Which AI tools can you use under the Privacy Act?
· Updated · Written and maintained by Joaquín Trapero, Nonimo
None of them, and all of them, depending on how you use it. There is no register of approved products under the Privacy Act 1988, no certification, no adequacy list, and no regulator approval that a vendor can buy. Compliance describes an act rather than a property a piece of software can hold, and the entity that has to be able to defend that act is you.
That sounds like a dodge until you look at what the question is really asking. Most people asking it want to know one of two things: whether they are allowed to use a tool at all, and whether the thing they already pasted into one has landed them in trouble. Those have different answers, and the second is a different guide, on whether a paste is a reportable breach.
This page answers the first. It sets out the questions that actually decide whether a use is lawful in Australia, applies them to the four assistants most Australian offices have open right now, and is honest about which of those questions the tool answers and which only you can. Every legal source is primary, and every one of them was open in front of us on 20 September 2026.
Is any AI tool “Privacy Act compliant”?
No, and the phrase is worth retiring. The Privacy Act does not regulate software. It regulates APP entities, meaning agencies and organisations that fall within its scope, and it regulates what they do with personal information. A product cannot be an APP entity, so it cannot comply or fail to comply with anything.
What a vendor can do is give you commitments that make your compliance easier to establish: a contract that binds them, a default that does not train on your input, a retention period you can point to. Those are useful and they are not the same thing.
The Act regulates you, not the software
The practical consequence is that two firms can run the same tool, on the same plan, on the same day, and be in completely different positions. One has a business agreement, a written rule about what may be entered, and a record of the decision. The other has four people signed in with personal accounts.
Nothing about the product distinguishes them. Everything about the Privacy Act does. That is why this page is organised around questions rather than around brands, and why the comparison table further down is deliberately not a ranking.
Saying a tool is compliant is itself a representation
There is a second reason to avoid the phrase, and it comes from a different Act. The Australian Government’s own survey of the legal landscape for AI notes that Australian Consumer Law prohibitions on misleading and deceptive conduct may apply to “misleading statements as to the performance and outputs of the AI systems”.
So a supplier who tells you their product is Privacy Act compliant is making a representation about performance, and a firm that repeats it to a client is making one too. If you need a sentence for a client letter, the defensible one describes what you do, not what you bought.
First check whether the Privacy Act applies to you at all
This is the step almost every article on this subject skips, and in Australia it changes the answer for a very large number of readers. The Act does not cover every business. It exempts small business operators, which the OAIC defines as an individual, body corporate, partnership, unincorporated association or trust with an annual turnover of $3,000,000 or less for a financial year, unless an exception applies.
Turnover here means all income from all sources. It does not include assets held, capital gains or the proceeds of capital sales.
The $3 million line, and the ways past it
The exceptions matter more than the threshold, because they catch precisely the kinds of practice that worry about this subject in the first place.
Is annual turnover above the $3 million line?
YesThe Act applies.
NoGo through the exceptions below.
Do you provide a health service to another individual and hold any health information other than in an employee record?
YesCovered. Turnover is irrelevant.
Do you trade in personal information, disclosing it for a benefit or providing a benefit to collect it, without consent or statutory authority?
YesCovered.
Are you an AML/CTF reporting entity, or an authorised agent of one?
YesCovered, for the activities connected with those obligations.
Are you a contracted service provider for a Commonwealth contract, or have you opted in to be covered?
YesCovered.
NoGenerally exempt as a small business operator.
A sole practitioner physiotherapist is covered. A marketing agency of two people with $600,000 of revenue generally is not, on these rules. Neither of those is intuitive, and both change what the rest of this page means for you.
What changed on 1 July 2026 for lawyers, accountants and agents
The third exception has just become the largest one in the country. From 1 July 2026, AML/CTF obligations reach lawyers, accountants, conveyancers, real estate professionals and dealers in precious stones and metals. AUSTRAC said in March that on that date the number of businesses it regulates would grow from around 19,000 to close to 100,000 nationwide.
The OAIC’s own guidance for those entities, last updated 28 August 2026, states that small businesses that are reporting entities under the AML/CTF Act, and their authorised agents, “are required to comply with the Privacy Act in relation to the activities for the purposes of, or in connection with their obligations under the AML/CTF Act”.
