- Who needs to comply: APP entities
- The 13 Australian Privacy Principles
- Having a privacy policy
- Privacy collection notices
- Data security obligations
- The Notifiable Data Breaches scheme
- Where businesses commonly go wrong
- How we can help with Privacy Act compliance
- The single most important thing to remember
If your business collects any personal information — customer names, email addresses, phone numbers, or payment details — you have legal obligations around how you handle that data. Those obligations come from the Privacy Act 1988 (Cth), and getting them wrong can lead to regulatory action, fines, and a serious hit to customer trust.
This article explains what "complying with the Privacy Act" actually means for a small-to-medium business owner. We will cover:
- Whether your business is covered by the Act
- The 13 Australian Privacy Principles and what they require day-to-day
- Privacy policies and collection notices
- Data security and breach notification
- Where businesses commonly slip up
Who needs to comply: APP entities
The Privacy Act 1988 (Cth) applies to "APP entities" — a term that covers Australian Government agencies and most private-sector organisations with an annual turnover of more than $3 million. It also covers some organisations below that threshold if they handle certain types of information, such as health information, or if they trade in personal information.
If your business has an annual turnover above $3 million, you are an APP entity and must comply with the Australian Privacy Principles. If your turnover is below $3 million, you may still be covered if your business:
- Provides a health service and handles health information
- Buys or sells personal information
- Is a contractor for a Commonwealth contract
- Operates a residential tenancy database
- Is related to a business that is already covered by the Act
If none of those situations apply and your turnover stays under $3 million, your business is generally exempt from the Act under the small business exemption. But exemption is not the same as immunity — if you send unsolicited commercial messages, those are regulated under the Spam Act 2003 (Cth), and the Australian Competition and Consumer Commission (ACCC) can still take action for misleading conduct around privacy. Many small businesses adopt privacy practices voluntarily because it builds trust and reduces risk.
The 13 Australian Privacy Principles
The Australian Privacy Principles (APPs) are the backbone of the Act. There are 13 of them, and they set out the standards for how APP entities must collect, use, store, and disclose personal information. You do not need to memorise all 13, but you do need to understand the ones that affect your daily operations.
The APPs group into five broad areas:
- Accountability and governance (APP 1) — you must manage personal information openly and transparently, and have a clearly expressed privacy policy
- Collection and notice (APPs 3–5) — you must only collect information you actually need, do it lawfully and fairly, and tell people what you are collecting and why
- Use and disclosure (APPs 6, 7–8) — you can only use or share personal information for the purpose you collected it, unless the person consents or an exception applies
- Data quality, security, and retention (APPs 10–11) — you must keep information accurate, secure it against misuse or loss, and destroy it when you no longer need it
- Access and correction (APPs 12–13) — individuals have the right to access their information and ask you to correct it
The full text of the APPs is available from the Office of the Australian Information Commissioner (OAIC).
Having a privacy policy
Under APP 1, if your business is an APP entity, you must have a privacy policy that is clearly expressed and up to date. You must make it available free of charge — typically on your website.
Your privacy policy should explain:
- What kinds of personal information you collect and hold
- How and why you collect it
- How you use and disclose it
- How you store it and keep it secure
- How individuals can access and correct their information
- How they can make a complaint about a privacy breach
- Whether you are likely to disclose information to overseas recipients and, if so, which countries
Even if the small business exemption means you are not required to have a privacy policy, having one is a straightforward way to show customers you take their privacy seriously. It also helps if a regulator or customer ever questions your practices.
Privacy collection notices
APP 5 requires APP entities to take reasonable steps to notify individuals when they collect personal information. This is not the same as your general privacy policy. A collection notice is specific to the interaction — it tells the person, at the point of collection, what information you are gathering and why.
A collection notice can be as simple as a short paragraph on a web form or a sign in a shop. The notice should cover:
- Your identity and contact details
- The fact that you are collecting the information
- The purpose of the collection
- The main consequences if they do not provide the information
- Who you might share the information with
- How the person can access or correct their information
- Whether you will send the information overseas
If you run an e-commerce store and collect a customer's delivery address through a checkout form, a collection notice might say: "We need your address to deliver your order. We will not share it with anyone outside our delivery partners. You can view our full privacy policy at [link]."
