AI and the Australian Privacy Act

There's a common assumption that AI sits in a legal grey area in Australia and that everyone is waiting for rules. For privacy, that isn't really the position. The Privacy Act already applies, and it applies in a way that's reasonably predictable once you look at it directly.

This is general information, not legal advice. If you handle health, financial, government or other regulated information, get advice specific to your circumstances.

The starting point

The Act regulates personal information — information about an identified individual, or one who is reasonably identifiable. It doesn't matter whether you process that information in a spreadsheet, a CRM or an AI tool. The obligations attach to the information, not the software.

So the question is never "is AI allowed". It's the same question you'd ask of any new system: what are we doing with personal information, and does that sit within what we've collected it for and told people about?

The principles that bite most often

APP 6 — use and disclosure. You can generally use personal information for the purpose you collected it for. Using it for something materially different needs consent or another basis. Running client data through an AI tool to do the work you were engaged for is usually consistent; using it to train something for an unrelated purpose usually isn't.

APP 8 — cross-border disclosure. This is the one most businesses miss. The major AI providers process outside Australia, so using them typically involves a cross-border disclosure — and you remain accountable for how that recipient handles the information. Business-tier terms matter here, because they're where those protections live.

APP 11 — security. You must take reasonable steps to protect personal information. Staff pasting client data into free consumer accounts on personal logins would be difficult to characterise as reasonable steps.

APP 1 — open and transparent handling. Your privacy policy has to actually describe what you do. If AI tools are now part of how you handle personal information, the policy should say so.

An Australian small-business example

A Queensland allied health practice starts using an AI tool to summarise session notes. It saves real time.

Three problems, none of them exotic. Health information is sensitive information, attracting higher protection. The tool is a consumer tier with no commitment against training. And the practice's privacy policy — written in 2019 — says nothing about disclosure to a third-party processor overseas.

The AI use isn't automatically unlawful. But it was adopted without anyone running the three checks that would have been run for any other new system touching patient records.

A practical sequence

Where this is heading

Australia has been consulting on AI-specific regulation, particularly for high-risk uses, and Privacy Act reform has been under way for some time. The direction of travel is toward more obligation rather than less.

That's an argument for building the habits now while the stakes are low — knowing your tools, using business tiers, keeping personal information out of places it shouldn't be. Businesses that do this will find future requirements a matter of documentation. Businesses that don't will be starting from an unknown position.

Frequently asked questions

Does the Privacy Act even apply to us?
It applies to most businesses with turnover above $3 million, and to some smaller ones regardless of turnover — including health service providers and businesses trading in personal information. Small-business exemptions have been under active review, so if you're relying on one, check where that currently stands.
Is using an AI tool a 'disclosure'?
Generally yes when the information leaves your control and goes to a provider — particularly one overseas. APP 8 deals with cross-border disclosure and is the one most often overlooked, since the major AI providers process outside Australia.
Do we need consent to use AI on customer data?
Not automatically — it depends on what you collected the information for and what you told people. If AI processing is consistent with the original purpose and your privacy policy covers it, that's a different position from feeding data into a new tool nobody was told about.
What if we remove names first?
De-identification genuinely reduces risk and is worth doing by default. But be realistic — information can remain identifiable through context even without a name, particularly in small markets or niche industries.
What's the practical minimum?
Know which tools staff use, know where those providers process data, make sure your privacy policy reflects reality, and don't put personal information into consumer-tier tools. That covers most of the exposure for most businesses.

Put this to work

Ad On Group runs AI training and enablement for Australian teams through Ad On AI — a three-month, self-paced program that takes non-technical staff from their first prompts to working AI agents.

Talk to us →

Keep reading

← All resources