- Why utilities businesses cannot rely on the small business exemption
- What counts as personal information in this sector
- The Consumer Data Right adds a separate layer
- What happens when there is a data breach
- Sharing data with third parties and industry participants
- Where Artificer Legal can help
- The detail that catches businesses out
If you run a utilities or environmental business — whether you supply electricity, gas, water, or environmental services — you are sitting on a significant volume of personal information about your customers and employees. Some of that data, such as smart meter readings or energy consumption patterns, can reveal far more about a person's daily life than many businesses realise. Getting your privacy obligations right is not optional, and for most utilities operators the question is not whether the Privacy Act 1988 (Cth) applies to you, but how comprehensively it applies.
Why utilities businesses cannot rely on the small business exemption
The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) it contains generally apply to organisations with an annual turnover above $3 million. Businesses below that threshold are ordinarily exempt. However, energy and water utilities fall into a specific exception.
Under the Act, an organisation that supplies goods or services where payment is deferred for seven days or more is treated as a credit provider. That description fits almost every electricity, gas, and water retailer — you send a bill after the service has been delivered, and customers pay later. As the Office of the Australian Information Commissioner (OAIC) explains, energy and water utilities are listed as examples of businesses that fall into this category regardless of turnover.
What this means in practice is that even a small utilities retailer operating well below $3 million in annual revenue must comply with the APPs. Environmental businesses that do not extend credit in this way, and whose turnover sits below the threshold, may still be exempt — but they should confirm their position before assuming the exemption applies. The OAIC's guidance for organisations sets out the full list of exceptions.
What counts as personal information in this sector
The APPs apply to "personal information" — any information or opinion about an identified individual, or an individual who is reasonably identifiable. For utilities and environmental businesses, the range of personal information you hold is broader than many operators appreciate:
- Customer contact and billing details — names, addresses, phone numbers, email addresses, and payment information
- Smart meter readings and consumption data — real-time energy usage records that can reveal when a property is occupied, sleep patterns, whether medical equipment is in use, and appliance usage at a granular level
- Distributed energy resource (DER) data — output from customer-owned solar panels or home batteries, which identifies specific properties and their energy generation and storage activity
- Employee information — tax file numbers, bank account details, payroll records, and health information where relevant to work
The OAIC has noted that metering data about electricity consumption can constitute personal information under the Privacy Act and that detailed consumption profiles may reveal sensitive information about individuals' habits and home circumstances. This means you should treat smart meter data with the same care as you would contact or financial information — not as a purely technical dataset.
Your obligations under the Australian Privacy Principles
The 13 APPs create a set of baseline obligations for every APP entity. For a utilities or environmental business, the most operationally significant ones are as follows.
Open and transparent management (APP 1)
You must have a clearly expressed, up-to-date privacy policy that explains how your business manages personal information. The OAIC's guide to developing an APP privacy policy specifies what it must cover, including the kinds of personal information you collect, how you collect it, the purposes for which you use and disclose it, how individuals can access or correct their information, and how to make a privacy complaint. The policy must be available free of charge — typically on your website.
Collection (APPs 3 and 5)
Only collect personal information that is reasonably necessary for your functions or activities. If you receive personal information that you did not solicit and would not have been permitted to collect, you must either destroy or de-identify it as soon as practicable. At or before the time of collection, you must notify individuals of the key matters set out in APP 5 — including who you are, the purposes of collection, and whether you are likely to disclose the information to anyone overseas.
Use and disclosure (APP 6)
You may use or disclose personal information only for the primary purpose for which you collected it, unless an exception applies. For example, if you collected a customer's address for billing purposes, you cannot share it with a third party for marketing purposes without consent. When sharing data with grid operators, market regulators, or industry partners — which utilities businesses do routinely — each disclosure must be justifiable under the APPs. Data-sharing agreements with counterparties should document what data is being shared, for what purpose, the security requirements on the receiving party, and what happens in the event of a breach.
Security (APP 11)
Under APP 11, you must take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. "Reasonable steps" is assessed against the circumstances, including the sensitivity of the information and the potential harm from a breach. For a utilities business holding smart meter data, consumption records, and employee financial details, you would be expected to implement measures such as access controls, encryption of data at rest and in transit, regular security testing, and staff training. Physical records — paper billing files, signed contracts — require equivalent protection. When you no longer need personal information for any permitted purpose, you must take reasonable steps to destroy or de-identify it.
Access and correction (APPs 12 and 13)
Individuals have the right to request access to the personal information you hold about them and to seek correction of inaccurate or out-of-date information. You must respond to an access request within a reasonable time and at no excessive charge. If you refuse access, you must provide reasons.
The Consumer Data Right adds a separate layer
Energy businesses designated as data holders under Australia's Consumer Data Right (CDR) framework face obligations that sit alongside, and are separate from, the APPs. The CDR is established under Part IVD of the Competition and Consumer Act 2010 (Cth), and the energy sector was brought into the scheme by the Consumer Data Right (Energy Sector) Designation 2020.
