General information only. This guide is not legal, privacy, clinical, financial or other professional advice. Coverage and duties depend on the entity, data, people, purpose and sector. Check current sources and obtain advice for the real use.
First, check coverage
The Privacy Act 1988 covers many Australian organisations. The usual small-business threshold is not the whole test. Some smaller organisations are covered, including many private health service providers and businesses that trade in personal information. Tax file number, credit, employee, health and other regimes can add separate duties.
The OAIC's small-business guidance is a useful starting point. In NSW, health information can also engage the Health Records and Information Privacy Act 2002. Its private-sector reach is fact-specific, so do not assume every mention of health data produces the same answer.
Map input and output
Personal information can appear in the prompt, attached file, recording, retrieved source, model output, feedback, access log and support record. Generated text can itself be personal information, even when the prompt looked harmless.
The OAIC's guidance on commercially available AI products recommends due diligence before use, ongoing review, clear policies and notices, and human oversight. It also recommends keeping personal information, especially sensitive information, out of publicly available generative AI tools as a matter of best practice.
The APP questions
- APP 3
- Is collection reasonably necessary, and is consent required for sensitive information?
- APP 5
- Were people told what is collected, why, who receives it and likely overseas disclosures?
- APP 6
- Is this use or disclosure within the original purpose, consent or another permitted basis?
- APP 8
- Before overseas disclosure, what reasonable steps and accountability rules apply?
- APP 10
- How will inaccurate personal information in AI inputs and outputs be found and corrected?
- APP 11
- How is information protected, and when is it destroyed or de-identified if no longer needed?
Not every APP applies to every organisation or fact pattern. The list is a review map, not a conclusion.
Automated-decision policy change: 10 December 2026
From 10 December 2026, new APP 1.7 to 1.9 obligations apply to an APP entity that has arranged for a computer program to make, or do something substantially and directly related to making, a decision where:
- personal information about an individual is used in the program; and
- the decision could reasonably be expected to significantly affect that person's rights or interests.
Where the test is met, the privacy policy must describe the kinds of personal information used and the relevant kinds of decisions. The rule is not limited to generative AI, and human involvement does not automatically put a process outside it. The OAIC's current APP 1 guidance sets out the test. Get advice on a real decision workflow before the commencement date.
When something goes wrong
Where the Notifiable Data Breaches scheme applies, reasonable grounds to suspect an eligible data breach trigger an assessment that must be reasonable and expeditious, with all reasonable steps taken to finish within 30 calendar days. Reasonable grounds to believe there has been an eligible breach trigger the statement and notification process as soon as practicable, subject to the Act.
The OAIC publishes the current NDB response guidance. Contracts, health-privacy law, professional duties and cyber reporting can set other steps or shorter times.
Sector rules still matter
A privacy review does not replace the rules for the work itself.
- Health: practitioner accountability, informed consent, clinical safety and possible TGA medical-device questions depend on intended purpose.
- Legal work: confidentiality, privilege, court practice directions and the duty to verify filed material remain with the practitioner.
- Financial work: licensing, digital-advice, APRA, ASIC and record obligations may apply beyond privacy law.
- Workplaces: surveillance, employee notice, consultation and employment rules need their own review.
What on-premise processing changes
Running model inference on a customer appliance can remove an external model provider from the normal prompt path. If a particular item is not disclosed to an overseas recipient, APP 8 does not apply to that disclosure because it did not occur.
That is narrower than saying an on-premise system is compliant. Consent, purpose, notice, access, accuracy, retention, backup, physical security and incident response remain. Web research, updates, external integrations, remote support and off-site fine-tuning are separate exceptions and need their own assessment.
Practical review list
- Inventory
- Every approved and staff-adopted AI tool listed with an owner.
- Purpose
- Intended use, affected people and unsuitable uses written down.
- Data
- Inputs, outputs, retrieval, logs, support copies and retention mapped.
- Vendors
- Providers, sub-processors, countries, terms and model-training rights checked.
- People
- Notice, consent, access, correction and complaint paths set.
- Decisions
- Significant-decision use assessed before 10 December 2026.
- Proof
- Accuracy, permission, security and incident controls, checked against the workflow you actually run.
LocallyAI can document the technical system and data paths. A qualified adviser should decide which laws and professional rules apply.
