AI can be safe for client data under the Australian Privacy Act — but only if you control what data goes in, where it is processed, and who can access it afterwards. The Act does not ban AI. It holds you to the same Australian Privacy Principles (APPs) you already follow: collect only what you need, use it only for the purpose you collected it, keep it secure, and be honest with clients about what happens to their information. An AI tool is just another place that data travels to, and the same rules apply.
This is a general guide for Australian accountants, lawyers, real estate agencies and conveyancers weighing up AI tools. It is not legal advice. Privacy obligations turn on your specific circumstances, so treat this as a way to ask better questions, then confirm the detail with a privacy lawyer or your professional body.
What does the Australian Privacy Act require when using AI?
If your firm has an annual turnover over $3 million, you are an APP entity and the Privacy Act 1988 applies directly. Many smaller firms are caught anyway — for example, if you trade in personal information or provide certain health-related services. Real estate agencies and legal practices frequently fall inside the net regardless of size. Assume you are covered unless you have confirmed otherwise.
The principles that matter most when AI enters the picture:
- APP 3 and 5 — collection and notice. You can only collect personal information you genuinely need, and clients should understand how it will be handled. Running their data through an AI tool is part of that handling.
- APP 6 — use and disclosure. Information collected for one purpose cannot quietly be repurposed. Feeding a client file into a tool that trains its models on your inputs can breach this.
- APP 8 — cross-border disclosure. This is the big one for AI. Most AI providers process data on servers overseas. If you send personal information offshore, you remain accountable for how it is handled there.
- APP 11 — security. You must take reasonable steps to protect personal information and destroy or de-identify it when no longer needed.
None of these prohibit AI. They shape how you deploy it. A firm that never sends identifiable client data to a public chatbot, and uses a properly contracted enterprise tool for anything sensitive, can stay well inside the lines.
Where AI tools actually create privacy risk
The risk is rarely the technology itself. It is the everyday habits around it. The common failure modes:
- Staff pasting client data into free consumer tools. A paralegal drops a full contract with names and addresses into a free chatbot to summarise it. That data has now left your control and may be used to improve the vendor's model.
- Assuming the paid version is private. Consumer and business tiers of the same product often have very different data terms. The label on the account matters less than the contract behind it.
- Offshore processing nobody checked. Data goes to a US or EU data centre by default. Under APP 8 you are still responsible for it there.
- Model training on your inputs. If the vendor reserves the right to train on submitted data, your client's information can influence outputs to other users. That is a disclosure you almost certainly did not authorise.
- No record of what was sent. When something goes wrong, you cannot investigate a breach you have no log of.
For a structured way to set expectations with staff before any of this happens, our AI policy template for law firms in Australia works just as well for accounting and conveyancing practices.
What questions should you ask an AI vendor about privacy?
Before you put any client data near a tool, get straight answers to these. If a vendor cannot answer clearly, treat that as your answer.
| Question | What a safe answer looks like |
|---|---|
| Do you use our data to train your models? | No, not on business/enterprise tiers, and it is stated in the contract — not just a blog post. |
| Where is our data processed and stored? | Named regions, with an option for Australian or at least clearly disclosed data residency. |
| How long do you retain our inputs? | A defined retention period, with the ability to disable retention or set it to zero. |
| Who inside your company can access our data? | Restricted, logged, and covered by confidentiality obligations. |
| Are you APP-compliant, and will you sign a data processing agreement? | Yes, with documentation you can show your own clients or regulator. |
| What happens to our data if we cancel? | Deleted within a stated period, with confirmation on request. |
Enterprise offerings from the major providers — Microsoft Copilot with commercial data protection, or ChatGPT Enterprise and Team — generally give firmer commitments on training and retention than their free counterparts. We compare the two in more detail in Microsoft Copilot vs ChatGPT for accounting firms. The point is not that one brand is safe and another is not — it is that the tier and contract decide, not the logo.
Safe deployment patterns for professional services firms
You do not need to solve every privacy question before you start. You need patterns that keep sensitive data out of the wrong places. In rough order of safety:
- De-identify before you send. Strip names, addresses, file numbers and dates of birth, and let the AI work on the anonymised text. A summary of "the vendor" and "the purchaser" is just as useful as one naming real people — and carries far less risk.
