- Does the GDPR apply to your Australian business?
- When does the Australian Privacy Act apply?
- The duty to justify collection and use
- Consent: the strictest point of difference
- Individual rights: access, correction and erasure
- Data breach notification: 72 hours versus as soon as practicable
- Penalties and enforcement risk
- A practical compliance checklist
- When a privacy lawyer should be involved
- The exemption that catches businesses by surprise
Most Australian businesses collect personal information without thinking of themselves as data handlers: names and email addresses for a mailing list, customer details for bookings and invoices, or payment information at checkout. Privacy law is part of that picture, and two regimes matter most. The Privacy Act 1988 (Cth) and its Australian Privacy Principles (APPs) regulate personal information across much of the Australian economy, and the European Union's General Data Protection Regulation (GDPR) can reach Australian businesses that serve or track customers in Europe.
This guide sets out when each regime applies to your business, the duties they impose when you collect and use personal information, the differences in consent and breach notification, the penalties for getting it wrong, and a compliance checklist you can act on.
Does the GDPR apply to your Australian business?
The GDPR protects the personal data of people in the European Union (EU) and the wider European Economic Area (EEA). It applies directly to controllers and processors established in the EU. It also reaches businesses with no European office at all. Under Article 3(2) of the GDPR, the regulation applies to a business outside the EU where its processing relates to offering goods or services to people in the EU or EEA, whether or not payment is required, or to monitoring their behaviour as far as that behaviour takes place within the EU.
Practical triggers for an Australian business include shipping products to EU or EEA addresses, running advertising aimed at EU audiences, providing subscriptions or apps to EU-based customers, or using analytics that track and profile EU visitors. The GDPR has no small business exemption, so a two-person online store can owe the same core duties as a multinational if it deliberately targets European customers.
When does the Australian Privacy Act apply?
The Privacy Act protects personal information, broadly defined as information or an opinion about an identified or reasonably identifiable individual. It binds most private sector businesses, with one significant carve-out. Under s 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover in the previous financial year was $3,000,000 or less, and a small business operator is generally outside the Act. Above that threshold the APPs apply, and the Notifiable Data Breaches scheme in Part IIIC applies as well.
The exemption is not automatic, however. Under s 6D(4) a business is not a small business operator if it provides a health service and holds health information (other than in employee records), if it discloses personal information for a benefit, service or advantage, if it collects personal information for a benefit, if it is a contracted service provider for a Commonwealth contract, or if it is a credit reporting body. A body corporate related to a larger business is also outside the exemption. Separate rules apply regardless of turnover: the tax file number rules bind recipients of tax file number information, and the credit reporting provisions bind credit providers that hold credit eligibility information.
The table below summarises the scope of the two regimes.
| GDPR | Australian Privacy Act | |
|---|---|---|
| Who is covered | EU-established businesses, plus any business offering goods or services to people in the EU/EEA or monitoring their behaviour there | Most businesses with annual turnover above $3 million, plus agencies and some smaller businesses by activity |
| Small business exemption | None | Businesses with turnover of $3 million or less, subject to exceptions |
| Regulator | EU and EEA supervisory authorities | Office of the Australian Information Commissioner (OAIC) |
The two regimes can apply at the same time. A small Australian online store with EU customers and EU-targeted marketing may owe duties under the GDPR even if it falls within the small business exemption, and a larger Australian business will often need to comply with both.
The duty to justify collection and use
Under the GDPR, every processing activity needs a lawful basis. Article 6(1) lists six: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task carried out in the public interest, and the legitimate interests of the controller. A business should be able to identify the basis that justifies each data flow, and it cannot quietly switch to a different basis later without checking that the change is compatible.
The Australian approach is structured differently. Rather than a list of lawful bases, the APPs set out standards that govern each stage. Collection must be reasonably necessary for the entity's functions or activities. At or before collection, the individual must be notified of matters including why the information is collected and to whom it may be disclosed. Use and disclosure is then confined largely to the primary purpose of collection or a related secondary purpose the individual would reasonably expect.
The practical difference is documentation. GDPR compliance tends to require you to record why you process each category of data. APP compliance centres on giving clear notice and staying within the purposes you have disclosed, so your privacy policy and your actual practice need to match.
Consent: the strictest point of difference
Both regimes treat consent as important, but the standards differ. The GDPR defines consent in Article 4(11) as a freely given, specific, informed and unambiguous indication of the data subject's wishes, given by a statement or a clear affirmative action. Pre-ticked boxes are not unambiguous, consent for one purpose does not cover another, and consent must be as easy to withdraw as to give.
The Privacy Act defines consent as express consent or implied consent. The APPs use consent as one gateway among several. Collection, use and disclosure can also be justified where they are reasonably necessary for the entity's functions or activities, or where the individual would reasonably expect the handling. In practice this means that under Australian law an opt-in tick is not always required, while under the GDPR it generally is, and the business should be able to show what each person agreed to and when.
