Free tool

AI privacy impact assessment template

A guided privacy impact assessment for a proposed generative AI use. Describe the project, map the information flows, answer questions on the Australian Privacy Principles and get a structured draft PIA report with risks and recommendations.

Runs in your browser. Nothing you enter is sent to AusGPT.

Describe your proposed AI use

Work through the sections in order, then generate a draft report. Fields marked * are required; leave anything you don't know yet blank or answer "Unsure". Your answers are saved in this browser so you can come back to them.

1. Project and threshold assessment

For example "AI meeting summaries for case notes".

For example your privacy officer or the project's senior owner.

The product name and the company that provides it.

Describe the tasks, who does them and how the AI fits in. For example "Support coordinators upload session notes and the AI drafts a progress summary, which the coordinator checks and edits before saving it to the client file."

Roles and roughly how many people.

Who is this PIA for?
Threshold question: will any personal information be collected, stored, used or disclosed in this project? *

This is the OAIC's first threshold question. Count prompts, uploaded files, recordings and AI outputs, not just your databases.

2. Information flows

Map what personal information goes into the AI tool, what comes out, where it is held and who can see it.

Kinds of personal information involved
Whose information is it?
What will be put into the AI tool?

For example collected from clients at intake, existing records or recordings of meetings.

Regions or countries for processing (inference) and storage, and any subcontractors. Answer the APP 8 questions below too.

Your staff roles, the provider's staff and any subcontractors.

3. APP-by-APP questions

Questions on the Australian Privacy Principles that matter most for generative AI, based on the OAIC's guidance on commercially available AI products.

APP 1: Open and transparent management of personal information

Does your privacy policy explain how you use AI with personal information?
Is there an accountable owner for this AI use, and does your AI policy cover it?

For example permitted uses, information staff must not enter, and when a person must check outputs.

Will the AI make, or do something substantially and directly related to making, decisions that could reasonably be expected to significantly affect individuals' rights or interests?

From 10 December 2026, APP 1.7 to 1.9 require privacy policies to describe these uses.

APP 3: Collection of solicited personal information

Is all the personal information that goes into the AI tool reasonably necessary for this purpose?
Will the AI generate or infer new personal information about people?

For example summaries, assessments, predictions or transcripts. The OAIC treats generated or inferred personal information as a collection.

If sensitive information is involved, will you have consent or another lawful basis to collect it?

Consent can't be implied just because a person was told about the collection.

Will the information be collected lawfully and fairly, and from the person themselves where that is reasonable and practicable?

Covert collection, such as recording people without telling them, is usually unfair.

APP 5: Notification of the collection of personal information

Will people be told, at or before collection, how their information will be used with AI, including any disclosure to the AI provider?
If people interact with the AI directly (for example a chatbot), will they be told it is AI and not a person?

APP 6: Use or disclosure of personal information

Is using the information with this AI tool within the primary purpose it was collected for?

The OAIC says primary purposes should be read narrowly.

If it is a secondary purpose, what permits it?

Generally consent, or that the person would reasonably expect it and it is related (directly related for sensitive information) to the primary purpose.

Can the AI provider access or use the information for its own purposes, such as training or improving its models?

APP 8: Cross-border disclosure of personal information

Where will the provider process and store the information, including through subcontractors?
If information may go overseas, have you taken reasonable steps (usually contract terms) to make sure the recipient doesn't breach the APPs?

An organisation that discloses personal information overseas is generally accountable for how the recipient handles it.

APP 10: Quality of personal information

Will a person check AI output for accuracy before it is relied on or saved to records?

Generative AI can produce inaccurate or false results.

Will AI-generated content be identifiable in your records?

For example a note that a summary was AI-generated and which system produced it.

APP 11: Security of personal information

Have you assessed the provider's security, including past incidents and who at the provider can access your data?
Are access controls in place, such as business accounts, strong sign-in, role-based access and removing access when people leave?
Will prompts, uploaded files and outputs be destroyed or de-identified once they are no longer needed?

For example retention settings agreed with the provider and applied in your own systems.

Does your data breach response plan cover this AI provider?

APP 12 and 13: Access to, and correction of, personal information

If someone asks for their personal information, could you find and provide what is held in the AI tool (chat histories, uploads and outputs)?
Can you correct inaccurate AI-generated personal information in your records, and stop it being reused?

4. Consultation, other risks and review

For example your privacy officer, IT security, frontline staff, clients or their representatives.

One per line. They are added to the risk table.

And why you think the benefits justify them, if they do.

General information only, not legal advice. Review the output with your own advisers before you rely on it.

This free AI privacy impact assessment template guides you through a PIA for a proposed generative AI use, such as AI meeting summaries, document drafting or a customer chatbot. Describe the project, map how personal information flows into and out of the AI tool, and answer questions on the Australian Privacy Principles that matter most for AI. The tool then produces a structured draft PIA report, with identified risks, recommendations and space for your responses, that you can copy or download as Word or Markdown.

What a privacy impact assessment is, and when you need one

The OAIC describes a privacy impact assessment as a systematic assessment of a project that identifies its impact on individuals' privacy and recommends ways to manage, minimise or eliminate that impact. For AI, its guidance on commercially available AI products recommends a PIA as part of a privacy-by-design approach, ideally while you are still choosing a product.

