ai privacy act australia — Pivot 2 Thrive

AI and the Privacy Act: A Compliance Checklist for Australian Businesses (2026)

September 14, 20269 min read

Last updated: September 2026.

Yes — the Privacy Act 1988 covers AI use in Australia. If your business is an APP entity, putting customer information into an AI tool is a use or disclosure like any other, and the same 13 Australian Privacy Principles apply. AI creates no exemption. It only creates more places for personal information to end up.

This article is written by Dr Priya Jaganathan, Claude AI expert and AI keynote speaker based in Brisbane, Australia. She is a Go High Level Certified Admin and Certified AI Tech Stack Consultant who builds AI and automation systems for Australian businesses, and speaks on AI adoption at conferences around the country. The checklist below is the same one used when auditing a client's stack before any AI tool touches a customer record. It is general information, not legal advice — for a binding view on your obligations, talk to a privacy lawyer.

Does the Privacy Act apply to AI in Australia?

The Privacy Act does not mention AI by name, and Australia still has no standalone AI Act. That is the point most business owners miss. The obligation attaches to the personal information, not to the technology handling it. The moment a name, email, phone number, health detail or customer note goes into an AI system, every rule that already governed that data still governs it.

Whether you are covered comes down to the small business test. Under the OAIC's small business guidance, a business with an annual turnover of $3 million or less is generally exempt — but that exemption falls away if you are a health service provider, trade in personal information, hold a Commonwealth contract, are a credit reporting body, are related to a covered body corporate, or are a reporting entity under the AML/CTF Act.

That last one matters more in 2026 than it ever has. According to AUSTRAC's 2026 guidance for tranche 2 reporting entities, lawyers, accountants, conveyancers, real estate agents, trust and company service providers and precious metals dealers took on AML/CTF reporting obligations from 1 July 2026. Plenty of those firms sit well under $3 million in turnover and assumed the Privacy Act was somebody else's problem. It is now theirs.

The OAIC has also published specific guidance on privacy and the use of commercially available AI products, aimed squarely at businesses buying off-the-shelf AI rather than building it. Its core recommendation is a privacy-by-design approach, including a privacy impact assessment before you adopt a product.

Why does AI privacy compliance matter in 2026?

Because the exposure is measurable and it is going up. The OAIC reported on 6 July 2026 that it received 1,205 data breach notifications in the 2025 calendar year — the highest annual figure since the Notifiable Data Breaches scheme started in 2018, and an 8% increase on 2024's 1,112. Of those 1,205 breaches, 716 were attributable to malicious or criminal attack, and health service providers alone accounted for 225 notifications, or 19% of the total.

Customers have noticed. The OAIC's 2026 Australian Community Attitudes to Privacy Survey found 82% of Australians are concerned about data breaches, up from 74% in 2023. That is the audience reading your privacy policy and deciding whether to hand over their details.

Two legal changes sharpen this further. A statutory tort for serious invasions of privacy commenced on 10 June 2025 under the Privacy and Other Legislation Amendment Act 2024, giving individuals a direct right to sue — including against entities that are not APP entities at all. And from 10 December 2026, new subclauses APP 1.7, 1.8 and 1.9 require APP entities to disclose automated decision-making in their privacy policy. The OAIC ran its consultation on that obligation through mid-2026 and has been publishing guidance ahead of commencement.

In plain terms: if a computer program uses personal information to make a decision that could reasonably be expected to significantly affect someone's rights or interests, your privacy policy has to say so — what kinds of information are used, what kinds of decisions are made, and how a person can seek meaningful human review.

The AI Privacy Act compliance checklist for Australian businesses

Ten items. Work top to bottom. Most businesses fail on items 2, 4 and 9.

# Check What it means in practice
1 Confirm whether you are covered Run the OAIC small business checklist. Turnover over $3m, health services, AML/CTF reporting entity or Commonwealth contract all mean yes.
2 Inventory every AI tool in use Including the ones staff signed up for themselves. You cannot govern a tool you do not know about.
3 Map what personal information each tool touches Names and emails are one risk tier. Health, financial and biometric data are another entirely.
4 Check the training clause in each contract Business and enterprise tiers usually exclude your inputs from model training. Free consumer tiers often do not.
5 Check where the data is stored and processed APP 8 governs cross-border disclosure. Know the hosting region and the sub-processors before you sign.
6 Run a privacy impact assessment The OAIC recommends one before adopting a commercially available AI product. Document it.
7 Apply collection limits inside the prompt APP 3 says collect only what you need. Strip identifiers out of prompts where the task does not require them.
8 Write an internal AI use policy One page. Approved tools, banned data types, who to ask. Staff follow rules they can actually read.
9 Update your privacy policy for automated decisions APP 1.7–1.9 commence 10 December 2026. Disclose the information used, the decisions made and how to request human review.
10 Extend your data breach response plan to AI tools A vendor breach is still your notification obligation. Know who you call and how fast.

