Your agency has just signed a retainer with a new client. Before you can run a single campaign you need to collect names, email addresses, behavioural data, and possibly sensitive profiling information. A colleague asks whether the agency needs a formal privacy policy. You are not sure — the business is not that big and you have always assumed that applied to larger companies.
That assumption is where marketing and advertising agencies most often go wrong. The decision is not simply about size.
The question behind the question
The Privacy Act 1988 (Cth) regulates how personal information is handled in Australia. Its obligations fall on "APP entities", a category that covers organisations — including companies, partnerships, trusts, and unincorporated associations in the private sector — that are bound by the Australian Privacy Principles (APPs).
Most small businesses sit outside the Act's reach because of the small business exemption in s 6D of the Privacy Act 1988 (Cth): an organisation whose annual turnover for the preceding financial year was $3,000,000 or less is ordinarily treated as a "small business operator" rather than an APP entity.
So the real question for a marketing agency is not just "are we big enough to be covered" — it is whether the agency fits one of the exceptions that pull small businesses back into the Act despite their size. For agencies, one exception is far more likely to apply than any other.
Trading in personal information removes the exemption
Section 6D of the Privacy Act 1988 (Cth) removes the small business exemption for any organisation that:
- discloses personal information about an individual to anyone else for a benefit, service or advantage; or
- collects personal information about an individual from someone else by providing a benefit, service or advantage in return.
The OAIC describes this as "trading in personal information". It captures arrangements that go beyond incidental data handling — classic examples include purchasing a mailing list, selling audience segments to a third party, or passing client contact data to a partner platform in exchange for an advertising tool or service.
For a marketing or advertising agency, this trigger is a genuine risk across day-to-day operations:
- Onboarding a data broker's audience list for a campaign
- Sharing a client's customer database with a retargeting platform under a commercial arrangement
- Receiving leads from a publisher under an arrangement where the agency provides something of value in return
The consent carve-out matters: collecting or disclosing personal information with the clear, informed consent of the individuals concerned does not constitute "trading in personal information" for the purposes of s 6D. If your data flows are properly consented, this exception does not catch you. If they are not — even for a single campaign — it may.
Turnover thresholds and when the Act applies
| Scenario | Likely outcome |
|---|---|
| Turnover above $3M, any structure | Covered by the Act — exemption unavailable |
| Turnover ≤ $3M, handles only own client data with consent | Likely not covered — exemption may apply |
| Turnover ≤ $3M, buys or sells audience data / mailing lists | Covered — trading in personal information trigger |
| Turnover ≤ $3M, uses client database without individual consent | Covered — same trigger |
| Turnover ≤ $3M, holds a Commonwealth contract | Covered — separate exception in s 6D |
| Turnover ≤ $3M, operates as a health service provider (unlikely for most agencies) | Covered — separate health exception |
The pattern is clear: the exemption is narrower than most small agency operators expect. If personal information changes hands commercially — without the consent of the individuals it concerns — size is irrelevant.
How much personal risk you are carrying
An agency that is an APP entity and does not have a compliant privacy policy is exposed in two directions.
First, there are direct enforcement consequences. The Office of the Australian Information Commissioner (OAIC) can investigate complaints and take enforcement action for breaches of the APPs. The OAIC can make determinations, accept enforceable undertakings, and seek civil penalty orders through the Federal Court. The Privacy and Other Legislation Amendment Act 2024 (Cth), which received Royal Assent on 10 December 2024, significantly strengthened the OAIC's enforcement powers and increased the penalties available for serious or repeated breaches. A new statutory tort of serious invasion of privacy also commenced on 10 June 2025, giving individuals a direct right of action in certain circumstances — relevant where an agency mishandles personal information in a way that causes harm.
It is worth noting that the small business exemption does not simply create a lower standard of care. If your agency is an APP entity, the full set of 13 APPs apply. That means obligations not just around having a policy, but around how you collect personal information (APP 3), what you do with it (APP 6), how you handle direct marketing (APP 7), how you secure it (APP 11), and how you respond to access and correction requests (APPs 12 and 13).
