AI Chatbots for Small Business: When They Help and When They Wreck Trust

Your AI Marketing Tools May Already Break Australia's Privacy Law
Picture this: you added a chatbot to your website last year, set up lead scoring in your CRM, and connected your email platform to send automated follow-up sequences based on how contacts behave. Good marketing. Sensible use of the tools available. The problem is that from 10 December 2026, these are exactly the kinds of systems that will trigger a new transparency obligation under Australia's privacy law, and most small business owners running AI marketing stacks have no idea this is coming.
This article is general information only, not legal advice. Your obligations will depend on your specific circumstances, and the OAIC is the right starting point for verifying where your business stands.
The Privacy Rule That Snuck Into Your AI Marketing Operations
The Privacy and Other Legislation Amendment Act 2024 passed Parliament in December of that year and introduced an automated decision-making (ADM) transparency obligation. The Office of the Australian Information Commissioner has since confirmed the detail: from 10 December 2026, any APP entity that uses personal information in automated decision-making with the potential to affect the rights or interests of individuals must disclose this in their privacy policy. Specifically, they must describe the kinds of personal information involved and the kinds of decisions being made.
That sounds like something for banks and government agencies. Read it again. Lead scoring assigns contacts a ranking based on their behaviour. Email automation decides who gets which message, and when. A chatbot collects names, contact details, business information, and enquiry history, then generates a response that shapes the customer's experience. These are algorithmic decisions affecting identifiable individuals. The OAIC has said as much in its guidance on commercially available AI products, noting that "the use of AI in relation to decisions that may have a legal or similarly significant effect on an individual's rights is likely a high privacy risk activity."
The exact boundary of what counts as "affecting rights or interests" is still being worked through. The OAIC ran a public consultation on guidance for transparency in automated decision-making that closed in June 2026, so finalised guidance may not yet be published. That is not a reason to wait. The statutory obligation kicks in at December regardless.
The Small Business Exemption: Still There, But Shrinking
Here is where most small business owners switch off. "We're under $3 million turnover, the Privacy Act doesn't apply to us."
That exemption still exists in its current form, but it is being eroded in several directions. The anticipated second tranche of reforms is expected to narrow or remove it, though that legislation had not passed as of mid-2026. More immediately, the AML/CTF reforms coming into effect on 1 July 2026 bring new categories of businesses under the Privacy Act regardless of turnover, including real estate agents, accountants, lawyers and conveyancers. If your business falls into one of those categories, the ADM obligation already applies to you.
Even if you sit outside those categories, the direction of travel is clear. The OAIC has stated publicly that it views the small business exemption as increasingly out of step with modern privacy risks. Businesses that handle large volumes of personal information, use third-party AI tools that process customer data, or operate customer-facing chatbots are doing so as regulatory expectations shift steadily against them. Sorting your privacy policy now costs almost nothing. Waiting until the exemption narrows to act costs considerably more.
What to Actually Do Before December
The practical response is not complicated, but it does require a clear-eyed look at your marketing stack. Start by listing every tool in your marketing operations that makes an automated decision touching personal data: your email platform, your CRM's lead scoring logic, your website chatbot, your retargeting rules. Then ask: does my privacy policy mention any of this?
If your policy is a generic template downloaded three years ago, the answer is almost certainly no. The fix is to update it to describe, in plain language, that you use automated systems to personalise communications, score contacts, or respond to enquiries, and what information those systems draw on. The OAIC's guidance on privacy and commercially available AI products is the right reference for understanding what good disclosure looks like.
The other thing worth doing is reading the vendor terms for each tool you use. When you plug customer data into a third-party AI platform, your obligations under APP 6 mean you need to understand what the platform does with that data, whether it uses it to train models, and whether you have disclosed that possibility to the people whose data you are processing.
None of this requires a lawyer on day one. A careful read of the OAIC's published guidance and an honest audit of your marketing tools is the place to start. Searchline works with Australian small businesses on their digital marketing operations, and increasingly that means helping clients think through what their AI-assisted tools are actually doing with personal data, not just whether those tools perform well.
If you want to read more about digital marketing practices and compliance, visit our blog for deeper resources.
The December deadline is six months away. That is enough time to get your privacy policy right and review your stack, if you start now.