Read the tail of that sentence carefully, because it is a limit and not a switch. The obligation attaches to the AML/CTF activities, not automatically to everything the firm does. But customer identification and verification records are exactly the material people feed into an assistant when they are drafting, summarising or checking something, so in practice the overlap is large.
If you are a council or a state agency rather than a business, none of this is your law. The Privacy Act is federal and does not cover local, state or territory government, which is a separate subject covered in our guide to AI in Australian councils.
The eight questions that decide whether a use is lawful
Once you know the Act applies, the assessment comes down to eight questions, and the useful thing about listing them is seeing how they split. Four are about the tool and can be answered from the vendor’s documentation. Four are about you and cannot be answered by any vendor at all.
That split is the whole argument of this page. A comparison of products can only ever settle half of it, which is why the tables further down are followed by six more sections rather than by a verdict.
The four the vendor can answer
- Does it train on what you type, and under which plan? The default reverses between personal and business accounts on every one of the four products below.
- Where does the content go, and who is the recipient? Not where the disk is. Which legal entity receives the information.
- How long is it kept, and what survives deletion? Retention windows, feedback copies, safety holds and enterprise defaults are all published, and they differ.
- Who can reach it? Human review policies, administrator access on a work account, and the circumstances in which a provider will hand material to an authority.
The four only you can answer
- What contract governs the text? Consumer terms and a privacy policy, or a business agreement that binds the provider to handle the information in a particular way.
- What are people allowed to enter? A written rule, not a shared understanding. This is the one that fails silently.
- What have they been told and shown? The Australian Government’s own AI guidance puts training and AI literacy in its first essential practice, before any technical control, and it applies to an organisation of any size.
- Can you evidence the decision? On the day a client, an insurer or the Commissioner asks, what exists in writing.
The second list is where compliance actually lives, and it is free. That is also why a page that answers only the first four, which is most of what is written about this, leaves you with a tidy comparison table and no position.
The four tools, question by question
Here is where the four assistants sit on the questions their own documents answer. Each name links to the page where the commitment is quoted with its date, because the detail changes often and a summary that drifts is worse than no summary.
| Tool | Personal plan, by default | Business or enterprise plan | Where the commitment lives |
|---|---|---|---|
| ChatGPT | Trains on your content unless you opt out | No training on inputs or outputs by default | Help centre article on model improvement |
| Claude | Trains only if you allowed it when signing up | Not used to train, outside a named partner program | Privacy centre, consumer and commercial articles |
| Gemini | A subset of chats is reviewed by people | Not human reviewed or trained on outside your domain without permission | Gemini Apps Privacy Hub and the Workspace hub |
| Copilot | History retained, with advertising in scope | Prompts, responses and Graph data not used to train foundation models | Microsoft Learn privacy documentation |
Each cell is sourced and dated on the linked page. Checked 19 September 2026.
The second table is the one that matters for APP 8, and it is the one where Australia looks different from Europe.
| Tool | Storage in Australia | Processing in Australia | Retention signal |
|---|---|---|---|
| ChatGPT | Offered on some plans | Not offered | 30 days after deletion, with named exceptions |
| Claude | Stored in the United States | Routing may include Australia | 30 days deleted, longer for feedback and safety |
| Gemini | Workspace data regions are US or Europe only | Two Gemini models on Vertex AI, in australia-southeast1 | 18 months by default on consumer apps |
| Copilot | Australia is a local region geography, with an extra licence | Queries may be processed elsewhere | 18 months on consumer history |
Each cell is sourced and dated on the linked page. Checked 19 September 2026.
What the table cannot tell you
Two things, and they are the two that decide most matters. It cannot tell you whether the plan your staff are actually signed into is the plan you bought, and it cannot tell you what they put in the box.
It also cannot rank these products, and we are not going to. The four companies have made different public commitments about their own services on different dates, and those commitments move. What does not move is that all four are overseas recipients of anything you enter, which is the subject of the next two sections.
APP 6: the paste is the disclosure, and the regulator wrote the example
The most useful paragraph the OAIC has published on this subject is a worked example rather than a rule, in its Guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025. The scenario is an insurance company whose staff enter customer details into a chatbot.
By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.
That is APP 6 territory, and APP 6 is binding. It governs use and disclosure of personal information for a purpose other than the one it was collected for, and the central question it asks is whether the individual would reasonably expect it. For sensitive information such as a diagnosis or a union membership, the bar is higher: the new purpose has to be directly related, not merely related.
Use or disclosure, and the test that decides
The same guidance draws the line on the other side, and the line is not about brands.
If your organisation is using a proprietary AI system rather than a publicly available chatbot, for example, and has protections in place to ensure that information entered into the system will not be disclosed outside the organisation (such as to the system developer), this will constitute a use rather than a disclosure of personal information.
That is a test about contract and configuration. A business tenancy with a signed agreement and training disabled sits much closer to it than a personal account does, which is why the plan behind each ChatGPT account matters more than the logo on the tab. It is still a position you have to be able to evidence, and the evidence is the agreement, not the marketing page.
What “would reasonably expect” means to a client who never heard of this
A client who instructed you on a conveyance, a claim or a diagnosis was not told a language model would read the file. If your engagement letter, your privacy policy and your collection notice say nothing about AI, the expectation argument is one you do not have. For a registered health practitioner, what Ahpra expects patients to be told sits on top of that.
Fixing that is cheap, and the OAIC asks for it directly under the heading of transparency and governance: businesses “should update their privacy policies and notifications with clear and transparent information about their use of AI”. A paragraph in the collection notice does more for your position than any product feature on this page. For a law or tax practice, those same words belong in the AI clause of its costs agreement or letter of engagement.
APP 8, section 16C and the contract that has to do the work
Every one of the four providers is overseas. That makes APP 8 the principle most Australian uses of generative AI engage, and it works differently from the European mechanism people assume.
APP 8.1 requires you to take reasonable steps before disclosing personal information to an overseas recipient, to ensure the recipient does not breach the APPs. The OAIC’s APP Guidelines, chapter 8, version 1.3, updated 3 October 2025, say what those steps normally are.
It is generally expected that an APP entity will enter into an enforceable contractual arrangement with the overseas recipient that requires the recipient to handle the personal information in accordance with the APPs (other than APP 1).
Australia has no adequacy list
The first exception, APP 8.2(a), lets you disclose without taking those steps if you reasonably believe the recipient is subject to a law or binding scheme that protects the information in a way that is, overall, at least substantially similar to the APPs, and that mechanisms can be accessed by the individual to enforce that protection.
There is no list of approved countries to point at. The belief has to be yours, the enforcement mechanisms have to be independent and accessible to the individual, and if you rely on this route you should be able to say how you formed the view. For a United States provider that route is, in practice, hard work.
Which entity you would be forming the belief about is at least published. Anthropic names the company that receives consumer content, and the other three name theirs in the same place, which is the first thing to write down if you go this way.
| Route under APP 8 | What it requires | What it costs you |
|---|---|---|
| Reasonable steps, APP 8.1 | An enforceable contract binding the recipient to the APPs | Getting the right agreement in place |
| Substantially similar law, APP 8.2(a) | A reasonable belief, plus accessible enforcement for the individual | A view you can justify, with no official list to lean on |
| Consent, APP 8.2(b) | Express informed consent, after a specific warning | Telling the individual what they give up |
OAIC, APP Guidelines chapter 8, version 1.3, 3 October 2025.
The consent route, and what it costs to use it
Consent looks like the easy option until you read what the guidelines require you to say first. The entity should give the individual a clear written or oral statement of the consequences, and at a minimum explain that if the overseas recipient breaches the APPs, “the entity will not be accountable under the Privacy Act, and the individual will not be able to seek redress under the Privacy Act”.
That is the sentence you would have to put in front of a client. Most firms, once they see it written down, decide the contract was the easier path after all.
Section 16C, in one sentence
If you do disclose to an overseas recipient, section 16C makes you accountable in certain circumstances for their acts. The guidelines put it plainly: the act or practice “is taken to have been done by the APP entity and to be a breach of the APPs by that entity”.
So the provider’s handling becomes your breach. That is the reason the contract question is not paperwork, and it is the reason a residency setting does not answer it. Storage in Sydney does not change who received the prompt.
What to look for in the agreement, and why “we comply with GDPR” is not an answer
Australian law has no statutory concept of a data processing agreement. What every vendor calls a DPA is simply a contract, and what matters is not its title but whether it does the work APP 8.1 expects of it.
Six clauses carry almost all of that work. The first three decide whether the document is a reasonable step at all; the last three decide whether it survives contact with a real problem.
The three that decide whether it is a reasonable step
- Does it bind the provider to handle the information in accordance with the APPs? This is the clause the OAIC describes. A GDPR addendum binds them to a different set of principles for a different regulator, which is not nothing and is not this.