Second, there is commercial exposure. Clients — especially enterprise and government clients — increasingly conduct privacy due diligence on their agency partners before awarding work. A publicly accessible privacy policy is often the first thing checked. An agency without one may lose pitches, fail pre-qualification assessments, or be excluded from government procurement panels entirely. This is separate from legal risk, but in practice it often carries more immediate financial consequence for a growing agency.
What the policy itself needs to cover
Under APP 1.3, an APP entity must have a clearly expressed and up-to-date privacy policy. The policy must cover at minimum:
- The kinds of personal information the agency collects and holds
- How the agency collects and holds that information
- The purposes for which the agency collects, holds, uses and discloses personal information
- How individuals can access their personal information and seek corrections
- How individuals can complain about a privacy breach and how the agency will handle that complaint
- Whether the agency discloses personal information to overseas recipients, and if so, in which countries
For a marketing agency, the practical content additions beyond this baseline are material:
Third-party platform disclosures
Almost every digital campaign involves passing audience data to ad platforms, analytics tools, or media buyers. The policy should identify the categories of third parties involved and whether any of those recipients are located outside Australia. Where data flows offshore, APP 8 imposes additional obligations — the agency must take reasonable steps to ensure the overseas recipient handles the information consistently with the APPs, and can be held accountable if the recipient does not. For agencies using US-based ad tech stacks, this is not a theoretical concern.
Direct marketing opt-out
APP 7 regulates the use of personal information for direct marketing. Where an agency handles personal information on behalf of clients for marketing purposes, it must be able to demonstrate that individuals have a simple means to opt out of direct marketing communications, and that opt-out requests are acted on within a reasonable period.
Consent mechanisms
If consent is the basis on which you are collecting or disclosing personal information — particularly to avoid the trading-in-personal-information trigger — your policy should record what that consent looks like and how it is obtained. Under the APPs, consent must be voluntary, informed, current, and specific. A pre-ticked box buried in a terms and conditions document is unlikely to meet this standard. Your policy should describe the consent mechanism clearly enough that any individual reading it understands what they agreed to.
Accessibility
The policy must be freely available and in an appropriate form. For most agencies this means a dedicated page on the agency website, linked from the footer of every page and from any online form that collects personal information. The OAIC's Guide to developing an APP privacy policy provides practical checklists for drafting and publishing a compliant policy.
Why even exempt agencies benefit from having a policy
Even if your agency genuinely falls within the small business exemption today, there are three practical reasons not to rely on that indefinitely.
The exemption may be removed. The Australian Government has signalled that a second tranche of privacy reforms will address the small business exemption. If those reforms proceed, agencies currently below the threshold will become APP entities — and will need compliant policies from the date the changes commence.
Turnover fluctuates. A business that crosses $3,000,000 in annual turnover mid-growth does not get a grace period. Compliance obligations attach from the moment the exemption no longer applies. Building a policy before you need it takes less effort than retrofitting one under time pressure.
Client contracts require it. Enterprise clients and government agencies increasingly include privacy compliance warranties in service agreements. A well-drafted policy provides the documentary foundation for those warranties.
How Artificer Legal can help your agency
Determining whether your agency is an APP entity requires working through the specific facts of how your business handles personal information — the types of data involved, the commercial arrangements around it, and who has consented to what. The line between exempt and non-exempt is not always obvious, particularly where data sharing happens through platform intermediaries rather than direct disclosure.
Artificer Legal works with marketing and advertising agencies to make that determination, then designs and drafts a privacy policy that reflects how the business actually operates. That means going beyond a template to address your specific data flows, third-party relationships, and client contractual requirements. As the legislative landscape evolves — including potential removal of the small business exemption — we can review and update your documentation to keep it current.
Why the turnover figure is not the real test
The question "do we need a privacy policy" is really two questions: are you currently an APP entity, and will you still not be one next year? Marketing agencies that buy data, sell data, or share audience information without individual consent are almost certainly APP entities regardless of turnover. For those that are not, the exemption is conditional and may not survive the next round of reforms.
A privacy policy costs relatively little to get right the first time. The commercial cost of not having one — lost contracts, enforcement action, client attrition — is disproportionately higher. The threshold that matters most is not the $3,000,000 turnover figure; it is whether any personal information in your campaigns changes hands commercially without the knowledge and consent of the people it concerns.