Interactive controls are loading. Phone and email links are available.

Skip to main content

AI data privacy starts with the information and the service configuration

Check what your AI tools receive, where it goes, who can access it and how long it remains. Supplier nationality and a no-training setting answer only part of those questions.

General information checked against the official sources linked below on 10 September 2026. Obtain advice for your circumstances; this page is not legal advice.

Discuss Your AI Workflow

Check which obligations apply

The Privacy Act covers Australian Government agencies and many organisations. Coverage includes exceptions and specific categories of small business; turnover alone does not settle the question. Start with the OAIC guide to rights and responsibilities.

Health information, professional confidentiality, government work and contractual commitments may need additional assessment. Record the requirements for the actual information and activity before selecting a product.

Overseas processing is not a blanket prohibition

APP 8 generally requires reasonable steps before an APP entity discloses personal information overseas and can make it accountable for the recipient's handling. Exceptions and the distinction between use and disclosure matter. Read the OAIC APP 8 guidance.

Australian hosting does not automatically establish compliance either. Review the complete data path, including subprocessors, logs, backups and remote access, against your requirements.

ChatGPT training controls depend on the product

Personal accounts

OpenAI permits an opt-out for new conversations. Temporary Chat is not used for model training. Sending feedback can allow the associated conversation to be used even after opting out.

OpenAI training controls and exceptions

Business products and API

OpenAI states that ChatGPT Business, Enterprise and API inputs and outputs are excluded from model training by default, unless an organisation explicitly opts in to sharing data.

OpenAI business data commitments

Training, retention, abuse monitoring and third-party app access are separate issues. Check the current documentation and settings for the features your team will use.

Build a provider data-handling record

Use this checklist to collect evidence for your review. It is not a legal compliance score or certification.

Information collected

List recordings, transcripts, prompts, attachments, identifiers, logs and any information retrieved from business systems.

Purpose and permissions

Identify why each item is needed, the authorised use and the approvals required before supplying it to a provider.

Providers and locations

Map the voice, transcription, model, hosting, analytics and integration services. Include processing, backups and support access.

Training and retention

Check the exact plan, settings and contract. Distinguish model training from operational storage, safety monitoring and deletion.

Access and separation

Document who can view, export or change records. Test separation between customers, workspaces and business entities.

Incident response

Agree supplier contacts, incident reporting, containment, evidence access and responsibilities for assessing notification obligations.

Changes and exit

Confirm how provider changes are communicated, how records can be exported and how deletion is requested when service ends.

The OAIC guidance on commercial AI products is a useful starting point when choosing and configuring a service.

Breach assessment and notification are different steps

For a suspected eligible breach, the OAIC says to take all reasonable steps to complete assessment within 30 calendar days. Notification obligations require prompt action when there are reasonable grounds to believe an eligible breach occurred; 30 days is not a general notification deadline.

Read the OAIC Notifiable Data Breaches scheme guidance and agree supplier incident contacts before introducing live information.

Frequently asked questions

Is using an overseas AI service automatically a Privacy Act breach?

No. The assessment depends on the organisation, information, proposed handling and applicable requirements. APP 8 sets a framework for overseas disclosure, with exceptions. Neither an overseas address nor an Australian server is enough to determine compliance.

Can personal ChatGPT users turn off model training?

Yes. OpenAI provides a training opt-out for new conversations. Temporary Chat is also excluded from training. Review the linked controls and their exceptions, including feedback, rather than assuming all personal-account conversations are used for training.

Does a business AI plan solve every privacy issue?

No. A no-training commitment is one control. You still need to assess collection, permitted disclosure, retention, access, connected apps, processing locations and any requirements specific to your work.

Does Yes AI guarantee that all customer information stays in Australia?

No blanket hosting guarantee is made here. The selected voice, AI, storage and integration services determine the data path. Confirm locations and provider terms in the agreed project design before supplying sensitive information.

Does a network trace prove where an AI provider stores information?

No. It may show a network endpoint without establishing the locations of model processing, storage, logs, backups or support access. Request documented architecture and contractual commitments for the service you will use.

Do I have 30 days before notifying a data breach?

Do not treat 30 days as a general waiting period. The OAIC distinguishes assessment of a suspected eligible breach from prompt notification once the notification requirements apply. Follow the current guidance and your incident-response process.

Can Yes AI provide a legal compliance certification?

No. We can help document an AI workflow and its technical data handling. A qualified adviser should assess the legal requirements that apply to your organisation. This page provides general information, not legal advice or a compliance certification.

Document your proposed AI workflow

We can help map the technical information flows and identify questions to take to your privacy adviser. Hosting, access and retention requirements should form part of the agreed design.

Book a Consultation