Free tool
AI privacy impact assessment template
A guided privacy impact assessment for a proposed generative AI use. Describe the project, map the information flows, answer questions on the Australian Privacy Principles and get a structured draft PIA report with risks and recommendations.
Runs in your browser. Nothing you enter is sent to AusGPT.
Your draft PIA report
Generated with the free AusGPT tool at https://ausgpt.com.au/tools/ai-privacy-impact-assessment. Review and adapt before use.
General information only, not legal advice. Review the output with your own advisers before you rely on it.
This free AI privacy impact assessment template guides you through a PIA for a proposed generative AI use, such as AI meeting summaries, document drafting or a customer chatbot. Describe the project, map how personal information flows into and out of the AI tool, and answer questions on the Australian Privacy Principles that matter most for AI. The tool then produces a structured draft PIA report, with identified risks, recommendations and space for your responses, that you can copy or download as Word or Markdown.
What a privacy impact assessment is, and when you need one
The OAIC describes a privacy impact assessment as a systematic assessment of a project that identifies its impact on individuals' privacy and recommends ways to manage, minimise or eliminate that impact. For AI, its guidance on commercially available AI products recommends a PIA as part of a privacy-by-design approach, ideally while you are still choosing a product.
Whether you must do one depends on who you are:
- Australian Government agencies must conduct a PIA for all high privacy risk projects under the Privacy (Australian Government Agencies — Governance) APP Code 2017.
- Private sector organisations aren't required to by the Privacy Act, but the OAIC encourages PIAs for any project that handles personal information, and encourages publishing the findings.
- Small businesses with an annual turnover of $3 million or less are mostly not covered by the Privacy Act, but some are regardless of turnover, including health service providers and businesses that trade in personal information. A PIA is still a sensible way to manage risk.
How this AI privacy impact assessment template follows the OAIC's 10 steps
The OAIC's Guide to undertaking privacy impact assessments sets out 10 steps. This generative AI PIA template covers them like this:
| OAIC step | Where it happens in this tool |
|---|---|
| 1. Threshold assessment | The threshold question in section 1 |
| 2. Plan the PIA | Document control: who prepares and who approves it |
| 3. Describe the project | Section 1 |
| 4. Identify and consult with stakeholders | Section 4, where you record who you consulted |
| 5. Map information flows | Section 2 |
| 6. Privacy impact analysis and compliance check | Section 3, APP by APP |
| 7. Privacy management: addressing risks | The risk table generated from your answers |
| 8. Recommendations | A recommendation for every risk identified |
| 9. Report | The draft report, structured with an executive summary, methodology, project description, analysis and conclusions |
| 10. Respond and review | A response column, a review date and sign-off |
The APPs that matter most for generative AI
| APP | What the questions check |
|---|---|
| APP 1: open and transparent management | Your privacy policy explains your AI use, and someone owns it. From 10 December 2026, APP 1.7 to 1.9 require privacy policies to describe the use of personal information in computer programs that make, or do something substantially and directly related to making, decisions that could significantly affect individuals' rights or interests. |
| APP 3: collection | Only necessary information goes in. The OAIC treats personal information that AI generates or infers as a collection, and sensitive information generally needs consent. |
| APP 5: notification | Collection notices cover AI purposes and any disclosure to the AI provider, and people know when they are dealing with AI rather than a person. |
| APP 6: use and disclosure | The use fits the primary purpose of collection, read narrowly, or has consent or a reasonable expectation behind it. If you can't clearly show people would expect a secondary AI use, such as training an AI system, the OAIC says to seek consent or offer a meaningful opt-out. |
| APP 8: cross-border disclosure | Where the provider processes and stores information, and what reasonable steps you've taken if it goes overseas. |
| APP 10: quality | AI can produce inaccurate or false results, so a person verifies outputs before they are relied on. |
| APP 11: security | The provider's security, access controls, retention and deletion, and whether your data breach response plan covers the provider. |
| APP 12 and 13: access and correction | You can find personal information in chat histories, uploads and outputs if someone asks for it, and correct it if it's wrong. |
The template doesn't cover APP 2 (anonymity), APP 4 (unsolicited information), APP 7 (direct marketing) or APP 9 (government related identifiers). The report says so, so reviewers know to consider them where relevant.
Tips for a PIA that holds up
- Answer from evidence. Base answers on the provider's contract, terms and settings, not its marketing. "Unsure" is a legitimate answer: it shows up as a risk to resolve.
- Check processing and storage locations separately. An AI service can store data in one country and process requests in another. If you are assessing AusGPT, our security page sets out where data is stored and processed.
- Map the real workflow. Include uploaded files, recordings, chat histories and AI outputs saved to your records, not just the database the information came from.
- Respond to every recommendation. The OAIC's final step is to record which recommendations you will implement and which you won't, with reasons, and to revisit the PIA when the project changes.
Add the AI use to your AI register with a link to the finished PIA, and use the AI readiness assessment to check your wider AI governance.
Sources
- OAIC: Guide to undertaking privacy impact assessments
- OAIC: Guidance on privacy and the use of commercially available AI products
- OAIC: Australian Privacy Principles quick reference
- OAIC: APP guidelines, Chapter 8 (cross-border disclosure of personal information)
- OAIC: New resources on transparency for use of AI and automated decision-making (30 September 2026)
- OAIC: Small business and the Privacy Act
- OAIC: About the Notifiable Data Breaches scheme
Frequently asked questions
- Is a privacy impact assessment mandatory for using AI in Australia?
- For Australian Government agencies, the Privacy (Australian Government Agencies — Governance) APP Code 2017 requires a PIA for all high privacy risk projects. The Privacy Act doesn't require private sector organisations to do PIAs, but the OAIC encourages them for projects that handle personal information and recommends one as part of a privacy-by-design approach to AI products.
- What is a threshold assessment?
- It is the first step in the OAIC's process: a quick check of whether a project involves personal information and needs a full PIA. The first question is whether any personal information will be collected, stored, used or disclosed. If the answer is no, keep a record of that decision and revisit it if the project changes.
- Is entering personal information into a generative AI tool a use or a disclosure?
- It depends on control. The OAIC says it may be a use if the information stays within your organisation's effective control, or a disclosure if it leaves your control. APP 6 applies either way, so the information should only be used or disclosed for the purpose it was collected for unless an exception, such as consent, applies.
- Does APP 8 apply if my AI provider processes data overseas?
- If you disclose personal information to an overseas recipient, APP 8 requires you to take reasonable steps to ensure the recipient doesn't breach the APPs, and you are generally accountable for its handling. The OAIC's APP guidelines say that giving information to a cloud provider for the limited purpose of storing it, under a contract that keeps you in effective control, may be a use rather than a disclosure. Check where processing and storage both happen.
- How often should we review an AI PIA?
- The OAIC describes a PIA as an ongoing process. Revisit it when the project changes, for example a new AI product, new data or a new use, and do a new PIA if substantial changes create significant new privacy impacts.
- Is anything I enter sent to AusGPT?
- No. The questionnaire and report run entirely in your browser. Answers are saved only in this browser so you can return to them, and Start again clears them.
Keep reading
Secure AI for your team, processed in Australia
Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.