AI Framework

Privacy and Confidentiality: What AI Changes

Privacy and confidentiality are legally different things. Privacy is a statutory obligation under the Privacy Act 1988, covering personal information about identifiable individuals. Confidentiality is usually contractual or an equitable duty, covering information someone promised to protect - trade secrets, client files, NDAs. A business can breach one without breaching the other, and AI tools can trigger either.

Most people use "privacy" and "confidentiality" interchangeably. Legally, they're not the same thing at all - and the difference matters more, not less, once AI tools enter the picture.

AI Framework's legislative register maps the statutory side of this - the Privacy Act and other Commonwealth and state instruments - against a business's actual profile. Confidentiality obligations sit outside any register, in contracts and case law, which is exactly why the two get confused.

The actual distinction

Privacy vs confidentiality - the actual difference

Privacy in Australia sits in the Privacy Act 1988 and the Australian Privacy Principles, enforced by the OAIC, applying to businesses over $3 million turnover (with some exceptions regardless of size). It governs one specific thing: personal information about an identifiable person.

Confidentiality covers different ground and comes from different places. Most commonly it's contractual - an NDA, a confidentiality clause in an employment contract, a supplier agreement. Separately, Australian law recognises an equitable duty of confidence that exists independently of any contract. And in specific relationships, confidentiality is a professional obligation - legal privilege, doctor-patient confidentiality, banker-customer confidentiality - layered on top of or instead of a contract.

Where privacy and confidentiality overlap - and where they don't

A business can breach confidentiality without touching privacy law, and breach privacy law without any confidentiality obligation being in play. Leak a pricing strategy or source code and there's no Privacy Act issue at all - none of that is personal information. Mishandle a customer's contact details that were never subject to any NDA or duty of confidence, and there's a privacy problem with no confidentiality obligation involved.

The two only combine when the same fact pattern hits both.

Privacy and AI - the well-covered side

The OAIC has covered this conversation since October 2024, with two guidance documents on using and building AI on personal information. The short version: entering personal information - especially sensitive information - into a public generative AI tool carries real privacy risk, and the OAIC recommends against it as a matter of best practice. The full picture of what applies to your business covers this in depth.

Confidentiality and AI - the gap almost nobody covers

Here's the part almost nothing written for a general business audience covers: putting information into a public AI tool can itself be the disclosure that breaches a confidentiality obligation - a completely separate question from whether any privacy law is engaged.

Queensland Courts' guidance to judicial officers puts it plainly: anything entered into a public AI chatbot should be treated as "published to all the world." In December 2024, three legal regulators - the Law Society of NSW, the Legal Practice Board of WA and Victoria's Legal Services Board - jointly warned that lawyers cannot safely enter confidential, sensitive or privileged client information into public AI tools. The privacy and confidentiality risk isn't limited to legal practice.

One detail worth knowing: not all AI tools handle input the same way. A consumer-tier tool whose terms allow retention or training on what users type sits in a different position from an enterprise-tier tool with a no-training, no-retention contract term. Whether that distinction matters for a given confidentiality obligation is a live, evolving question in Australian law, not settled doctrine.

Two questions the distinction creates

The distinction creates two separate questions for any business using AI tools - and clearing one doesn't clear the other:

  1. Is the information personal information, and does privacy law apply to how it's being handled?
  2. Is there a promise - by contract, by an equitable duty, or by professional obligation - to keep it confidential, and does putting it into this tool count as disclosing it to a third party under that promise?

Privacy compliance is one half of this. See what actually applies to your specific business - the Privacy Act, plus other Commonwealth and state instruments - so the privacy question has a real answer before you get to the confidentiality one.

How often privacy and confidentiality breaches are actually happening

A 2026 PagerDuty survey of 1,250 office professionals at large companies across the US, UK, Australia and Japan found 88% had shared work-related information with public AI tools. Of those surveyed, 34% had input customer data, 31% had shared financial information or confidential documents, and 43% had shared emails and correspondence. Two-thirds (66%) had used AI tools at work that weren't approved by their employer.

FAQ

What's the difference between privacy and confidentiality? Privacy is a statutory obligation under the Privacy Act 1988, covering personal information. Confidentiality is usually contractual or an equitable duty, covering information someone promised to protect - the two are legally distinct and can apply separately or together.

Is private information the same as confidential information? No. Private information (personal information about someone) is defined by the Privacy Act regardless of how it was shared. Confidential information generally loses its confidential status once disclosed, regardless of whether it's personal information at all.

Does the Privacy Act cover trade secrets or business confidential information? No - the Privacy Act only covers personal information about an identifiable individual. Trade secrets, pricing strategies and source code are protected by confidentiality obligations, not privacy law.

Is it a breach of confidentiality to paste information into ChatGPT? It can be - pasting confidential information into a public AI tool can itself count as disclosure to a third party, separate from any privacy law question. Whether it's a breach depends on the specific confidentiality obligation and what the AI tool's own terms say about retaining or training on your input.

Does a confidentiality obligation require proof of harm? Not necessarily - Australian case law has held the test is whether unfair advantage was taken of the information, not whether harm resulted. The unauthorised disclosure itself is generally what matters.

For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.

This page covers the privacy and confidentiality distinction, not a compliance answer. If your business handles personal information and uses AI, address it today with AI Framework.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights