APP 8 and AI — how cross-border disclosure rules apply to chatbots
APP 8 was written long before anyone was pasting client files into chatbots. It applies to them anyway, and section 16C is the part that bites.
Published 26 July 2026
Australian Privacy Principle 8 deals with cross-border disclosure of personal information. It predates modern AI services by many years and does not mention them. It applies to them regardless, because it is drafted around the act of disclosing personal information to an overseas recipient rather than around any particular technology.
If your staff use overseas AI services with personal information, APP 8 is the provision that governs it.
What APP 8 requires
APP 8.1 sets the basic obligation: before an APP entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information.
Note the structure. The obligation attaches before the disclosure. It is a due diligence requirement, not a remedy you can apply afterwards.
APP 8.2 provides exceptions — including where you reasonably believe the recipient is subject to a substantially similar law or binding scheme that the individual can enforce, or where the individual has been expressly informed and consents. These exceptions are narrower in practice than they look, and the consent exception in particular requires the individual to be properly informed before consenting, which is difficult to achieve for an ad hoc disclosure a staff member makes on the spot.
Section 16C is the part that catches people
APP 8 tells you what to do beforehand. Section 16C of the Privacy Act tells you what happens afterwards.
Where an APP entity discloses personal information to an overseas recipient, and the recipient does something that would have breached the APPs had they applied, that act is generally taken to be a breach by the disclosing entity.
Read that again, because it is the whole ballgame. Accountability does not transfer with the data. You remain answerable for what an overseas recipient does with information you gave them.
Applied to AI services, this means:
- You are accountable for the handling of client information you disclosed.
- You are accountable even though you have no visibility of the handling.
- You are accountable even if a staff member made the disclosure without approval.
- The provider’s terms of service are your evidence of “reasonable steps” — and if you have never read them for the tier your staff actually use, you do not have that evidence.
“Disclosure” versus “use”
There is a technical distinction worth understanding, because it is sometimes raised as a defence.
Broadly, “use” is handling information within your organisation. “Disclosure” is releasing it outside your effective control. Some argue that sending data to a processor acting purely on your instructions is a use rather than a disclosure, particularly where a contract binds the processor tightly.
This argument is strongest where you have a proper written agreement with defined purposes and enforceable restrictions — for example, an enterprise AI arrangement negotiated by your organisation.
It is weakest, close to hopeless, where an employee pastes client data into a consumer chat product under standard terms they have never read, on a personal account, from a personal device. There is no agreement, no defined purpose, and no control. Calling that a “use” does not survive contact with an OAIC assessment.
What “reasonable steps” would actually look like
If you intend to rely on APP 8.1 compliance, the steps generally expected scale with the sensitivity of the information and the risk involved. In practice that means something like:
- Identify the specific service and tier. Not “ChatGPT” — the precise product, plan, and account type your staff use.
- Read the terms that apply to that tier. Free, paid consumer, business and API terms differ materially.
- Establish the processing locations. Where you cannot establish this, that itself is a finding worth recording.
- Assess whether the recipient’s obligations are substantially similar to the APPs. For most US-based consumer services, they are not.
- Put a contract in place where the risk warrants it. Consumer terms are not negotiated and offer you nothing bespoke.
- Record the assessment. An undocumented assessment is very hard to rely on later.
- Control which tier is actually used, and be realistic about whether you can.
Step 7 is where most firms fail, and it is not a paperwork failure. You can complete steps 1 to 6 immaculately for your enterprise tenancy and still have half the firm using free accounts on their phones. The assessment describes a system that does not match reality.
Why the sensitivity level matters
The APPs treat sensitive information — health information, biometric data, information about race, religion, sexual orientation, criminal record, union membership — as requiring higher protection.
For a medical practice, essentially every disclosure involves sensitive information, which raises the standard of “reasonable steps” accordingly. For a law firm handling criminal or family matters, much of the material is sensitive too. This is why a generic AI policy copied from a template rarely holds up: the standard is not uniform across sectors.
The penalty environment has changed
Australian privacy enforcement is materially more serious than it was a few years ago. Maximum civil penalties for serious or repeated interference with privacy were increased substantially in 2022, and later reforms introduced a statutory tort for serious invasions of privacy — meaning affected individuals may have a direct avenue in addition to regulatory action.
The practical shift is that a privacy failure is no longer only a regulatory matter. It can be a litigation matter brought by the people whose information you held.
The structural way out
Every obligation described above is triggered by one event: personal information being disclosed to an overseas recipient.
Remove that event and the analysis stops. If the AI runs on hardware physically located in your office, on your network, there is no overseas recipient, no cross-border disclosure, and no section 16C accountability, because nothing has been disclosed to anyone. There is no provider whose terms you need to assess, and no processing location you need to establish, because the processing location is your building.
This is not a claim that on-premise AI makes you compliant with the Privacy Act generally. APP 11 still requires you to secure the system. Your other obligations are untouched. What it does is eliminate one specific and otherwise very difficult category of risk — the one that is hardest to control precisely because it depends on individual behaviour rather than organisational policy.
Whether that is worth doing depends on how much confidential material your team handles and what a disclosure would cost you. For some firms it plainly is not worth it. For others it is the only approach that actually holds.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.