- Is it enforceable by you, and in which forum? An enforceable contractual arrangement that is uneconomic to enforce is a weaker step than it looks.
- Does it say the input is not used for training? On business plans all four providers say some version of this. Get the version that is in your contract, not the version on the website.
The three nobody reads until they need them
- Does it set retention, and can you configure it? Enterprise defaults vary, and at least one of the four defaults to indefinite retention unless you set a period.
- Does it name subprocessors and notify changes? The model you think you are using is not always the model that answers.
- What happens on termination? Deletion timelines and exit obligations decide what happens to your data when the contract ends.
If a supplier or a managed service provider handles this for you, these six are the questions to put to them in writing, and the people who run your systems are usually the right recipient. The answers belong in the same folder as your AI policy.
Retention, security, and the first Privacy Act penalties ever ordered
APP 11 has two halves and Australian commentary tends to quote only the first. APP 11.1 requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
APP 11.2 is the half that bites in this subject. It requires reasonable steps to destroy or de-identify personal information when it is “no longer needed for any purpose for which the personal information may be used or disclosed under the APPs”, unless a recordkeeping law or a court order says otherwise.
The retention clock that is not yours
A provider’s retention window and your APP 11.2 obligation are different clocks. Theirs governs what they hold. Yours governs what you hold, including the copy of the conversation sitting in a chat history on a work account, which is personal information you are holding on a system you control.
The guidelines accept that destruction is not always technically possible and allow information to be put “beyond use” with appropriate controls, or de-identified instead. They also confirm that outsourcing does not move the obligation, because an entity that outsources storage but retains the right to deal with the information still holds it.
$4.2 million of $5.8 million was one principle
On 8 October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties over a data breach at its Medlab Pathology business. The OAIC announced it the following day and called them the first civil penalties ordered under the Privacy Act 1988.
The rest was split into two penalties of $800,000 each: one for failing to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred, and one for failing to give the Commissioner a statement as soon as practicable. Justice Halley described the contraventions as “extensive and significant”.
That case was a cyberattack, not an AI incident, and it should not be dressed up as one. It is here because of what the penalties were for. Two of the three were not about the breach at all. They were about what the organisation did in the weeks afterwards, and those two obligations apply identically when the cause is a person pasting a file into a chatbot, which has its own assessment machinery.
One more point of context, since it cuts the other way: those penalties were imposed under the regime in force at the time, capped at $2.22 million per contravention. The current maximum for a serious interference with privacy reaches $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover.
The 30 days in section 26WH start at suspicion, not at certainty
Section 26WH applies at a precise moment, and it is earlier than most offices assume. It bites once an entity is aware that there are reasonable grounds to suspect an eligible data breach, and before it is aware of reasonable grounds to believe there has been one. Suspicion opens the window. Certainty is the thing the section sends you out to find.
What it then demands repays reading twice. The entity must carry out a reasonable and expeditious assessment, and take all reasonable steps to ensure that assessment is completed within 30 days of becoming aware of those grounds to suspect. That is not a duty to reach the right answer inside 30 days. It is a duty to have tried properly, and to be able to show it.
Two other windows of 30 days appear in the retention column of the second table, and they are a different subject entirely. Those describe how long a provider keeps your text after you delete it. This one describes how long you have to work out what happened. The number is a coincidence, and nothing in the Act connects the two.
Serious harm is a list in section 26WG, not a feeling
The judgement at the centre of that assessment has a statutory checklist, which is the part most commentary leaves out. Section 26WG sets out what to have regard to in deciding whether a reasonable person would conclude that an access or disclosure would be likely to result in serious harm. There are eight matters, lettered (c) to (j), because the first two letters belong to the section’s opening alternatives.
| Four of the eight matters in section 26WG | Why it bites when a file goes into a chatbot |
|---|---|
| The kind of information, and its sensitivity | A hardship application is not a mailing list |
| Whether it is protected by security measures | Account settings become evidence, not decoration |
| The likelihood those measures could be overcome | Reversible protection is still reversible |
| The nature of the harm that could result | Identity, reputation, the client relationship |
Privacy Act 1988 (Cth), Compilation No. 104, dated 4 June 2026. The other four cover who has obtained or could obtain the information, paragraph (h), and any other relevant matters.
