- Why your IT setup carries legal obligations
- Do these obligations apply to your business?
- Secure the personal information you hold
- Publish a privacy policy and make your practices match it
- Assess and report data breaches within 30 days
- Get consent before sending marketing emails and texts
- Don't overstate your security in public
- Follow workplace surveillance rules in your state
- Keep records for as long as the law requires
- What happens if you get it wrong
- A practical compliance checklist
- When to bring in a lawyer
- Where written policies fall short
Why your IT setup carries legal obligations
If your business stores customer details, emails suppliers, markets by text message or lets staff work from laptops and phones, your technology choices are not just operational decisions. They are compliance decisions. Australian laws impose duties on how you handle personal information, how you send marketing messages, how you monitor staff and how long you keep records. IT policies and procedures are the practical mechanism for meeting those duties, and they double as your evidence if a regulator comes asking.
This guide sets out who those obligations apply to, what each duty actually requires, and what happens if you miss them. The short version is that the law expects you to secure information, be transparent about what you collect, respond quickly to breaches, obtain consent before marketing, and not promise more security than you deliver.
Do these obligations apply to your business?
The most common misconception is that every small business must comply with the Privacy Act. In fact, the Act contains a small business exemption with a clear turnover threshold, but it also has exceptions that catch more businesses than owners expect.
Under s 6D of the Privacy Act 1988 (Cth), a business is exempt from most of the Act if its annual turnover for the previous financial year was $3 million or less. The exemption does not apply if your business:
- Health services: provides a health service to an individual and holds health information, which includes many allied health, fitness and wellness providers
- Trading in personal information: discloses personal information for a benefit, service or advantage, or collects it from others in exchange for a benefit
- Commonwealth contracts: is a contracted service provider for a Commonwealth contract
- Credit reporting: is a credit reporting body
- Related entities: is related to a body corporate that is not itself a small business
If your turnover is above $3 million, or any exception applies, the Privacy Act and the Australian Privacy Principles (APPs) bind your business in full. The Notifiable Data Breaches scheme in Part IIIC of the Act only applies to entities already covered by the Privacy Act, so the same scoping question decides whether you must report breaches.
Other obligations are not gated by turnover:
- Spam Act 2003 (Cth): applies to any business sending commercial electronic messages with an Australian link, regardless of size
- Australian Consumer Law (ACL): applies to anyone acting in trade or commerce, including statements you make about your security and data practices
- Workplace surveillance: regulated at state and territory level wherever you monitor staff, with rules that differ between jurisdictions
- Record keeping: s 286 of the Corporations Act 2001 (Cth) requires companies to retain financial records for seven years after the transactions they record
Secure the personal information you hold
If the Privacy Act applies to you, Australian Privacy Principle 11 sets the baseline: you must take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. That is a positive duty, not a suggestion. It is why an information security policy matters, and why it needs to describe real controls rather than aspirations.
Reasonable steps in practice include:
- Access control: role-based access so staff only reach the information their job requires
- Passwords and authentication: unique passwords and multi-factor authentication where available
- Encryption: device and data-at-rest encryption, plus automatic locking on laptops and mobiles
- Backups: a defined backup schedule and tested restore procedures
- Disposal: APP 11.2 separately requires you to destroy or de-identify personal information once you no longer need it and no law requires you to keep it
A security policy that names these controls, and names who is responsible for each, is what turns the statutory duty into something an employee can follow.
Publish a privacy policy and make your practices match it
Australian Privacy Principle 1 requires a clearly expressed and up-to-date privacy policy covering the kinds of personal information you collect, how you collect and hold it, and how individuals can access and correct it. APP 1.2 goes further: it requires you to implement practices, procedures and systems that ensure compliance and that let you deal with inquiries and complaints.
That second limb is the part businesses overlook. A privacy policy on your website is not enough if your internal collection, storage and deletion habits do not match what it says. Regulators and customers alike compare the two, and the mismatch itself becomes a problem under the consumer law below.
Assess and report data breaches within 30 days
Under Part IIIC of the Privacy Act, an eligible data breach arises when there is unauthorised access to or disclosure of personal information, or loss in circumstances where unauthorised access or disclosure is likely, and a reasonable person would conclude the event is likely to result in serious harm to affected individuals.
The duties that follow have built-in deadlines:
- Assess: if you suspect a breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware
- Notify the OAIC: once you have reasonable grounds to believe an eligible data breach has occurred, you must prepare a statement describing the breach and give it to the Office of the Australian Information Commissioner as soon as practicable
- Notify affected individuals: you must take reasonable steps to notify each individual at risk, or publish the statement on your website if individual notification is not practicable
A documented data breach response plan, with a named incident lead, is what allows a small team to hit those timeframes. Without one, the 30-day clock runs while you work out who does what.
Get consent before sending marketing emails and texts
The Spam Act 2003 (Cth) applies to every commercial electronic message with an Australian link, which covers emails and SMS that advertise or promote goods, services, land or business opportunities. Section 16 prohibits sending such messages without consent, and the burden of proving consent sits with the sender. Section 17 requires accurate sender identification, and s 18 requires a functional unsubscribe facility that works for at least 30 days after each message.
Practical implications for your marketing workflow:
- Consent: keep a record of when and how each contact consented, including the wording they agreed to
- Unsubscribe: make the mechanism obvious and test it, because a broken unsubscribe link is a breach in its own right
- Sender details: use an accurate sender name and contact details, not a generic or misleading identity
- Staff rules: an email and communications policy should tell staff never to buy lists or scrape addresses, and how to handle unsubscribe requests when they arrive
Don't overstate your security in public
The ACL in Schedule 2 of the Competition and Consumer Act 2010 (Cth) prohibits misleading or deceptive conduct in trade or commerce (s 18) and false or misleading representations about the standard or quality of services (s 29). Statements on your website about being "fully secure", "bank-grade encrypted" or "100 per cent protected" are representations, and they must be accurate.
This is why your public privacy policy and your actual practices need to align. If you tell customers you never share their data and your marketing agency has a copy of the customer list, the statement and the practice cannot both be true. An internal data handling procedure that mirrors your public promises is the control that keeps you honest.
Follow workplace surveillance rules in your state
Monitoring staff through cameras, computer monitoring software, keystroke logging or vehicle tracking is regulated state by state, and the regimes differ. New South Wales, for example, has a dedicated Workplace Surveillance Act 2005, which requires at least 14 days' written notice before surveillance of an employee commences, with the notice describing the kind of surveillance, how it will be carried out and when it starts. Camera surveillance in NSW also requires visible cameras and clear signage at entrances, and covert surveillance is only lawful under a written authority in limited circumstances.
If monitoring is part of your IT setup, an employee monitoring or surveillance policy should set out what is monitored, why, and how the results are used, and it should be checked against the rules in every state and territory where you employ staff. A workplace lawyer can map the applicable regime to your actual tools.
Keep records for as long as the law requires
Section 286 of the Corporations Act 2001 (Cth) requires a company to keep written financial records that correctly record and explain its transactions and financial position, and to retain those records for seven years after the transactions are completed. Sector-specific regimes add their own retention periods for health records, tax documents and other categories.
A data retention schedule that names each record type, its retention period and its disposal method turns this from an unknown into a managed process, and it satisfies the APP 11.2 destruction duty at the same time.
What happens if you get it wrong
The consequences scale with the breach, but the headline figures are significant:
- Privacy Act: a serious interference with privacy attracts a civil penalty for a body corporate of the greatest of $50 million, three times the benefit obtained from the conduct, or 30 per cent of adjusted turnover, with individuals exposed to penalties up to $2.5 million
- Statutory tort: the Privacy Act now includes a cause of action in tort for serious invasions of privacy, allowing individuals to sue directly for intrusion upon seclusion or misuse of information where the invasion was intentional or reckless and serious
- Spam Act: civil penalties run up to 100 penalty units per contravention for a body corporate, capped at 2,000 penalty units (currently about $660,000 at $330 per unit) for multiple contraventions on the same day, rising to 10,000 penalty units where there is a prior record, and the ACMA can also issue infringement notices without going to court
- ACL: for false or misleading representations about services, a body corporate faces a pecuniary penalty of the greater of $100 million, three times the benefit, or 30 per cent of adjusted turnover, with individuals exposed up to $2.5 million
- Enforcement: the OAIC can investigate, seek civil penalties and issue infringement notices under the Privacy Act, and the ACMA enforces the Spam Act through the Federal Court
Beyond penalties, a data breach or a finding of misleading conduct damages the customer trust that small businesses rely on, which is often the more expensive outcome.
A practical compliance checklist
Working through the duties above, a small business can take these steps:
- Scope yourself: confirm whether the Privacy Act applies, including the health, trading, Commonwealth contract and related entity exceptions
- Name a lead: appoint a named person responsible for security, privacy and incident response
- Write the core policies: an acceptable use policy, an information security policy, an internal data handling procedure and a breach response plan
- Publish and match: make your public privacy policy accurate, then make your internal practices match it
- Build a breach plan: document triage, containment, assessment and notification steps, and run a practice scenario once a year
- Fix the marketing flow: record consent, test unsubscribe links, and never buy or scrape lists
- Check monitoring: if you use cameras or monitoring software, confirm the notice and signage rules in your state
- Schedule retention: list record types, retention periods and disposal methods
- Review annually: update policies after major system changes, new software, new vendors or any incident
When to bring in a lawyer
A lawyer's role here is usually threefold. First, scoping: confirming whether the Privacy Act applies to your business at all, which turns on turnover and the exceptions. Second, drafting: turning your actual systems and workflows into policies that meet the statutory standards, rather than generic templates that describe controls you do not operate. Third, incident response: when a breach happens, a lawyer can help you run the assessment, decide whether notification is required and communicate with the OAIC in a way that does not compound the problem.
Where written policies fall short
The gap that costs businesses most is not the absence of a policy document. It is the distance between what the document says and what staff actually do. APP 1.2 does not ask for a policy on a shelf; it asks for practices, procedures and systems that ensure compliance, and APP 11 asks for reasonable steps to protect information. A regulator investigating a breach will look at whether access was actually role-based, whether the unsubscribe link actually worked and whether the privacy policy matched the practice, not whether a document with the right heading existed.
If you take one action this week, choose the single highest-risk flow in your business, whether that is how customer data is shared with a marketing agency, how a lost laptop is reported or how consent is recorded for your mailing list, and write the procedure for exactly that flow. Then test it with the person who does the job. That one working procedure, aligned to a real risk, does more for compliance than a library of untouched templates.