1. What the Privacy Act covers and who it applies to
    1. What counts as personal information
  2. The Australian Privacy Principles — what they require
  3. The notifiable data breaches scheme
  4. Where businesses commonly get this wrong
    1. No privacy policy, or a policy that is out of date
    2. No collection notices at the point of collection
    3. No data processing agreements with vendors
    4. Forgetting that the employee records exemption is limited
    5. Treating the AUD 3 million exemption as complete protection
  5. How Artificer Legal can help with your privacy framework
  6. Getting the foundations right

Customer data is one of the most valuable things your business collects — and one of the most regulated. Australia's privacy laws set specific rules for how you gather, use, store, disclose, and ultimately dispose of personal information. Getting this wrong can mean regulatory action, financial penalties, and the harder-to-quantify cost of losing customer trust.

This article explains what the Privacy Act 1988 (Cth) requires, which businesses it applies to, what the Australian Privacy Principles cover, how the notifiable data breaches scheme works, and the practical steps you need to take to build a framework that holds up.

What the Privacy Act covers and who it applies to

Australia's primary privacy statute is the Privacy Act 1988 (Cth), administered by the Office of the Australian Information Commissioner (OAIC). It is supported by the Australian Privacy Principles (APPs) — 13 principles that govern how organisations handle personal information across its full lifecycle.

The Act applies to:

  • Australian businesses and not-for-profits with an annual turnover of more than AUD 3 million
  • Health service providers regardless of size (including allied health, telehealth, and wellness operators)
  • Businesses that trade in personal information for benefit, service, or advantage
  • Commonwealth government agencies and their contracted service providers
  • Some credit reporting bodies, tax file number recipients, and other specifically defined entities

If your business falls below the AUD 3 million turnover threshold and does not fall into an exception category, you may be exempt. However, that exemption is narrower than many businesses assume. A business that collects health information, operates a website capturing personal data, or holds contracts with government entities may be covered regardless of size.

Even exempt businesses have good reasons to follow the APPs. Enterprise clients increasingly require privacy compliance as a contractual condition, and privacy-conscious practices reduce the risk of data breaches and associated reputational harm.

What counts as personal information

Personal information is any information or opinion about an identifiable individual — including names, email addresses, phone numbers, postal addresses, payment identifiers, IP addresses linked to a person, and device identifiers where they can identify someone. Sensitive information — which includes health data, biometric information, racial or ethnic origin, religious beliefs, and criminal record information — attracts stricter rules, including mandatory consent for collection in most circumstances.

The Australian Privacy Principles — what they require

The 13 APPs are grouped by function. Here is what they require in practice:

Transparency and openness (APPs 1–2): Organisations must have a clearly expressed, up-to-date privacy policy, and where practicable must allow individuals to interact anonymously or using a pseudonym.

Collection (APPs 3–5): You can only collect personal information that is reasonably necessary for your functions or activities, collected by lawful and fair means. At or before the time of collection, you must notify individuals of how the information will be used and who it will be disclosed to.

Use and disclosure (APPs 6–7): Personal information can generally only be used or disclosed for the purpose for which it was collected (or a directly related secondary purpose the individual would reasonably expect). Direct marketing using personal information must comply with APP 7, including mandatory unsubscribe mechanisms.

Cross-border disclosure (APP 8): Before disclosing personal information to an overseas recipient — including sending data to a cloud platform hosted overseas — you must take reasonable steps to ensure the recipient handles it in a way that is consistent with the APPs, or obtain the individual's consent to the cross-border disclosure.

Security and destruction (APP 11): You must take reasonable steps to protect the personal information you hold from misuse, interference, loss, and unauthorised access, modification, or disclosure. When you no longer need the information for a permitted purpose, you must take reasonable steps to destroy it or permanently de-identify it.

Access and correction (APPs 12–13): Individuals have the right to request access to and correction of their personal information. Requests must be responded to within a reasonable time, and you must not charge a fee for making a request.

The notifiable data breaches scheme

Australia's Notifiable Data Breaches (NDB) scheme, which operates under Part IIIC of the Privacy Act 1988 (Cth), requires organisations covered by the Act to notify the OAIC and affected individuals when an eligible data breach occurs.

