The Data‑Privacy Compliance Gap: Why Current Regulations Fall Short When Assessing Rapidly Evolving AI Therapy Apps - expert-roundup

Regulators struggle to keep up with the fast-moving and complicated landscape of AI therapy apps — Photo by Anna Tarazevich o
Photo by Anna Tarazevich on Pexels

Look, here's the thing: the privacy gap in AI-driven mental health apps is wider than most people realise, and it’s growing faster than the rules meant to protect us.

In my experience around the country, I’ve seen a surge in apps promising instant relief, yet the data-protection oversight hasn’t kept pace. This article pulls together the latest research, legal commentary and on-the-ground advice for anyone considering a digital therapist.

Medical Disclaimer: This article is for informational purposes only and does not constitute medical advice. Always consult a qualified healthcare professional before making health decisions.

1. The privacy gap in AI-driven therapy apps

In 2023, the Mental Health Apps: Game-Changer or Gimmick? surveyed 42 Australian users and found 57% were unaware that their chat logs could be sold to third-party advertisers. That’s a stark illustration of the “AI therapy privacy gap” that keeps widening.

Why does this matter? Because mental health data is among the most sensitive personal information. When an app’s algorithm stores your mood scores, voice recordings or even biometric data, a breach can expose more than a name and email - it can reveal your deepest anxieties.

Researchers have been flagging the relationship between digital media use and mental health since the mid-1990s, noting how excessive or problematic use can become a "digital dependency" that varies across cultures. Wikipedia notes that this field now includes digital care programmes designed to boost efficiency, but the same sources point out the glaring lack of consistent oversight.

In my reporting, I’ve spoken to a Sydney-based psychiatrist who warned that "the moment you type ‘I feel hopeless’ into an app, that data could be repurposed for marketing if the company’s privacy policy is vague". This isn’t speculation - it’s a real risk that legal experts are beginning to spotlight.

Below is a quick snapshot of how the top-selling apps stack up on privacy features.

App Data Encryption Third-Party Sharing User-Control Options
MindMate AES-256 Limited (research only) Delete chat, opt-out of research
CalmSpace TLS/SSL (in-transit) Broad (advertising partners) Limited - only delete account
TalkWell AES-128 None disclosed Export data, delete chats
WellBeing AI End-to-end encrypted Minimal (aggregated stats) Full data export, opt-out of analytics

Notice how many apps still rely on basic TLS encryption and give users little control over what’s shared. That’s the crux of the privacy gap: advanced AI features come without matching safeguards.

2. Regulatory lag: Who’s watching and why the rules are stuck

When I asked the Australian Competition and Consumer Commission (ACCC) for comment, a spokesperson said the body is currently reviewing the digital health market, but no definitive framework exists yet for AI-powered therapy platforms. The ACCC’s last major update on digital health privacy was in 2020, before the current AI boom.

Meanwhile, a See what legal professionals say about the role of AI and law, noting that “real-time compliance” is still a concept rather than a legal requirement. In plain English, regulators are still trying to catch up to the speed at which these apps are being rolled out.

Key points of the lag include:

  1. Algorithmic transparency. Companies are not required to disclose how their AI decides to suggest a coping strategy, leaving clinicians unable to assess safety.
  2. Data-protection oversight. The Privacy Act 1988 does not specifically address AI-generated insights, meaning “data-privacy compliance” is interpreted loosely.
  3. Cross-border data flows. Many apps host servers overseas, sidestepping Australian data-sovereignty rules.
  4. Real-time monitoring. There is no mandated audit of how apps handle a data breach the moment it occurs.

Because of these gaps, a user could be handed a “digital therapist” that stores information on a server in the US, where the GDPR-style protections simply don’t apply. The lack of a specific regulatory regime means the burden falls on the consumer to vet the app.

In my experience around the country, community health workers in regional NSW have reported that their clients often use free apps without any privacy briefing. That’s a risk both for the individual and for the broader health system if data leaks feed into insurance premiums or employment screenings.

Key Takeaways

  • AI therapy apps often lack end-to-end encryption.
  • Regulators haven’t kept pace with AI-driven mental health tools.
  • Users can mitigate risk by checking data-control settings.
  • Transparency around algorithmic decisions is still scarce.
  • Cross-border data storage may bypass Australian privacy law.

3. What can users do right now? Practical steps to protect your mind and data

While we wait for legislation to catch up, there are concrete actions you can take before you type your first worry into an app.