Paragraph (h) is the one worth knowing, because here it is the statute rather than a vendor describing this category of control. It directs you to consider whether a security technology or methodology was used, one designed to make the information unintelligible or meaningless to persons not authorised to obtain it.
Then it narrows. It asks how likely it is that people who have or could obtain the information, and who intend harm, could also obtain what they would need to circumvent that protection. The Act’s own example of that missing piece is an encryption key. No regulator or court has yet applied paragraph (h) to masking in those words. Whether masked text is still personal information turns on who holds the key.
Sections 26WK and 26WL are two clocks, and they are routinely merged
Section 26WK starts where 26WH finishes. Once an entity is aware of reasonable grounds to believe there has been an eligible data breach, it must prepare a statement and give a copy to the Commissioner as soon as practicable after becoming so aware. Grounds to believe, not belief: the trigger sits below certainty here as well.
Section 26WL covers telling the people whose information it was, and its clock is a different one. It runs from the completion of the preparation of that statement, not from the day anyone first knew. Until the statement exists, the duty to notify individuals has not started.
That gap is where offices misdiagnose themselves. A firm that drafts slowly is not breaching 26WL, because 26WL has not begun. It is breaching 26WK. Those are the two provisions behind the penalties described above: Australian Clinical Labs paid $800,000 under section 26WH(2) and another $800,000 under section 26WK(2).
Free accounts and business accounts: where the answer changes
If you only change one thing after reading this page, change this one. Across all four products, the plan a person signs into does more to determine your legal position than the brand on the tab.
Personal plans train on content, by default or by a choice made when signing up. Business and enterprise plans do not.
Consumer terms and a public privacy policy, or an agreement your firm signed, which is the instrument APP 8.1 is asking about.
On a work tenancy someone in your firm can see and enforce settings, and can also read content. That is uncomfortable and it is a control.
Usually for storage, sometimes as a paid extra, never as a complete answer to APP 8.
The setting is per account, which is what undoes a good policy
A firm that switched training off on the office account has done nothing about the four people who signed in with their own. The setting does not travel, the policy does not enforce itself, and nothing on the screen announces which account is in use.
Writing down which account each person uses takes an afternoon and costs nothing. It is the single most useful entry in the record described further down, and it is the first thing worth checking across an organisation of any size.
What the OAIC has said about generative AI, and what it has not
This is where accuracy earns its keep, because the guidance is quoted wrongly more often than it is quoted correctly. The OAIC has published on this twice in a way that matters to an ordinary office, once in 2024 as formal guidance and once in 2025 as a blog post with a case study.
Both are worth reading in full, and both say less than the commentary about them claims. What follows changes what you do on Monday.
It recommends. It does not prohibit.
The sentence everyone paraphrases, in full and unedited:
As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools, due to the significant and complex privacy risks involved.
“As a matter of best practice” is doing real work in that sentence. It is a recommendation, not an enforceable obligation, and anyone who tells you the OAIC has banned staff from using ChatGPT has not read it. The binding obligations are the ones quoted above: APP 6, APP 8 and APP 11.
The due diligence it does ask for
The same guidance is direct about what to do before you adopt something, and it is short enough to act on.
Carefully review the terms and settings which will apply to your organisation’s use of the product. In particular, you should understand whether the service terms provide the developer with access to data which your organisation inputs or generates when using the AI.
It also notes that some commercial products include terms or settings allowing the owner to collect input data for further training and development. The provider guides linked above answer that product by product.
Accuracy is an obligation too
APP 10 is the principle this subject keeps forgetting. The guidance restates it: reasonable steps to ensure personal information collected is accurate, up to date and complete, and that information used or disclosed is accurate, up to date, complete and relevant having regard to the purpose.
A model that invents a detail about a named person, and a person who then acts on it, is an APP 10 problem before it is anything else.
In December 2025 the regulator returned to the subject with a post on generative AI in the workplace whose case study is an employee uploading a customer’s hardship application, with health and family details, against their employer’s own written policy. That is the scenario we build for, described by a regulator rather than by a vendor.
Australia has no AI Act, and one date in December that people are missing
Readers who follow European coverage often assume there is an Australian equivalent of the EU AI Act. There is not. What exists is government guidance that says of itself:
This standard and the 10 guardrails are voluntary. The standard does not seek to create new legal obligations for Australian organisations.
