1. Which businesses are covered
  2. The laws that govern how you handle data
    1. The Privacy Act 1988 and the Australian Privacy Principles
    2. The Notifiable Data Breaches scheme
    3. The Spam Act 2003
    4. The Australian Consumer Law and misleading conduct
    5. Sector-specific regimes
  3. What the 2024 amendments mean for your business
  4. The documents your business needs
  5. Where businesses actually fall short
  6. Your legal obligations when a breach occurs
  7. How Artificer Legal can help
  8. Privacy compliance is an ongoing practice

Every Australian business that collects customer information is already operating inside a legal framework — whether it knows it or not. The question is not whether data protection law applies to you. It is whether you understand your obligations clearly enough to meet them and, increasingly, whether you have prepared for the consequences of falling short.

The rules have sharpened. The Privacy and Other Legislation Amendment Act 2024 (Cth) commenced on 10 December 2024, bringing expanded enforcement powers and new civil penalty tiers to a framework that many small and medium businesses had treated as background noise. Getting across these laws now — before a complaint or a breach — is the practical move.

Which businesses are covered

The core framework for handling personal information in Australia sits inside the Privacy Act 1988 (Cth). Its 13 Australian Privacy Principles (APPs) govern how personal information is collected, used, disclosed, stored and corrected.

The primary coverage threshold is annual turnover. Businesses with an annual turnover of more than $3 million must comply with the Privacy Act. But the turnover test is only part of the picture. The Office of the Australian Information Commissioner (OAIC) confirms that a range of smaller businesses are also covered regardless of their turnover, including:

  • private sector health service providers (including allied health, complementary therapists and other health services)
  • businesses that trade in personal information
  • credit reporting businesses and credit providers
  • operators with accreditation under the Consumer Data Right system
  • contractors to Commonwealth agencies

In practice, the $3 million threshold is a starting point, not a safe harbour. If your business collects sensitive information — health data, financial details, identity documents — or operates in a regulated sector, there is a reasonable chance you are covered even if your revenue sits below the threshold. And even where the exemption technically applies, enterprise customers and digital platforms increasingly require Privacy Act compliance as a contractual condition.

Small businesses that are not currently covered can also opt in to the Privacy Act voluntarily — a step that can be commercially useful when pursuing larger clients or government contracts.

The laws that govern how you handle data

The Privacy Act 1988 and the Australian Privacy Principles

The APPs establish binding rules across the full lifecycle of personal information. At a high level:

  • APPs 1–3 deal with transparency, anonymity and what you can collect. APP 1 requires you to maintain a publicly available privacy policy and to manage personal information openly and transparently. From 10 December 2026, updated APP 1 obligations will also require entities that use automated computer programs to make decisions that significantly affect individuals' rights or interests to include specific disclosures in their privacy policy.
  • APPs 4–6 deal with unsolicited information, what you told people when you collected their data, and what uses and disclosures you can make.
  • APPs 7–8 deal with direct marketing and the rules that apply when personal information is sent overseas. Under APP 8, before you disclose personal information to an overseas recipient — including by using a US-based cloud platform — you must take reasonable steps to ensure that recipient will not breach the APPs. The entity making the disclosure remains accountable if the overseas recipient mishandles the data.
  • APPs 9–13 deal with government identifiers, data quality, security, access and correction. APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. Since December 2024, APP 11.3 makes explicit that 'reasonable steps' includes implementing technical and organisational security measures.

The Notifiable Data Breaches scheme

The Notifiable Data Breaches (NDB) scheme, contained in Part IIIC of the Privacy Act 1988 (Cth), applies to entities covered by the Privacy Act. An eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to one or more individuals — and the risk of serious harm cannot be prevented by remedial action.

When an entity becomes aware of grounds to suspect an eligible data breach, it must take all reasonable steps to complete an assessment within 30 calendar days. If the assessment confirms an eligible breach, the entity must notify the OAIC and affected individuals as soon as practicable.

The Spam Act 2003

The Spam Act 2003 (Cth) applies to commercial electronic messages — emails, SMS and instant messages sent for commercial purposes. Three conditions must be met: the recipient must have consented (express or inferred), the message must clearly identify who sent it, and it must include a functional unsubscribe mechanism. Consent records matter; if consent is later disputed, you need to be able to demonstrate when and how it was obtained.

