Privacy Law and AI: Your Compliance Checklist

Privacy Law and AI: Your Compliance Checklist - feature image for the Rapid Ready AI blog.

Who this checklist is for

If you're a small business owner using AI tools—whether that's a chatbot handling customer enquiries, automation software processing orders, or analytics tracking customer behaviour—this checklist is for you. It covers the practical steps you need to take to stay compliant with Australian Privacy Law when AI touches customer data.

You don't need to have built the AI yourself. Whether you've bought a ready-made tool or developed something custom, the same compliance rules apply. This checklist takes about 20 minutes to work through and will show you exactly where your gaps are.

The checklist

1. Do you have documented consent for each use of customer data in AI?

What to check: Whether you've asked customers permission before feeding their data into any AI system, and whether that permission is specific to that particular use.

How to check it (under 10 minutes): Pull up your last customer sign-up form or terms and conditions. Search for the word "AI". If it's not there, or if you're using AI for something customers didn't explicitly agree to, you have a gap. Check your email records too—did you notify existing customers about new AI uses?

What good looks like: Your privacy policy or sign-up process says something like: "We use AI chatbots to answer your support questions. Your name and query will be processed by [tool name]." Customers actively tick a box or agree before data flows into the AI system.

2. Have you told customers in your privacy policy that you use AI?

What to check: Whether your privacy policy mentions AI at all, and whether it explains what data goes into which AI tools.

How to check it (under 10 minutes): Read your privacy policy from top to bottom. Search for "AI", "automation", "machine learning", or the name of any tool you use. If none of these terms appear, your policy is out of date.

What good looks like: Your privacy policy has a section that lists each AI tool you use, what data it processes, and why. For example: "We use Acme Analytics to track which products you view. This helps us show you relevant recommendations."

3. Are you feeding AI only the customer data it actually needs?

What to check: Whether you're sending full customer records to AI tools when they only need a subset of that information.

How to check it (under 10 minutes): Open your AI tool's settings or ask your developer. Look at what data fields are being sent. Does a chatbot really need the customer's full purchase history, or just their current question? Does an analytics tool need email addresses, or just anonymised user IDs?

What good looks like: Your AI tool receives only the minimum data required to do its job. A support chatbot gets the customer's name and current query—nothing else. An analytics tool gets anonymised session data, not personal details.

4. Do you know where your AI tool stores customer data?

What to check: Whether customer data is stored in Australia, overseas, or both, and whether you've documented this.

How to check it (under 10 minutes): Check your AI vendor's privacy policy or terms of service. Search for "data centre", "storage location", or "jurisdiction". If it's vague, email the vendor and ask directly: "Where do you store Australian customer data?" Keep their written answer.

What good looks like: You have a written statement from your vendor confirming data storage location. If data leaves Australia, you've documented why it's necessary and what protections are in place.

5. Can you delete customer data from the AI tool if asked?

What to check: Whether the AI tool allows you to delete or export a customer's data when they request it (their right under Australian Privacy Law).

How to check it (under 10 minutes): Log into your AI tool and look for a delete or export function. If you can't find one, check the vendor's help documentation or contact support and ask: "How do I delete a specific customer's data from your system?" If they say "we can't", that's a red flag.

What good looks like: You can delete or export a customer's data within a few clicks, or you have a documented process with your vendor to do so within 30 days of a request.

6. Have you checked your AI vendor's privacy terms?

What to check: Whether your vendor has a privacy policy, data processing agreement, or terms of service that cover how they handle customer data.

How to check it (under 10 minutes): Visit your vendor's website and find their privacy policy and terms of service. Look for sections on: data security, data retention, data breaches, and your rights as a customer. If these sections don't exist or are vague, email the vendor and ask for a Data Processing Agreement.

What good looks like: Your vendor has a clear privacy policy. You've read the key sections and you're comfortable with how they handle data. Ideally, you have a signed Data Processing Agreement that outlines responsibilities.

7. Do you have a data breach response plan?

What to check: Whether you have documented steps for what to do if customer data is compromised through your AI tool.

How to check it (under 10 minutes): Search your files for a "breach response plan" or "incident response plan". If it doesn't exist, create a simple one-page document that answers: Who do I contact first? How quickly must I notify customers? What will I tell them?

What good looks like: You have a one-page plan that lists: your security contact, your lawyer's contact, the Office of the Australian Information Commissioner's contact, and the steps you'll take in the first 24 hours of discovering a breach.

8. Are you using AI to make decisions about customers without human review?

What to check: Whether AI is making significant decisions about customers (like approving credit, denying a claim, or flagging them as high-risk) without a person reviewing it first.

How to check it (under 10 minutes): List the key decisions your business makes about customers. For each one, ask: Is AI involved? If yes, does a human review the AI's recommendation before a final decision is made? If AI makes the final call alone, that's a gap.

What good looks like: AI provides recommendations or flags, but a human always reviews and approves before any significant decision is made about a customer. You can explain to a customer why a decision was made.

9. Have you documented why you're using AI for this task?

What to check: Whether you have a record of the business reason for using AI, not just "because it's convenient".

How to check it (under 10 minutes): For each AI tool you use, write one sentence: "We use this tool because [reason]." Examples: "We use a chatbot to answer routine support questions faster." "We use analytics to identify which products are popular so we can stock them better." If you can't articulate a clear reason, you may not need the tool.

What good looks like: You have a simple document listing each AI tool, what it does, and the business benefit. This shows regulators that your use of AI is intentional and justified.

Scoring: what your answers mean

9 out of 9: You're in good shape. Your AI use is documented, your customers know about it, and you have processes in place to handle requests and breaches. Keep this checklist handy and review it annually.

7–8 out of 9: You have minor gaps. These are fixable in a few hours. Prioritise items 1, 2, and 5 first—these carry the most customer-facing and legal risk.

5–6 out of 9: You have gaps that need attention. Some of these could expose you to complaints or regulatory action. Work through the "Fix the worst one first" section below.

Below 5 out of 9: You need to pause and act. Your AI use may not be compliant with Australian Privacy Law. Before you continue using these tools, work through items 1, 2, 4, and 5 as a priority.

Fix the worst one first

Don't try to fix everything at once. Start with whichever gap carries the most risk:

Highest legal risk: Items 1 (consent) and 4 (data storage location). If you don't have consent or you don't know where data is stored, stop and fix this first. These are the most common compliance failures.

Highest customer impact: Items 2 (privacy policy) and 5 (data deletion). Customers have a right to know what you're doing with their data and to have it deleted. Gaps here damage trust and invite complaints.

Quick wins: Items 3 (data minimisation), 7 (breach plan), and 9 (documentation). These take 30 minutes to an hour and remove obvious gaps.

Pick one item from each category and work through it this week. You'll move from "at risk" to "mostly compliant" quickly.

If you'd like a privacy policy template tailored to AI use, or you want to talk through your specific setup, get in touch. We help small businesses stay compliant without the jargon.

Powered by WHMCompleteSolution