Privacy Act 1988

You Don't Need a Regulator's Letterhead to Have a Confidentiality Problem

Under the Privacy Act 1988, any business handling someone else's personal information is expected to keep it secure and use it only for the purpose it was given for. Pasting a client's name, ID document, or personal details into a public AI tool routes that information to a third party the client never agreed to, and that's true whether you're a law firm or a business with no regulator watching over your shoulder at all.

Law firms, accounting practices, and financial advisers get the guidance documents, the industry bodies, and the headlines. Real estate agencies, recruiters, migration agents, insurance brokers, HR teams, and a dozen other trades handle exactly the same kind of information, with none of that scaffolding telling them to be careful. The absence of a named regulator hasn't made the underlying obligation disappear. It's just made it easier to miss.

Where this shows up, in practice

  • A recruiter pastes a candidate's CV into ChatGPT to shortlist or summarise it. That CV usually carries a name, a phone number, a work history, sometimes a reference's private details, none of which the candidate agreed to send to an AI vendor.
  • A real estate agent drops a tenant's rental application, including payslips and ID, into an AI tool to draft a reference or summary. That application is exactly the kind of identity-fraud bait a bad actor wants, now sitting on a server outside the agency's control.
  • A migration agent summarises a client's visa file, passport details and all, to save time on a submission. Immigration files are among the most sensitive documents a person will ever hand over.
  • An HR team uses AI to draft a redundancy letter or investigate a workplace complaint, feeding it the names, medical notes, or personal circumstances of staff who never consented to any of it leaving the business.

None of these businesses think of themselves as "handling sensitive data." They think of themselves as doing their job faster. That's exactly the gap.

The part that isn't in a compliance document

A client, tenant, candidate, or patient doesn't read your privacy policy before deciding to trust you. They just expect that what they hand over stays with the person they handed it to. Losing that trust doesn't require a headline-grabbing breach, it only takes one person finding out their information went somewhere they never agreed to.

How Althorn closes the gap

You don't need to stop using AI. You need it to stop leaving the building.

Althorn installs private AI that runs entirely on hardware inside your own office, not a cloud subscription, not an overseas server. Your team keeps drafting, summarising, and searching at AI speed. The difference is that a candidate's CV, a tenant's application, or a client's file never becomes something sent to a third party, because it never leaves your network.

What this looks like in practice

  • The same AI-assisted speed for drafting, summarising, and searching, without a single file leaving your premises.
  • A straightforward answer if anyone asks where their information went: "it never left our office."
  • No vendor terms, sub-processors, or offshore servers to explain or defend.

The reputation case, not just the compliance case

Whatever your industry, your clients chose you over a competitor for a reason, and "we're careless with your information" has never been that reason. Being able to say, plainly, that your AI use never sends anyone's details outside your business is a quiet but real edge, especially once a client or candidate starts asking questions your competitors can't answer as cleanly.

Book a 20-minute confidentiality audit

For your business, no obligation.

Book a Consultation

Common questions

Does the Privacy Act actually apply to a small business like mine?

Businesses under $3 million annual turnover are generally exempt from the Privacy Act itself, but several categories (health service providers, businesses trading in personal information, and others) are covered regardless of size, and most client-facing trades hold themselves to the same standard anyway, since it's the client relationship at stake, not just the legislation.

What exactly counts as "sensitive data" here?

Anything that identifies a real person: names, contact details, ID documents, financial details, health information, employment history. If you'd be uncomfortable explaining to that person exactly where it went, it belongs in this category.

We already have a privacy policy on our website. Isn't that enough?

A public-facing privacy policy tells clients what you do with their data in general. It doesn't cover, or excuse, a staff member pasting their specific file into a public AI tool that policy never mentioned.