The voluntary guidance, and why it still matters
That was the Voluntary AI Safety Standard, published 5 September 2024 and updated 2 December 2025. On 21 October 2025 the National AI Centre published the Guidance for AI Adoption, which reorganises it into six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control.
It is not law, so it cannot be breached. It is still worth reading, for a practical reason: it is the document an insurer, a client or a court would most plausibly reach for when asking what a reasonable Australian organisation should have done. Its very first “getting started” action is to create an AI policy, which is the same conclusion this page reaches from the other direction.
Being outside Europe does not always mean being outside the EU AI Act either, and whether it reaches you is a separate question with its own answer.
10 December 2026, and the difference between drafting and deciding
The real Australian date is closer than the EU one. The Privacy and Other Legislation Amendment Act 2024 inserts new obligations into APP 1 on transparency about automated decision-making, and they commence on 10 December 2026.
Where an entity uses personal information in automated decision-making with the potential to affect rights or interests, its privacy policy must set out the kinds of personal information used and the kinds of decisions made. The OAIC is still consulting on guidance, having issued an issues paper with submissions closing 15 June 2026.
Here is the limit, and it is the part the current crop of Australian blog posts on this deadline mostly blurs. The obligation is about a computer program making a decision. Asking a model to draft a letter, summarise a file or suggest wording is not that. Using one to triage claims, score applicants or decide eligibility is. If your use is the first kind, this date changes your reading list and not your privacy policy.
The tort that does not go through the regulator
Since 10 June 2025 there has also been a statutory tort for serious invasions of privacy, in Schedule 2 of the Privacy Act. The OAIC has no direct role in administering it, and it is broader than the Act, reaching parties who are not APP entities at all.
Remedies can include damages, an injunction or an order requiring an apology. The practical significance for this subject is simple: after that commencement, the regulator is no longer the only party who can bring the question to you.
What should never go in, even on a business account
A business plan changes the default, the contract and the retention. It does not change the fact that the text left your office, and it does not make some categories a good idea. For a disability provider, the NDIS Commission adds an instruction of its own, and it starts with what has to come out of a case note.
The scale of the ordinary problem is published. For January to June 2025, the most recent period the OAIC has released commentary on, it received 532 breach notifications. Human error accounted for 37 per cent of all breaches, which the OAIC reports as 193 notifications, up from 29 per cent in the previous six months.
Five categories, and the reason for each
- Sensitive information, which the Act treats differently and which the OAIC singles out in its recommendation: health, biometrics, and information about race, political opinions, religion, sexual orientation and criminal record.
- Identifiers you do not need in the prompt, such as a tax file number or a Medicare number, which add nothing to the answer and everything to the consequence.
- Whole documents when an extract would do, because a file carries metadata, headers and third parties who are not the subject of your question.
- Anything covered by legal professional privilege or a duty of confidence, where the exposure is not only a privacy question.
- Another person’s information you hold on someone else’s behalf, which is the case that turns one mistake into two notifications.
None of this means “never use AI”. The useful part of most prompts is the pattern of the problem, not the identity of the person in it, and the second can usually be removed without losing the first. Turning that into a habit takes one written page, not a purchase.
A tax file number drags an exempt business into the breach scheme, for that information
One of those five carries a consequence the other four do not, and it reaches firms that are confident none of this is their law. The $3 million line near the top of this page sets out the ways past the exemption. This is the case where the exemption is simply beside the point.
Section 11(1) provides that a person in possession or control of a record containing tax file number information, lawfully or unlawfully, is a file number recipient. Section 11(2) adds that where an employee holds such a record in the course of their employment, the file number recipient is the employer. Running payroll is enough to put a firm there.
| The link in the chain | What it does |
|---|---|
| Section 11(1) | Possession or control of a record containing tax file number information makes you a file number recipient |
| Section 11(2) | Where an employee holds that record at work, the file number recipient is the employer |
| Section 26WB | For the purposes of Part IIIC, entity includes a person who is a file number recipient |
| Section 26WE(1)(d) | A file number recipient holding tax file number information is inside the eligible data breach provisions |
Privacy Act 1988 (Cth), Compilation No. 104, dated 4 June 2026.
The exemption does not reach any of that, because of the way it is built. Section 6C(1) works by keeping a small business operator outside the definition of organisation, which is what stops the Australian Privacy Principles applying. Part IIIC does not lean on that definition. Section 26WB says so directly, and section 18 binds file number recipients with no turnover test anywhere in it.