Individual rights: access, correction and erasure
Under the Privacy Act, APP 12 gives individuals the right to request access to the personal information an entity holds about them, and APP 13 gives the right to request correction. The entity must respond within a reasonable period and, where it refuses access or correction, explain why.
The GDPR gives a broader set of rights: access, rectification, erasure (often called the right to be forgotten), restriction of processing, data portability and objection. A business subject to the GDPR needs documented processes to locate, correct, export and delete personal data on request, and to respond within the regulation's timeframes. Under the APPs alone the rights are narrower, but access and correction requests still need a sensible process and a written response.
Data breach notification: 72 hours versus as soon as practicable
Both regimes require breach notification, and this is where the deadlines differ sharply.
The GDPR requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals (Article 33). Where a breach is likely to result in a high risk to individuals, the affected individuals must be told about it directly.
Australia's Notifiable Data Breaches scheme sits in Part IIIC of the Privacy Act. An eligible data breach arises where there is unauthorised access to, unauthorised disclosure of, or loss of, personal information and a reasonable person would conclude the breach is likely to result in serious harm to affected individuals. When an entity becomes aware of reasonable grounds to believe an eligible data breach has happened, it must prepare a statement and give it to the OAIC as soon as practicable, and take reasonable steps to notify affected individuals, or publish the statement on its website where individual notification is not practicable. The OAIC can also direct an entity to notify. If an entity acts before serious harm eventuates and the access or disclosure is no longer likely to result in serious harm, the incident can fall outside the scheme altogether.
There is no 72-hour clock in Australia, but "as soon as practicable" is a real obligation. The assessment of whether serious harm is likely, and the decision to notify, should be made quickly and recorded, because the OAIC can ask how the decision was reached.
Penalties and enforcement risk
The GDPR's fines are set out in Article 83: up to EUR 10 million or 2 per cent of total worldwide annual turnover, whichever is higher, for lesser infringements, and up to EUR 20 million or 4 per cent of total worldwide annual turnover for the most serious, including breaches of the conditions for consent and of data subject rights.
Australian penalties have moved closer in scale. Under s 13G of the Privacy Act, serious or repeated interference with privacy is a civil penalty provision. An individual faces a maximum of $2.5 million. A body corporate faces the greatest of $50 million, three times the value of any benefit obtained and reasonably attributable to the contravention, or 30 per cent of its adjusted turnover during the breach turnover period. The OAIC can investigate, accept enforceable undertakings and seek civil penalties through the Federal Court.
For most small businesses the realistic risk sits below those ceilings: the time and cost of responding to a complaint or investigation, operational disruption, and the loss of customer trust that follows a poorly handled breach. Penalties are the ceiling, not the typical outcome.
A practical compliance checklist
Work through the checklist in order:
- Map your data: list what personal information you collect, where it comes from, why you collect it, who you share it with and how long you keep it. A spreadsheet is enough to start.
- Make your privacy policy match your practice: an APP entity must maintain a privacy policy. If the policy says data never leaves Australia but your email platform stores data offshore, the mismatch is itself a problem.
- Sort out marketing consents: use genuine opt-ins, make unsubscribe easy, and keep a record of what each person agreed to and when.
- Check your suppliers: document who has access to personal information and make sure contracts cover data handling, confidentiality and security. The APPs require reasonable steps before disclosing personal information to an overseas recipient, and the GDPR restricts transfers out of the EU and EEA.
- Prepare a breach response plan: decide who assesses incidents, how you contain them, how you judge likely serious harm, how you document decisions, and when you would notify the OAIC and affected individuals.
- Train your team: everyone who handles personal information should know what counts as personal information, which systems are approved, how to spot phishing and who to tell if something goes wrong.
- If the GDPR applies to you: identify the lawful basis for each processing activity and set up processes for rights requests and 72-hour breach notification.
When a privacy lawyer should be involved
Some assessments are genuinely difficult and are worth a lawyer's time:
- whether the GDPR reaches your business, which turns on whether you target or merely serve incidental EU customers;
- whether you fall inside or outside the Privacy Act, including the health, credit and Commonwealth contract exceptions;
- drafting a privacy policy and website terms that reflect your actual data flows rather than a generic template;
- negotiating contracts with processors, overseas recipients and developers so that overseas disclosure and GDPR transfer obligations are properly allocated;
- advising during a breach, including whether an incident is an eligible data breach and how to frame a statement to the OAIC; and
- responding to complaints, investigations and enforceable undertakings.
The exemption that catches businesses by surprise
The point most Australian businesses miss is that the small business exemption is an exemption from the APPs, not a licence to handle personal information however they like. A health service provider holding health information is covered whatever its turnover, as is any business that trades in personal information, and the tax file number and credit reporting rules apply to small businesses too. On top of that, a business with no Australian obligation at all can still owe GDPR duties the moment it deliberately targets European customers. The first step is the same in every case and costs nothing: write down what personal information you actually collect and what you do with it. That inventory drives your privacy policy, your breach plan and any conversation you have with a lawyer, and it is something you can finish this week.