AI in Australian councils: which privacy law applies to yours
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Your council is not covered by the Privacy Act 1988, and that is the first thing to get straight about AI in local government. The OAIC says so in one line: the Privacy Act “does not cover local, state or territory government agencies, except the Norfolk Island administration”. The law that does cover you is your state’s, there are eight different answers to that question in Australia, and two of them changed on 1 July 2026.
That matters more than it sounds, because almost every piece of AI guidance a council officer gets handed is written against the wrong statute. The federal policy is for Commonwealth departments. The OAIC material is for APP entities. The vendor deck quotes both.
Meanwhile the rule that decides whether a customer service officer can paste a complaint into a chat window sits in a state Act the deck never mentions. In New South Wales that rule has nothing to do with consent: it turns on the information leaving the state, and a free chat account fails it before anyone has read a privacy policy.
This guide is the operational version: which law binds your council, the two rules that decide it, the closest thing Australia has to a worked example, what your prompts do to your records, and what to put in a tender. If someone has already pasted something they should not have, that question has its own clock, and if a renewal pack asked you about AI, that is a different document again.
How AI in local government is already being used, and which of it touches a resident
In November 2024, Noosa Shire Council bolted a camera to a waste truck. As the garbage runs went out on their normal routes, the camera scanned roads and paths, an AI model picked out defects, triaged them by urgency, and wrote work orders straight into the council’s asset management system with location, maps and photographs attached. The system covers all 871 square kilometres of the shire in a fortnight. In the first two months it found and fixed 4,356 defects.
Nothing in that system is a resident. It is bitumen, and the risk it carries is a wrong work order, not a privacy breach. Hold that thought, because it is the distinction most council AI conversations skip.
There are 537 councils in Australia and they employ about 213,500 people, so there is a great deal of this going on, and only some of it is the kind that should worry a privacy officer.
The other kind of use is the one nobody procured. Maddocks surveyed 337 local government officers across 75 Victorian councils in September and October 2025, then ran a pulse survey of 100 officers in June 2026.
The picture it published on 22 July 2026 is of a sector using AI mainly for drafting, research and everyday productivity, with comparatively little of it embedded in service delivery. Governance is running behind: around one third of respondents believed their council had a finalised governance structure in place.
Of those officers, 74 per cent named customer service as the greatest opportunity. Customer service is also where the resident’s name is. That is the whole tension in one survey answer.
| What the council bought | What goes into it | Where the risk sits |
|---|---|---|
| Asset and defect detection, like Noosa’s | Road surfaces, images of public space | Wrong work order, wasted crew time |
| A chatbot on the website | Whatever the public types into it | Collection you did not plan for |
| Microsoft 365 Copilot on the tenancy | Everything the staff member can already open | Access scope, not transmission |
| A free account somebody opened themselves | Whatever is on screen at the time | Disclosure, and you will not know it happened |
The fourth row is the one this guide is about. It is also the only one with no procurement record.
The first three went through procurement. The fourth is a browser tab, and the tools in it are the ones a council officer already knows by name. What each of them does with what you type is documented, and it differs: ChatGPT keeps more than most people assume, and Copilot’s question is a different one altogether, because the issue there is what the account can reach rather than where the text goes.
The information a council holds, and the part that is sensitive without looking it
A council is not a hospital and it is not a bank, which is why its data keeps getting described as low risk. Then you list it.
Rates accounts and hardship applications, which often carry a Centrelink customer reference number. Parking and animal infringements, with a registration plate and a home address. Planning objections, where the objector’s name may be public but their phone number is not. Home care and Meals on Wheels rosters, immunisation records, library borrowing. Immunisation sessions are usually run by registered nurses, and Ahpra’s guidance on patient data and AI applies to them too.
Then the two that would stop a lawyer in their tracks. Complaints about a neighbour, which is a named allegation about a person who has not been told. And arrangements made with a family violence service to keep someone safe at home, where the address is the protection and disclosing it is the harm.
The trap is the word “sensitive”. In the Victorian Act it has a narrow statutory meaning: nine categories listed in Schedule 1, things like racial or ethnic origin, religious beliefs and political opinions. OVIC’s own investigation report stops to make this point, and coins a second term for everything else:
What individuals may think of as information that is sensitive to them, for example, information they regard as embarrassing or secret, may not fall within one of the nine categories. The term ‘delicate information’ is used to refer to such information.
A neighbour dispute is delicate and not sensitive. A hardship application is delicate and not sensitive. Both of them are personal information, which is the definition that actually triggers the obligations, and a staff member checking whether something is “sensitive” before pasting it is checking the wrong box.
There is also a set of identifiers that turn up in council files and almost nowhere else.
| Identifier | Where a council meets it | Looks like |
|---|---|---|
| Centrelink CRN | Rates hardship, financial counselling referrals | Nine digits and a letter |
| Medicare number | Aged care and home support referrals | Ten digits plus an IRN |
| Registration plate | Parking and animal infringements, abandoned vehicles | Up to six characters, format varies by state |
| ABN | Contractor invoices, grant acquittals | Eleven digits |
| NMI | Utility and connection disputes | Ten or eleven characters |
None of these looks like a name, and every one of them identifies someone.
