Does GDPR Apply to a Business Using AI Tools (and What Do You Actually Need to Do)?
Last updated 22 July 2026 · 8 min read
Direct Answer
For an Australian business, the primary law that applies to using an AI tool is the Privacy Act 1988 (Cth) and its Australian Privacy Principles (APPs), regulated by the OAIC — not GDPR. If your business is an APP entity (broadly, most businesses with turnover over $3 million, plus some smaller ones handling health or other sensitive information), feeding personal information into an AI tool needs a lawful basis under the APPs, a data-handling arrangement with the vendor that covers use, disclosure, and cross-border transfer, and human oversight of anything that amounts to an automated decision about a specific person. GDPR sits on top of this only if your business separately processes the personal data of people in the EU or EEA — customers, employees, or users you serve there, or whose behaviour you monitor — regardless of where your business is headquartered. Most Australian businesses without EU customers, staff, or users never trigger GDPR at all; most Australian businesses using AI tools do need to think through the Privacy Act and APPs, and that analysis applies whether or not GDPR is also in the picture.
Detailed Explanation
For an Australian business, privacy law doesn't switch on only when AI is involved — the Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) already apply to any third-party software processing personal information, and an AI tool is handled through that same basic framework. If your business already thinks through Privacy Act obligations for its CRM, its email platform, or its accounting software, an AI tool goes through the same analysis: identify what personal information is involved, establish the APP basis for handling it, confirm the vendor relationship, and watch for the specific triggers — automated decisions about people, sensitive information — that raise the bar. GDPR is a separate, additional question that only matters if your business also handles the personal data of people in the EU or EEA.
Your business is generally the "APP entity," and the AI vendor handles the data on your behalf. Most businesses with turnover over $3 million are APP entities under the Privacy Act (some smaller businesses are covered too — health service providers, credit reporting bodies, and others). Your business remains responsible for the personal information going into an AI tool being collected, used, and disclosed consistently with the APPs, even though the AI vendor is the one actually processing it — using a well-known, reputable AI vendor doesn't shift that responsibility onto them. See how do you evaluate an AI vendor's data processing agreement for what to check in the vendor contract that covers this.
You need a proper basis under the APPs for the collection and use, not just a general "we use AI tools" policy. APP 3 governs collection of personal information, and APP 6 governs using it for a purpose beyond what it was originally collected for. For most routine internal business use (drafting a document that happens to mention a customer's name, summarising an email chain), this is usually a reasonably expected, related use. Anything using AI to make decisions about a specific person — screening a job application, scoring a customer — needs closer scrutiny of both the APP basis and the automated-decision-making considerations below.
Automated decision-making is an active area of Australian privacy reform. Recent amendments to the Privacy Act introduced new transparency obligations around automated decision-making that significantly affects a person's rights, and the OAIC has been progressively issuing guidance on AI use as this area develops. In practice, this points the same direction global regulators are heading: a human needs to be meaningfully involved in any AI-assisted decision that materially affects someone — hiring, credit, pricing, service eligibility — not a rubber-stamped AI output. See how do you decide when an automated process needs a human in the loop for the general design pattern this requires.
A Privacy Impact Assessment is the Australian equivalent of a DPIA, and is recommended (not universally mandatory) for higher-risk projects. The OAIC recommends a PIA for any project likely to have a significant impact on privacy — this isn't a bright-line legal requirement for private-sector businesses the way a DPIA is under GDPR, but it's the standard, regulator-endorsed way to document that risk has been considered before rollout. AI-assisted hiring decisions, health-information processing, or large-scale customer profiling are the situations where doing one is genuinely worthwhile.
GDPR is a separate, additional layer — only relevant if your business has an EU/EEA connection. If your business offers goods or services to people in the EU/EEA, employs staff there, or monitors the online behaviour of people located there, GDPR applies on top of the Privacy Act, regardless of where your business is headquartered. It brings its own controller/processor terminology, its own Article 6 lawful-basis requirement, and its own Article 22 automated-decision-making right, alongside a mandatory DPIA for high-risk processing. A business with no EU customers, staff, or users doesn't need to engage with GDPR's specifics at all — the Privacy Act and APPs are the whole analysis.
What to Actually Do
1. Identify what personal information your AI use actually touches. Internal drafting that never includes real customer or employee data is a much lower-friction case than any workflow where personal information is genuinely part of the input or output — be specific about which of your AI use cases actually involve it.
2. Confirm the vendor relationship in writing. A reputable AI vendor's business or enterprise plan should offer contract terms covering data handling, use, and disclosure as standard — see how do you evaluate an AI vendor's data processing agreement for what that document needs to cover, including subprocessors and cross-border transfer terms.
3. Check whether any use involves automated decisions about a specific person. If AI output feeds directly into a decision affecting someone (hiring, pricing, service access) without meaningful human review, that's the situation requiring the closest attention under the Privacy Act's automated-decision-making transparency rules and, if it applies, GDPR's Article 22 — not routine drafting or internal research.
4. Confirm where the data goes for an overseas AI vendor. Many widely used AI tools are US-based; APP 8 requires reasonable steps before disclosing personal information overseas, including satisfying yourself the overseas recipient handles it consistently with the APPs. See does it matter which country an AI tool stores your data in for the fuller treatment of this specific question.
5. Build individual rights requests into your process. If a person exercises their right under the APPs to access or correct their personal information and that information has gone into an AI tool, your business needs a way to locate and address that — confirm with your vendor how their retention and deletion controls work before you need the answer under time pressure.
