1. Privacy is a statutory regime about personal information
  2. Confidentiality is a contractual and equitable duty about secret information
  3. Where the two regimes overlap
  4. A worked example: the agency engagement
  5. Common misconceptions worth flushing out
  6. Where Artificer Legal can help
  7. Conclusion

Privacy and confidentiality sit close enough together that founders, directors, and operators routinely treat them as one obligation. They aren't. They're two distinct legal regimes, with different sources, different triggers, and different remedies when something goes wrong. Conflating them is how businesses end up with a polished privacy policy and zero protection against an ex-employee walking out with the customer list — or, in the other direction, an airtight non-disclosure agreement and no idea what to do when an email export goes to the wrong recipient.

This article explains:

  • What privacy means under Australian law, and who it actually applies to.
  • What confidentiality means, where it comes from, and how it is enforced.
  • How the two regimes overlap in real situations.
  • A worked example of an information leak that engages both.
  • When you should bring a lawyer in, and what they will actually do.

Privacy is a statutory regime about personal information

Privacy in Australia is, for the most part, a creature of statute. The principal source is the Privacy Act 1988 (Cth), and the operative rules are the Australian Privacy Principles (APPs) in Schedule 1 of that Act. The APPs govern how an organisation may collect, use, disclose, store, and secure personal information, what notices it must give, and what rights individuals have to access and correct their data.

"Personal information" is broader than most people assume. It covers any information or opinion about an identified individual, or an individual who is reasonably identifiable — names, contact details, payment data, IP addresses, location data, photographs, health records, and increasingly, behavioural data tied back to an account.

Not every Australian business is bound by the APPs. The Act applies to APP entities, which include Australian Government agencies and private sector organisations with an annual turnover of more than $3 million. Smaller businesses are generally exempt, but several carve-outs override the exemption. According to the OAIC's small business guidance, a small business will still be covered if it is a private sector health service provider, trades in personal information, is a credit reporting body, is a contracted service provider for a Commonwealth contract, or is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), among other categories.

The regulator is the Office of the Australian Information Commissioner (OAIC). It investigates complaints, accepts notifications under the Notifiable Data Breaches scheme, and can pursue civil penalty proceedings for serious or repeated interferences with privacy.

Confidentiality is a contractual and equitable duty about secret information

Confidentiality is a different beast. It is not a single statute. It comes from two sources running in parallel:

  • Contract. A non-disclosure agreement, an employment contract, a supplier agreement, or a services agreement that includes a confidentiality clause. The parties decide what counts as confidential, what can be done with it, how long the obligation lasts, and what happens on breach.
  • Equity. Even without a contract, Australian courts will enforce an obligation of confidence where information has the necessary quality of confidence, was communicated in circumstances importing an obligation of confidence, and is being (or is about to be) used in an unauthorised way to the disclosing party's detriment. That equitable doctrine traces back to Coco v A N Clark (Engineers) Ltd and has been applied repeatedly by Australian courts.

What confidentiality protects is also different. It is not limited to personal information. It typically covers trade secrets, source code, pricing models, supplier terms, customer lists, financial forecasts, product roadmaps, and any other information a business treats as commercially sensitive. Much of that has nothing to do with individuals at all.

Enforcement looks different too. There is no regulator. The remedy lies with the party whose information was misused, and it is pursued through the courts — typically an injunction to stop further use or disclosure, an account of profits, or damages.

Where the two regimes overlap

The cleanest way to keep the distinction is to look at what the information is and where the obligation comes from.

  • A customer's email address is personal information. The Privacy Act governs how you collect and store it. If your supplier contract also says the supplier must keep your customer list secret, that same email address is also confidential information under that contract. Both regimes apply to the same data, in parallel.
  • A pricing model used internally is confidential information, but unless it identifies individuals, it is not personal information. Privacy law has nothing to say about it.
  • Anonymous, aggregated analytics about how many users clicked a button is neither. Once you re-identify an individual user, privacy law re-engages.

The practical point: one regime does not substitute for the other. A privacy policy will not protect your trade secrets. A non-disclosure agreement will not satisfy your APP obligations. A business handling customer and employee data needs both layers in place.

A worked example: the agency engagement

Picture a small e-commerce business with a $4.8 million annual turnover. It engages a marketing agency to run an email campaign and hands over its customer database — names, emails, purchase history, and a draft promotional pricing structure for the next quarter.

Two parallel obligations spin up.