They identify someone without an officer registering it as personal information. And they survive a careless copy and paste better than a name does, because an officer skimming a prompt before sending it is looking for words, not for nine digits and a letter in the middle of a case note.
The practical consequence is that “no personal information in the prompt” is a harder instruction to follow than it sounds, and an officer who believes they have complied often has not. Whether that failure is also a notifiable breach depends on the harm, not the intent, and the tool the text went into decides how far it travels afterwards: a consumer chat account and a managed tenancy behave differently with the same paragraph.
Which privacy law applies to your council, state by state
Start with what is not in play. The OAIC’s own page on state and territory privacy legislation is unambiguous, and it was last updated on 1 December 2025:
The Privacy Act is a federal law which does not cover local, state or territory government agencies, except the Norfolk Island administration.
The same page tells you where to go instead, and it names councils explicitly: complaints about a New South Wales, Queensland, Northern Territory, Tasmanian or Victorian public sector agency, “including a local council”, go to that jurisdiction’s commissioner.
| Jurisdiction | What binds your council | Who you answer to |
|---|---|---|
| New South Wales | PPIP Act 1998 and HRIP Act 2002 | Information and Privacy Commission NSW |
| Victoria | Privacy and Data Protection Act 2014 | OVIC |
| Queensland | Information Privacy Act 2009 | Office of the Information Commissioner Qld |
| Tasmania | Personal Information Protection Act 2004 | Tasmanian Ombudsman |
| Northern Territory | Information Act 2002 | OIC Northern Territory |
| Western Australia | PRIS Act 2024, in force since 1 July 2026 | Office of the Information Commissioner WA |
Six jurisdictions with a statute. Sources: OAIC, State and territory privacy legislation, updated 1 December 2025, and the WA Government’s Privacy and Responsible Information Sharing page, updated 1 July 2026.
That leaves two that are not on the list, and neither is an omission.
The five where nothing has changed, and one that just added a clock
In New South Wales, Victoria, Queensland, Tasmania and the Northern Territory, your council has been inside a privacy statute for years, and the officer who has been doing this a while knows it. What changed recently is in Queensland, and it is about what happens after something goes wrong, not about what you are allowed to do.
Queensland’s mandatory notification of data breach scheme, in Chapter 3A of the Information Privacy Act 2009, started for the rest of the Queensland public sector on 1 July 2025. It reached local government on 1 July 2026.
A Queensland council now has three things to get right, and the first is a judgement call made under time pressure.
- Decide whether it is an eligible breach. Unauthorised access, disclosure or loss, likely to result in serious harm.
- Notify. The affected people and the Information Commissioner, unless an exemption applies.
- Publish, if you cannot reach people directly. The notice stays online for at least twelve months.
| A Queensland council’s position | Before 1 July 2026 | From 1 July 2026 |
|---|---|---|
| Handling personal information under the IP Act 2009 | Bound | Bound |
| Notifying an eligible data breach | Outside the scheme | Mandatory, unless an exemption applies |
| Publishing a notice when people cannot be reached | Not required | Online for at least twelve months |
Only the middle row changed, and it is the row that turns a quiet mistake into a public one.
That is worth sitting with in an AI context. When an officer pastes a case file into a free chat account, that is an unauthorised disclosure, and whether it is an eligible breach turns on likely serious harm. For a family violence address or a child protection note, that is not a difficult argument to make.
New South Wales has had its own mandatory scheme in Part 6A of the PPIP Act for longer, and the IPC’s generative AI guide says plainly that information resurfacing from an AI tool may constitute a notifiable breach under it. So when a paste becomes a reportable breach is live in most of the country, and in Queensland and Western Australia it is newly live.
Western Australia, where it started on 1 July 2026
Until 1 July 2026, a WA council had no privacy statute at all. On that day the Privacy and Responsible Information Sharing Act 2024 commenced, and the WA Government’s own page is explicit about who it catches: the privacy obligations apply to WA public sector entities, “including local governments”, along with government trading enterprises and public universities.
There is a second date behind it. From 1 January 2027, WA agencies must report serious data breaches to the Information Commissioner and to the people affected. Until then a WA council sits in the gap: obliged on handling, not yet obliged on notification, and obliged on both from 1 January 2027.
South Australia, which has no Act and the sector’s best toolkit
| Jurisdiction | Why it is not in the table above |
|---|---|
| South Australia | No privacy statute. Obligations come from the council’s own policy, its records and FOI duties, and its contracts |
| Australian Capital Territory | No council layer exists. The ACT Government does the municipal work, under the Information Privacy Act 2014 (ACT) |
The ACT row is not a gap in the research. There is nothing there to regulate.
