privacy Act |
| Should AI outputs be reviewed for accuracy? | Yes, as part of ongoing compliance obligations |
| How often should AI tool use be audited? | At least annually |
| Should staff be trained on what data to enter into AI tools? | Yes |
| Must collection notices be added when AI tools collect customer data? | Yes, at the point of first collection |
| Is a vendor's data processing agreement important before adopting an AI tool? | Yes, confirm data is not used for model training |
| Must you check where an AI tool stores data? | Yes, overseas storage triggers APP 8 obligations |
| What is the OAIC's regulatory posture trend? | Becoming more active, not less |
| Does compliance require a legal team or IT department? | No, clear thinking about data use is sufficient |
| What is the primary recommended action for AI-using businesses right now? | Update your privacy policy to disclose AI use |
Label Facts Summary
Disclaimer: All facts and statements below are general informational summaries extracted from the source content, not legal advice. Consult a qualified legal or privacy professional for guidance specific to your circumstances.
Verified label facts
No data provided. The content analysed is a legal and regulatory guidance article, not a product with packaging, ingredients, certifications, dimensions, or manufacturer specifications. There is no Product Facts table or label information present in the content.
General product claims
Not applicable to this content. The content contains no product marketing or benefit claims. It is an informational article covering Australian privacy law (Privacy Act 1988), the Australian Privacy Principles (APPs), and regulatory guidance from the Office of the Australian Information Commissioner (OAIC) as they relate to AI tool use by Australian businesses.