The Privacy Act, the APPs and AI: what actually applies.
Every Australian business evaluating AI tools eventually asks the same question: is this legal under the Privacy Act? The Act itself does not mention AI at all. It regulates what you do with personal information, and AI tools matter only insofar as they collect, use, disclose or store it. Three of the Australian Privacy Principles (APPs) do almost all of the work.
General information only. This guide is not legal advice and is not a substitute for advice about your specific obligations. Verify positions against the primary sources linked throughout, and take professional advice where it matters.
First, what an APP actually is
The Australian Privacy Principles are thirteen legally binding rules set out in Schedule 1 of the Privacy Act 1988. Together they govern the full life of personal information: how it may be collected, used, disclosed, kept secure, sent overseas, and accessed or corrected by the person it belongs to. When this guide says APP 6 or APP 8, it means principle 6 or 8 of those thirteen.
They bind what the Act calls APP entities: Australian Government agencies and private organisations with annual turnover above $3 million, plus some organisations regardless of size, including every private health service provider. Practices under the turnover threshold are often still bound in effect: health practices are covered outright, and professional practices are routinely held to the same standard by client contracts and their own professional obligations (OAIC, Australian Privacy Principles).
APP 6: use and disclosure
APP 6 restricts using or disclosing personal information for a purpose other than the one it was collected for, absent consent or an exception. Client information collected to deliver professional services was not collected for the purpose of being processed by an AI vendor, so the analysis starts here: is sending it to an AI service a use within the original purpose, or a disclosure to a third party? The OAIC's published guidance on commercially available AI products makes clear the regulator is alive to exactly this question (OAIC guidance on AI products).
APP 8: cross-border disclosure, the core of it
APP 8 is where cloud AI analysis concentrates. Before an entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient does not breach the APPs, and in many cases the discloser remains accountable for what the recipient does. Sending prompts containing personal information to an AI service processed offshore is the textbook case (OAIC, Australian Privacy Principles). The practical difficulty is verification: certifications and contract clauses are attestations about infrastructure you cannot inspect. This is why deployment posture, not vendor policy, is the variable that actually changes the analysis: processing that never leaves your premises never engages APP 8 at all.
APP 11: security of personal information
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. For AI tools the questions are concrete: who can see prompts and outputs, where are they retained, for how long, and who at the vendor has access? For an on-premise unit the answers collapse into your existing physical and network security, which your business already manages and can audit.
Reform direction
Privacy Act reform has been in progress for several years, with the general direction being stronger individual rights, higher penalties and narrower exemptions. Businesses adopting AI should assume the compliance bar rises over time, not falls, and prefer architectures that do not depend on today's thresholds (Attorney-General's Department, privacy reform).
The practical takeaway
The Privacy Act does not prohibit AI. It makes you accountable for where personal information travels. Cloud AI puts the answer partly in a vendor's hands and partly offshore; a no-egress unit keeps the answer inside your building. Our comparison of the four deployment postures maps each option against exactly these questions.
Common questions
Is ChatGPT compliant with the Privacy Act?
Does APP 8 apply if the vendor has Australian data residency?
What is the safest posture under the APPs?
See Dominion answering from your own documents.
A demonstration takes 30 minutes, uses no client data, and comes with no obligation.
Book a demo