The short answer
If you feed customer data into an AI tool, the Privacy Act applies. You need documented consent from customers, you must share only the minimum data the AI actually needs, and you must tell customers in your privacy policy that you use AI. Miss any of these and you have a compliance breach.
Why it matters to a small business
Privacy breaches carry penalties under Australian law, but the real cost is customer trust. If a customer finds out you've shared their details with an AI tool without telling them, they're unlikely to come back. The Privacy Commissioner can investigate complaints, and your business reputation takes a hit even if no fine applies. More importantly, using customer data in AI without proper consent is not a grey area—it's a breach of the Privacy Act.
Small businesses often think privacy rules are for big corporates. They're not. The Privacy Act applies to any business collecting personal information, regardless of size.
How it actually works
Think of feeding customer data into an AI tool like giving a contractor access to your customer list. You wouldn't hand over names, addresses, and phone numbers to a stranger without telling your customers first. You'd also only give the contractor the details they actually need for the job. And you'd tell your customers you'd done it. The Privacy Act works the same way with AI.
There are three core obligations:
- Consent: Before you use customer data in an AI tool, you need to tell customers you're doing it and get their permission. This can be part of your terms and conditions or privacy policy, but it must be clear and specific. Vague language like 'we may use your data for business purposes' isn't enough. You need to say: 'We use AI tools to process your data, and here's what that means.'
- Data minimisation: Only send the AI tool the data it actually needs. If you're using AI to summarise customer feedback, you don't need to send phone numbers or payment details. The less data you share, the lower your risk and the better you protect your customers.
- Transparency: Your privacy policy must disclose that you use AI and explain which tools you use, what data goes into them, and why. This isn't optional. It's a legal requirement under the Privacy Act.
If you use a third-party AI service (like ChatGPT or a cloud-based analytics tool), you're still responsible for what happens to customer data. Using an external tool doesn't transfer your privacy obligations.
What it is NOT
You don't need permission for every single use. Once you have consent to use customer data in AI, you can apply that consent to similar uses. You don't need to ask again each time. But if you change how you use the data—for example, moving from customer service AI to marketing AI—you should update your privacy policy and ideally get fresh consent.
Anonymised data isn't a free pass. If you think anonymising customer data before feeding it into an AI tool removes your obligations, think again. Data that can be re-identified (even with effort) is still personal information under the Privacy Act. True anonymisation is rare and difficult to prove. Don't rely on it as your compliance strategy.
Using an Australian-hosted AI tool doesn't exempt you. Some businesses assume that because their AI platform is hosted in Australia, the Privacy Act doesn't apply. Wrong. The Privacy Act applies based on where your business is and where your customers are, not where the AI server sits. You're still responsible.
Where to start
Three concrete first steps:
- Audit your AI use. List every AI tool you currently use and what customer data goes into it. Include obvious ones like chatbots and customer service tools, but also less obvious ones like analytics platforms, email marketing software with AI features, or scheduling tools. Write down what data each tool receives.
- Update your privacy policy. Add a section that explains you use AI tools, which tools you use, what data goes into them, and why. Use plain language. Your customers should understand it without a law degree. If you don't have a privacy policy, now is the time to create one.
- Document your consent process. Record how and when you told customers you use AI. Keep copies of the consent language in your terms, privacy policy, or sign-up forms. If the Privacy Commissioner asks, you need to prove you had consent.
These three steps won't take long and they'll put you on solid ground.
Privacy compliance with AI isn't complicated, but it does require intention. If you're using customer data in any AI tool and haven't done these three things, now is the moment to act. We've built compliance resources and guides specifically for Australian small businesses using AI. If you'd like to talk through your setup or need help updating your privacy policy, get in touch.
