Skip to main content

AI receptionist privacy · Australia

AI receptionist privacy checklist for service businesses

An AI receptionist may handle names, phone numbers, addresses, booking details and the reason for a call. Privacy cannot be added after the script is finished. Map the information, notice, access and handoff rules before the first live conversation.
By Ajay DabhiPublished 5 August 2026Updated 5 August 2026

01 / DECISION

Pass six privacy checks before the number goes live.

  1. 01List every piece of caller information and the business reason for collecting it.
  2. 02Give the caller a short, accurate notice before collecting the details.
  3. 03Move sensitive, urgent or uncertain conversations to an approved person.
  4. 04Record every system, supplier and staff role that can receive the information.
  5. 05Set retention, correction, deletion and access rules for audio, transcripts and summaries.
  6. 06Run test calls and inspect the real records, permissions and handoffs they create.

02 / DATA MAP

What does the call flow actually collect?

Start with the fields and records, not the software features. If a detail has no clear job in the enquiry or booking process, leave it out.
Walk through a normal call from greeting to follow-up. Write down each item the caller may provide, including their name, contact details, service address, preferred time and the problem they want solved. Then add what the system creates, such as audio, a transcript, a summary, a lead record, a calendar entry or a notification.
Give every item an owner and a purpose. A phone number may be needed for a callback. A service address may be needed to check coverage. A full date of birth probably has no place in a routine quote request. The Office of the Australian Information Commissioner says an organisation covered by Australian privacy law may only collect personal information that is reasonably necessary for its work.
Do not treat a transcript as harmless because it was generated automatically. It may contain more detail than the booking team needs. Decide whether the useful record is the audio, full transcript, short summary or a few structured fields. Keeping less can make the process easier to explain and control.
  • Caller-provided details and free-form answers.
  • Audio, transcript, summary and booking records created by the system.
  • The business purpose and owner for each item.
  • The system or supplier that receives each record.
  • The point when the information is no longer needed.

03 / NOTICE

What should the caller hear before giving details?

The notice should be short enough to hear and accurate enough to be useful. It must describe the real call flow rather than a generic privacy promise.
The OAIC says organisations should take reasonable steps to tell people who is collecting their information, how and why it is being collected, the usual disclosures, where to find the privacy policy and whether overseas disclosure is likely. Put the essential points near the start of the conversation, before the receptionist asks for personal details.
Plain wording works better than a long legal script. Identify the business, say that an automated receptionist is handling the call, explain the immediate purpose and offer the privacy-policy path. If the call is recorded or transcribed, address that specifically after confirming the applicable recording and consent requirements.
Give the caller another route. Someone who does not want to continue with the automated flow should be able to leave a minimal callback request, reach a person during suitable hours or end the call without being pushed through unnecessary questions.
  • Business identity and contact path.
  • The fact that an automated receptionist is handling the call.
  • What is being collected and the immediate purpose.
  • Any recording or transcription notice required for the setup.
  • Privacy-policy location and an alternative contact path.

04 / BOUNDARIES

Which calls need a person instead?

Routine booking details suit narrow automation. Sensitive information, emergencies, complaints and uncertain requests need a clear human boundary.
Sensitive information includes health information and other protected categories. The OAIC says an organisation will usually need consent to collect sensitive information when Australian privacy law applies. A clinic, allied-health practice or support service should not let a general booking script drift into clinical intake simply because a caller keeps talking.
Write down the phrases and situations that stop the normal flow. These may include immediate danger, medical symptoms, threats, payment-card details, a privacy complaint, a request to access or correct information, or a caller who asks for a person. The receptionist should acknowledge the limit and follow the approved handoff rather than improvise advice.
A handoff is not complete when the system merely sends a notification. Name the person or roster, the hours they cover, what the caller hears while waiting and what happens if nobody accepts the transfer. Test the failure path as carefully as the successful booking path.
  • Urgent safety, medical or emergency language.
  • Sensitive information outside the approved intake.
  • Payment details or identity documents the flow does not need.
  • Complaints, access requests and correction requests.
  • Any request to speak with a person.

05 / ACCESS

Where do the call records go?

