Back to Home
Business Automation

Which AI Tools Can You Safely Put Client Data Into? An Australian Small Business Checklist

Most owners are not blocked by AI capability but by not knowing the data-safety line. A practical checklist covering vendor questions, the Privacy Act, and...

13Labs Team27 July 20269 min read
AI data privacyclient dataPrivacy Act AustraliaAI vendor checklistcompliancebuildAutomation

Contents

The real problem: not knowing where the line is

Most business owners who hesitate on AI are not blocked by capability. They are blocked by not knowing where the data-safety line sits, and nobody has drawn it for them. One accounting firm owner told an industry podcast that a new AI agent was the best tool he had seen for his practice, then added the honest part: "the problem is I can't yet trust it with sensitive client info. I can't yet." He had run a 40-person firm. He understood the tool. He still would not put a client file into it, because he did not know which plan, which settings, or which vendor made that safe. That hesitation is reasonable. Australian organisations reported 1,205 data breaches to the privacy regulator in the 2025 calendar year, an 8 per cent rise on 2024 and the highest annual total since mandatory reporting began in 2018 (Office of the Australian Information Commissioner, Notifiable Data Breaches statistics, 2025). Of those, 716 were caused by malicious or criminal activity, and health service providers reported more breaches than any other sector, 225 in total (OAIC, 2025). The gap this guide fills is practical, not technical. Below is a checklist for any AI vendor, a plain-English summary of your Privacy Act obligations, and notes for the professions with extra rules on top.

What to ask any AI vendor before you enter client data

Ask six questions before any staff member pastes a client name, file, or record into an AI tool. If a vendor cannot answer clearly, treat that as your answer. - Does it train on your data? Free consumer tiers of most major chatbots use your prompts to improve their models by default. Business and team-tier plans (such as ChatGPT Team or Claude for Business) typically exclude your inputs from training by default, but policies change and vary by plan, so check the current terms of service before you rely on this for a single client file. - Is it a consumer tier or a business tier? Consumer tiers are built for individuals and rarely carry contractual data protections. Business tiers usually add a data processing agreement, an admin console, and audit history. If your staff are using a personal login on a personal card, you are on the consumer tier by definition, whatever the marketing says. - Does it carry an independent security certification? SOC 2 Type 2 is the certification most enterprise AI plans point to, and it means an outside auditor has tested the vendor's security controls over a period of months, not just reviewed a policy document once. Ask for the certificate or the audit summary, not just the claim. - Does it offer audit logs? You want a record of who asked what, and when, inside your business account. Without logs, you cannot show a regulator, an insurer, or a client what happened if something goes wrong. - Can an admin revoke access instantly? When someone leaves your business, you need a single console where you can cut their access the same day, not a list of personal logins you have to hope they close. - Does it offer Australian data residency? Some vendors now let you choose to store and process data on servers located in Australia. This will not suit every business, but for firms handling health records or financial data, it is worth asking about directly rather than assuming.

What the Privacy Act actually asks of you

The Australian Privacy Principles boil down to three obligations that apply directly to how you use AI tools with client information. Use it only for the reason you collected it. If a client gave you their details to complete a job, that is what you can use them for. Pasting the same details into an AI tool to draft an unrelated marketing email is a different purpose, and the Privacy Act cares about that distinction. Do not disclose it without consent. Sending client information to a third-party AI vendor is a disclosure. If your engagement terms do not already cover this, a short line telling clients you may use approved AI tools to help prepare their work is worth adding. Take reasonable steps to keep it secure. This is where vendor tier, training settings, and admin controls stop being a nice-to-have and become the actual compliance question. The Privacy Act was strengthened in December 2024, and penalties for serious or repeated breaches can now reach $50 million, three times the benefit gained, or 30 per cent of adjusted turnover, whichever is greatest (Privacy Act 1988, as amended 2024). The regulator can also issue infringement notices of up to $66,000 for failing to maintain a compliant privacy policy, without needing to prove a breach occurred at all (OAIC enforcement powers, 2024 amendments). This is general guidance, not legal advice. Your specific obligations depend on your industry, your turnover, and what data you hold, so confirm the detail with a lawyer or your professional body before you finalise a policy.