South Australia is the last state standing without privacy legislation. The OAIC describes the state privacy committee’s remit as state government agencies’ compliance with a set of Information Privacy Principles, and does not include SA in its list of jurisdictions where a local council complaint has a commissioner to go to. In practice an SA council’s obligations come from what it has adopted itself, plus its records and freedom of information duties, plus whatever its contracts say.
And then the thing you would not predict. The most complete AI governance kit in Australian local government came out of South Australia: LGITSA published an AI Adoption Toolkit in September 2025, built with the Local Government Association of South Australia, Local Government Risk Services and LG Professionals SA.
It runs to an adoption manual, a governance guide, a strategy guide and a transparency guide. The state with the least law wrote the most guidance. Make of that what you will, but do not take the lack of a statute to mean nobody expects anything, and do not assume a resident in Adelaide has lower expectations than one in Hobart.
In the absence of an Act, an SA council’s obligations are assembled from three other places:
- Its own adopted policy, which is enforceable internally and is what an ombudsman or an auditor will read first.
- Records and freedom of information duties, which apply regardless and reach prompts as readily as emails.
- Its contracts, including with suppliers who are APP entities in their own right and can be bound through the agreement.
One last wrinkle that catches councils out in every state. You may not be an APP entity, but your supplier probably is. A private company turning over more than $3 million is covered by the Privacy Act in its own right, whatever your state law says about you.
That is a lever to use in a contract, not a loophole to worry about, and it is the reason the procurement section further down is the most useful part of this guide for a council with no privacy officer. It is also why the policy that governs your own staff and the clauses that govern your suppliers have to say the same thing, or the gap between them is where the incident happens.
The two rules that decide it: disclosure, and sending it out of the state
Once you know which Act applies, only two ideas in it do most of the work.
| The rule | In New South Wales | In Victoria |
|---|---|---|
| You may only use and disclose it for the purpose you collected it for | IPPs 10, 11 and 12 | IPP 2.1, with IPP 4.1 on security |
| You may not send it out of the state without an equivalent protection | Section 19(2), PPIP Act | IPP 9, transborder data flows |
The second row is the one vendors never raise, and in New South Wales it is the harder of the two.
The first is use and disclosure. Putting personal information into a tool run by another company is a disclosure to whoever runs the tool. The IPC NSW guide sets it against IPP 10, which limits use to the purpose of collection, and IPPs 11 and 12, which limit disclosure to what is directly related and unlikely to be objected to.
Victoria gets to the same place through IPP 2.1, with IPP 4.1 covering the security side of the same paste. Nothing about this is new law, and none of it was drafted with a chat window in mind. It still catches one, and a ratepayer who gave you their details to fix a footpath did not expect them in a language model.
The second is the one almost nobody quotes at councils, and in New South Wales it is decisive. Section 19(2) of the PPIP Act stops a public sector agency disclosing personal information to anyone outside New South Wales unless the agency reasonably believes the recipient is subject to a law, binding scheme or contract that upholds substantially similar principles, or the individual expressly consents, or another exception applies. The IPC’s guide spells out the consequence:
Most major Gen AI providers are established in jurisdictions outside of New South Wales and may process personal information offshore.
Read that against a free account. There is no contract, no binding scheme, and certainly no express consent from the ratepayer whose complaint is in the prompt. Victoria has its own version in IPP 9 on transborder data flows, and OVIC’s guidance says entering personal information into publicly available generative AI tools will likely contravene the IPPs.
This is why “the model is hosted in the United States” is not a footnote for an Australian council. In NSW it is close to the whole question, and it is a question about where the text goes, not about which brand is on the tab. It is worth knowing what each provider actually does with it: Gemini’s answer and Claude’s are not the same, and neither of them turns an offshore disclosure into a domestic one.
The closest thing Australia has to a worked example, and it is not a council
There is no published Australian case of a council being sanctioned over generative AI. There is something almost as useful: a regulator’s full investigation into a Victorian public sector body, under the exact Act and the exact principles that bind a Victorian council, published in the open.
In December 2023 the Department of Families, Fairness and Housing told OVIC that a child protection worker had used ChatGPT while drafting a Protection Application Report. The report went to the Children’s Court, in a matter concerning a young child whose parents had been charged over sexual offences.
The detail that made it a national story is in the Commissioner’s foreword. The report described a doll, which had been reported to child protection as having been used by the child’s father for sexual purposes, as a mitigating factor: evidence that the parents had provided the child with “age appropriate toys”.
The effect was to downplay the severity of the harm to the child. OVIC records that the deficiencies did not in the end change the decision of either child protection or the Court. That is luck, not a control, and the Commissioner’s own summary of the lesson is that there are circumstances where “the privacy risks involved are simply too great”.
