Does putting tenant or vendor details into an AI tool send their information overseas?
Not automatically. Where the processing happens overseas APP 8 may be engaged, but two limits sit in front of it. Under OAIC APP Guidelines 8.14, providing personal information to an overseas contractor may be a use rather than a disclosure where you do not release its handling from your effective control, and APP 8 then does not apply at all. And where a provider has an Australian link under s 5B(3)(b), the Act binds it directly and s 16C switches off. The practical rule survives either answer: keep client personal information out of general AI tools, because APP 6 and APP 11.1 apply regardless.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why is this the exposure nobody notices?
Because it never goes through a procurement decision. A property manager pastes a difficult email thread into a chatbot to soften the tone. A sales agent drops an applicant's details in to draft a rejection. Someone uploads a rental ledger to get a summary. None of that appears in a systems review, and none of it was anyone's decision.
None of it is written down, so the honest test is a question: in the last month, what client information went into a tool nobody signed a contract with? Disclosure or use, APP 11.1 applies either way.
What is the actual rule for staff?
Write one they can follow, because a ban nobody obeys is worse than a rule people use.
- No names, addresses, contact details, identity documents, bank or income details go into a general AI tool.
- Draft with the specifics stripped out, then add them back locally.
- No uploading of application files, ledgers, ID scans or inspection photos.
- If a tool is genuinely useful, ask for it properly rather than working around the rule.
This rule is correct whether or not APP 8 is engaged, which is the point. APP 6 governs whether the use is within the purpose the information was collected for, and APP 11.1 governs the security of what you hold. Both apply regardless of where the server is.
If you want AI tooling properly, the OAIC has already written the test. Provision to an overseas provider is a use rather than a disclosure only where a binding contract limits the provider to your purposes, binds any subcontractor to the same obligations, and leaves you effective control, including the right to access, change, retrieve or permanently delete the information (APP Guidelines 8.14). Read your own agreement against those three and see which one it is missing. Even where it is a use, you still hold the information, so APP 11.1 does not go away (8.15).
Sources: Privacy Act 1988 (Cth), APP 6, APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 6, 8 and 11 · OAIC APP guidelines
Are we accountable for what the AI provider does with it?
This is the part that is genuinely unsettled, and we are not going to pretend otherwise.
Section 16C makes a disclosing entity accountable for an overseas recipient's acts only where three conditions are all met: APP 8.1 applies, so no APP 8.2 exception is in play; the APPs do not already apply to the overseas recipient; and the act would breach an APP other than APP 1.
The second condition is where AI tools sit awkwardly. Where a provider has an Australian link under s 5B(3)(b) (carrying on business in Australia), with the Act extended to its overseas acts by s 5B(1A), the Privacy Act binds it directly, and s 16C does not operate at all. Several large AI providers plausibly carry on business in Australia. Whether a particular one does is a question about that provider, not a question we can answer generically, and asserting it either way would be guessing.
What does not change: your own obligations for the information you hold and the use you make of it.
Sources: Privacy Act 1988 (Cth), ss 5B(1A), 5B(3)(b) and 16C, and APP 8.1 and 8.2 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.60 to 8.63 · OAIC APP guidelines
What about using AI to screen or rank tenants?
That is a different question, and a dated one. The automated decision-making transparency rule inserting APP 1.7 to 1.9 commences on 10 December 2026 and applies to decisions made from that date. It is not yet in force, and it binds APP entities: a small business operator with no other trigger is outside it under s 6C(1), whatever AI it uses.
When it commences, it will reach computer programs that make a decision, or do something substantially and directly related to making one, where the decision could reasonably be expected to significantly affect a person's rights or interests. A human making the final call does not take a part-automated process out of it, and APP 1.9(c) counts a beneficial effect as well as an adverse one. The obligation is disclosure in your privacy policy, and s 13K is headed "Civil penalty provision for which infringement notices or compliance notices can be issued", capped at 200 penalty units (s 13K(4)). So the work is knowing what your software actually does before then.
Sources: Privacy and Other Legislation Amendment Act 2024 (Cth), Act No. 128 of 2024, inserting APP 1.7 to 1.9, commencing 10 December 2026 · OAIC APP guidelines · See also automated decision-making and privacy for real estate
→ The Kit includes staff-use rules covering what may and may not be pasted into an AI tool.