AI Automation and the Australian Privacy Act: What SME Owners Need to Know

Quick answer. AI automation and the Australian Privacy Act intersect the moment your business connects an AI tool to personal information. The Privacy Act 1988 and its Australian Privacy Principles set out how personal information should be collected, used, stored and disclosed in Australia, and a Notifiable Data Breaches scheme requires certain organisations to report serious data breaches. Many small businesses assume a "small business exemption" means the Act doesn't apply to them at all — but that exemption has specific conditions and doesn't cover every SME or every activity. This is a plain-language overview, not legal advice: check the OAIC website and speak to a privacy lawyer before you rely on any of it for your specific business.

Key takeaways

  • The Privacy Act 1988 and its Australian Privacy Principles (APPs) govern how personal information is collected, used, stored and disclosed in Australia, and they apply the moment an AI automation touches personal information.
  • The Notifiable Data Breaches (NDB) scheme requires organisations covered by the Privacy Act to notify affected individuals and the OAIC when a breach is likely to cause serious harm.
  • The "small business exemption" is not a blanket pass — it comes with conditions and carve-outs, so check your current status on the OAIC website rather than assuming your size exempts you.
  • Before connecting a new AI tool to customer data, check what it collects, where the data is stored, whether it is used to train models, and whether the vendor's contract includes privacy and security commitments.
  • Treating the APPs as a practical baseline — even where the small business exemption technically applies — is generally the lower-risk approach for a growing business.

Why AI Automation Brings the Australian Privacy Act Into Play

When you connect an AI tool to customer data — a chatbot, an automated email responder, a data-enrichment workflow — you're not just adopting new software. You may also be changing how personal information is collected, used or disclosed in your business, which is exactly what Australian privacy law is concerned with.

Most SME owners aren't trying to avoid their privacy obligations — they simply haven't realised an AI automation project touches them at all. A Melbourne retail business adding an AI tool that reads customer emails to draft responses is now processing customer personal information through a new system. That's worth a few minutes of thought before go-live, not because it's necessarily a problem, but because it's the kind of thing worth doing deliberately rather than accidentally — which is exactly why AI automation and the Australian Privacy Act need to be thought about together, not as two separate projects.

This post gives you the shape of the landscape so you know what questions to ask — not a compliance checklist you can tick off without advice.

The Privacy Act and the Australian Privacy Principles, in Plain Language

The Privacy Act 1988 is Commonwealth legislation that governs how personal information is handled in Australia. It's built around a set of Australian Privacy Principles (APPs) that cover things like:

  • How personal information is collected, and what people need to be told when it's collected
  • How it can be used and disclosed, including for purposes beyond what it was originally collected for
  • How securely it needs to be stored
  • People's rights to access and correct their own information

The APPs are principle-based rather than a list of specific technical rules, which means how they apply to a specific AI automation often depends on the details of what data is involved and what the automation actually does with it. That's precisely why generic advice (including this article) can only take you so far — the specifics matter.

The Notifiable Data Breaches Scheme

Australia has a Notifiable Data Breaches (NDB) scheme, which requires organisations covered by the Privacy Act to notify affected individuals and the OAIC when a data breach is likely to result in serious harm.

For an SME adopting AI tools, the practical implication is this: if an AI tool or automation you've connected causes a breach involving customer personal information, you need to be able to recognise that quickly and know your obligations — not work it out for the first time during the incident. This is one of the strongest arguments for keeping some kind of record of what data each AI tool and automation in your business can access, which we cover in our companion post on AI security and privacy risks for SMEs.

The Small Business Exemption — and Why It's Not a Blanket Pass

Many small business owners have heard that "small businesses are exempt from the Privacy Act" and stop thinking about it there. That's an oversimplification that can leave a business exposed.

The Privacy Act does include an exemption pathway for some small businesses, but it comes with conditions and carve-outs — certain types of businesses and certain types of activities are excluded from the exemption regardless of size, and the exemption can turn on factors specific to your business (such as whether you trade in personal information, or operate in certain sectors). Because these conditions and thresholds are the kind of detail that changes and that a general blog post shouldn't state definitively, check your current status directly on the OAIC website or with a privacy lawyer rather than relying on general assumptions about your size.