The finding that surprises people is the accuracy one
OVIC framed the case through two Information Privacy Principles, and the first is not the one anyone expects. IPP 3.1 requires an organisation to take reasonable steps to make sure personal information it collects, uses or discloses is accurate, complete and up to date. IPP 4.1 requires reasonable steps to protect it from misuse, loss and unauthorised access or disclosure. The Deputy Commissioner found the department contravened both, and that the contraventions were serious.
Accuracy as a privacy obligation is the part that changes how a council should think about drafting. A summary that softens a complaint, or invents a mitigating factor, is not just poor work. Under these Acts it is a handling failure with a regulator attached.
It was not one worker, and there was already a policy
A departmental review of one unit’s cases over a year found 100 with indicators that ChatGPT may have been used. Between July and December 2023, nearly 900 staff across the department accessed the ChatGPT website, close to 13 per cent of a workforce of around 7,000.
The department told OVIC it had controls: an Acceptable Use of Technology Policy, and eLearning modules on privacy, security and human rights. The regulator was unimpressed, and the sentence that follows is the one to read to your executive team:
However, OVIC found that these controls were far from sufficient to mitigate the privacy risks associated with the use of ChatGPT in child protection matters. It could not be expected that staff would gain an understanding of how to appropriately use novel GenAI tools like ChatGPT from these general guidance materials.
On 24 September 2024 it issued a compliance notice with six specified actions, including IP and DNS blocking for child protection staff, to be in place by 5 November 2024 and maintained until 5 November 2026. A regulator ordering a department to block a website for two years is about as clear a statement of where the line sits as this jurisdiction has produced.
Substitute a council’s community services team for child protection, and every element of that finding survives the swap: the same Act, the same principles, the same regulator, and very probably the same set of existing policies. A Victorian council reading the report will recognise its own control environment in it.
Two things follow for the rest of the country. The Victorian IPPs are not unique, so the reasoning transfers to any state with an equivalent Act. And the exposure did not come from an exotic tool: it came from the chat product everybody already has open, used by one competent person under deadline, in a way nobody had told them was a disclosure.
What the official guidance says, and how much of it binds you
Councils get handed three layers of AI guidance and are rarely told which layer is an obligation. It is worth separating them out.
| Document | Issued by | Date | Does it apply to your council? |
|---|---|---|---|
| Policy for the responsible use of AI in government, version 2.0 | Digital Transformation Agency | In effect from 15 December 2025 | No. It is for non-corporate Commonwealth entities |
| National framework for the assurance of AI in government | Data and Digital Ministers Meeting | Agreed 21 June 2024 | Only if your state passes it down |
| Guide on the privacy risks of generative AI tools | IPC NSW | May 2026 | Yes, in NSW: it comes from your regulator |
| Guides on publicly available and on enterprise AI tools | OVIC | First one updated 26 June 2026 | Yes, in Victoria: it comes from your regulator |
| AI Adoption Toolkit, and the AI Roadmap | LGITSA in South Australia, MAV in Victoria | Toolkit: September 2025 | No. Free, and none of it is binding |
Three layers: federal, your state regulator, your own sector. Only the second applies to you, and it is the layer to read.
The federal layer, which does not apply to you
The Digital Transformation Agency’s Policy for the responsible use of AI in government is the document most often waved at local government. Version 2.0 took effect on 15 December 2025, after version 1.1 on 1 September 2024, and it carries real mandatory requirements: accountable officials, transparency statements, internal use case registers, staff training, impact assessments. Its scope line is also plain. It “applies to all non-corporate Commonwealth entities, with some exceptions”. Your council is not one.
Alongside it sits the National framework for the assurance of artificial intelligence in government, agreed by the Data and Digital Ministers Meeting on 21 June 2024. That one is genuinely national in reach: Commonwealth, states and territories. Local government does not have a seat at that meeting, so the framework arrives at your council only if your state chooses to pass it down. Useful as a model. Not a duty.
Your state’s regulator, which does
This is the layer to read. IPC NSW published a guide on the privacy risks of generative AI tools, most recently in May 2026, addressed to NSW public sector agencies, which includes councils. OVIC has two, on publicly available tools and on enterprise tools, the first updated on 26 June 2026.
They are short, they are specific, and between them they already contain most of what a council policy needs to say. Both regulators draw the same line between a consumer account and a managed one, and a council tenancy is there to keep you on the right side of that line.
They also contain a measurement nobody enjoys. In a desktop review of NSW agency Privacy Management Plans, the IPC found that only 13 per cent made any direct or indirect reference to the agency’s use of AI or automated decision-making. That is the regulator counting how many of its own agencies had written the thing down.
A privacy management plan is a statutory document under section 33 of the PPIP Act. If yours does not mention AI and your staff are using it, the gap is not theoretical.
Your own sector, which got there first
The peak bodies moved before most councils did. LGITSA’s AI Adoption Toolkit came out in September 2025 with an adoption manual, governance, strategy and transparency guides. In Victoria, MAV built an AI Roadmap through MAVlab and an AI Taskforce drawn from council staff, out of work on AI in statutory planning with the City of Greater Dandenong.