Follow one test call through every destination. The privacy risk often sits in copies, alerts and old user access rather than the phone conversation itself.
A single enquiry may appear in the receptionist platform, email, SMS, calendar, customer record and a staff notification. List each destination and what it receives. A booking calendar may need a name, service and time, but it may not need the full transcript. A text alert may only need the lead ID and a prompt to open the approved system.
Ask each supplier where the information is processed and stored, which subcontractors can access it, whether it may be disclosed overseas, how deletion works and what happens when the service ends. Record the answers. Do not replace them with a vague statement that the system is secure.
Use named accounts, practical role access and prompt offboarding. Review permissions after staff or supplier changes. If the business downloads transcripts or sends them through another channel, those copies need the same ownership and retention decision as the original record.
  • Receptionist platform, calendar, CRM, inbox and notification channels.
  • Information fields sent to each destination.
  • Staff, supplier and subcontractor access.
  • Storage location, overseas disclosure and deletion method.
  • Account owner, permission reviewer and offboarding step.

06 / TEST

How do you test privacy before launch?

Run realistic calls, inspect the resulting records and test what happens when the caller refuses, corrects, escalates or stops.
Use fictional test details that cover a normal booking, an out-of-area enquiry, a request for a person, a sensitive disclosure and a caller who refuses a question. Check what the receptionist says, what it stores, what reaches staff and whether the handoff works. Delete the test records through the same process the business would use for a real request.
Read the summary beside the audio or transcript. It should not invent facts, flatten uncertainty into a confident statement or expose more detail than the receiving person needs. Check that the team can correct a wrong detail and trace which downstream records also need updating.
Repeat the review after any prompt, integration, supplier or booking-field change. My AI receptionist versus answering service guide can help when the privacy boundary suggests a human or hybrid call path instead.
  • Normal, refused, sensitive, urgent and human-handoff test calls.
  • Notice timing and the caller's alternative path.
  • Audio, transcript, summary, booking and notification contents.
  • Correction and deletion across every destination.
  • A dated owner sign-off before live traffic is connected.

CALL PRIVACY WORKSHEET

Complete the record before approving the call flow.

Use the real setup. A blank field is a reason to pause, not permission to assume the supplier or staff member has handled it.

01

Collection purpose

The exact caller detail, why it is needed and who owns the decision.

WHY / OWNER
02

Caller notice

What the caller hears before collection and where the full privacy information lives.

WORDS / TIMING
03

Human boundary

The calls that must leave automation and the person responsible for receiving them.

TRIGGER / ROSTER
04

Record destinations

Every platform, alert and calendar that receives a copy, with the fields each one needs.

SYSTEM / FIELD
05

Retention and requests

How records are retained, corrected, accessed and deleted across all destinations.

PERIOD / PROCESS
06

Test evidence

The completed scenarios, issues found, fixes made and person who approved launch.

DATE / OWNER

This worksheet is not legal advice. Privacy Act coverage, call-recording rules and sector obligations depend on the business, information and circumstances. Confirm the legal position for the final call flow when it is unclear.

SOURCES

What this guide relies on

Official sources establish the platform or Australian compliance facts. The operating method is my practical interpretation, not a promise of a particular result.

OAIC: collection of personal information

Explains reasonably necessary collection, sensitive-information consent and the matters organisations should tell people near the time of collection. Accessed 5 August 2026.

QUESTIONS

Questions worth answering before you start.

What should an AI receptionist tell callers?
Use a short notice that identifies the business, explains that the call is being handled by an automated receptionist, says what information is being collected and why, and points callers to the privacy policy or a person who can help. The exact wording should match the actual call flow and legal advice for the business.
Should an AI receptionist record every call?
Not by default. Decide whether the business genuinely needs audio, a transcript, a structured summary or only a booking record. Recording laws and privacy duties can depend on the circumstances, so confirm the requirement before recording and give callers an honest notice.
Can an AI receptionist collect health information?
Health information is sensitive information under Australian privacy law. An organisation will usually need consent to collect sensitive information when the Privacy Act applies. Keep the automated intake narrow and move clinical, urgent or uncertain conversations to an approved person.
Who should be able to read AI receptionist call summaries?
Only people who need the information to answer, quote, book or review the enquiry should have access. Give each role the minimum practical access, remove old users promptly and keep an owner responsible for reviewing permissions.
Does this checklist replace privacy or legal advice?
No. It is an operating checklist for scoping the call flow. Whether the Privacy Act, state recording laws, health rules or another obligation applies depends on the business, information and use. Get advice for the final setup when the position is unclear.

YOUR NEXT MOVE

Bring me the call flow before you connect the number.

I will help you map what the receptionist needs, what it should never collect, where each record goes and when a person must take over. Then the build can follow approved rules instead of making them up during a live call.