Why 'we're too small for this' is getting harder to say

The long-standing exemption for businesses turning over less than $3 million a year is being eroded from multiple directions at once, not repealed in one clean step. Health service providers have never been covered by the small business exemption, regardless of turnover. If you hold health information in any form, the Privacy Act already applies to you in full. Reforms taking effect from 1 July 2026 also brought designated services under anti-money-laundering law, including real estate, legal, accounting, and conveyancing, under the Privacy Act for that data handling, regardless of their size. The regulator estimates more than 100,000 small businesses were affected by that change alone (OAIC, 2026). None of this requires you to become a compliance department. It does mean the reasonable assumption to make in 2026 is that your business is covered, or will be shortly, and to set up your AI use accordingly rather than waiting for a formal announcement.

Extra obligations if you are an accountant, lawyer, or allied health provider

Three professions carry rules on top of the general Privacy Act, and each changes what counts as safe AI use. Accountants and tax agents have confidentiality duties under the Tax Agent Services Act 2009, enforced by the Tax Practitioners Board regardless of which software or AI tool you use. The obligation sits with you, not the vendor. Lawyers hold legal professional privilege on top of ordinary privacy law, and most state law societies have published specific guidance on generative AI use in practice. A tool being privacy-compliant does not automatically mean it preserves privilege, so check your jurisdiction's professional conduct rules before relying on AI for anything client-privileged. Allied health and medical practices are covered by the Privacy Act for health information regardless of turnover, and have been since the Act's health-specific provisions were introduced. This is the profession where the small business exemption argument has the least standing, and the one where getting the AI data question wrong carries the most direct professional risk. It is also worth remembering that client trust is not only a compliance question. Research covering consumers across seven countries, Australia included, found Australians among the least tolerant of AI handling their service interactions without a human option, and most said they would stop using a business that could not resolve an issue without one (cited in Australian small-business industry commentary, 2026). The data-safety line and the trust line usually sit close together.

Turning this into a one-page policy your team actually follows

A usable AI policy for client data fits on one page and answers three questions: which tools are approved, what can go into them, and who to ask when unsure. Start by naming the approved tool, not just the category. "Staff may use our business ChatGPT Team workspace" is a rule your team can follow. "Use AI responsibly" is not. - List the specific tools and plans your business has approved, by name - State plainly what cannot go in: full client files, health records, financial account numbers, anything a client asked you to keep confidential beyond normal business use - Name one person staff can ask when a new situation comes up, so the answer is never "just use your judgement" - Review the policy every six months, because vendor terms and your own risk profile both change This is where most small businesses stall, not because the checklist is hard, but because nobody in the business has the spare time to work through vendor terms, draft the policy, and train the team on it while also running the business day to day.

Frequently Asked Questions

Is ChatGPT safe for client data in Australia? It depends entirely on the plan, not the brand name. Free and personal Plus accounts commonly train on your inputs by default and carry no business-grade contractual protections, so treat them as unsafe for client information. Business and team-tier plans typically exclude your data from training and add admin controls, but confirm the current terms before you rely on this, since policies change. What is the Privacy Act 1988 and does it apply to my small business? The Privacy Act 1988 is the federal law governing how organisations handle personal information in Australia. The long-standing exemption for businesses under $3 million turnover is being eroded: health providers were never covered by it, and reforms from 1 July 2026 brought AML/CTF-designated services, including real estate, legal, and accounting, under the Act regardless of size. This is general guidance, not legal advice, so confirm your specific position with a lawyer or professional body. What does SOC 2 Type 2 actually mean? It means an independent auditor has tested a vendor's security controls over a period of months, not just reviewed a policy on paper. It is a reasonable signal of vendor security maturity, but ask for the certificate itself rather than accepting the claim, and remember certification covers the vendor's systems, not how your own staff use them. Should I ask an AI vendor about data residency? Yes, if you handle health records, financial data, or anything sensitive. Some vendors now offer the option to store and process data on Australian servers. This will not be a deciding factor for every business, but it is a reasonable question to put to any vendor handling client information, and a straightforward one to compare across options. What is the difference between a personal AI account and a business AI account for this purpose? A personal account is set up by an individual on a personal card, usually with no admin console, no audit log, and consumer-tier data terms. A business account is set up under the company, gives an admin visibility into every user and the ability to revoke access, and generally carries a data processing agreement absent from consumer tiers. If your staff are using personal logins for client work, you have no visibility into what has been entered, by whom, or where it went.

We help you draw the line, not just hand you a tool

buildAutomation trains two or three of your own staff to work out where your data-safety line actually sits, set up the right tier on the right AI tool, and build the habits that keep client data safe day to day. No retainer, no dependency, the judgement stays in-house.

Explore buildAutomation