None of it is binding, all of it is written by people who know what a council actually does, and it is free. If your council is starting from nothing, start there rather than with a vendor’s framework, then put the policy itself in place: there is a template you can adapt in an afternoon.
Your prompt is a record, and an access request can reach it
Here is the obligation that has nothing to do with privacy and catches councils completely unprepared.
State Records NSW published guidance on AI and recordkeeping on 9 February 2024, and its starting position is simple: any record created during government business, whether by a person, a computer system or AI, is a State record. What follows from that is the part worth reading twice. Metadata for a record that AI produced must include confirmation that AI generated it, the software used, and “the prompts, inputs or algorithms used to create the record”.
Then the storage rule, with its own example attached:
AI-generated records must be saved in official recordkeeping systems to ensure they are secure and accessible when required (for example, for GIPA requests).
| What the task produces | Where it ends up | Who can reach it |
|---|---|---|
| The final letter to the resident | The council’s CRM and records system | The council, and an access request |
| The prompt that contained the details | A chat history on someone’s account | Not the council. Possibly the provider |
| The draft the officer discarded | Usually nowhere | Nobody, which is its own problem |
Only the first row is under the council’s control, and it is the least revealing of the three.
Follow that through. An officer drafts a response to a noise complaint in a chat window, tidies it and pastes the final text into the CRM. The council’s record system now holds the polished answer. The prompt, which contained the complainant’s name, the neighbour’s address and the officer’s own uncharitable summary of the dispute, lives in a chat history on a personal account, outside the record system, where the council can neither find it nor dispose of it, though someone else may be able to.
Victoria runs the same logic through the Public Records Act and PROV’s AI recordkeeping policy, and Queensland has its own. The access side varies by name: GIPA in New South Wales, RTI in Queensland, FOI in Victoria.
The practical point does not vary. A resident unhappy with how their complaint was handled can ask what the council holds about them, and a prompt is something the council either holds properly or has lost track of. Neither answer is comfortable, and one of them is a records failure sitting on top of a privacy one.
The obligation a masking layer does not touch
It is worth being clear about this early, because no masking tool fixes it. Stripping the names out of a prompt makes the disclosure smaller. It does not put the prompt in your records system. Where the text ends up is a separate design decision, and a managed tenancy keeps it somewhere you can reach while a personal account keeps it somewhere you cannot.
Accuracy, automated decisions, and the resident nobody told
Councils make decisions about people all day. A hardship remission. A pensioner rebate. A permit. An infringement review. A priority rating on a home care waitlist. None of those are high risk in the way a child protection report is, and all of them significantly affect somebody.
The IPC’s guide carries a worked case study that reads like a council grants round. An officer uploads every application, plus a spreadsheet of applicants’ personal information, and asks the tool to summarise and rank them.
The outputs weigh irrelevant matters, overemphasise the strengths of certain demographic groups, and ignore the published selection criteria. The officer approves the grants on that basis without validating anything. Strong applicants miss out, and every applicant’s personal information has now been disclosed without their knowledge.
Three obligations fail at once in that paragraph, and only one of them is about data leaving.
| What fails | Where it comes from | Why a tool will not fix it |
|---|---|---|
| Accuracy | IPP 3.1 in Victoria, IPP 9 in New South Wales | A confident summary that is wrong breaches this even if nothing leaked |
| The decision itself | The delegation or local law the officer acts under | “The model ranked them” is not a reason a review body accepts |
| Transparency | IPC guidance on notices and human review | The resident has to be told, and told how to reach a person |
All three sit inside one paragraph of the IPC’s case study.
On the federal side, APP 1.7 to 1.9, introduced by the Privacy and Other Legislation Amendment Act 2024, commence on 10 December 2026. They will require APP entities to disclose in their privacy policy where a computer program uses personal information to make decisions significantly affecting someone’s rights or interests.
Your council is generally not an APP entity, so this is not your obligation, and a vendor telling you otherwise has not checked. It is a clear signal about where the state equivalents are heading, and from 10 December 2026 your contracted suppliers will be inside it even where you are not.
The cheapest response is to know which of your decisions a machine has touched, before somebody asks. That is the same inventory your AI policy should already be building, and it is the same list you will need if an incident ever has to be assessed.
What a council AI policy says, and what it cannot do on its own
Plenty of Australian councils have now adopted one, and they are public, which makes them the cheapest research available.
Murrindindi Shire Council adopted its Generative Artificial Intelligence Policy on 26 June 2024. It binds “Councillors, employees, contractors, and service providers”, and says adherence is mandatory across all council operations involving AI. Councillors being in scope is the detail worth copying.
It restricts entering information into public AI tools where the information is not already public, would not be released under the council’s Public Transparency Policy, or carries an Official Sensitive or Protected Sensitive label. Then it puts the position bluntly in its privacy principle: entering confidential, private or otherwise sensitive information into an AI tool “is not consented”.