The Australian Consumer Law and misleading conduct

The Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)) prohibits misleading or deceptive conduct. This reaches your privacy materials. If your published privacy policy says your business does not share personal information with third parties but your systems actually do — through analytics tools, advertising pixels or CRM integrations — that gap can constitute misleading conduct. Your external representations must accurately reflect what your systems actually do.

Sector-specific regimes

Health, financial services and telecommunications businesses carry additional obligations beyond the APPs. Health providers are subject to applicable state-based health records legislation as well as Commonwealth privacy law. Financial services firms have obligations under the Privacy (Credit Reporting) Code 2025. Telecommunications providers are regulated under the Telecommunications Act 1997 (Cth). If you operate in a regulated sector, map these requirements alongside the APPs early — they affect system design and vendor selection, not just policy documents.

What the 2024 amendments mean for your business

The Privacy and Other Legislation Amendment Act 2024 (Cth), which commenced 10 December 2024, made a set of changes that are directly relevant to business operators:

Expanded civil penalties. The OAIC can now seek civil penalties in court for interferences with privacy under s 13H of the Privacy Act 1988 (Cth), with a maximum of 2,000 penalty units ($660,000) for a covered entity. A new mid-tier penalty also applies to less serious (but still legally significant) interferences. This is a meaningful shift from the previous regime, where civil penalties were only available for serious and repeated breaches.

Infringement notices. The OAIC now has the power to issue infringement notices for administrative breaches — a faster enforcement pathway that does not require court proceedings.

APP 11 security floor. The amendment made explicit in APP 11.3 that 'reasonable steps' to secure personal information includes technical and organisational measures. This codifies what was already considered good practice and gives the OAIC a clearer basis to assess whether an entity's security posture met the standard.

Children's Online Privacy Code. The OAIC has been mandated to develop a Children's Online Privacy Code, which must be in place by 10 December 2026. If your platform or service is likely to be accessed by children, this is worth tracking now.

The documents your business needs

Compliance lives in practice, not just in policy. But the documents are where your legal obligations are made visible — to customers, staff, vendors and regulators. For most covered businesses, the essential set includes:

Privacy Policy. A publicly available document setting out what personal information you collect, why you collect it, how you use and disclose it, how you keep it secure, how individuals can access or correct their data, and whether you disclose information to overseas recipients. Under APP 1, this must accurately reflect your actual practices. If you use automated decision-making tools that significantly affect individuals, additional disclosures will be required from December 2026.

Privacy Collection Notice. A concise notice provided at or before the point of collection — typically a short statement in a web form, intake form or onboarding flow. It identifies who is collecting the information, the purpose, and how to find your full privacy policy. It complements rather than replaces your policy.

Data Processing Agreement. A contract with each third-party provider that processes personal information on your behalf — cloud storage, CRM platforms, analytics tools, marketing platforms and support desks. The agreement should address security obligations, confidentiality, breach notification timelines, sub-processor arrangements and what happens to data when the arrangement ends.

Information Security Policy. An internal document setting out access management, encryption standards, password requirements, device controls, backup procedures and how third-party access is managed. APP 11 requires reasonable steps to secure personal information; this document operationalises that requirement for your team.

Data Breach Response Plan. A practical playbook defining who does what when a breach is suspected. It should include the roles and escalation path, the 30-day assessment window, the criteria for an eligible data breach, communication templates, and record-keeping requirements. A plan that has never been tested is only marginally better than no plan.

Not all of these documents will be needed from day one by every business. The set that applies to you depends on how you collect information, which systems you use, how many people have access to personal data, and whether you operate across sectors or borders. The key is that the documents match how your business actually operates.

Where businesses actually fall short

Most data protection failures are not dramatic. They are quiet misalignments between what a business says it does and what its systems actually do. The patterns that tend to attract OAIC attention or generate complaints fall into a few consistent categories:

Privacy policies that are out of date or inaccurate. A policy drafted when the business launched and never updated is a liability. Every time you add a new tool, integration, vendor or product feature that touches personal information, your policy should be reviewed against your actual practices.

No records of consent. The Spam Act requires consent for commercial electronic messages. Collecting email addresses through a competition entry or a download does not automatically generate valid marketing consent. If you cannot demonstrate consent, you cannot demonstrate compliance.