On the privacy side, the business is an APP entity (above the $3 million threshold) and is disclosing personal information to a third party. APP 6 limits the purposes for which the agency can use that data; APP 11 requires reasonable steps to protect it. The business should give a collection notice or have one already in place via its privacy policy, and it should have a written data handling arrangement with the agency setting out permitted uses, security obligations, sub-processing, and what happens to the data at the end of the engagement.

On the confidentiality side, the pricing structure is commercially sensitive but is not personal information. Privacy law does not protect it. What does protect it is the services agreement with the agency, which should include a confidentiality clause defining the pricing data as confidential information, restricting its use to the engagement, and requiring the agency to return or destroy it on termination. If the agency then leaks the pricing to a competitor, the remedy is contractual, not regulatory.

Now reverse the leak. Suppose the agency emails a spreadsheet of customer addresses to a competitor by mistake. That is a privacy incident first — the business has to assess whether it is an eligible data breach under the Notifiable Data Breaches scheme, and if it is likely to result in serious harm, notify affected individuals and the OAIC. It is also a confidentiality breach against the contract — the business can pursue the agency for damages, indemnity, or termination.

Same engagement. Same data flow. Two different legal regimes engaged depending on the slice of information involved and the angle of the loss.

Common misconceptions worth flushing out

A few errors come up often enough to be worth flagging directly.

  • "We're under $3 million, so privacy law doesn't apply to us." Sometimes true, often not. Health service providers of any size are caught. Businesses that buy or sell personal information are caught. Contractors providing services to the Commonwealth are caught for the work done under that contract. AML/CTF reporting entities are caught. The threshold is a starting point, not a conclusion.
  • "Our privacy policy covers our confidentiality obligations." It does not. A privacy policy is a public-facing transparency document about personal information. It says nothing about your trade secrets, your supplier pricing, or your product roadmap, and it gives you no enforceable right against a third party who misuses that information.
  • "We have an NDA, so we're covered." An NDA addresses confidentiality. It does not satisfy any APP obligation, it does not create a privacy policy, and it does not relieve you of breach-notification duties under the Privacy Act.
  • "Confidentiality only applies if we mark something 'confidential'." Marking helps prove the intention, but information can be confidential by its nature and the circumstances in which it was shared, even without a label. Conversely, marking something confidential does not make it confidential if it is already public or trivial.
  • "The Privacy Act only applies to the data we store in Australia." The APPs follow the personal information, not the server. If you collect data from Australian individuals, the obligations apply, and APP 8 imposes additional accountability when you disclose that information overseas.

Most privacy and confidentiality work for a small or mid-sized business does not require litigation. It requires the right documents drafted to match what the business actually does, and a credible plan for the day something goes wrong. A solicitor working in this area will usually:

  • Map the data. Walk through what personal information and what confidential information the business holds, where it sits, who has access, and which third parties touch it. Most gaps are surfaced here, before any drafting starts.
  • Draft or update the privacy stack. A privacy policy that reflects actual practice, a collection notice for the point of capture, a data processing arrangement for each processor, and a breach response plan that nominates owners and timelines.
  • Draft or tighten the confidentiality stack. Non-disclosure agreements that survive a court's reasonableness test, employment contracts with confidentiality and intellectual property clauses that hold up post-termination, and supplier agreements with use restrictions and return/destruction obligations.
  • Triage an incident. When a breach happens, assess whether it engages the NDB scheme, advise on notification timing and content, manage communications with affected individuals, and pursue contractual remedies against any third party involved.
  • Train the team. A short, targeted session that translates the documents into day-to-day behaviour. Most breaches are operational, not technical.

If you want to talk through where your business sits on either regime, Artificer Legal can take you through a privacy and confidentiality review tailored to your operations.

Conclusion

Privacy and confidentiality are not synonyms, and the documents that protect one will not protect the other.

Privacy is a statutory regime under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It governs personal information, applies to APP entities (broadly, those above $3 million turnover plus several carve-out categories), and is enforced by the OAIC. Confidentiality is a contractual and equitable regime, applies to any information a business treats as secret regardless of whether it relates to a person, and is enforced privately through the courts. They overlap whenever the information involved is both personal and commercially sensitive, which in practice covers most customer and employee data a business holds. A serious approach needs both layers — the privacy stack and the confidentiality stack — drafted to match how information actually moves through the business and paired with a response plan for the day something goes wrong.