An AI voice agent that handles inbound business calls is processing personal information from every caller — names, contact details, what they want, sometimes sensitive information. The Privacy Act 1988 governs how you handle that. Here's the plain-English version for the operator who needs to get it right, not become a privacy lawyer.

Who the Act applies to

If your business has annual turnover above $3 million, or you handle health information of any kind, or you provide certain services to government, the Privacy Act applies. For most AU SMBs that are serious about voice agents, it applies.

Even if it doesn't strictly apply to your business size, following the Australian Privacy Principles (APPs) is the right baseline — and most of your enterprise customers will require it of you.

Five things every voice agent must do

1. Notify callers about recording

Every Australian state requires participants in a recorded conversation to be informed. Your voice agent's opening line must include this — built in by default in any agent we ship. Typical phrasing: "Hi, you're speaking with [Business]'s AI receptionist. Calls may be recorded for quality and training purposes."

2. Collect only what's needed

APP 3 — collect the minimum personal information required for the purpose. Don't have your agent ask for everything ("can I have your name, email, phone, address, date of birth, Medicare number..."). Train it to ask for what the specific scenario requires.

3. Use enterprise model tiers

The biggest mistake we see: businesses pasting customer-call transcripts into consumer ChatGPT. That's almost certainly a disclosure under APP 6 you didn't authorise. Always use enterprise tiers — OpenAI Enterprise, Anthropic, Google Vertex, ElevenLabs Business — which contractually do not train on your data.

4. Store call data in Australia (or document the cross-border flow)

APP 8 governs cross-border disclosure. For voice agents specifically:

  • Telephony (Twilio) — has AU regions, use them.
  • Speech-to-text (Deepgram, OpenAI Whisper) — AU residency available.
  • LLM (Claude, GPT, Gemini) — enterprise tiers offer regional processing.
  • TTS (ElevenLabs) — currently US-hosted. For sensitive workloads, self-hosted alternatives exist.

If your data crosses borders, document the flow and the safeguards in your privacy notice.

5. Define your retention policy

Call transcripts and recordings are personal information when they include identifiable details. APP 11 requires reasonable retention — usually 30–90 days for routine business calls, longer for regulated industries with specific requirements.

The Notifiable Data Breaches scheme

If a breach happens that's likely to result in serious harm, you must notify the OAIC and affected individuals — usually within 30 days. Make sure your voice agent vendor contractually commits to notifying you about breaches affecting your data fast enough that you can meet your own timeline.

Industry-specific considerations

Healthcare

Health information is sensitive information under the Privacy Act. Extra obligations apply. For health-adjacent voice agents (clinic intake, GP triage, after-hours emergency triage), we strongly recommend on-prem deployment so no health data leaves your network.

Legal

The Australian Solicitors Conduct Rules add a confidentiality layer on top of the Privacy Act. Client information disclosed to a voice agent counts as disclosed to a third party unless the agent is contractually bound to confidentiality and uses enterprise model tiers.

Financial services

Add ASIC obligations to APP. Any voice agent giving financial advice (which usually means: any voice agent for a financial services firm) needs careful scoping to avoid crossing into licensed advice territory.

What 2026 reforms add

The second tranche of Privacy Act reforms is progressing in 2026. Key items affecting voice agents:

  • Automated decision-making disclosure — required when a decision substantially affecting an individual is made by automation. Voice agent answering and routing usually isn't a "decision" in this sense, but auto-rejecting an application would be.
  • Statutory tort — new cause of action for serious privacy invasions. Increases the cost of getting it wrong.
  • Stricter consent — particularly for sensitive uses. Plan for opt-in becoming the norm.

A six-step compliance checklist

  1. Update your privacy notice to mention AI voice agent use, in plain English.
  2. Confirm caller-recording notification is in the agent's opening line.
  3. Confirm enterprise AI model tiers (not consumer) for every component.
  4. Document the data flow — what data goes where.
  5. Set a retention policy and configure the agent to enforce it.
  6. Define your breach-response process — including how you'll know.

Key takeaways

  • The Privacy Act applies to most serious AU businesses running voice agents.
  • Caller-recording notification belongs in the agent's opening line — non-negotiable.
  • Enterprise AI tiers only. Never consumer ChatGPT for customer data.
  • For health, legal, financial — consider on-prem deployment.
  • Document your data flow. It's required for NDB readiness regardless.

Want a voice agent like this for your business?

30-minute discovery. We'll spec your build and send a demo within one business day.

Request a demo