  • Read the privacy policy - but skim for red flags. Look for clauses about "third-party sharing" or "data analytics". If the policy is longer than a page and uses legal jargon, that’s a warning sign.
  • Prefer apps with end-to-end encryption. This ensures only you and the service can read your messages, not the cloud provider.
  • Check for a data-export feature. Being able to download and delete your data gives you control.
  • Use a dedicated email address. Don’t sign up with your primary personal or work email - it limits cross-platform tracking.
  • Enable two-factor authentication (2FA). Even if the app’s database is breached, 2FA adds a layer of protection.
  • Turn off location services. Many apps request GPS data for “personalisation”, which isn’t needed for text-based therapy.
  • Read reviews from Australian users. Local forums like Whirlpool or Reddit’s r/AusHealth can highlight hidden privacy issues.
  • Consider a therapist-led telehealth service. If you need guaranteed confidentiality, a licensed professional using a secure platform may be safer than an anonymous chatbot.
  • Stay updated on the ACCC’s digital health report. The regulator usually releases an annual summary - the 2024 draft is due in October.
  • Report any suspicious activity. If you notice your data being used for ads you didn’t consent to, lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

These steps aren’t a guarantee, but they shrink the exposure gap dramatically. I’ve seen clients avoid a potential data breach simply by opting out of a default data-sharing setting that was buried three screens deep.

To get a full picture, I spoke with three people who sit at the crossroads of mental health, law and technology.

Dr. Priya Narayanan - Clinical Psychologist, Sydney

“I recommend digital tools as a supplement, not a replacement. The biggest danger is when a client believes the AI knows them better than a human therapist, and then that data ends up in a marketing database. That erodes trust in the whole health system.”

Dr. Narayanan highlighted that many apps claim to be “evidence-based” but have not been peer-reviewed. She advised users to look for a clear citation of a randomised controlled trial (RCT) in the app’s marketing material.

“The law is playing catch-up. Current privacy legislation does not define ‘algorithmic transparency’, so companies can hide how they generate therapeutic suggestions. Until a statutory definition lands, we’ll see a patchwork of self-regulation.”

McAllister warned that “real-time compliance” is an aspirational term many startups use to sound cutting-edge, but there is no regulatory audit to back it up.

Dr. Lena Huang - Data Scientist, University of Melbourne

“From a technical standpoint, many of these AI models are trained on large, public datasets that may include de-identified mental health records. Re-identification risk is low but not zero. Encryption at rest is more critical than most users realise.”

Huang suggested a practical test: during a free trial, ask the app what data it stores. If the response is generic, it may be a sign they haven’t built a robust data-governance framework.

Combining these perspectives, a clear picture emerges: the technology can be useful, but the surrounding ecosystem - privacy policies, regulatory oversight, and user literacy - is uneven.

5. The road ahead - what to expect in the next 12-24 months

Industry insiders say we’ll see three major shifts:

  1. Regulatory clarification. The ACCC is expected to release a consultation paper on AI-driven health services by early 2025, which could introduce mandatory algorithmic transparency clauses.
  2. Standardised privacy certifications. A coalition of Australian digital health firms is piloting a "Privacy-by-Design" seal, similar to the ISO 27001 framework, to reassure users.
  3. Integration with Medicare-eligible telehealth. Some apps are negotiating partnerships with private health insurers to offer subsidised, clinically supervised digital therapy, which may bring stricter data safeguards.

Until those changes materialise, the best defence remains an informed consumer. As I always say, “if it sounds too good to be true, ask how they’re protecting the data that makes it work”.

Frequently Asked Questions

Q: Are mental health apps covered by the Australian Privacy Act?

A: They are, but the Act was written before AI-driven therapy became mainstream. It requires organisations to handle personal information responsibly, yet it does not specifically regulate how AI algorithms process or store mental-health data, leaving a compliance gap.

Q: How can I tell if an app encrypts my data end-to-end?

A: Look for phrases like “AES-256 end-to-end encryption” in the security section of the privacy policy. If the policy only mentions “TLS/SSL” for data in transit, the data at rest may not be encrypted.

Q: What should I do if I suspect my therapy data has been shared without consent?

A: First, contact the app’s support team and request a data-access report. Then lodge a complaint with the OAIC, providing any screenshots or emails that show the unauthorised sharing. You may also want to consult a legal professional specialising in privacy law.

Q: Are free mental-health apps safe to use?

A: Free apps often monetise through data advertising. While they can be a useful entry point, you should verify that they do not sell your session transcripts or use your mood scores for targeted ads.

Q: Will my Medicare rebate cover a digital therapy service?

A: Currently, Medicare rebates apply to telehealth sessions with a registered practitioner. Some hybrid apps that pair AI tools with a licensed therapist are seeking accreditation, but most pure-AI services remain out-of-pocket.

Bottom line: digital therapy apps can be a helpful part of a broader mental-health plan, but they’re not a free-pass to hand over your most private thoughts. By staying alert to privacy policies, demanding encryption, and keeping an eye on emerging regulations, you can reap the benefits without sacrificing your data.

Read more