An eligible data breach occurs when:

  • There is unauthorised access to, disclosure of, or loss of personal information held by the entity
  • A reasonable person would conclude that the access, disclosure, or loss is likely to result in serious harm to any of the individuals whose information is involved

Common examples include: a phishing attack that compromises customer email accounts, ransomware that encrypts and exfiltrates customer data, or a staff member accidentally emailing a client list to the wrong recipient.

If a breach occurs, you must:

  1. Promptly assess whether the breach meets the eligible data breach threshold
  2. If it does, notify the OAIC and affected individuals as soon as practicable
  3. Your notification to individuals must describe the breach, the kinds of information involved, and what steps you recommend they take to protect themselves

Where there is uncertainty about whether serious harm is likely, the Act permits a 30-day period to assess before the notification obligation is triggered. However, containment steps — revoking compromised credentials, patching vulnerabilities — should begin immediately regardless of the assessment timeline.

Where businesses commonly get this wrong

No privacy policy, or a policy that is out of date

The APPs require you to have a clearly expressed privacy policy and to make it available to anyone who asks. Many businesses either have no policy, or have one that was generated years ago and does not reflect how the business actually operates. A policy that lists categories of data you do not actually collect, or fails to mention third-party platforms you send data to, can itself be misleading.

No collection notices at the point of collection

A privacy policy explains your overall practices — but the APPs also require a collection notice at or before the time of collection. This is the short statement that appears on a form, at checkout, or on a sign-up page telling the person why you are collecting their information and what you will do with it. Many businesses have a privacy policy linked in the footer but nothing at the actual collection point.

No data processing agreements with vendors

Most businesses use third-party platforms — email marketing tools, CRMs, cloud storage, analytics services — that process personal information on their behalf. APP 8 requires you to take reasonable steps to ensure overseas recipients handle data appropriately. Without a data processing agreement (DPA) with your key vendors, it is difficult to demonstrate you have met this obligation.

Forgetting that the employee records exemption is limited

The Privacy Act 1988 (Cth) includes an exemption for employee records in the context of the current employment relationship. However, this exemption does not cover job applicants, independent contractors, or former employees' ongoing claims. Businesses that assume the exemption covers all HR data are exposed.

Treating the AUD 3 million exemption as complete protection

Small businesses below the turnover threshold that handle health information, trade in personal data, or supply services to Commonwealth agencies are covered regardless of size. The exemption should be checked against the specific exceptions before assuming it applies.

Privacy compliance is not a one-time project — it requires an initial build and ongoing maintenance. Artificer Legal can assist with:

  • Privacy Act coverage assessment — reviewing whether the Act applies to your business given your size, sector, and activities
  • Privacy policy drafting — a policy that accurately reflects your actual data practices and meets APP 1 requirements
  • Collection notice templates — short-form notices for forms, checkout pages, and other collection points
  • Data processing agreements — vendor agreements that address APP 8 cross-border disclosure obligations
  • Data breach response planning — preparing a response plan so that if a breach occurs, you can act quickly within the NDB scheme's requirements
  • Privacy audits — reviewing existing practices and documentation to identify gaps before a regulator or a client does

Getting the foundations right

The single most important thing most businesses can do to improve their privacy compliance is to map their data — list what personal information they actually collect, where it goes, who can access it, and which vendors process it on their behalf. Without that map, a privacy policy is speculative and a data breach response plan cannot be specific. The map is the foundation that makes every other document accurate.

Key points:

  • The Privacy Act 1988 (Cth) applies to businesses with annual turnover above AUD 3 million, health service providers regardless of size, and others in specific categories — the small business exemption has meaningful limits.
  • The 13 Australian Privacy Principles cover the full information lifecycle: collection, use, disclosure, security, cross-border transfers, and individuals' access and correction rights.
  • APP 11 requires active steps to secure and eventually destroy or de-identify personal information — not just avoiding obvious breaches.
  • Under the Notifiable Data Breaches scheme, eligible data breaches — those likely to cause serious harm — must be notified to the OAIC and affected individuals as soon as practicable.
  • A privacy policy, collection notices at the point of collection, and data processing agreements with key vendors are the minimum documentation most covered businesses need.