- The two regimes and their regulators
- Who the APPs apply to
- Who the GDPR applies to
- What counts as protected information
- Consent under each regime
- Rights to erasure, portability and objection
- Data breach notification
- Where Australian reform is heading
- When a lawyer can help
- The compliance gap that catches Australian businesses
If your business collects customer data, runs a website with analytics or sells online, at least one of two privacy regimes almost certainly governs what you do with that data: the Australian Privacy Principles (the APPs) in Schedule 1 of the Privacy Act 1988 (Cth), and the European Union's General Data Protection Regulation (the GDPR). Both regulate how businesses collect, use, store and disclose information about identifiable individuals, and both were built on the same family of fair information principles. They differ sharply, however, in who they catch, what they demand and how breaches are handled.
The practical problem for Australian businesses is that the two regimes do not overlap neatly. A business can be fully compliant with the APPs and still owe obligations under the GDPR, because the GDPR reaches businesses outside the EU. The reverse is also true: a small Australian business exempt from the APPs entirely can still be caught by the GDPR through its online activity. This article sets out how each regime operates, where the obligations diverge, and how to work out which rules apply to your business.
The two regimes and their regulators
The APPs are 13 principles that sit inside the Privacy Act 1988 (Cth) and bind "APP entities". They cover collection, use and disclosure of personal information, security, access and correction, and the handling of information transferred overseas. The regime is administered and enforced by the Office of the Australian Information Commissioner (OAIC), which investigates complaints, can make determinations and can seek civil penalties for serious or repeated interferences with privacy.
The GDPR is an EU regulation that has applied since 25 May 2018. It binds "controllers" and "processors" of personal data and gives individuals a set of enforceable rights over their data. Enforcement sits with each EU member state's supervisory authority, which can investigate and impose fines on businesses that fall within its reach.
Both regimes put the individual at the centre. The difference is that the GDPR is the more prescriptive of the two: it spells out individual rights such as erasure and data portability that the APPs do not contain, and it imposes a hard deadline for reporting data breaches where Australia's scheme uses a softer "as soon as practicable" standard.
Who the APPs apply to
The APPs apply to APP entities, which are agencies and organisations as defined in the Privacy Act 1988 (Cth). In practical terms:
- Government agencies: Australian Government agencies are covered, along with some state and territory bodies by separate legislation.
- Private sector businesses: an organisation includes most businesses, and the key threshold is turnover. Under s 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover is $3 million or less, and small business operators are generally exempt from the APPs.
- Small businesses that lose the exemption: the exemption does not apply if the business provides a health service and holds health information, discloses personal information for a benefit, service or advantage, collects personal information for a benefit, service or advantage, is a contracted service provider for a Commonwealth contract, or is a credit reporting body.
- Small businesses that opt in: a small business operator can choose to be treated as an organisation under s 6EA of the Privacy Act 1988 (Cth), for example to reassure customers or to deal with larger businesses that require contractual privacy compliance.
So the first question for an Australian business is turnover-based: if you earn more than $3 million a year, the APPs apply to you. If you earn less, they generally do not, unless one of the carve-outs or an opt-in choice brings you within the regime.
Who the GDPR applies to
The GDPR does not use a turnover test. Under Article 3 of the GDPR, it applies in two situations:
- Establishment in the EU: the regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or processor in the EU, regardless of whether the processing happens in the EU. An establishment can be a branch, subsidiary or other stable arrangement in a member state, not necessarily a separate company.
- Targeting people in the EU: for a business with no EU presence, the GDPR still applies where the business offers goods or services to people in the EU, whether or not payment is required, or monitors the behaviour of people in the EU.
The second limb is what catches Australian businesses. A website that sells to EU customers is offering goods or services to them. A website that uses cookies or analytics to track visitors is monitoring behaviour, and the size of your business is irrelevant to whether the regulation applies. The trigger is where your activity reaches, not what your revenue is.
As a practical example, an Australian online store that ships to EU addresses is within the GDPR's scope for the personal data it processes about those customers. So is an Australian business running behavioural advertising that profiles EU visitors through cookies, even if it never makes a sale in Europe.
What counts as protected information
The APPs protect "personal information". Under s 6(1) of the Privacy Act 1988 (Cth), that means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.
The GDPR protects "personal data". Under Article 4(1) of the GDPR, that means any information relating to an identified or identifiable natural person, and the definition expressly lists identifiers such as a name, an identification number, location data and an online identifier.
The two definitions are close in effect: an IP address or a cookie ID can be personal information under the APPs and personal data under the GDPR. The GDPR's definition is more explicit that online identifiers and location data count as identification factors, which makes the position clearer for analytics-heavy businesses. If you operate a website that assigns cookies to visitors, you should assume both regimes treat the resulting data as protected.
Consent under each regime
Consent is where the two regimes diverge most in practice.
Under the APPs, consent is defined in s 6(1) of the Privacy Act 1988 (Cth) as express or implied consent. The principles use consent at key points, for example before collecting sensitive information, and before using or disclosing personal information for a secondary purpose. An Australian business can often rely on implied consent, such as a customer voluntarily completing a web form.