The limit matters as much as the rule. This reaches tax file number information and nothing else the firm holds. But for that information the assessment duty, the 30 days and the two clocks above all apply, to a business that was never an APP entity at all. For a tax agent this is the everyday case, and what the TPB now expects before client TFNs reach an AI tool sits on top of it.
Writing it down: the policy, the register and the assessment
Three documents cover almost all of this, and none of them takes long. They are also the only things that exist on the day someone asks, because a setting you changed in March leaves no trace by itself.
None of the three is filed anywhere. They live in your own records, and the point of them is to turn a decision you made once into something a third party can see you made.
A privacy impact assessment is not compulsory for a business
This is another point where European advice misleads Australian readers. There is no general private sector equivalent of a DPIA. The OAIC requires Australian Government agencies to undertake a privacy impact assessment for all high privacy risk projects, and recommends assessments more broadly as part of a privacy by design approach.
So for a business, a PIA is good practice rather than an obligation. That does not make it pointless, because a short written assessment of a new tool is the most convincing artefact you can produce later, and the AI guidance above asks for a risk screening process in the same spirit.
The record that matters on the day someone asks
Three things, kept where someone other than you can find them.
One page saying what may be entered, on which account, and who to call when something goes in that should not have.
Which tools are in use, on which plan, under which contract, and who is accountable for each. This is the first essential practice of the national guidance, and it is a spreadsheet.
A page per tool recording what you checked, which is where the eight questions above turn into evidence.
For the policy there is a template to start from. The assessment is also, not incidentally, most of what an insurer wants, which is covered in our guide to the AI questions on a cyber questionnaire and in what an Australian cyber policy actually covers.
What none of them fixes
Every control on this page governs what happens after the text arrives somewhere else. Contracts, retention settings, paid residency options and training switches are all downstream of the moment a person selects a paragraph and pastes it. Not one of them is a control over whether that paragraph leaves.
That gap is where our own software sits, and it is worth being exact about what it does. Nonimo runs on the machine, replaces identifiers in the text before it goes anywhere, and shows what it changed so a person can overrule it.
It pseudonymises, which means the correspondence can be reversed and is kept encrypted on the user’s own computer. That is a smaller claim than anonymisation, and reversible means the information is still personal information. What it keeps is set out on Nonimo’s security page, and the licence terms on the licence page.
The ranking that works is unglamorous. Find out whether the Act applies to you. Decide which accounts people sign into. Write the one page. Keep the record. A firm that has done those four is in a better position than one that bought something and did none of them. Comparing tools comes afterwards, which is the right order.
Sources
Every page below was open in front of us on 20 September 2026.
- OAIC, Guidance on privacy and the use of commercially available AI products, published 21 October 2024, updated 17 January 2025. The insurance company disclosure example, the proprietary system counterexample, the best practice recommendation quoted in full, the due diligence passage on terms and settings, the note that some products collect input for further training, the APP 10 accuracy restatement, and the transparency passage on updating privacy policies and notifications.
- OAIC, APP Guidelines chapter 8, version 1.3, updated 3 October 2025. The expectation of an enforceable contractual arrangement, the APP 8.2(a) substantially similar test and its enforcement mechanisms, the APP 8.2(b) consent warning quoted in full, and the section 16C accountability statement.
- OAIC, APP Guidelines chapter 11, version 1.3, updated 3 October 2025. The APP 11.1 reasonable steps formulation, the APP 11.2 destruction or de-identification obligation and its exceptions, the “beyond use” alternative, and the statement that an entity outsourcing storage while retaining the right to deal with information still holds it.
- OAIC, small business. The $3,000,000 annual turnover threshold, what turnover includes and excludes, and the exceptions covering health service providers, businesses that trade in personal information, AML/CTF reporting entities, Commonwealth contracted service providers and those who opt in.
- OAIC, privacy guidance for reporting entities under the AML/CTF Act, published 27 February 2026, updated 28 August 2026. That small business reporting entities and their authorised agents must comply with the Privacy Act in relation to activities connected with their AML/CTF obligations, and the 1 July 2026 commencement.
- AUSTRAC, AUSTRAC opens enrolment for new professions in next step for AML reforms, 31 March 2026. The professions reached on 1 July 2026, the obligations that start that day, and the growth of the regulated population from around 19,000 to close to 100,000 businesses nationwide.