Unsecured vendor access. Many businesses grant third-party platforms and integrations far broader access to customer data than they intend. Review your CRM, help desk, analytics and advertising integrations regularly. APP 8 means that when that data flows overseas, you remain responsible for how it is handled.

No breach process. The 30-day assessment window under the NDB scheme is tight when you are operating under pressure. If the first time your team thinks about breach response is during an actual incident, you will almost certainly miss steps and create compliance exposure alongside the operational disruption.

Collecting more data than you need. APP 3 limits collection to what is reasonably necessary for your functions or activities. Businesses that collect extensive data on the basis that it might be useful later run a larger security and compliance perimeter than they need to.

If your business suspects that personal information has been compromised, the NDB scheme imposes a structured response.

First, contain the incident — secure accounts, revoke access, isolate affected systems and stop further unauthorised access or disclosure. Document your actions from the outset.

Second, assess whether the breach is an eligible data breach. This means determining what information was involved, who is affected, and whether serious harm to any individual is a likely outcome. Examples of serious harm include financial loss, identity theft, discrimination, and physical harm. The Privacy Act does not prescribe a specific assessment methodology, but the OAIC expects the assessment to be reasonable, expeditious, and completed within 30 calendar days of becoming aware of grounds to suspect a breach.

Third, if the breach is eligible, notify the OAIC and affected individuals as soon as practicable. The notification must include what happened, what personal information was involved, what steps the individuals can take to protect themselves, and how they can contact you for further information.

Fourth, remediate — fix the gap that allowed the breach, review contributing controls, and keep records of the incident and your response whether or not notification was required.

Vendor cooperation matters significantly here. A breach involving a third-party provider requires prompt coordination under your data processing agreement to determine what data was involved, when the breach occurred, and what the provider has done to contain it.

The Privacy Act and the APPs are framework legislation — they set the standard of conduct, but applying them to a specific business requires judgement about how the rules interact with your particular systems, data flows, industry obligations and commercial arrangements. That is where legal advice adds value that a general guide cannot.

An Artificer Legal practitioner can help you:

  • assess whether and how the Privacy Act applies to your business, including any sector-specific obligations that sit alongside the APPs
  • draft or review your privacy policy, collection notices and internal security policy so they accurately reflect your actual practices and meet the current APP 1 standard
  • prepare data processing agreements with your vendors that allocate risk appropriately and set clear breach notification obligations
  • develop a data breach response plan that is calibrated to the 30-day NDB assessment window and your specific operations
  • advise on APP 8 obligations where your business uses overseas-hosted platforms or has offshore operations
  • guide you through an OAIC complaint or investigation if one arises

If your business has grown, changed its technology stack, or has not reviewed its privacy documents since the December 2024 amendments commenced, that review is the practical next step.

Privacy compliance is an ongoing practice

The most common and costly mistake Australian businesses make with data protection law is treating it as a one-time documentation exercise rather than an ongoing operational practice. A privacy policy published at launch and never touched again does not discharge your obligations under APP 1 — it creates a gap between your stated practices and your actual ones, and that gap is exactly what the OAIC's compliance sweeps and individual complaints are designed to find.

The 2024 amendments have raised the stakes. The OAIC now has broader civil penalty powers, faster enforcement tools, and the explicit ability to seek $660,000 in penalties in court for covered entities that breach the Act. For SMBs that assumed data protection law was something only large organisations needed to worry about, the current framework is a prompt to reassess.

Key points:

  • The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles are the primary framework for handling personal information in Australia. They apply directly to businesses with annual turnover above $3 million and to a range of smaller businesses depending on what they do.
  • Several other laws layer on top: the Notifiable Data Breaches scheme, the Spam Act 2003 (Cth) for commercial electronic messages, and the Australian Consumer Law's prohibition on misleading conduct.
  • The Privacy and Other Legislation Amendment Act 2024 (Cth), in force since December 2024, introduced expanded civil penalties, infringement notice powers, a codified security standard under APP 11, and a future Children's Online Privacy Code.
  • Every covered business needs at minimum a current and accurate privacy policy, a collection notice, data processing agreements with third-party vendors, and a data breach response plan.
  • The NDB scheme requires an assessment of any suspected eligible breach within 30 calendar days, followed by notification to the OAIC and affected individuals as soon as practicable if the breach is confirmed.
  • Data protection compliance is a continuous obligation — your documents and practices need to be updated each time your systems, vendors or data flows change.