Governance
7 min read

Before anything gets built, most business owners ask a version of the same question. If we put our customer list, our pricing, or our supplier emails into one of these systems, where does it end up?
It is the right question, and it usually gets answered badly, either with reassurance that means nothing or with technical detail that answers something else. Here is the plain version.
First, who is actually doing what
We do not build language models. Almost nobody in this country does. The models come from a small number of providers, principally Anthropic and OpenAI, and firms like ours build systems on top of them: the connections to your platforms, the rules, the checks, the interface your team actually uses.
That distinction matters because it tells you where to ask your questions. The model provider governs what happens to text sent to the model. The firm building your system governs what gets sent in the first place, what is stored, and who can see it. Those are two different sets of answers and you are entitled to both.
The consumer account and the business account are not the same product
This is the single most useful thing to understand, and it is where most of the anxiety comes from.
A staff member pasting a customer list into a free consumer chat account is governed by that product’s consumer terms. A system built on the same provider’s business platform is governed by different terms, usually with different defaults on retention and on whether inputs are used for training. They are not the same arrangement and they should not be assessed as if they were.
Terms change, so we will not restate any provider’s current position here as if it were fixed. What we will say is that any vendor should be able to tell you, in writing, which terms your system operates under, and point you to the clause. If they cannot, that is the answer to your question.
What Australian law asks of you
The obligation sits with your business, not with the technology provider. If the Privacy Act applies to you, using an AI tool does not move that responsibility somewhere else.
In October 2024 the OAIC published guidance specifically on using commercially available AI products. The practical requirements it sets out are not exotic. Do due diligence before you adopt a product rather than after. Consider whether personal information needs to be involved at all, since the guidance is explicit that a product should not be used simply because it is available. Test before deployment, particularly anything customer facing. Be transparent with people about how outputs affect them. Meet your accuracy obligations, which do not soften because a system generated the output.
Whether the Act applies to you at all is worth checking rather than assuming. The long standing exemption for businesses with turnover of three million or less has not been repealed, but it is narrowing: health service providers, businesses trading in personal information and Commonwealth contractors were always outside it, and from 1 July 2026 the expanded anti money laundering regime pulled a substantial number of professional services businesses in for their regulated data handling. Broader removal of the exemption has been signalled but not legislated. If you are near any of those edges, get advice specific to your situation rather than relying on an article.
Where the data physically sits
Australian law does not require business data to stay in Australia. It does require you to take reasonable steps before disclosing personal information overseas, and to understand where it goes.
In practice that means asking three things. Which region your workloads run in. Which sub-processors touch the data on the way. How long anything is retained, and by whom. These are answerable questions with documented answers, and a vendor who treats them as excessive is telling you something.
The controls that do most of the work
Most of the risk is removed by design rather than by contract.
Send less. The majority of business processes do not need names, addresses or payment details to work. A system that reads order quantities does not need the customer’s phone number. Deciding what never leaves your systems is more effective than any assurance about what happens to it once it does.
Keep less. Retention should be a deliberate decision with a number attached, not a default.
Log everything. Every request, every output, every action taken. Not for surveillance, but because the first serious question anyone asks after a problem is what the system did and when.
Restrict access. Same principle as any other system holding commercial data. Role based, reviewed, revoked when people leave.
Seven questions for any vendor
Which model providers does this use, and under which terms. Are our inputs used to train models, and where is that stated. Which region does this run in. Who else touches this data. What is retained, and for how long. Who at your firm can see our data, and is that logged. If we stop working with you, what happens to what you hold.
Seven answers, in writing, before anything is built. Any competent supplier will have them ready.
Working through this for your own business? We are happy to answer these about our own systems before you commit to anything. Start a conversation.
Related reading: Is your business ready for AI? and what an AI consultant actually does.
Frequently asked questions
Is it safe to put company data into ChatGPT?
It depends entirely on which account and which terms. A free consumer account and a business platform account from the same provider are governed differently, particularly on retention and on whether inputs are used for training. The practical risk in most businesses is not the technology, it is staff using personal accounts for work data without a policy. Decide what may and may not be pasted into any external tool, and write it down.
Does Australian law require business data to stay in Australia?
No. There is no general data residency requirement for Australian businesses. Under the Australian Privacy Principles you do need to take reasonable steps before personal information is disclosed overseas, and you remain accountable for how it is handled. Some sectors and some government contracts impose stricter requirements, so check your own obligations.
Does the Privacy Act apply to my small business?
The exemption for businesses with annual turnover of three million or less still exists, but it has never been absolute and it has been narrowing. Health service providers, businesses that trade in personal information and Commonwealth contractors are covered regardless of size, and the anti money laundering changes from 1 July 2026 brought many professional services firms in. Removal of the broader exemption has been flagged but not legislated. Confirm your position rather than assuming it.
Who is responsible if the system gets something wrong?
Your business, in every way that matters commercially and legally. That is why the useful designs keep a person accountable for consequential decisions and use the system to prepare, check and flag rather than to decide unsupervised.
Have a process worth improving? Let’s find the highest-value place to begin.