- Who must comply with the Privacy Act
- Your day-to-day duties under the Australian Privacy Principles
- Disclosure: consent, marketing and sending data offshore
- The Notifiable Data Breaches scheme
- Protecting confidential information
- What happens if you get it wrong
- A practical compliance checklist
- When to bring in a lawyer
- Why the small business exemption is narrower than it looks
Every Australian business handles information it does not own. Customer names and email addresses, employee records, supplier pricing, a formula or a pitch deck. The law treats these very differently depending on what the information is and who it is about, and getting the difference wrong is where the cost shows up: a fine for a data breach you thought did not apply to you, a customer list you cannot claw back, a former employee trading on your pricing.
Three regimes do most of the work. The Privacy Act 1988 (Cth) (the Act) sets out how you collect, use, store and disclose personal information, including when you must notify people about a data breach. Confidentiality is a matter of contract and of equity: it protects information that is valuable because it is secret, whether or not it is about a person. And the Spam Act 2003 (Cth) controls how you can email or message customers for marketing. This guide sets out who each obligation applies to, what you must actually do, and what happens if you get it wrong.
Who must comply with the Privacy Act
The Act binds APP entities: Australian government agencies and private sector organisations. Most businesses are organisations, but the Act carves out a genuine exemption for small business. Under s 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover for the previous financial year was $3 million or less. If you are a small business, you are generally exempt from the Australian Privacy Principles (the APPs) and the Notifiable Data Breaches scheme.
The exemption is narrower than most owners assume. You are brought inside the Act regardless of turnover if you:
- Provide a health service and hold health information, other than in employee records. This covers allied health, fitness assessments and wellness apps, not just doctors and dentists.
- Trade in personal information: you disclose personal information about someone else for a benefit, service or advantage, or provide a benefit, service or advantage to collect personal information from others.
- Work under a Commonwealth contract as a contracted service provider.
- Are a credit reporting body, or are related to a body corporate that carries on a business that is not a small business.
Two further points. Even an exempt small business must still comply with the Act's separate rules for credit reporting and tax file numbers if it handles that information. And if you deal with state or territory government agencies, separate public sector privacy laws, such as the Privacy and Personal Information Protection Act 1998 (NSW), can apply to information you hold for them.
The turnover test is also a moving target. It is measured against the previous financial year, so a strong year can take you over the line unexpectedly. If you are close to the threshold, plan as though the Act applies to you.
Your day-to-day duties under the Australian Privacy Principles
If the Act applies to you, the 13 APPs in Schedule 1 set the standard. The principles that drive most of the day-to-day work are:
- APP 1, open and transparent management: have a clearly expressed, up-to-date privacy policy that is free of charge and easy to access.
- APP 5, notification of collection: at or before the time you collect personal information, tell the person who you are, what you are collecting, why, and who you may share it with.
- APP 6, use and disclosure: only use or disclose personal information for the purpose you collected it, for a related secondary purpose the person would reasonably expect, or with consent.
- APP 8, cross-border disclosure: before sending personal information overseas, take reasonable steps to ensure the overseas recipient handles it in line with the APPs.
- APP 11, security: take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
- APPs 12 and 13, access and correction: give people access to the information you hold about them and correct it when it is wrong.
Two of these deserve emphasis. The APP 5 notice belongs at the point of collection. Every web form, sign-up page or in-store intake should carry a short collection notice that links to your full policy, because the Act requires the notice at or before collection, not somewhere buried in your website.
The other is APP 8. If you use cloud hosting, a customer support team or analytics tools that store data outside Australia, information has been disclosed overseas. Section 16C of the Act makes you accountable for what the overseas recipient then does with it: their breach of the APPs is treated as your breach. Contractual safeguards are the practical answer, and a data processing agreement should sit behind every service provider arrangement.
Disclosure: consent, marketing and sending data offshore
Disclosure is the act that needs managing. Most disclosures are lawful if they fit the purpose you told people about at collection, or fall within a permitted situation such as a serious threat to health or safety. You should also disclose when the law compels you: court orders, subpoenas, and tax or regulator requests. The practical rule is to disclose only what the request requires and keep a record of what you sent and to whom.
Marketing sits under a separate regime. The Spam Act 2003 (Cth) applies to commercial electronic messages, including email and SMS. Each message must have the recipient's consent, identify the sender accurately, and carry a functional unsubscribe facility that works for at least 30 days after the message is sent. Consent can be express or inferred, for example from an existing business relationship, and you need records that prove it. The Australian Communications and Media Authority enforces the scheme and can issue infringement notices or seek civil penalties, so marketing lists need permission records, not just an unsubscribe button.
The Notifiable Data Breaches scheme
Entities covered by the Act must handle serious breaches in a set sequence. A breach is an eligible data breach when there is unauthorised access to, or unauthorised disclosure or loss of, personal information, and a reasonable person would conclude there is a likely risk of serious harm to any affected individual. Serious harm can include financial loss, damage to reputation and identity theft, and the assessment should weigh the sensitivity of the information and how many people are affected.
If you become aware of reasonable grounds to suspect an eligible data breach, you need to assess the situation before you can know whether notification is required. Where the assessment leaves you with reasonable grounds to believe an eligible data breach has occurred, s 26WK requires you to prepare a statement setting out what happened, the kinds of information involved and the steps individuals should take, and to give it to the Office of the Australian Information Commissioner as soon as practicable. Section 26WL then requires you to notify the affected individuals, again as soon as practicable, or to publish the statement on your website if individual notification is not practicable. The Commissioner can also direct an entity to notify if it has not done so itself.
The serious harm test is where most businesses get stuck. A breach is notifiable only if serious harm is likely, which means the assessment step is not optional: you need enough of an investigation to make the call, and a record of how you made it. A tested response plan, run through with your team, is what lets you decide quickly and defensibly.
Protecting confidential information
Privacy law protects information about people. Confidentiality protects information that is secret and valuable, whether it is about people or not: pricing, margins, source code, formulas, customer lists, supplier terms and deal terms. The protection comes from two places.
-
Contract: A non-disclosure agreement before you share sensitive information with a prospective partner, contractor or investor. Confidentiality clauses in customer and supplier contracts that define what is confidential, limit use to the purpose, and require return or deletion. Obligations in employment agreements that survive the end of the job. The contract does the defining, so the definition matters: a vague clause about "confidential information" is hard to enforce against a former employee who took what they regard as general knowledge.
-
Equity: Australian courts will protect confidential information even without a contract where the information has the necessary quality of confidence, was received in circumstances importing an obligation of confidence, and is then used without authorisation. SWF Hoists and Industrial Equipment Pty Ltd v Polli [1996] FCA 7 is a classic example: a former employee who took information acquired during employment was restrained from using it for a competing business. The remedies include injunctions to stop the use, damages or an account of profits, and delivery up of the materials.
The practical point is that confidentiality needs marking and management. Limit access on a need-to-know basis, label documents, control what leaves the business, and keep a record of what you shared, with whom and why. Equity will not rescue information given away casually: the more openly it circulates, the harder it is to call it confidential.
What happens if you get it wrong
The Privacy Act penalties were substantially increased in 2022. Under s 13G, a serious interference with privacy by a body corporate carries a maximum civil penalty of the greatest of $50 million, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover during the breach period. Individuals face up to $2.5 million. Other interferences with privacy, including most breaches of the APPs, carry up to 2,000 penalty units under s 13H.
Beyond penalties, the Office of the Australian Information Commissioner can investigate, accept enforceable undertakings, and make determinations after a complaint that can include compensation for loss or damage suffered by the individual. It can also issue infringement notices for specific APP breaches, such as failing to have a privacy policy or failing to honour an opt-out request. A disclosure that is also a breach of confidence exposes you to injunctions and damages from the person whose information it was, quite apart from any regulator.
The Spam Act adds its own layer: the ACMA can issue infringement notices or pursue civil penalties in the Federal Court for messages sent without consent or without a working unsubscribe facility.
None of this is theoretical for a small business. The largest penalties are aimed at the biggest operators, but the OAIC's jurisdiction over an exempt small business can turn on a single exception, and a compensation order or a leaked customer list can hurt a small business far more than a headline fine.
A practical compliance checklist
Work through these items, roughly in order:
- Work out your position and revisit it at each financial year end: turnover moves and exceptions appear.
- Publish a privacy policy and put a collection notice on every form that gathers personal information.
- Review service provider contracts that touch personal information, and put data processing obligations in place, including for offshore transfers.
- Write confidentiality into customer, supplier and employment agreements, and use an NDA before sharing sensitive information.
- Keep marketing permission records and maintain a working unsubscribe process.
- Write a data breach response plan and walk through it with your team at least once a year.
- Keep a record of every disclosure you make under compulsion, and of each assessment of a suspected breach.
When to bring in a lawyer
Most of this framework is document work a lawyer can do once and you can maintain. A practitioner can audit what you collect and where it goes, draft your privacy policy and collection notices to match your actual practices, prepare NDAs and confidentiality clauses that survive the relationship, and advise on whether a data processing agreement or a whistleblower policy is required for your structure. Where something has already gone wrong, a lawyer's value is speed and accuracy: assessing whether a breach meets the serious harm test, preparing the statement for the OAIC, and deciding who needs to be told and when. The cost of a wrong call in a data breach is usually much higher than the cost of the advice.
Why the small business exemption is narrower than it looks
The exemption is routinely described as "under $3 million turnover means the Privacy Act does not apply to you". That sentence is false in three ways. The test uses last financial year's turnover, so growth catches you from behind. The exceptions pull in health providers, anyone trading in personal information and Commonwealth contractors whatever their size. And even where the exemption holds, your customers and enterprise clients will contractually require APP-aligned practices, and a data breach that causes serious harm is a reputational event no exemption protects against.
So the first action this week is not to draft a new policy. It is to work out whether the Act applies to you at all, then map where personal information lives: what you collect, where it is stored, who can reach it and who you share it with. Everything else, the policy, the notices, the contracts, the breach plan, hangs off that map. Do it once, correctly, and the rest of the framework stops being guesswork.