The sequencing matters. Items 1 to 3 are diagnosis and take an afternoon. Items 4 to 7 are procurement and configuration decisions. Items 8 to 10 are governance, and they are the ones that hold up when something goes wrong. Skipping to item 8 without doing item 2 produces a policy that governs an imaginary business.

Want this audited properly rather than guessed at? Book a call with Pivot 2 Thrive and we will map every AI tool touching your customer data, flag the ones that need to change, and give you the fix list in priority order.

What does AI privacy compliance look like for an Australian business?

Take a Brisbane allied health clinic with eight staff and $1.6 million in turnover. Under the turnover test alone it would be exempt. It is a health service provider, so it is covered regardless — and health data is sensitive information, which carries higher consent requirements.

The clinic was using a free AI transcription tool for session notes, a consumer chatbot account for drafting referral letters, and an AI phone answering service. Three tools, none of them procured, none of them in the privacy policy, and two of them on consumer tiers where inputs were not contractually excluded from training.

The fix was not to stop using AI. It was to move the transcription and drafting work onto business-tier accounts with contractual training exclusions, strip patient identifiers out of the referral drafting workflow entirely, document a privacy impact assessment for each tool, and rewrite the privacy policy to name the categories of information involved. The AI phone answering stayed, because a well-configured AI receptionist that captures a name and a callback number handles far less sensitive data than a transcription tool sitting inside a consultation.

Same capability, defensible position. That is the outcome to aim for — not abstinence. The cost side of that decision is covered in our guide to AI implementation costs in Australia.

What are the most common AI privacy mistakes Australian businesses make?

  • Assuming the small business exemption protects them. The carve-outs are broad and getting broader. Health providers and AML/CTF reporting entities are covered at any turnover, and the exemption has been flagged for removal in future reform.
  • Treating consumer and business AI tiers as the same product. They are not. The contractual treatment of your inputs is the single biggest difference, and it is the one nobody reads before signing up. We covered this in detail in is Claude AI safe for client data.
  • Shadow AI. Staff adopt tools faster than management approves them. Every unapproved tool is an undocumented disclosure of personal information, and you will only find out about it during a breach investigation.
  • Writing the policy and stopping there. A privacy policy that says you use AI, with no inventory or controls behind it, is a written admission rather than a defence.
  • Leaving the privacy policy untouched before 10 December 2026. The automated decision-making disclosure is a hard date, not a recommendation. If AI touches decisions about credit, eligibility, pricing or service access, this applies to you.

Most of these are governance failures rather than technical ones, which is the pattern we see across the board — see the mistakes killing AI adoption in Australian businesses.

Frequently asked questions about AI and the Privacy Act

Does the Privacy Act apply to my small business if I use AI?

It depends on your turnover and your industry. Businesses with annual turnover of $3 million or less are generally exempt, but the Privacy Act covers health service providers, credit reporting bodies, Commonwealth contractors, businesses trading in personal information and AML/CTF reporting entities regardless of size. Since 1 July 2026, that last category includes lawyers, accountants, conveyancers and real estate agents.

Can I put client data into ChatGPT or Claude in Australia?

There is no blanket prohibition, but the Australian Privacy Principles still apply to that disclosure. Check whether your plan contractually excludes your inputs from model training, where the data is processed for the purposes of APP 8, and whether the individual would reasonably expect their information to be used this way. Business and enterprise tiers generally give you the contractual position you need; free consumer tiers often do not.

What changes on 10 December 2026?

New subclauses APP 1.7, 1.8 and 1.9, introduced by the Privacy and Other Legislation Amendment Act 2024, commence on that date. APP entities must disclose in their privacy policy the kinds of personal information used by computer programs that make decisions significantly affecting individuals' rights or interests, the kinds of decisions made, and how someone can seek meaningful human review.

Do I need to tell customers I am using AI?

Not for every use, but yes where automated decision-making significantly affects their rights or interests — that becomes a privacy policy requirement from 10 December 2026. More broadly, APP 1 requires open and transparent management of personal information, and the OAIC's AI guidance recommends transparency as good practice well beyond the minimum.

What happens if an AI vendor causes a data breach?

If the breach involves personal information you hold and is likely to result in serious harm, the notification obligation under the Notifiable Data Breaches scheme is yours, not just the vendor's. The OAIC received 1,205 notifications in 2025, the highest since the scheme began. Your response plan should name who assesses a vendor incident and how quickly.

Where to start

Pick the three AI tools your team uses most and check item 4 on the checklist — the training clause. That one check tells you more about your exposure than a week of reading legislation. Then work the rest of the list in order before the December deadline.

If you would rather have it done properly, book a call with Pivot 2 Thrive. We audit the stack, document what needs documenting, and rebuild the workflows that cannot stay as they are. More guides are on the Pivot 2 Thrive blog, and you can see the full range of what we build at pivot2thrive.com.au.

Related articles

Priya Jaganathan

Priya Jaganathan

Dr Priya Jaganathan is a Go High Level Certified Admin, trusted CRM consultant based in Australia, and a keynote speaker at SaaSpreneur Sydney and Level Up 2025 in Dallas.

Back to Blog