Data security obligations
APP 11 requires APP entities to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. What is "reasonable" depends on your business — a larger operation handling sensitive data will be expected to have stronger protections than a small retail shop collecting names and email addresses.
Practical steps that make a real difference include:
- Limiting access to personal information to only those employees who genuinely need it
- Using strong passwords and multi-factor authentication on systems that hold customer data
- Encrypting personal information, especially when sending it over the internet
- Regularly reviewing what data you hold and deleting what you no longer need
- Training staff on basic data handling practices
If you outsource data storage or processing to a third party (such as a cloud accounting platform), you remain responsible for the security of that information under the APP. You need to take reasonable steps to ensure your provider handles the data in a way that complies with the APPs.
The Notifiable Data Breaches scheme
If your business is an APP entity and experiences a data breach that is likely to result in serious harm to any affected individual, you must notify the OAIC and those individuals as soon as practicable. This is required under the Notifiable Data Breaches (NDB) scheme, which is part of the Privacy Act.
A data breach is any unauthorised access to or disclosure of personal information, or the loss of information that could lead to unauthorised access or disclosure.
When you become aware of a suspected breach, you should carry out a quick assessment. If your assessment confirms the breach is likely to result in serious harm, notification is mandatory. You must:
- Notify affected individuals directly (by email, phone, or letter)
- Notify the OAIC formally
- Include a description of the breach, the kinds of information involved, and recommended steps for affected individuals
The NDB scheme does not apply to businesses that are exempt from the Act under the small business exemption. But if you are exempt and still experience a breach, it is worth notifying affected customers anyway — it limits reputational damage and shows good faith.
Where businesses commonly go wrong
Even well-intentioned businesses make mistakes with privacy compliance. Here are the patterns that come up most often.
Assuming the small business exemption means zero obligations. If you handle health information, trade in personal data, or send marketing emails, you may be covered even with turnover below $3 million. And even if you are fully exempt, consumer law still applies — misleading customers about how you handle their data can attract ACCC action.
Collecting more information than needed. It is common to see businesses asking for phone numbers, dates of birth, or addresses when all they really need is an email address. If you do not have a clear purpose for holding a piece of information, do not collect it.
Not having a data breach response plan. Many businesses assume they will never be breached. The NDB scheme requires a timely response, and without a plan you waste critical hours figuring out who does what. A simple one-page plan is better than no plan.
Forgetting about third-party providers. If your CRM provider, email marketing platform, or cloud storage service suffers a breach, your customers' data is exposed — and your business carries the responsibility under APP 11. You need to check that your providers have adequate security measures.
How we can help with Privacy Act compliance
Privacy compliance is not a one-off task. It involves drafting documents, reviewing processes, training staff, and responding to incidents when they happen. An experienced privacy lawyer can help you get the framework right from the start.
Here is how we typically assist businesses:
- Assessing whether your business is covered. We review your operations, turnover, and the types of information you handle to determine whether you are an APP entity
- Drafting a privacy policy and collection notices. We create documents that are tailored to your business and compliant with the APPs
- Reviewing data handling practices. We look at how you collect, store, and share personal information and identify gaps
- Preparing a data breach response plan. We document the roles, steps, and timelines your team will follow if a breach occurs
- Responding to a breach. If you have already had an incident, we can guide you through the assessment and notification process
If you would like to discuss your business's privacy obligations, contact us.
The single most important thing to remember
The most common mistake Australian businesses make with the Privacy Act is treating compliance as a set of documents rather than a set of practices. You can have the best privacy policy on the internet, but if your staff are emailing spreadsheets of customer data to personal accounts or leaving client files on the shop counter, you are not complying.
Here is a summary of the key points covered in this article:
- The Privacy Act 1988 (Cth) applies to most businesses with annual turnover above $3 million, and to some smaller businesses that handle certain types of information
- The 13 Australian Privacy Principles govern how you collect, use, store, and disclose personal information
- APP entities must have a privacy policy, give collection notices, secure personal information, and notify the OAIC of serious data breaches
- The small business exemption is narrower than many business owners assume
- Practical compliance — how your team actually handles customer data day to day — matters more than the documents on your website