It also requires a disclaimer where AI content may be present, and it sends anything that becomes a corporate record into the records policy with its sensitivity labelling, storage and retention intact. A short document, adopted at a council meeting, free to read. If you are starting from a blank page, start from theirs and a model policy rather than from a vendor’s template.
North Sydney, a different route to the same place
North Sydney Council went about it differently. It adopted its Use of Artificial Intelligence Policy at the 9 February 2026 council meeting, after putting the draft on public exhibition with submissions closing on 25 January 2026, and it is building operational policies underneath it.
A council consulting its community on its own AI policy is a small thing that says a lot about where the trust question sits for AI in local government. Nobody puts their email retention policy on exhibition.
| What a written policy does well | What it cannot do |
|---|---|
| Sets the rule, in writing, with a date | Stop a paste at the moment it happens |
| Binds contractors and councillors, not just staff | Reach a personal account on a personal phone |
| Gives an officer cover to say no | Tell you when it was ignored |
| Puts AI into the records and privacy plans | Detect a CRN inside a pasted case note |
The left column is necessary. The OVIC case is the evidence that it is not sufficient.
Because that is the finding worth repeating. DFFH had a policy and had training, and the regulator still called the controls far from sufficient.
Maddocks found around a third of Victorian council officers believed their council had a finalised governance structure, which means two thirds were working without one or did not know whether they had one.
A rule nobody can see being enforced decays into a rule nobody follows, and the council finds out from the regulator or from a journalist. That gap between the rule and the mechanism is the only good reason to look at what a tool on the desktop can do about it.
What to ask a vendor before the procurement closes
Council procurement is a tender, not a conversation, which is an advantage: the questions have to be written down. The IPC’s guide effectively drafts them for you, and the list transfers to any state. The first clause on it is the one providers answer differently in their own terms, which is why it belongs in a contract rather than in a settings screen.
| Ask for | Why it matters here |
|---|---|
| An enterprise service, not a consumer plan | Consumer defaults often train on what you send |
| A clause prohibiting use of your data for model training | Turns a setting you can lose into a term you can enforce |
| Protection aligned to your state Act, including breach notification | In Qld and WA this now has statutory deadlines behind it |
| Defined data retention and deletion timeframes | Extended retention multiplies every other risk |
| Audit rights and a right to terminate for privacy failure | Without it, failing to comply costs the vendor nothing |
| Australian data residency where possible | In NSW this speaks directly to section 19(2) |
| Named status as a contracted service provider | Decides whether your Act reaches them at all |
Source: the IPC NSW generative AI guide, May 2026, which lists the first six as terms agencies should require.
Two additions from the local government side. Ask where the processing happens, not where the company is registered, because those are different answers and only one of them is the disclosure that section 19(2) cares about.
And ask what happens on exit. A council that has to switch suppliers after a contract dispute needs the data out in a usable format, not a migration quote, and that clause costs nothing at tender and a great deal afterwards.
One adjacent question is worth resolving in the same quarter, because it lands in the same file from a different direction. Cyber cover is where a breach becomes a number, and what an Australian policy does and does not include is easier to establish now than during an incident.
Answering a complaint without the resident’s details leaving the building
Abstractions do not help an officer at 4pm on a Thursday. Here is the concrete version.
A resident emails about a neighbour’s barking dog. The file on screen has the complainant’s name, their street address, their mobile number, a note that they are on a rates hardship arrangement with a Centrelink reference number, the neighbour’s address, and the registration of a car from an earlier complaint.
The officer wants help writing a firm, polite response that explains the council’s process. That is a completely legitimate thing to want, and refusing it is why staff open a personal account on their phone instead.
| What is on the officer’s screen | What the model needs to do the job |
|---|---|
| The complainant’s full name | “the resident” |
| Their address and the neighbour’s | “the property” and “the adjoining property” |
| Mobile number, CRN, registration | Nothing. None of it is relevant to the drafting |
| The chronology of the complaint | The chronology of the complaint |
| The council’s local law and process | The council’s local law and process |
Done by hand, this takes about ninety seconds and produces a better prompt, because the model is no longer distracted by identifiers it cannot use.
The three checks before anything is sent
- Is there a name, a number or an address still in the box? Read the prompt, not the file. The usual failure is a copy that went one paragraph too far.
- Would this sentence be fine if the resident read it? They may. It is a record, and it is reachable.
- Where is this going? A council tenancy with training turned off is a different disclosure from a personal free account, and in NSW section 19(2) treats them differently too.
The reason to do it by hand once is that it shows you where the work is. The work is in the stripping rather than the drafting, every time, under time pressure, by somebody with forty of these in the queue. That is the part that fails, and it fails quietly.
It is also worth knowing that the destination matters as much as the content. The same stripped prompt behaves differently depending on whether the provider trains on it, and the major assistants do not answer that the same way, including on what the default setting actually is.
