AI Fast Tracker
AI compliance, without the panic

Does using AI breach the Privacy Act? A plain-English guide for Australian small business (2026)

Does using AI breach Australia's Privacy Act? A plain-English 2026 guide for small business: the new rules, a red-yellow-green paste rule, and a 5-step quickstart.

Free guide · about 6 min read · written for Australian businesses · no sign-up

The short answer

Using AI does not breach the Privacy Act by itself. Pasting the wrong thing into an AI tool can. That is the whole game in one line: the law does not care that you used Claude or ChatGPT, it cares what personal information you handled, and whether you handled it the way the Australian Privacy Principles require.

Two things before we go further. First, this is general information, not legal advice. Privacy law turns on your specific situation, and if real client data or real consequences are on the line, pay a professional for an hour of their time. Second, the rules are moving. Every date and claim in this guide should be verified at oaic.gov.au, the Office of the Australian Information Commissioner, before you rely on it.

With that said, here is what an Australian small business actually needs to know in 2026, written by someone who uses these tools daily in a real business, not a compliance consultant selling fear.

Does the Privacy Act even cover your business?

The Privacy Act 1988 has long had a small business exemption. Broadly, if your annual turnover is $3 million or less, you have generally sat outside most of the Act, with long-standing exceptions: private health service providers, businesses that trade in personal information, credit reporting bodies, and a few other categories. Check the current list at oaic.gov.au, because it is more detailed than any blog summary, including this one.

Two warnings on that exemption. It has been under formal review for years and the government has agreed in principle to wind it back, so treat it as borrowed time rather than a permanent shield. And as of 1 July 2026, a large group of small businesses lost it for part of their work anyway, which is the next section.

What changed in 2024

In late 2024, Parliament passed the first tranche of Privacy Act reforms, publicly reported as the Privacy and Other Legislation Amendment Act 2024. The headline items: a new statutory tort for serious invasions of privacy, meaning individuals can now sue directly; criminal offences for doxxing; stronger OAIC enforcement powers, including a tiered penalty structure so mid-level breaches can be fined rather than only catastrophic ones; and a requirement for privacy policies to disclose certain automated decision-making, with a roughly two-year lead time landing in December 2026.

None of that mentions AI by name. It does not need to. If an AI tool helps you collect, store, use, or disclose personal information, the existing Australian Privacy Principles already apply to that handling. The 2024 reforms mostly raised the stakes for getting it wrong. Verify the details and commencement dates at oaic.gov.au.

The 2026 changes that actually bite

First, 1 July 2026. From that date, real estate agents, lawyers, conveyancers, and accountants became reporting entities when they provide certain designated services, under the expanded anti-money-laundering regime, the AML/CTF tranche 2 reforms. Here is the privacy sting: the small business exemption does not apply to a reporting entity's AML/CTF-related activities, so these professions are now covered by the Privacy Act for that work regardless of turnover. A two-person conveyancing firm turning over $400,000 is in. I sold property on the Gold Coast for years, so this one landed on an industry I know. Verify exactly how it applies to your profession at oaic.gov.au and austrac.gov.au.

Second, 10 December 2026. From that date, covered businesses' privacy policies must disclose the use of automated decisions that significantly affect people's rights or interests, think automated tenant screening or loan pre-assessments. If software makes or heavily shapes a decision about a person, your privacy policy needs to say so. The exact scope sits in the legislation and OAIC guidance, so verify at oaic.gov.au before you rewrite anything.

The red, yellow, green rule

Forget memorising all 13 Australian Privacy Principles. For day-to-day AI use, one traffic-light rule covers most situations.

Green: public information that is not about an identifiable person. Suburb data, listing copy, legislation, your own marketing, published market reports. Paste freely. One caveat that catches people out: public does not mean exempt. A person's public social media post, or their entry on a public register, is still personal information under the Privacy Act, so anything public that is about an identifiable person belongs in yellow or red, never green.