- Use enterprise-tier tools for anything identifiable. If you genuinely need to process client information, use a contracted business account with training disabled and retention controlled, not a personal login.
- Keep data inside tools you already trust. AI features built into platforms you already use — your practice management system, Microsoft 365, Xero — usually inherit that platform's existing data terms, which you have already accepted.
- Automate the plumbing, not the judgement. Tools like Zapier can move data between systems without a human copy-pasting it into a chatbot at all. Just confirm where each connected app processes data. Our guide to Zapier for lawyers covers this style of automation.
- Log what goes where. Keep a simple register of which tools touch client data and on what terms. It makes any future breach assessment far quicker.
When you are ready to roll something out properly, our AI automation implementation guide walks through doing it in controlled stages rather than all at once.
When is AI the wrong answer for client data?
Sometimes the honest recommendation is not to automate. Be cautious — or stay fully manual — when:
- The data is highly sensitive and cannot be de-identified. Health information, information about children, or matters where identity is the whole point (family law, criminal matters) deserve extra care.
- You cannot get a straight answer from the vendor. No data processing agreement, no clarity on training or offshore storage — then it is not ready for your client data.
- The task requires professional judgement you are accountable for. AI can draft, summarise and sort. It should not make the final call on advice, valuations, legal positions or anything a client relies on. A human name goes on the work.
- The time saved is trivial. If a task takes two minutes and the privacy setup takes an afternoon, do it by hand.
Telling a client their data went through an AI tool should never be an awkward conversation. If it would be, you have your answer.
What do you do when the AI gets it wrong?
Plan for error before it happens, because it will. Two kinds of failure matter here.
Accuracy failures. AI produces confident, wrong output — a misquoted clause, an invented figure, a mangled name. The fix is process, not technology: every AI output that leaves your firm is checked by the responsible person, exactly as you would check a junior's draft. Never send AI output to a client unread.
Privacy incidents. If personal information is exposed — data pasted somewhere it should not have been, or a vendor breach — the Notifiable Data Breaches scheme may require you to notify affected individuals and the Office of the Australian Information Commissioner where serious harm is likely. Know who in your firm owns that decision, and keep enough logs to assess what was actually exposed. This is exactly where earlier legal advice pays off.
The firms that handle AI well are not the ones with the fanciest tools. They are the ones who decided in advance what data could go where, wrote it down, and checked the vendor's terms before anyone hit paste.
If you want a practical starting point, our free guide, 10 AI Workflows to Save 10+ Hours a Week, shows automations designed around keeping client data controlled — useful whether you are just testing the water or tightening up an existing setup. Pair it with proper advice on your own obligations, and you can adopt AI without gambling on your clients' trust.
Common questions
Is it legal to use ChatGPT with client information in Australia?
It can be, but not with a free personal account for identifiable client data, because those terms often allow the provider to use your inputs for training. Use an enterprise or business tier with training disabled and retention controlled, or de-identify the data first. Your obligations under the Australian Privacy Principles follow the data wherever it goes.
Does the Australian Privacy Act apply to small firms using AI?
Not automatically for businesses under $3 million turnover, but many exceptions catch smaller firms — including those trading in personal information or handling health data. Real estate and legal practices are frequently covered regardless of size. Unless you have confirmed you are exempt, assume the Act applies and handle client data accordingly.
What is the biggest AI privacy risk for professional services firms?
Staff pasting identifiable client data into free consumer AI tools out of convenience. That data can leave your control, be stored offshore, and be used to train the vendor's models — potentially breaching cross-border disclosure and use principles. A clear internal policy and enterprise-tier accounts for sensitive work prevent most of these incidents.
Can I send client data overseas through an AI tool?
Cross-border disclosure is permitted under APP 8, but you remain accountable for how the data is handled overseas. You should know where processing occurs, take reasonable steps to ensure the recipient meets Australian standards, and tell clients if their information may be handled offshore. Where possible, choose tools offering Australian data residency.
What should I do if AI exposes client data?
Assess what was exposed and to whom, using your access logs. Under the Notifiable Data Breaches scheme you may need to notify affected individuals and the Office of the Australian Information Commissioner if serious harm is likely. Decide in advance who owns that call in your firm, and get legal advice on your specific obligations.
Want these ideas working in your firm? We build controlled AI workflows for Australian professional services firms — starting with a free automation audit.