What a tool fixes, and what it does not
Be honest about the scope of the problem a masking layer solves, because it is narrower than the pitch usually suggests. It changes what text leaves the building. It does not create a record, it does not make an output accurate, it does not make a decision lawful, and it does not tell a resident that AI was involved. Four of the five obligations in this guide survive the purchase untouched.
| Obligation in this guide | Does a masking layer help? |
|---|---|
| Disclosure, and border rules such as section 19(2) | Yes, that is the whole job |
| Records: capturing the prompt | No. That is your records system |
| Accuracy of an output about a resident | No. That is a human reading it |
| Lawful decision by the right officer | No. That is a delegation question |
| Telling a resident AI was involved | No. That is your privacy notice |
One row in five. Worth establishing before a procurement paper implies otherwise.
Nonimo is a Mac and Windows app that sits in front of whatever AI tool you already use, with the policy set by IT rather than by each officer. The officer selects the text and presses a key, and the identifiers it recognises become labels such as [PERSON_1], [ADDRESS_1], [PHONE_1] or [REFERENCE_1] before anything is sent. What it recognises includes each Australian number it knows by name, from the TFN to the Medicare card.
It is pseudonymisation rather than anonymisation, and the difference is legal rather than cosmetic. The mapping is kept, encrypted, on the user’s own machine, so the officer can restore the real names in the answer that comes back. Reversible by design is the right behaviour for council work, where the finished letter has to name the actual resident, and for that very reason it is not the same thing as anonymous.
What the app keeps on the machine is set out on Nonimo’s security page.
When your council should not buy anything
Three cases, and they are common.
- You have already blocked public tools and issued an enterprise tenancy with training off. Your remaining exposure is training and records, not transmission. Spend the money on half a day of staff training.
- Your problem is the decision, not the disclosure. If AI is drafting determinations, no masking layer touches that. You need a delegation review and a human review path.
- You have no policy yet. Write it first. A control with no rule behind it is unenforceable, and the policy template costs nothing.
The council that should look at a tool is the one where the rule exists, staff broadly accept it, and it still gets broken at four in the afternoon by someone with a queue. That is a mechanism problem, and policies do not solve mechanism problems.
Whatever you decide about tools, the page worth writing this week is shorter than any of this. Which Act binds us. What our staff may and may not enter, named tool by named tool. Where the prompt gets saved. Who reviews an output before it affects a resident. And who a resident asks when they think a machine was involved.
Five answers, on one page, dated and adopted. Your regulator has published most of them already and two councils in this guide have published theirs. For the rest, the model policy will get you started, and the cover that pays when this goes wrong is easier to read once that page exists.
Sources
- OAIC, State and territory privacy legislation, updated 1 December 2025. That the Privacy Act “does not cover local, state or territory government agencies, except the Norfolk Island administration”, and that NSW, Queensland, NT, Tasmanian and Victorian commissioners handle complaints about a public sector agency “including a local council”. oaic.gov.au
- OVIC, Investigation into the use of ChatGPT by a Child Protection worker, report dated 24 September 2024. The findings against IPP 3.1 and IPP 4.1, the “age appropriate toys” passage, the 100 cases, the nearly 900 staff and 13 per cent of a workforce of around 7,000, the controls found “far from sufficient”, and the compliance notice with six actions running to 5 November 2026. Regulatory action page and the full report
- OVIC, Use of publicly available Generative AI tools in the Victorian public sector, last updated 26 June 2026. That organisations should ensure staff do not enter personal information into publicly available generative AI tools, that doing so will likely contravene the IPPs, and the IPP 9 transborder point. ovic.vic.gov.au
- IPC NSW, Guide: Privacy risks associated with the use of generative AI tools, May 2026. Section 19(2) of the PPIP Act and the offshore processing point, IPPs 10, 11 and 12, the grants case study, the 13 per cent finding on Privacy Management Plans, and the vendor contract terms. ipc.nsw.gov.au
- Government of Western Australia, Privacy and Responsible Information Sharing, updated 1 July 2026. That the PRIS Act 2024 commenced on 1 July 2026, that the privacy obligations apply to WA public sector entities “including local governments”, and that serious data breach reporting starts on 1 January 2027. wa.gov.au
- Office of the Information Commissioner Queensland, What is Queensland’s data breach scheme, in effect from 1 July 2026. The eligible data breach test, the notification content, and the requirement to keep the notice published for twelve months. oic.qld.gov.au
- Digital Transformation Agency, Policy for the responsible use of AI in government, version 2.0, effective 15 December 2025, after version 1.1 on 1 September 2024. That it “applies to all non-corporate Commonwealth entities, with some exceptions”. digital.gov.au
- Department of Finance, National framework for the assurance of artificial intelligence in government, agreed by the Data and Digital Ministers Meeting on 21 June 2024, by the Australian, state and territory governments. finance.gov.au