Yellow: internal but non-identifying. Your processes, templates, pricing structures, and de-identified summaries like "a three-bed buyer with a $600,000 budget". Generally workable in a business-grade tool, but strip names, addresses, and anything that could re-identify a person, because de-identification fails the moment combined details point at one individual.

Red: client personal information. Names attached to financials, ID documents, contracts, health details, anything about a specific identifiable person. This never goes into a consumer AI tool. Not because a law names ChatGPT specifically, but because you likely cannot meet your obligations around disclosure, security, and overseas transfer once that data leaves your hands on consumer terms. If you genuinely need AI to work on red-zone material, that is a job for a paid business or API tier with contractual data commitments, and even then only after you have actually read them.

Check your training-data settings

Here is the default worth assuming: consumer AI tools train on your conversations unless you have opted out. As publicly reported at time of writing, most free and personal tiers of the major chatbots either use inputs to improve their models by default or have shifting policies about it, while business and API tiers generally commit to not training on your data. Those settings change without much fanfare, so do not rely on this paragraph. Open your tool, find the data or privacy settings, and check what it says today.

The practical move for a small business: turn training off wherever the option exists, prefer a business tier for anything beyond green-zone work, and write down which tools you have approved and on what tier. That last step sounds bureaucratic. It is one page, and it is the page that saves you when a client or regulator asks what you actually do.

A five-step compliance quickstart

Step 1: work out if you are covered. Check the small business exemption and its exceptions at oaic.gov.au, and if you are a real estate agent, lawyer, conveyancer, or accountant, assume the 1 July 2026 change reaches you until you have verified otherwise.

Step 2: list your AI tools and tiers. Every tool anyone in the business uses, consumer or paid, sanctioned or sneaky. You cannot manage what you have not written down.

Step 3: apply the traffic-light rule and put it in writing. One page: green, yellow, red, with examples from your actual business. Walk the team through it once. Most staff misuse AI through ignorance, not malice.

Step 4: fix the settings. Opt out of training on every consumer tool, move yellow and red work to business tiers or out of AI entirely, and update your privacy policy, especially if automated decisions are in scope for the December 2026 disclosure rule.

Step 5: put a date in the calendar to re-check. Quarterly is plenty for most small businesses. The tools change their policies and the law is mid-reform, so a short regular review beats an annual panic. How long each step takes varies with your setup, but none of them should need more than an afternoon.

The honest wrap-up

So, does using AI breach the Privacy Act? Not inherently. Careless AI use can, and the room for careless is shrinking: more businesses covered from July 2026, disclosure duties from December 2026, real penalties behind both, and a regulator with sharper teeth than it had two years ago.

The fix is not abstinence, it is setup. A business that knows its traffic lights, has its settings sorted, and can show one page of policy is in a far stronger position than the many still pretending AI is not in the building.

One more time, because it matters: this is general information, not legal advice. For your specific obligations, check oaic.gov.au and talk to a professional who can look at your actual business.

Claude Setup Mastery — $49 AUD, once

The privacy chapter in Claude Setup Mastery ($49) turns this guide into a working setup: the data-safety settings to change, a copy-paste traffic-light policy for your team, and a workspace arranged to keep client information out of consumer training pipelines. Buy it once, own it forever, no subscription.

See what ships →

More free guides

→ 7 AI prompts Australian real estate agents actually use (2026)→ AI for tradies: quote follow-ups that send themselves (Australian guide)→ Claude vs ChatGPT for Australian small business (2026): the honest answer→ AI for Australian Online Stores (2026): Product Descriptions, Support Replies and Cart Follow-Ups That Sound Like You→ Faceless AI Creators and Australian Rules (2026): The Disclosure-First Guide→ The $0 AI Stack (2026): How Far Free AI Tiers Actually Take an Australian Small Business→ AI Follow-Up Emails That Don't Sound Like AI (2026): An Australian Sales and Service Guide→ Should You Build Your Own Tool, or Buy One? An Australian Small Business Guide (2026)