This checklist is designed for small business owners and sole traders in Australia who want to use AI tools with confidence. It is not legal advice, and privacy obligations depend on your circumstances, but it will help you ask the right questions before customer information goes anywhere near an AI tool.

First, understand the basic rules

In Australia, the main privacy law for businesses is the Privacy Act 1988 (Cth), which includes the 13 Australian Privacy Principles (APPs). The APPs cover how personal information is collected, used, disclosed, stored and kept secure. The Office of the Australian Information Commissioner (OAIC) is the regulator and publishes plain-English guidance on its website, oaic.gov.au.

Many small businesses with an annual turnover of $3 million or less are not covered by the Privacy Act. However, there are important exceptions. For example, businesses that provide a health service, or that trade in personal information, are generally covered regardless of turnover. The small business exemption has also been part of the ongoing review of the Privacy Act. The OAIC website explains how to check whether the Act applies to your business.

Even if you are not legally covered, it is worth treating customer information as if you were. Customers do not check your turnover before deciding whether to trust you, and good privacy habits are much easier to build now than to retrofit later.

In October 2024 the OAIC also published guidance on privacy and the use of commercially available AI products. It is worth reading in full, but one of its clearest recommendations is that, as a matter of best practice, organisations should not enter personal information, and particularly sensitive information, into publicly available generative AI tools.

The checklist

1. Know what counts as personal information

Personal information is broader than many people expect. It is not just names and phone numbers. It includes any information about an identified person, or a person who is reasonably identifiable. A detailed description of a customer’s situation can identify them even without their name attached.

Some information is “sensitive information” under the Privacy Act and needs extra care, including health information, racial or ethnic origin, religious beliefs, sexual orientation and criminal records. As a rule of thumb, sensitive information should not go into a general-purpose AI tool.

2. Check the tool’s data settings before you use it

Different AI products, and different plans of the same product, handle your data differently. Before using any tool for business work, find out:

  • Whether your conversations may be used to train or improve the provider’s models, and whether you can switch that off.
  • How long your conversations and uploaded files are kept.
  • Where the data is stored and processed.
  • Whether a business or team plan offers stronger protections than the free version.

You can usually find this in the provider’s privacy policy, terms of use or a “data controls” section in the settings. If you cannot get a clear answer, treat the tool as unsuitable for customer information.

3. Remove or replace identifying details

Often you do not need the personal details at all to get a useful result. Instead of pasting in a complaint as it arrived, replace the name with “the customer”, remove addresses, phone numbers, email addresses, order numbers and account details, and generalise anything unusual enough to identify someone.

For example, rather than “Sarah Nguyen from Ballarat says her order #4471 arrived damaged”, try “A customer says their order arrived damaged and they are frustrated about the delay. Draft a polite reply offering a replacement.” The AI can write an excellent response without knowing who the customer is.

4. Use it for the purpose the customer would expect

Under the APPs, organisations covered by the Act generally need to use personal information for the purpose it was collected for, or for a related purpose the person would reasonably expect. A good test for any business: would my customer be surprised or uncomfortable if they knew I did this with their information?

Using AI to help draft a reply to a customer’s own enquiry is likely to feel reasonable to most people. Uploading your entire customer list to an AI tool to build marketing profiles is a very different matter.

5. Update your privacy policy and be open about it

If AI tools form part of how you handle customer information, say so in your privacy policy in plain language. Explain what kinds of tools you use, what for, and how you protect information. Being upfront builds trust, and it saves an awkward conversation if a customer asks.

If your website has a contact form, it is also worth checking that your privacy policy accurately describes where those form submissions go.

6. Keep a human in charge of decisions about people

AI can help you summarise, sort and draft, but decisions that significantly affect a person, such as refusing a service, assessing an application or handling a dispute, should be made by a human who has looked at the facts. AI output can be wrong, incomplete or unfair, and you remain responsible for the outcome.

7. Set simple rules for your team

If you have staff or contractors, write down a one-page AI policy. It does not need to be complicated. Cover:

  • Which AI tools are approved for work use.
  • What information must never be entered (for example, sensitive information, payment details, passwords and anything confidential to a client).
  • How to de-identify information before using AI.
  • Who to ask when unsure.

Then walk the team through it with real examples. A rule people understand is far more effective than a long policy nobody reads.

8. Know what to do if something goes wrong

Mistakes happen. Someone might paste a full customer record into the wrong tool, or share a chat link that contains personal details. Decide in advance what you will do: delete the conversation where possible, record what happened, assess whether any harm is likely and, if needed, notify the people affected.

Organisations covered by the Privacy Act also have obligations under the Notifiable Data Breaches scheme when a data breach is likely to result in serious harm. The OAIC website explains how the scheme works and when a notification is required.

A safe way to start

If you are not sure where to begin, start with tasks that use no personal information at all: drafting your standard FAQ answers, improving your service descriptions, planning content or writing templates for common replies. Once you are comfortable, move on to de-identified customer scenarios. Keep identifiable and sensitive information out of general AI tools unless you have checked the tool’s protections and your obligations carefully.

Privacy and AI are not opposites. With a few simple habits, you can save time with AI while keeping the trust your customers have placed in you.