The GDPR sets a higher bar. Under Article 4(11) of the GDPR, consent must be freely given, specific, informed and unambiguous, and must be signified by a statement or a clear affirmative action. Silence, pre-ticked boxes and inactivity do not qualify. Under Article 7 of the GDPR, the business must be able to demonstrate that consent was given, and if consent is sought in a written declaration that also covers other matters, the request must be presented in a clearly distinguishable way using clear and plain language. The individual also has the right to withdraw consent at any time, and withdrawal must be as easy as giving consent.
For an Australian business inside the GDPR's scope, the practical implication is that an implied-consent model that satisfies the APPs will not satisfy the GDPR. An unticked consent box that the customer actively ticks, with the wording recorded and a simple withdrawal mechanism, is the standard to aim for.
Rights to erasure, portability and objection
The GDPR gives individuals three rights that have no direct equivalent in the APPs:
- Erasure: Under Article 17 of the GDPR, an individual can require a business to erase personal data without undue delay where the data is no longer necessary for the purposes it was collected, where the individual withdraws consent and no other legal ground for processing exists, where the data was unlawfully processed, or where erasure is needed to comply with a legal obligation.
- Data portability: Under Article 20 of the GDPR, an individual can require a business to provide the personal data they supplied in a structured, commonly used and machine-readable format, and to transmit it to another business without hindrance, including direct transmission between businesses where technically feasible.
- Objection: Under Article 21 of the GDPR, an individual can object at any time to processing based on certain grounds, and can object at any time to direct marketing, after which the data must no longer be processed for that purpose.
The APPs do not contain these rights. The closest equivalents are APP 11.2, which requires an APP entity to take reasonable steps to destroy or de-identify personal information it no longer needs, and APP 12.4, which requires access to be given in the manner the individual requests if it is reasonable and practicable to do so. These are real obligations, but they are not enforceable individual rights of the GDPR kind. A customer asking an Australian-only business to "delete all my data" is asking you to apply APP 11.2 and your legal retention obligations, whereas a customer covered by the GDPR has a direct right to erasure with limited exceptions.
Data breach notification
Both regimes require businesses to report serious data breaches, but the timing rules are different.
Australia's Notifiable Data Breaches scheme sits in Part IIIC of the Privacy Act 1988 (Cth). Under s 26WE, an eligible data breach arises where there is unauthorised access to, or unauthorised disclosure or loss of, personal information and a reasonable person would conclude the access, disclosure or loss is likely to result in serious harm to affected individuals. Where an APP entity has reasonable grounds to believe an eligible data breach has occurred, s 26WK requires it to prepare a statement and give it to the OAIC as soon as practicable, and s 26WL requires it to notify affected individuals, or to publish a copy of the statement on its website if it is not practicable to notify individuals directly.
The GDPR works on a clock. Under Article 33 of the GDPR, a business must notify its supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. Under Article 34 of the GDPR, where a breach is likely to result in a high risk to the rights and freedoms of individuals, the business must also communicate the breach to those individuals without undue delay.
Two points follow for Australian businesses. First, the thresholds differ: Australia asks whether serious harm is likely, while the GDPR asks whether there is a risk to rights and freedoms, which is a lower trigger for notification to the regulator. Secondly, if a breach involves the personal data of EU residents, the 72-hour clock starts regardless of how the breach would be assessed under the Notifiable Data Breaches scheme.
Where Australian reform is heading
Australian privacy law is moving toward the GDPR model, but has not arrived. The first tranche of reform, the Privacy and Other Legislation Amendment Act 2024 (Cth), passed in late 2024 and introduced measures including a statutory tort for serious invasions of privacy and a Children's Online Privacy Code, and expanded the OAIC's powers. It did not introduce GDPR-style rights such as a direct right to erasure or data portability, which the Government has flagged as part of the ongoing reform agenda. Businesses should expect the gap between the two regimes to narrow over time, which is a reason to design consent mechanisms and data-handling practices now that would satisfy the stricter regime.
When a lawyer can help
Working out which regime applies is usually the hardest step, and it is a legal assessment rather than a box-ticking exercise. A privacy lawyer can help by:
- Scoping GDPR exposure: assessing whether your business is established in the EU or whether your offering or monitoring activity reaches people in the EU, based on how your website, marketing and customer base actually operate.
- Mapping data flows: identifying what personal information you collect, where it comes from, how long you keep it and where it is stored or transferred.
- Reviewing consent mechanisms and privacy documents: checking that consent collection, privacy policies and breach response procedures meet the stricter of the two regimes that applies to you.
- Handling breaches and individual requests: advising on whether a breach is notifiable, to whom and within what timeframe, and on how to respond to erasure, portability and objection requests from individuals covered by the GDPR.
The compliance gap that catches Australian businesses
The most expensive mistake is assuming that APP compliance means GDPR compliance. The two regimes answer different questions: the APPs ask about your turnover and your status as an APP entity, while the GDPR asks about where your customers are and what your website does. A sub-$3 million business can be exempt from the APPs yet squarely within the GDPR because of its online reach, and an APP-compliant business can still miss the GDPR's consent, erasure and 72-hour notification requirements. Before you invest in further privacy work, identify which regime actually applies to each stream of data you handle, and design your consent and breach-response practices to the stricter standard. A scoping assessment of your GDPR exposure is a relatively contained piece of work, and it is the difference between knowing your obligations and discovering them after a regulator comes calling.