Whether you must do one depends on who you are:

  • Australian Government agencies must conduct a PIA for all high privacy risk projects under the Privacy (Australian Government Agencies — Governance) APP Code 2017.
  • Private sector organisations aren't required to by the Privacy Act, but the OAIC encourages PIAs for any project that handles personal information, and encourages publishing the findings.
  • Small businesses with an annual turnover of $3 million or less are mostly not covered by the Privacy Act, but some are regardless of turnover, including health service providers and businesses that trade in personal information. A PIA is still a sensible way to manage risk.

How this AI privacy impact assessment template follows the OAIC's 10 steps

The OAIC's Guide to undertaking privacy impact assessments sets out 10 steps. This generative AI PIA template covers them like this:

OAIC step Where it happens in this tool
1. Threshold assessment The threshold question in section 1
2. Plan the PIA Document control: who prepares and who approves it
3. Describe the project Section 1
4. Identify and consult with stakeholders Section 4, where you record who you consulted
5. Map information flows Section 2
6. Privacy impact analysis and compliance check Section 3, APP by APP
7. Privacy management: addressing risks The risk table generated from your answers
8. Recommendations A recommendation for every risk identified
9. Report The draft report, structured with an executive summary, methodology, project description, analysis and conclusions
10. Respond and review A response column, a review date and sign-off

The APPs that matter most for generative AI

APP What the questions check
APP 1: open and transparent management Your privacy policy explains your AI use, and someone owns it. From 10 December 2026, APP 1.7 to 1.9 require privacy policies to describe the use of personal information in computer programs that make, or do something substantially and directly related to making, decisions that could significantly affect individuals' rights or interests.
APP 3: collection Only necessary information goes in. The OAIC treats personal information that AI generates or infers as a collection, and sensitive information generally needs consent.
APP 5: notification Collection notices cover AI purposes and any disclosure to the AI provider, and people know when they are dealing with AI rather than a person.
APP 6: use and disclosure The use fits the primary purpose of collection, read narrowly, or has consent or a reasonable expectation behind it. If you can't clearly show people would expect a secondary AI use, such as training an AI system, the OAIC says to seek consent or offer a meaningful opt-out.
APP 8: cross-border disclosure Where the provider processes and stores information, and what reasonable steps you've taken if it goes overseas.
APP 10: quality AI can produce inaccurate or false results, so a person verifies outputs before they are relied on.
APP 11: security The provider's security, access controls, retention and deletion, and whether your data breach response plan covers the provider.
APP 12 and 13: access and correction You can find personal information in chat histories, uploads and outputs if someone asks for it, and correct it if it's wrong.

The template doesn't cover APP 2 (anonymity), APP 4 (unsolicited information), APP 7 (direct marketing) or APP 9 (government related identifiers). The report says so, so reviewers know to consider them where relevant.

Tips for a PIA that holds up

  • Answer from evidence. Base answers on the provider's contract, terms and settings, not its marketing. "Unsure" is a legitimate answer: it shows up as a risk to resolve.
  • Check processing and storage locations separately. An AI service can store data in one country and process requests in another. If you are assessing AusGPT, our security page sets out where data is stored and processed.
  • Map the real workflow. Include uploaded files, recordings, chat histories and AI outputs saved to your records, not just the database the information came from.
  • Respond to every recommendation. The OAIC's final step is to record which recommendations you will implement and which you won't, with reasons, and to revisit the PIA when the project changes.

Add the AI use to your AI register with a link to the finished PIA, and use the AI readiness assessment to check your wider AI governance.

Frequently asked questions

Is a privacy impact assessment mandatory for using AI in Australia?
For Australian Government agencies, the Privacy (Australian Government Agencies — Governance) APP Code 2017 requires a PIA for all high privacy risk projects. The Privacy Act doesn't require private sector organisations to do PIAs, but the OAIC encourages them for projects that handle personal information and recommends one as part of a privacy-by-design approach to AI products.
What is a threshold assessment?
It is the first step in the OAIC's process: a quick check of whether a project involves personal information and needs a full PIA. The first question is whether any personal information will be collected, stored, used or disclosed. If the answer is no, keep a record of that decision and revisit it if the project changes.
Is entering personal information into a generative AI tool a use or a disclosure?
It depends on control. The OAIC says it may be a use if the information stays within your organisation's effective control, or a disclosure if it leaves your control. APP 6 applies either way, so the information should only be used or disclosed for the purpose it was collected for unless an exception, such as consent, applies.
Does APP 8 apply if my AI provider processes data overseas?
If you disclose personal information to an overseas recipient, APP 8 requires you to take reasonable steps to ensure the recipient doesn't breach the APPs, and you are generally accountable for its handling. The OAIC's APP guidelines say that giving information to a cloud provider for the limited purpose of storing it, under a contract that keeps you in effective control, may be a use rather than a disclosure. Check where processing and storage both happen.
How often should we review an AI PIA?
The OAIC describes a PIA as an ongoing process. Revisit it when the project changes, for example a new AI product, new data or a new use, and do a new PIA if substantial changes create significant new privacy impacts.
Is anything I enter sent to AusGPT?
No. The questionnaire and report run entirely in your browser. Answers are saved only in this browser so you can return to them, and Start again clears them.

Secure AI for your team, processed in Australia

Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.