Skip to content
BalancedFinancial Services

AI & Automation

Before you paste client data into an AI tool: the Australian privacy questions

Practical guidance on using AI tools with client information under Australian privacy law — data location, training on your inputs, confidentiality obligations and a workable internal policy.

Balanced Financial Services5 min read

The most common way an Australian business creates a privacy problem with AI is not a sophisticated attack. It is someone pasting a client list into a free chatbot to reformat it.

This is a solvable problem, and solving it does not require abandoning the tools. It requires deciding a few things deliberately rather than by default.

The obligations that actually apply

The Privacy Act and the Australian Privacy Principles apply to most businesses with turnover above $3 million, and to some smaller ones regardless of turnover — including health service providers, businesses trading in personal information, and some contractors to government. Many small businesses that assume they are exempt are not.

The APPs most relevant when using AI tools:

  • APP 6 — you can generally only use or disclose personal information for the purpose you collected it. Feeding it to a third-party tool is a disclosure.
  • APP 8 — before disclosing personal information overseas, you must take reasonable steps to ensure the recipient does not breach the APPs. Most major AI services process offshore.
  • APP 11 — you must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access.
  • APP 1 — you need a clearly expressed, up-to-date privacy policy that reflects what you actually do. If you now use AI tools on customer data, your policy should say so.

Separately, the Notifiable Data Breaches scheme requires you to notify affected individuals and the OAIC where a breach is likely to result in serious harm. A misconfigured AI tool exposing client records is squarely within scope.

There are also obligations that sit outside the Privacy Act entirely and often bite harder: professional confidentiality duties, contractual confidentiality clauses with your own clients, and for regulated professions, the standards of your professional body. A tax agent's obligations regarding client information do not soften because a tool is convenient.

The three questions to ask about any AI tool

1. Is my input used to train the model?

This is the single most important question and the answer differs by product tier. Consumer and free tiers of major AI services have historically used conversations to improve models by default. Business, team, enterprise and API tiers generally do not, and say so contractually.

The practical rule: paid business tier, with a written commitment that inputs are not used for training. The price difference is small. The difference in exposure is not.

2. Where is the data processed and stored, and for how long?

Most large providers process in the United States or a mix of regions. Some offer regional processing or data residency on higher tiers. For APP 8 purposes you need to know, and you need to have taken reasonable steps — which in practice means reading the terms and relying on the provider's contractual commitments, not assuming.

Retention matters too. Many providers retain inputs for a period for abuse monitoring even where they do not train on them. That is usually acceptable; it is not acceptable to be unaware of it.

3. Who inside my business can access it, and is that logged?

A shared login on a personal account is a bad answer. Named accounts on a business plan, with an administrator who can see usage and revoke access when someone leaves, is the minimum.

A policy that people will actually follow

Long policies do not get read. This one fits on a page and works.

Never put into an AI tool:

  • Tax file numbers, ABNs tied to individuals in a sensitive context, bank account or card numbers
  • Passwords, API keys or credentials
  • Health information or anything else that is "sensitive information" under the Act
  • Complete client files or database exports
  • Anything covered by a specific confidentiality undertaking, unless you have checked that undertaking

Fine to put in, on an approved business-tier tool:

  • De-identified data — figures and patterns with names and identifiers removed
  • Your own internal documents, templates and processes
  • Public information
  • Draft writing that contains no client identifiers

Always:

  • Use the business account, never a personal one
  • Check output before it goes to a client — you are responsible for it, not the tool
  • Ask before using a new tool on anything client-related

That is the whole policy. Circulate it, get people to acknowledge it once, and revisit it when you adopt a new tool.

De-identification, and why it is harder than it sounds

Removing names is not de-identification. A record with a date of birth, a postcode and a diagnosis can identify someone even with no name attached. The test is whether the individual is reasonably identifiable from the information, alone or combined with other available information.

For most business analysis this is manageable — replace client names with codes, round figures, remove dates where they are not needed. But treat de-identification as a real step you take deliberately, not a label you apply to data you did not want to think about.

Being transparent with your clients

If you use AI tools on client work, say so. It is a requirement under APP 1 to have a privacy policy that reflects actual practice, and it is a straightforward commercial advantage — clients increasingly ask, and "yes, here is how we handle it" is a much better answer than a vague one.

A short paragraph is enough: what tools you use, what you do and do not send to them, that inputs are not used for training, and that a qualified person reviews everything before it reaches the client.

What to do this week

  1. Find out what is already being used. Someone in your business is using an AI tool on work data right now. Ask without blame; you cannot manage what you do not know about.
  2. Move everyone onto a business-tier account with training on inputs disabled.
  3. Circulate the one-page policy.
  4. Update your privacy policy to reflect what you actually do.
  5. Check your professional and contractual confidentiality obligations — they may be stricter than the Privacy Act.

None of this is expensive and none of it takes long. The alternative is discovering your exposure at the same moment your client does.


General information only, current at the time of writing. Privacy law is under active reform in Australia and obligations vary by business. This is not legal advice — for anything material, get advice from a lawyer. If you want help setting up AI tools safely in your business, book a free consult.

Keep reading

Let's find out what you're leaving on the table.

A 30-minute call, no charge. Bring last year's numbers, a loan you are not sure about, or a process that keeps eating your week — we will tell you straight whether we can help.

Book a free consult(02) 9750 4884

Monday to Friday, 9:00am – 5:00pm