6. Only then, separately, check whether GDPR adds anything. If your business has EU/EEA customers, staff, or users, work through GDPR's controller/processor, lawful-basis, and DPIA requirements as an additional layer on top of the Privacy Act analysis above — not as a replacement for it.
Things to Consider
- The Privacy Act and APPs are the default for an Australian business; GDPR is a bolt-on for EU exposure, not the other way around. Build your AI governance around the APPs first, and treat GDPR as an additional checklist only if you genuinely have EU/EEA customers, staff, or users.
- This applies independently of, and alongside, the EU AI Act for any business with EU exposure. The EU AI Act governs AI systems by risk tier regardless of personal data; GDPR governs personal-data processing. See does the EU AI Act apply to a business using ChatGPT or Claude — relevant only if your business has an EU-facing angle.
- A business with no EU/EEA connection isn't in scope for GDPR at all — its AI-related privacy obligations start and end with the Privacy Act and APPs, regulated by the OAIC.
- Free-tier AI products carry more risk than business plans on this specific point. Many free consumer AI tools have historically used conversation content for model training by default, which complicates the APP 6 use analysis considerably — see is it safe to put company data into AI tools for the broader vendor-safety framework this sits inside.
- OAIC guidance in this area is still developing. The OAIC has been issuing AI-specific guidance progressively, and interpretation continues to evolve — verify your specific situation against current OAIC guidance rather than treating any fixed rule (including this page) as permanent.
Common Mistakes
- Treating "our AI vendor says it's GDPR compliant" as evidence of Privacy Act compliance. GDPR compliance and Privacy Act/APP compliance are separate legal questions with overlapping but different requirements — a vendor's GDPR posture doesn't establish that your specific use, as the APP entity, has a valid basis under the APPs or has addressed the Privacy Act's automated-decision-making rules.
- Assuming a Privacy Impact Assessment is required for all AI use, or never worth doing. Both extremes are wrong — check your specific use case against the actual risk (automated decisions with significant effects, large-scale sensitive information, large-scale profiling) rather than defaulting to either assumption.
- Not knowing where a well-known AI vendor's servers are. A vendor's popularity doesn't establish that overseas disclosure has been handled consistently with APP 8 — confirm this explicitly rather than assuming a major vendor has already handled it invisibly.
- Letting an AI tool make a real decision about a real person with no human step. Even where the automation is technically accurate, skipping meaningful human review on anything affecting a specific person's rights or opportunities cuts against both the Privacy Act's direction of travel and, if it applies, GDPR's automated-decision-making rule.
- Assuming GDPR is the primary law to worry about because it's the most talked-about privacy regulation. For a business without EU customers, staff, or users, GDPR is close to irrelevant — the Privacy Act and APPs are the law that actually governs day-to-day AI use.
Frequently Asked Questions
- Does GDPR ever apply to an Australian business?
- Yes, but only in a specific circumstance: GDPR applies based on whose personal data is being processed, not where your business is headquartered — an Australian business that offers goods or services to people in the EU/EEA, employs staff there, or monitors the online behaviour of people located there can fall within GDPR's scope alongside its Privacy Act obligations at home. An Australian business with no EU customers, staff, or users generally isn't affected by GDPR at all — its AI-related privacy obligations come from the Privacy Act 1988 and the APPs instead.
- Is GDPR the same thing as the EU AI Act?
- No — they're separate regulations governing different things. GDPR governs the processing of personal data generally, regardless of whether AI is involved. The EU AI Act governs AI systems specifically, based on risk tier, regardless of whether personal data is involved. Using an AI tool with EU personal data typically means both apply simultaneously and independently — see does the EU AI Act apply to a business using ChatGPT or Claude for that separate set of obligations.
- Do I need a Privacy Impact Assessment every time I use an AI tool?
- No — for an Australian business, the OAIC recommends (and for Commonwealth agencies requires) a Privacy Impact Assessment (PIA) for a project that's likely to have a significant privacy impact, not for routine, low-risk use. AI-assisted hiring decisions, health-information processing, or large-scale customer profiling are the kinds of uses where a PIA is genuinely worth doing; routine internal use of an AI tool for drafting or research doesn't typically warrant one. A business that also falls within GDPR's scope faces a separate, more strictly mandatory Data Protection Impact Assessment (DPIA) requirement tied to similar high-risk triggers — systematic automated decision-making, large-scale special-category data, or large-scale monitoring.
References
Related Questions
Does the EU AI Act Apply to a Business Using ChatGPT or Claude?
Australia has no EU AI Act equivalent: existing law and the Guidance for AI Adoption apply instead; the EU Act only matters with EU staff or customers.
Is It Safe to Put Company Data into AI Tools?
It depends on the data, the plan, and the vendor's terms. Business/enterprise AI plans typically differ from free consumer tiers — here's how to check safely.
How Do You Evaluate an AI Vendor's Data Processing Agreement?
Before adopting an AI tool, check its DPA for subprocessors, data residency, retention, training defaults, and certifications — here's what to look for.
Does It Matter Which Country an AI Tool Stores Your Data In (Data Residency)?
Where an AI vendor stores your data matters most under APP 8's overseas disclosure rules, for regulated industries and government contracts, less so elsewhere.
How Long Should You Keep Records of AI Tool Conversations and Outputs?
Keeping AI records too briefly weakens dispute defense; too long adds Privacy Act and breach exposure. Here's how to set a practical retention period.
How Do You Automate Handling Privacy Act Access and Correction Requests?
Automating APP 12 access and APP 13 correction requests under the Privacy Act 1988: intake, identity checks, the 30-day clock, and what to log.