Can you put client information into ChatGPT? What the privacy rules say

What the privacy regulator says about entering customer and patient details into AI tools, which businesses the rules cover, and what to check first.

A laptop on a wooden desk shows OpenAI's ChatGPT web page, beside a coffee cup.
Illustrative photograph: Emiliano Vittoriosi / Unsplash

A client emails a long complaint and you want a polite reply drafted. A patient’s notes need summarising for a referral. A customer list needs tidying before a mail-out. Pasting it all into ChatGPT, Copilot or Gemini takes seconds. The question owners and practice managers keep asking is whether they’re allowed to.

The short answer from Australia’s privacy regulator: if your business is covered by the Privacy Act, the normal privacy rules apply to any personal information you type into an AI tool. The regulator’s best-practice advice is to keep personal information out of public AI chatbots altogether.

What the regulator has said

The Office of the Australian Information Commissioner (OAIC) published guidance on privacy and the use of commercially available AI products in October 2024 and updated it in January 2025. It names ChatGPT and Microsoft Copilot as examples, and says it also covers freely available tools such as public chatbots.

Its five headline points, in brief:

  1. Privacy obligations apply to any personal information entered into an AI system, and to AI output that contains personal information.
  2. Businesses should update their privacy policies and notices with clear information about their use of AI, and chatbots should be clearly identified as chatbots to customers.
  3. If AI generates or infers personal information about someone, that counts as collecting personal information, and the collection rules apply. The OAIC says this includes made-up output (“hallucinations”) and deepfakes.
  4. Personal information should only be used or disclosed for the purpose it was collected for, unless the person consents, or would reasonably expect the other use and it’s related to the original purpose (directly related, for sensitive information).
  5. “As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, due to the significant and complex privacy risks involved.”

That fifth point is guidance, not a legal ban. The legal obligations sit in the Australian Privacy Principles (APPs), and the guidance explains how they apply.

Use or disclosure: why the tool’s terms matter

The OAIC draws a line that decides how much trouble a paste can cause. Typing personal information into an AI tool is a use if the information stays within your organisation’s control. It’s a disclosure if it becomes accessible to others outside the organisation and leaves your effective control.

The guidance gives its own example: staff at an insurance company paste a claim, including health information, into a public chatbot. The OAIC says that by doing so, the company is disclosing the information to the chatbot’s owners. By contrast, it says a business’s own AI system with protections that stop data reaching the developer would be a use rather than a disclosure.

Either way, the purpose rule applies. The OAIC says the original purpose should be read narrowly where it’s unclear, and that “in many cases it will be difficult to establish” that a secondary use such as training an AI system was within people’s reasonable expectations. Where you can’t establish that, it says to seek consent or offer a meaningful opt-out. It also warns that once information is entered, it may be “potentially impossible to remove the information from the system”.

Sensitive information, such as health information, race and religious beliefs, generally needs consent, and the OAIC says consent can’t be implied just because someone was notified.

Does this apply to your business?

The Privacy Act doesn’t cover most small businesses. The OAIC says a small business, for these purposes, has annual turnover of $3 million or less, counting income from all sources.

But some businesses are covered regardless of turnover, including:

  • health service providers, which the OAIC says includes complementary therapists, child care centres, private schools and gyms
  • businesses that trade in personal information, such as selling a customer list without consent
  • contractors providing services under a Commonwealth contract
  • credit reporting bodies, and reporting entities under the anti-money laundering law (for their activities under that law)
  • businesses related to a covered business, or that have opted in

That list isn’t complete; the OAIC’s page has the full set. If you’re not covered, the OAIC still recommends protecting the personal information you hold as a matter of best practice. Our story on Privacy Act changes for small businesses covers the exemption in more detail, including the new privacy tort that applies regardless of turnover.

Free chatbot or business plan?

This is where the tool you choose matters. The OAIC says some AI products have terms or settings that let the provider collect what customers type in for further training, “with the potential for personal information input into an AI product then surfacing in response to a prompt from another user”. It tells businesses to review terms and settings, turn off features that would disclose personal information, and back any staff rules with training and auditing. It also says to use or disclose only the minimum personal information needed.

Here’s what the vendors say about their products:

  • Microsoft says that in Microsoft Copilot and Copilot Chat with enterprise data protection, prompts, responses and data accessed through Microsoft Graph “aren’t used to train foundation models”, and that it acts as a data processor. It notes that web searches sent to Bing are handled differently, with Microsoft acting as an independent data controller.
  • Google says in its Workspace generative AI privacy hub that Workspace “does not use customer data for training models without customer’s prior permission or instruction”, for qualifying Workspace editions.
  • Google’s consumer Gemini app is different. Its privacy hub asks users not to enter confidential information they wouldn’t want a reviewer to see, says a subset of chats is reviewed by people, and says reviewed chats are kept for up to three years.

Whichever tool your team uses, including ChatGPT, check the current data terms for the specific plan and account, rather than assuming a free personal account works the same way as a business one.

A business plan doesn’t make every paste lawful. It reduces the disclosure risk, but the purpose, sensitive-information and accuracy rules still apply. The OAIC also says “a human user should be responsible for verifying the accuracy of any personal information obtained through AI”, and that records should show where information is AI output, “a probabilistic assessment rather than fact”.

What’s coming in December

From 10 December 2026, amendments made by the Privacy and Other Legislation Amendment Act 2024 require businesses covered by the Privacy Act to say in their privacy policy when they use a computer program, with personal information, to make decisions that could significantly affect someone’s rights or interests. If you’re using AI to screen job applicants, approve accounts or decide who gets an offer, that’s the one to watch.

Checklist

  • Check whether the Privacy Act covers you. Confirm turnover against the $3 million threshold, and check the OAIC’s list of businesses covered regardless of size, such as health service providers.
  • List the AI tools staff actually use. Note whether each is a personal free account or a business plan your organisation controls.
  • Read each tool’s data terms and settings. Check whether what staff type in can be used to train the provider’s models, and switch that off where you can.
  • Move client work to business accounts you control. Keep customer and patient details out of personal chatbot accounts.
  • Keep sensitive information out of AI tools without consent. That includes health information, race and religious beliefs.
  • Paste only the personal information the task needs. Leave out client details the AI tool doesn’t need to do the job.
  • Have a person check AI output about clients. Correct errors before anything is saved to a record or sent.
  • Update your privacy policy if you use AI with personal information. Say how you use it, and label any customer-facing chatbot as a chatbot.
Sources 8 sources
  1. OAIC: Guidance on privacy and the use of commercially available AI products (published 21 October 2024, updated 17 January 2025)
  2. OAIC: Top 5 takeaways – privacy and the use of commercially available AI products (PDF)
  3. OAIC: Small business
  4. OAIC: Rights and responsibilities
  5. Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024 (as made)
  6. Microsoft Learn: Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat (updated 18 August 2026)
  7. Google Workspace Admin Help: Generative AI in Google Workspace Privacy Hub (updated 14 August 2026)
  8. Gemini Apps Help: Gemini Apps Privacy Hub (updated 24 September 2026)

How this story was made. Researched from the primary sources listed above (open Sources to see them), drafted with AI assistance and checked against those sources before publication. Details can change after publication; check the original source before acting. Spotted an error? Tell us and we will check it.

General information only, not legal, tax or financial advice.

Editorial standards · Corrections · Ownership

Help us improve Digital Advisors

Allow Google Analytics to measure visits and use of our guides and resources? You can decline and still use everything, or change your choice below.

Read our privacy notice