← Back to blog

Does the Privacy Act Cover Your Small Business in Australia?

August 26, 2026
Does the Privacy Act Cover Your Small Business in Australia?

If your business has an annual turnover exceeding $3 million, the Privacy Act applies to you, full stop. If you turn over less, you may still be covered if you handle health information, deal in trading personal information, hold tax file numbers, or work under a Commonwealth contract. Either way, three things need doing this week. Run the coverage check below, publish a clear privacy policy, and lock down your most sensitive data with multi-factor authentication (MFA).

  • Check the $3 million turnover threshold against activity-based triggers like health services or TFN handling.
  • Publish or refresh your privacy policy so it's easy to find and understand.
  • Secure high-risk data now and switch on MFA everywhere you can.

Pro Tip: If you already suspect a data breach, don't wait to finish reading. Start your assessment today. The clock on notification decisions starts the moment you become aware, not when you get around to it.

Key Takeaways

Small businesses that pass the $3 million turnover test, or trigger an activity-based exception, must meet Privacy Act obligations covering policy transparency, reasonable security steps, and breach notification.

PointDetails
Confirm coverage firstCheck the turnover threshold and activity triggers before assuming your business is exempt.
Publish a real policyCover collection, purpose, access, correction, and complaints in plain language.
Minimize what you collectReducing the personal information you hold is the cheapest way to cut breach risk.
Know the 30 day clockAssess suspected breaches promptly and document every step you take.
Get support to implementChampionbusinesscoaching helps owners turn these obligations into an owned, scheduled task list.

Table of Contents

Data Privacy for Small Business in Australia: The Coverage Test

Most owners assume the Privacy Act only applies to big companies. That's true only up to a point. The Privacy Act generally applies once annual turnover passes $3 million, and that figure includes income from all sources, not just your main revenue line. If you're a new business without a full year of trading, you need to project your turnover honestly rather than guess low.

Turnover isn't the only door in. Several activities pull a business under the Act regardless of size:

  • Providing a health service (this covers far more than clinics: naturopaths, gyms with health assessments, and allied health providers all count).
  • Trading in personal information, meaning you buy or sell personal data as part of how you operate.
  • Handling tax file numbers as part of your recordkeeping.
  • Working as a contractor under a Commonwealth contract.
  • Operating in credit-related roles or running a residential tenancy database.

If none of these apply and you're under the threshold, you're technically exempt. Many small businesses still choose to follow the Australian Privacy Principles anyway, because clients increasingly ask about data handling before signing a contract. Use the OAIC's small-business guidance to make the call, and write down your reasoning. If a client or regulator ever asks, you want a paper trail showing you actually checked.

What a Compliant Privacy Policy Actually Requires

Hands configuring wireless router settings

Coverage under the Privacy Act brings a specific set of obligations, and the privacy policy is where most businesses start. A compliant policy needs to be clearly written, current, and freely available to anyone who asks, not buried behind a login or a request form.

At minimum, it should spell out:

  • The types of personal information you collect and how you collect it.
  • Why you collect it and what you do with it.
  • How someone can access or correct their own information.
  • How to lodge a complaint if something goes wrong.
  • Whether any data goes overseas, and to whom.

This isn't just paperwork for its own sake. APP 1 requires open and transparent management of personal information, which means reasonable steps to build privacy into your actual systems and processes, not just a page on your website. When you change how you collect or use data, whether that's adding a new booking app or starting an email newsletter, the policy needs updating to match.

Pro Tip: Voluntarily opting into the APPs, even if you're under the turnover threshold, tends to reassure larger clients doing due diligence before they sign with you.

Low-Cost Security Steps That Satisfy APP 11

APP 11 requires taking reasonable steps to protect the personal information you hold and to destroy or de-identify it once you no longer need it. What counts as "reasonable" scales with your size and resources, so a five-person business isn't held to enterprise standards. Still, a handful of moves cover most of the risk:

  1. Collect less. Only ask for what you actually need. Practitioners consistently point to minimizing collection as the single most effective risk reducer for businesses with tight security budgets.
  2. Lock the technical basics down. Strong passwords, MFA on every account that allows it, encryption for anything sensitive, and a routine for patching software and backing up data.
  3. Train your people. Most breaches start with a person clicking the wrong thing, not a sophisticated hack. Role-based access limits the damage when someone does.
  4. Vet your vendors. Know where your cloud provider actually hosts your data, and check overseas recipients are bound by comparable privacy protections before you sign a contract.

Pro Tip: Ask every new supplier one question before you sign anything: where physically does our data sit? If they can't answer quickly, that's a red flag.

How to Handle the NDB Scheme When a Breach Happens

An "eligible data breach" under the Notifiable Data Breaches (NDB) scheme is one likely to cause serious harm that you can't otherwise mitigate. Not every incident qualifies. If you catch it fast and remediate before harm occurs, notification may not be required at all.

Work through it in order:

  1. Contain it. Stop the bleeding first, whether that's revoking access or pulling a system offline.
  2. Gather the facts. What data, how many people, how did it happen.
  3. Assess the harm. You typically have 30 days to complete this assessment once you become aware of a suspected breach.
  4. Remediate where you can, and document every decision along the way. That paper trail is your evidence of a reasonable process.
  5. Notify if required. Tell the OAIC and affected individuals, covering what happened, what information was involved, and what steps people should take.

When more than one business is involved, such as a shared platform or a joint venture, one entity should take the lead on notifying rather than everyone scrambling separately. The OAIC's quick reference guide walks through exactly this kind of multi-party scenario.

A Prioritized Privacy Checklist for Small Business Data Protection

Prioritized data protection checklist for small businesses

Trying to fix everything at once is how compliance projects stall. Break it into three timeframes instead.

Immediate, within 7 days:

  • Finalize your coverage decision and document it.
  • Publish or update your privacy policy.
  • Identify your highest-risk data and lock it down.
  • Turn on MFA everywhere it's available.

Within 30 days:

  • Review contracts with vendors and cloud providers.
  • