1. Does the Privacy Act apply to your business?
    1. What counts as personal information
  2. Your core duties under the Australian Privacy Principles
    1. Be transparent about what you do with data
    2. Collect, use and disclose only what you need
    3. Respect the direct marketing rules
    4. Manage overseas transfers carefully
    5. Secure the information and delete it when it is no longer needed
    6. Honour access and correction rights
  3. Notifiable data breaches: when you must report
  4. What happens if you get it wrong
  5. A practical compliance checklist
  6. When to involve a lawyer
  7. The exemption trap: check your status before you scale

If your business collects customer names, email addresses or health details, you may already be subject to Australian privacy law without realising it. The Privacy Act 1988 (Cth) (the Act) and the 13 Australian Privacy Principles (APPs) that sit inside it impose detailed obligations on how personal information is collected, used, stored and shared. Breaching them can now cost a business up to $50 million in civil penalties, and individuals can take direct court action for serious invasions of privacy.

The rules apply to far more businesses than most owners assume. This article sets out who the Act covers and the turnover threshold that triggers coverage, the core duties you must meet if you are covered, the penalties for getting it wrong, and the practical steps to become compliant. It closes with the exemption trap that catches small businesses by surprise.

Does the Privacy Act apply to your business?

The starting point is turnover. The Act applies to "organisations", which means businesses and not-for-profits with an annual turnover of more than $3 million (s 6D of the Act). A business is a small business for a financial year if its annual turnover for the previous financial year was $3 million or less, and a new business is tested against its projected current-year turnover. Annual turnover means income from all sources earned in the course of the business, including sales, commission, rent and interest, but not capital gains or the value of assets (s 6DA).

Below that threshold sits the small business exemption. A "small business operator" is exempt from most of the Act, including the APPs. That exemption is narrower than it sounds: the OAIC's small business guidance lists the situations in which a business is covered regardless of turnover. Your small business is subject to the Act if any of the following apply:

  • Health services: you provide a health service and hold health information, which includes clinics, allied health providers, pharmacies, private schools and wellness apps.
  • Trading in personal information: you buy, sell, barter or exchange personal information for a benefit, service or advantage, such as selling a customer list to a marketing company.
  • Commonwealth contracts: you provide services to an Australian government agency under a Commonwealth contract or subcontract.
  • Credit and tenancy data: you are a credit reporting body, a credit provider handling credit eligibility information, or the operator of a residential tenancy database.
  • AML/CTF reporting: you are a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), a category that expanded in 2026 to bring many real estate, legal, accounting and similar professionals within the Act.
  • Related entities: you are related to a larger body corporate that is itself subject to the Act.
  • Other categories: you are accredited under the Consumer Data Right, an employee association, a protected action ballot agent, or prescribed by the Privacy Regulation 2013, or you have voluntarily opted in to the Act.

Handling tax file numbers attracts separate obligations under the Privacy (Tax File Number) Rule 2015 even for businesses that would otherwise be exempt. If any of these descriptions fit, the small business exemption does not protect you, and the APPs apply in full.

What counts as personal information

The Act protects "personal information": information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded (s 6(1)). Names, addresses, emails, phone numbers, dates of birth and bank details are the obvious examples. Less obvious identifiers, such as IP addresses and location data, can also qualify where an individual is reasonably identifiable from them, and information can become personal information when combined with other data you hold. The OAIC's guidance encourages entities to err on the side of treating information as personal information.

A subset, "sensitive information", attracts higher protection because of the harm its misuse can cause. It includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records, and biometric and genetic information, among other categories (s 6(1)). Collecting sensitive information generally requires consent, and using or disclosing it is more tightly restricted. This matters for scope as well as compliance: holding health information is itself one of the reasons a small business is caught by the Act.

Your core duties under the Australian Privacy Principles

The APPs are 13 principles in Schedule 1 of the Act that govern the entire lifecycle of personal information. The OAIC publishes the full text of the principles, which replaced the older National Privacy Principles in 2014. The duties that generate the most day-to-day work for SMEs are these.

Be transparent about what you do with data

APP 1 requires every APP entity to manage personal information openly and transparently, and to have a clearly expressed, up-to-date privacy policy (APP 1.3 and 1.4). The policy must set out the kinds of information you collect, how you collect and hold it, the purposes for which you use and disclose it, how individuals can access and correct their information, and how they can complain. A policy that exists only as a template is not enough: it must describe what your business actually does.

Collect, use and disclose only what you need

The APPs restrict collection and use at every stage. You may collect only the personal information that is reasonably necessary for your functions or activities (APP 3), and you must collect it by lawful and fair means. At or before the time of collection you must notify individuals of what you are collecting, why, and who else may see it (APP 5), which is why a short collection notice on your web forms and intake documents matters. Once collected, you must not use or disclose the information for a secondary purpose unless the individual consented, or would reasonably expect the use or disclosure because it is related to the original purpose (APP 6). For sensitive information, the related purpose must be directly related to the original purpose, and many secondary uses require express consent.

Respect the direct marketing rules

APP 7 restricts using or disclosing personal information for direct marketing. You may do so only where you collected the information from the individual, they would reasonably expect to receive marketing from you, and you provide a simple means to opt out that you actually honour. Marketing that relies on purchased lists, or on sensitive information such as health data, is far more tightly constrained. Commercial email and SMS are also regulated separately under the Spam Act 2003 (Cth), so a marketing campaign needs to satisfy both regimes at once.

Manage overseas transfers carefully

If you use a cloud CRM, helpdesk tool or overseas development team, APP 8 applies. Before disclosing personal information to a recipient outside Australia, you must take reasonable steps to ensure the recipient does not breach the APPs, and you remain accountable for how the information is handled overseas (s 16C). Practical safeguards include checking that the destination country has adequate privacy protections, putting contractual protections in place, and telling individuals in your privacy policy which countries are involved.

Secure the information and delete it when it is no longer needed

APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, using both technical and organisational measures (APP 11.1 and 11.3). Multi-factor authentication, role-based access, encryption and staff training are the standard technical steps; documented policies and processes are the organisational half of the obligation. APP 11 also requires you to destroy or de-identify personal information when you no longer need it for any permitted purpose, unless another law or a court order requires you to keep it (APP 11.2). A retention schedule that says what you keep, for how long and when it is deleted is the practical way to meet this duty.

Honour access and correction rights

Individuals can ask for access to the personal information you hold about them and to have it corrected if it is inaccurate (APPs 12 and 13). You must respond within a reasonable period, and you can only refuse on the limited grounds set out in the Act. These requests arrive with little warning, so your team needs to know who handles them and how quickly they must respond.

Notifiable data breaches: when you must report

Part IIIC of the Act creates the Notifiable Data Breaches (NDB) scheme. An eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of, personal information (or credit reporting, credit eligibility or tax file number information) and a reasonable person would conclude the access, disclosure or loss is likely to result in serious harm to any affected individual (s 26WE).

The duties operate on a timeline. If you have reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware (s 26WH). If the assessment confirms an eligible data breach, you must prepare a statement describing the breach and the kinds of information involved, give it to the OAIC as soon as practicable, and notify affected individuals or, where that is not practicable, publish the statement on your website (ss 26WK and 26WL). The Commissioner can also direct an entity to notify (s 26WR). One qualification softens the scheme: if you take remedial action before the access or disclosure results in serious harm, and a reasonable person would conclude from that action that serious harm is no longer likely, the incident is not an eligible data breach and no notification is required (s 26WF).

A documented breach response plan matters because the assessment clock starts the moment you become aware. Deciding who leads the assessment, how you contain the incident and how you draft the statement in advance is the difference between a controlled response and a rushed one.

What happens if you get it wrong

The OAIC can investigate complaints about your handling of personal information, including through Commissioner-initiated investigations, and can conciliate disputes and make determinations. Beyond that, the financial exposure is substantial:

  • Serious or repeated interferences with privacy: a body corporate faces a maximum civil penalty of the greatest of $50 million, three times the value of the benefit obtained from the contravention, or 30% of adjusted turnover during the breach period; for individuals and other entities the cap is $2.5 million (s 13G). These tiers were introduced by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth).
  • Other interferences with privacy: a maximum penalty of 2,000 penalty units applies (s 13H).
  • The OAIC can also issue infringement notices and compliance notices for specific APP breaches, including failures to maintain a compliant privacy policy (s 13K).

The reform pipeline has added new exposure. The Privacy and Other Legislation Amendment Act 2024 (Cth), which received assent in December 2024, introduced a statutory tort for serious invasions of privacy that gives individuals a direct route to seek redress in the courts, expanded the OAIC's enforcement and investigation powers including new tiers of civil penalties and infringement notices, and requires privacy policies to disclose substantially automated decisions that significantly affect individuals. The OAIC has been directed to develop a Children's Online Privacy Code covering online services likely to be accessed by children, and a mechanism now exists to prescribe countries with adequate privacy protections for cross-border transfers. Taken together, these changes mean the cost of getting privacy wrong is no longer just a regulator's determination: it includes court judgments and the reputational damage that follows a public breach notification.

A practical compliance checklist

If the Act covers your business, these are the minimum steps to work through:

  • Confirm your status: work out whether you are over the turnover threshold or caught by one of the carve-outs, and record that conclusion.
  • Map your data: identify what you collect, where it is stored, who has access, which third-party systems handle it, and when it is deleted.
  • Publish a compliant privacy policy: ensure it matches your actual practices, and add collection notices to every form that gathers personal information.
  • Harden your security: enable multi-factor authentication, restrict access by role, encrypt data in transit and at rest, and document your arrangements.
  • Align your vendors: make sure contracts with cloud and software providers that process personal information for you include security, breach notification and data return or deletion terms.
  • Train your team: cover data handling, phishing awareness and how to respond to access or correction requests.
  • Prepare a breach response plan: test it once a year so the 30-day assessment clock does not catch you unprepared.
  • Set a retention schedule: review it annually and delete data you no longer need.

When to involve a lawyer

Some parts of this regime are straightforward, but several are not. Getting professional help is usually worthwhile where your business handles health or credit information, where you rely on overseas vendors, where a breach has occurred and you must assess whether notification is required, or where the OAIC has opened an investigation into your handling of personal information. A privacy lawyer can confirm whether the exemption applies to your particular structure, draft an APP-aligned privacy policy and data processing agreements that match your operations, run the serious harm analysis after a suspected breach, and represent you in dealings with the OAIC. Given the reform pipeline, a lawyer can also help you decide how much to build now rather than waiting for the next tranche of changes.

The exemption trap: check your status before you scale

The duty small businesses miss most often is not any individual APP. It is the threshold question itself. Many owners assume that because their turnover is under $3 million they have no obligations, and that assumption survives until a customer complains, a supplier loses their data, or a health-related business discovers that the exemption never applied to them in the first place.

The exemption is also a moving target. The first tranche of reform has already delivered the statutory tort, expanded OAIC powers and new disclosure duties, and the government has signalled a second tranche that has targeted the blanket small business exemption for removal, with consultation ongoing. A business that is exempt today may not be exempt in a year. The cheapest insurance is to confirm your status now, and if the Act covers you, put the privacy policy and the breach response plan in place first. Those two documents are the foundation everything else builds on, and they are the ones regulators and customers look for first.