- Maddocks, Bridging the Gap: AI risk and governance in local government, released 22 July 2026. Survey of 337 local government officers across 75 Victorian councils in September and October 2025, plus a 2026 pulse survey of 100 officers: around one third believing a governance framework is in place, 74 per cent naming customer service as the greatest opportunity, and privacy and data protection as the leading concern. maddocks.com.au
- State Records NSW, Artificial intelligence and public office recordkeeping, last updated 9 February 2024. That any record created during government business is a State record, the metadata requirement covering “the prompts, inputs or algorithms used to create the record”, and that records generated by AI must be saved in official recordkeeping systems, “for example, for GIPA requests”. nsw.gov.au
- ALGA, Facts and Figures. That there are 537 councils across Australia and that local government employs about 213,500 people, nearly 12 per cent of the total public sector. alga.com.au
- Noosa Shire Council, Council supercharges road safety using AI, 26 November 2024. The camera on a waste truck with TechnologyOne, the sweep of 871 square kilometres in two weeks, and 4,356 defects identified and rectified in the first two months. noosa.qld.gov.au
- Murrindindi Shire Council, Generative Artificial Intelligence Policy, adopted 26 June 2024. The scope covering councillors, employees, contractors and service providers, the restrictions on entering information into public AI tools, the “is not consented” wording, the transparency disclaimer and the corporate records requirement. murrindindi.vic.gov.au
- North Sydney Council, Draft Use of Artificial Intelligence Policy. That the policy was adopted at the 9 February 2026 council meeting following public exhibition, with feedback closing 25 January 2026. yoursay.northsydney.nsw.gov.au
- LGITSA, AI Adoption Toolkit, documents version 1.0, September 2025. Funded by LGITSA with the Local Government Association of South Australia, Local Government Risk Services and LG Professionals SA. lgitsa.com.au
- Municipal Association of Victoria, The AI Roadmap for Local Government. The MAVlab roadmap and AI Taskforce, out of the Advancing AI in Statutory Planning project with the City of Greater Dandenong. mav.asn.au
- OAIC, APP Guidelines chapter 1. That APP 1.7 to 1.9, introduced by the Privacy and Other Legislation Amendment Act 2024, commence on 10 December 2026 and apply to APP entities. oaic.gov.au
Every source above was opened and read on 20 September 2026. Australian privacy law for councils is moving: Western Australia commenced on 1 July 2026, Queensland’s breach scheme reached local government the same day, and the federal provisions on automated decision-making arrive on 10 December 2026. Check the dates against the page before you rely on anything here.
Common questions
Does the Privacy Act 1988 cover AI in local government?
Generally no. The OAIC states that the Privacy Act is a federal law which does not cover local, state or territory government agencies, except the Norfolk Island administration. Councils are covered by their own state or territory privacy law instead, where one exists.
Can council staff use ChatGPT at work?
It depends on the state and on what goes in. OVIC tells Victorian public sector organisations their staff should not enter personal information into publicly available generative AI tools, and says doing so will likely contravene the Information Privacy Principles.
Which Australian states have privacy laws covering councils?
New South Wales, Victoria, Queensland, Tasmania and the Northern Territory have had one for years, and the OAIC names local councils in each. Western Australia joined them on 1 July 2026 under the Privacy and Responsible Information Sharing Act 2024.
Do South Australian councils have to follow privacy law?
South Australia has no privacy statute. The OAIC describes the state privacy committee's remit as state government agencies, so an SA council's obligations come from its own adopted policy and from its records and freedom of information duties. Check what your council has adopted.
Is a ChatGPT prompt a public record?
In New South Wales, yes in substance. State Records NSW says any record created during government business is a State record, and that metadata for records generated by AI must include the prompts, inputs or algorithms used to create the record.
Can a resident get the AI prompt about them through a GIPA request?
It can be. State Records NSW says records generated by AI must be saved in official recordkeeping systems so they are accessible when required, and it gives GIPA requests as the example. What lives only in a chat history is a separate problem.
What happened in the OVIC ChatGPT investigation?
A Victorian child protection worker used ChatGPT to draft a court report. OVIC found the department contravened IPP 3.1 and IPP 4.1, and on 24 September 2024 issued a compliance notice with six actions, including blocking the tools until 5 November 2026.
Does a council AI policy stop staff pasting resident data?
Not by itself. In the OVIC case the department already had an acceptable use policy and privacy eLearning, and OVIC found those controls far from sufficient to mitigate the risks of ChatGPT use. A policy sets the rule, it does not enforce it.
What should a council ask an AI vendor before signing?
The IPC NSW guide lists terms to require: no use of customer data for model training, protection aligned to the PPIP Act including breach notification, defined retention and deletion, audit and termination rights, and Australian data residency where possible.
Do the December 2026 privacy reforms cover councils?
APP 1.7 to 1.9 commence on 10 December 2026 and require disclosures about automated decision-making in privacy policies. They bind APP entities under the Privacy Act, which a council generally is not, so they set direction rather than obligation.