A useful way to think about it: even where the exemption technically applies, most AI vendors, business customers and increasingly customers themselves expect good privacy practice regardless. Treating the APPs as a practical baseline — whether or not you're strictly required to — tends to be the lower-risk path for a growing business.

A Practical Checklist for AI Vendors and Automations

This won't tell you whether you're compliant — only a lawyer familiar with your business can do that. What it will do is surface the questions worth raising before and after you adopt an AI tool.

Area Question to ask
Collection Does the AI tool collect any personal information beyond what customers would reasonably expect?
Notice Does your privacy policy or customer-facing notice mention that an AI tool is involved in handling their enquiry or data?
Use and disclosure Is customer data used only for the purpose it was collected for, or could it be repurposed (e.g. used to train a model) without the customer knowing?
Storage and security Is the data encrypted, access-controlled, and stored somewhere you've actually reviewed?
Retention Does the AI vendor keep data indefinitely, or can you set a retention period?
Cross-border Is data sent to servers outside Australia, and does that change your obligations?
Breach response If this tool were breached tomorrow, would you know what data was affected and who to tell?
Vendor terms Does the vendor's contract include privacy and security commitments you can point to later?

Practical Steps Before You Automate a Customer-Facing Process

  1. List what personal information the automation will touch. Be specific — "customer emails" is too broad; "name, email, order history" is useful.
  2. Update your privacy policy if the automation changes how data is used or disclosed. This is often a small addition, not a rewrite, but it needs to happen before launch, not after a customer asks.
  3. Check the AI vendor's own privacy and security commitments, including whether they'll act as your service provider under a data processing arrangement.
  4. Decide who in your business owns privacy questions. For most SMEs this doesn't need to be a dedicated role — it needs to be one named person who knows to ask "have we checked this?" before a new tool goes live.
  5. Get advice before scaling anything involving sensitive information — health data, financial data, information about children — regardless of your business size.

FAQ

Does the Privacy Act apply to my small business?

It depends on your specific circumstances, including your business's activities and turnover, and there are exceptions to the general small business exemption that can bring smaller businesses back into scope. Don't assume either way — check current guidance on the OAIC website or ask a privacy lawyer about your specific business.

What counts as a "notifiable" data breach?

The Notifiable Data Breaches scheme covers breaches that are likely to result in serious harm to the individuals whose information was involved, and the assessment depends on the nature of the information and the circumstances of the breach. This is a judgement call that often benefits from legal advice rather than a business owner deciding alone under pressure — which is exactly why it's worth understanding the scheme before an incident happens, not during one.

Do I need to tell customers I'm using AI to handle their data?

Good privacy practice generally favours transparency about how customer data is handled, including where automated tools are involved, and your privacy policy should reflect what actually happens to customer information. Whether a specific disclosure is legally required in your case depends on your circumstances — this is worth confirming with a privacy advisor rather than guessing.

Is using an overseas AI provider automatically a problem?

Not automatically, but sending personal information to servers or providers outside Australia can bring additional obligations into play depending on your business's situation. Check the vendor's data location and processing terms, and get advice if you're dealing with sensitive personal information rather than general contact details.

How do I find authoritative, current information on this?

Start with the Office of the Australian Information Commissioner (oaic.gov.au), which publishes current guidance on the Privacy Act, the Australian Privacy Principles, the Notifiable Data Breaches scheme and the small business exemption. For anything specific to your business, engage a privacy lawyer rather than relying on general online guidance, including this post.

Next step

Before connecting a new AI tool to customer data, run through our related post on AI security and privacy risks for SMEs, and see how Sketchli builds privacy-aware automation into projects through AI transformation. If you'd like a second set of eyes on a planned automation, book a free 30-minute call.


Want to take your business to the next level with AI? Contact us or chat on WhatsApp.

Vish PrasadFounder & Product Lead, Sketchli

Sketchli designs, builds and launches AI-powered products and automations for first-time founders and growing Australian businesses, then stays until the numbers move.

Let's talk

Ready to find out what it would actually take?

Book a free 30-minute call. Tell us about your idea or your biggest bottleneck, and we'll tell you honestly whether AI can solve it, and exactly what it would cost. No pitch. No pressure.

or send us a note
Sent straight to Vish. Answered personally within one business day.
AI Automation and the Privacy Act | Sketchli