Under the CDR regime, designated data holders in the energy sector must:
- maintain the technical infrastructure to receive and respond to consumer data requests
- disclose product reference data (such as tariff structures and available plans) to accredited data recipients
- obtain the consumer's authorisation before sharing their data, and honour any withdrawal of that authorisation
- transfer consumer data securely to accredited recipients when authorised to do so
The ACCC administers the CDR rules and conducts compliance reviews of energy sector data holders. CDR obligations do not replace your privacy obligations under the APPs — both frameworks apply simultaneously, and the OAIC provides separate CDR privacy guidance for data holders.
Not every utilities or environmental business is a CDR-designated data holder. You should confirm whether your business is in scope and, if so, which obligations apply to your specific role in the energy supply chain.
What happens when there is a data breach
If your business is covered by the Privacy Act, you are also subject to the Notifiable Data Breaches (NDB) scheme. When a data breach is likely to result in serious harm to one or more individuals whose personal information is involved, you must:
- Assess within 30 days whether the breach meets the "eligible data breach" threshold
- Notify the OAIC by submitting a report through the OAIC's online portal
- Notify the affected individuals directly, including recommendations for steps they should take
An eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and the breach is likely to result in serious harm. Remedial action that successfully prevents the risk of serious harm before it materialises can avoid a notification obligation — but the 30-day assessment clock still starts from when the business becomes aware of the breach.
For a utilities business, a breach involving smart meter data, consumption records, or financial information could readily meet the "serious harm" test, given the sensitivity of what those records reveal. Having a documented incident response plan — with nominated contacts, escalation paths, and pre-agreed procedures — before a breach occurs will determine how effectively you can respond within the regulatory timeframe.
Sharing data with third parties and industry participants
Utilities businesses regularly share data beyond their own systems — with the Australian Energy Market Operator (AEMO), network service providers, metering coordinators, and environmental regulators. Each of these transfers carries privacy implications.
Before sharing personal information with any third party, confirm that the disclosure is permitted under APP 6. Where you are contracting with a service provider to handle personal information on your behalf (such as a cloud infrastructure provider or a metering data manager), ensure the contract includes:
- a clear description of what data is being shared and for what purpose
- security requirements the service provider must meet
- obligations to notify you of any security incidents or breaches involving your data
- restrictions on further disclosure or use of the data
If personal information will be sent outside Australia, the cross-border disclosure obligations in APP 8 apply. You are generally required to take reasonable steps to ensure the overseas recipient does not breach the APPs, and in many cases you remain accountable for how that recipient handles the data.
Where Artificer Legal can help
The privacy framework for utilities and environmental businesses involves decisions that an article cannot make for you. These include:
- Assessing your coverage — confirming whether your business is covered by the Act, which exceptions apply, and whether you are a CDR-designated data holder or accredited data recipient
- Drafting or auditing your privacy policy — ensuring your APP privacy policy satisfies the current requirements under the Act as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), which commenced its principal provisions on 11 December 2024
- Data-sharing agreements — preparing or reviewing contracts with third-party data processors, market participants, and overseas recipients to allocate privacy risk clearly
- Breach response planning — developing an incident response plan and testing your 30-day NDB assessment procedures before a breach occurs
- CDR compliance — mapping your data architecture against your CDR obligations and advising on any gaps
Artificer Legal's commercial and privacy practitioners work with utilities and environmental businesses to build compliance frameworks that are proportionate to the business, not just generically compliant. If you would like advice on your specific situation, contact our team.
The detail that catches businesses out
The most common misconception in this sector is that the $3 million turnover threshold offers a safe harbour for smaller operators. For utilities businesses, it does not. The deferred-payment exception pulls energy and water retailers into the Privacy Act regardless of size, and failing to recognise that can leave a business without a privacy policy, without APP-compliant data practices, and without a breach response plan — at the exact moment a regulator or a data incident makes those gaps consequential.
Key points from this article:
- The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles apply to utilities businesses regardless of annual turnover, because energy and water utilities are treated as credit providers under the Act's small business exemption exceptions.
- Smart meter data, consumption profiles, and distributed energy resource data can constitute personal information and may reveal sensitive lifestyle details — they must be treated accordingly under the APPs.
- APP 1 requires an up-to-date, publicly available privacy policy; APP 11 requires reasonable security steps; APP 6 restricts use and disclosure to the primary purpose of collection.
- Energy sector businesses designated as CDR data holders face additional obligations under the Competition and Consumer Act 2010 (Cth) and the CDR Rules, administered by the ACCC, separate from their Privacy Act obligations.
- The Notifiable Data Breaches scheme requires eligible breaches to be assessed within 30 days and, where the serious harm threshold is met, notified to the OAIC and affected individuals.
- Data-sharing agreements with third parties — including industry operators and overseas recipients — must address purpose, security, breach notification, and ongoing accountability.