AI security & privacy · Guide
AI and the Australian Privacy Principles: a plain-English guide for firms
When a firm covered by the Privacy Act uses AI, the Australian Privacy Principles apply to the personal information staff put into the tool and to anything it produces about a person. APPs 1, 3, 5, 6, 8, 10 and 11 matter most. This guide explains each, what the OAIC expects and what changes on 10 December 2026.
- By
- Peter
- Published
- Last reviewed
- Reading time
- 8 min read
Does the Privacy Act apply to your firm?
Most law, accounting and advisory firms with annual turnover above $3 million are covered by the Privacy Act 1988 (Cth) and must follow the 13 Australian Privacy Principles (APPs). Smaller firms are often exempt, but the exceptions catch more professional firms than partners expect.
Under section 6D of the Privacy Act, a business is small if its annual turnover for the previous financial year was $3 million or less. The OAIC’s small business guidance lists the exceptions. Those most relevant to professional firms:
- AML/CTF reporting entities. From 1 July 2026, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 applies to lawyers, accountants and conveyancers who provide designated services. A small firm in that position must comply with the Privacy Act for its AML/CTF activities, such as customer due diligence and record-keeping (OAIC guidance for reporting entities).
- Tax file numbers. Anyone holding tax file number information must follow the TFN rules, and the Notifiable Data Breaches scheme applies to that information regardless of turnover. Tax practices routinely hold TFNs.
- Government work and related companies. A small firm working under a Commonwealth contract is covered for that contract work, and a company related to a larger company that is not a small business is covered.
Two things apply whatever your size. Your professional duty of confidentiality does not depend on the Privacy Act. And since 10 June 2025, individuals can sue for serious invasions of privacy under a statutory tort added by the Privacy and Other Legislation Amendment Act 2024. The tort is not limited to entities bound by the APPs.
What has the OAIC said about firms using AI?
The OAIC published two guides on 21 October 2024. The first, on privacy and the use of commercially available AI products, is for organisations using AI tools, even internally. The second, on developing and training generative AI models, applies when an organisation trains or fine-tunes a model, including with data it already holds.
The points that matter most for a firm:
- Privacy obligations apply to personal information entered into an AI system and to any output that contains it.
- If AI generates or infers information about a person, that is a collection under APP 3. Hallucinations about an identifiable person are still personal information.
- Privacy policies and notices should say clearly how the organisation uses AI.
- As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools.
- Due diligence is not “set and forget”: review the product, training and monitoring across its life, starting with a privacy impact assessment.
The training guidance matters for firms thinking of building on their own files. Using personal information you already hold to train or fine-tune a model, where that was not a purpose of collection, needs careful APP 6 analysis. If you cannot clearly show it was within people’s reasonable expectations, the OAIC says to seek consent or offer a meaningful opt-out.
Which APPs matter most when a firm uses AI?
Seven of the 13 APPs do most of the work. The table maps each, using the OAIC’s APP titles, to what a firm should do.
| APP | What it requires | What a firm using AI should do |
|---|---|---|
| APP 1: Open and transparent management | Practices to comply with the APPs and a clear, current privacy policy | Keep a register of approved AI tools and the data each may receive. Say in your privacy policy how you use AI, including automated decisions from 10 December 2026. |
| APP 3: Collection of solicited information | Collect only what is reasonably necessary, by lawful and fair means; sensitive information usually needs consent | Treat anything AI infers about a person, such as a risk rating, as a new collection. |
| APP 5: Notification of collection | Take reasonable steps to tell people about the collection and its purposes | Update collection notices and engagement letters. Label any client-facing chatbot as AI. |
| APP 6: Use or disclosure | Use or disclose information only for the purpose it was collected, unless an exception applies | Decide which client data may go into which tool. Do not train or fine-tune a model on client files without consent or advice. |
| APP 8: Cross-border disclosure | Take reasonable steps before disclosing overseas; the firm stays accountable | Find out where each tool stores and processes data, and what the contract says. |
| APP 10: Quality of personal information | Keep information accurate, up to date, complete and relevant | Have a person review AI output before it is relied on or sent. Mark AI-generated content on the file. |
| APP 11: Security of personal information | Reasonable steps, including technical and organisational measures; destroy or de-identify what is no longer needed | Use single sign-on, multi-factor authentication and retention settings. Delete AI chat histories you do not need. |
The other APPs still apply. APP 12 and APP 13, for example, give people rights to access and correct information you hold about them, including AI output.