- OAIC, Australian Clinical Labs ordered to pay penalties, 9 October 2025. The $5.8 million total, the $4.2 million APP 11.1 penalty, the two penalties of $800,000 under sections 26WH(2) and 26WK(2), the description of the contraventions as extensive and significant, the cap of $2.22 million per contravention that applied, and the current maximum penalties.
- OAIC, latest Notifiable Data Breach statistics for January to June 2025, 4 November 2025. The 532 notifications, the 193 caused by human error, and the rise from 29 per cent to 37 per cent.
- OAIC, consultation on guidance for transparency in automated decision-making, 18 May 2026. The 10 December 2026 commencement, the Privacy and Other Legislation Amendment Act 2024 as the source, what must appear in a privacy policy, and the consultation closing 15 June 2026.
- OAIC, statutory tort for serious invasions of privacy. The 10 June 2025 commencement, its place in Schedule 2, the absence of a direct OAIC role, its reach beyond APP entities, and the available remedies.
- OAIC, privacy impact assessments. That Australian Government agencies are required to undertake a PIA for all high privacy risk projects, and the privacy by design framing for everyone else.
- OAIC, GenAI tools in the workplace, 4 December 2025. The hardship application case study and the products named in it.
- Department of Industry, Science and Resources, the legal landscape for AI in Australia. That the standard and its 10 guardrails are voluntary and do not seek to create new legal obligations, and that Australian Consumer Law may apply to misleading statements about the performance and outputs of AI systems.
- National AI Centre, Guidance for AI adoption: foundations. The six essential practices, the first “getting started” action of creating an AI policy, the risk screening process, and the AI literacy and training material.
- Privacy Act 1988 (Cth), Compilation No. 104, compilation date 4 June 2026. Australian Privacy Principles 6, 8, 10 and 11, section 16C, and the notifiable data breach provisions in Part IIIC. For the sections quoted above: section 11 on file number recipients and on the employer being the recipient, section 18, section 26WB on what entity includes in that Part, section 26WE(1)(d), section 26WG and its paragraph (h) with the note on encryption keys, section 26WH, sections 26WK and 26WL, and sections 6C and 6D on the small business exemption.
Product commitments in the two comparison tables are quoted from each provider’s own documentation on the four linked pages, which were checked on 19 September 2026. Three of those publishers block automated requests: industry.gov.au, ai.gov.au and austrac.gov.au return no response to a fetch from the command line and load normally in a browser, which is where they were read.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Is any AI tool Privacy Act compliant?
No tool is, because compliance is not something software can hold. The Privacy Act regulates APP entities and their acts, so the question it answers is whether your use of a tool meets the Australian Privacy Principles, not whether a product has passed something.
Does the Privacy Act apply to my small business?
Only if an exception catches you. The Act exempts small business operators with annual turnover of $3 million or less, but not health service providers, businesses that trade in personal information, or AML/CTF reporting entities acting on those obligations.
Is pasting client information into ChatGPT a disclosure?
The OAIC says it is. In its 2024 guidance, an insurance company whose staff enter customer details into a chatbot is described as disclosing that information to the owners of the chatbot, which brings APP 6 into play at the moment of the paste.
Does the OAIC ban staff from using AI chatbots?
No. It recommends as a matter of best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools. That is a recommendation, not a prohibition.
Do I need a data processing agreement with an AI provider?
Australian law does not use that term. Under APP 8 the OAIC says an entity is generally expected to enter an enforceable contractual arrangement requiring the overseas recipient to handle the information in accordance with the APPs, other than APP 1.
Can I keep AI data in Australia?
Sometimes for storage, rarely for processing, and it does not settle APP 8 either way. Cross-border disclosure turns on who received the information rather than where the disk sits, so an overseas provider stays an overseas recipient.
Do I need a privacy impact assessment before using AI?
Not as a legal obligation if you are a private sector organisation. The OAIC requires Australian Government agencies to undertake one for all high privacy risk projects and recommends them more broadly as part of a privacy by design approach.
What changes on 10 December 2026?
New APP 1 obligations on automated decision-making commence. Where a computer program uses personal information to make decisions that affect rights or interests, privacy policies must set out the kinds of information used and the kinds of decisions made.
Which AI tool is safest for confidential information?
The Privacy Act does not rank products and neither do we. The four major assistants publish different commitments on training, retention, human access and location, and the plan you buy changes the answer more than the brand you choose.