Can staff put client information into ChatGPT or Copilot?
Only when the use fits APP 6 and the firm has checked where the data goes under APP 8. The question is not which brand of AI a staff member opens, but whether this client’s information may be used for this task, in this tool, on these terms.
The OAIC’s strongest warning is about publicly available generative AI tools. Business plans come with contract terms and admin controls, and as at September 2026 OpenAI, Anthropic and Microsoft each state that they do not train models on business customers’ content by default. That removes one risk, but does not settle whether the use fits the purpose of collection or where the data is processed. Our guide to where ChatGPT stores your data sets out the storage options plan by plan.
For example, picture a family law practice where a paralegal pastes a client’s medical report into a personal chatbot account to get a summary. Health information is sensitive information under the Act, the disclosure goes to a provider the firm has no contract with, and the client would not reasonably expect it. The same summary produced in an approved tool, under the firm’s contract, with retention set and a lawyer reviewing the result, is a very different risk.
Does using an overseas AI provider breach APP 8?
Not automatically, but the firm remains accountable. Under APP 8.1, before disclosing personal information to an overseas recipient you must take reasonable steps to ensure the recipient does not breach the APPs, which usually means an enforceable contract. Under section 16C, the firm is accountable for the recipient’s breaches.
The OAIC’s APP 8 guidelines say that giving information to a cloud provider can be a “use” rather than a “disclosure” if a binding contract limits the provider to handling it for limited purposes, binds its subcontractors to the same terms and gives the firm effective control. Whether an AI service meets that test depends on its contract, so get advice.
Where processing happens varies by product and plan. Firms that cannot accept offshore processing of client data need a different architecture. Pylon Digital’s Private AI and knowledge assistants are built for that case, with client data stored in fully GDPR-compliant data centres.
What should happen if client data leaks through an AI tool?
Treat it as a suspected data breach. Under the Notifiable Data Breaches scheme, an eligible data breach is unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to someone, where remedial action has not removed that risk.
The OAIC’s data breach guidance works in four steps:
- Contain it, for example by deleting the conversation and asking the provider to remove the content.
- Assess it reasonably and expeditiously, within 30 calendar days of becoming aware.
- Notify the OAIC and affected individuals as soon as practicable if it is eligible.
- Review what happened and fix the control that failed.
If the information went to an overseas recipient under APP 8.1, the firm is treated as still holding it for the scheme. Prevention sits under APP 11, which since 11 December 2024 states that reasonable security steps include technical and organisational measures. For AI, that means approved tools only, single sign-on, controlled connectors, sensible retention and a written AI acceptable-use policy that staff are trained on.
What changes on 10 December 2026?
From 10 December 2026, privacy policies must explain certain automated decisions. The 2024 amending Act inserts APP 1.7 to 1.9, which apply where a firm has arranged for a computer program to make a decision, or do something substantially and directly related to making it, that could reasonably be expected to significantly affect a person’s rights or interests, using their personal information.
The privacy policy must then describe the kinds of personal information used and the kinds of decisions involved. The Act’s examples include decisions affecting rights under a contract or access to a significant service. The OAIC consulted on guidance for this obligation in May and June 2026.
The test turns on decisions, not on AI as such. An intake agent that automatically declines prospective clients, or a tool that decides which debtors are referred for recovery action, is the kind of arrangement to map now and take advice on. More reform may follow: the Attorney-General’s Department released the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 for consultation, with submissions closing on 18 September 2026. It is not law.
What should a firm do first?
Start with an inventory, then set rules, then choose tools. These steps suit a 10 to 100 person firm:
- Confirm coverage: turnover history, AML/CTF status, TFN handling and related companies.
- List every AI tool in use, including free accounts staff use informally.
- Classify your data: general, client personal information, sensitive information and TFNs.
- Decide which data may go where, tool by tool, in an acceptable-use policy.
- Configure approved tools: business plans, single sign-on, training settings, retention and connectors.
- Run a privacy impact assessment for any tool handling client files or sensitive information.
- Update your privacy policy and collection notices, including automated-decision content by 10 December 2026.
- Add AI to your data breach response plan.
Law firms weighing the confidentiality side can read whether AI is safe for Australian law firms. To talk through your own setup, book a free 45-minute discovery call.
This is general information, not legal advice.
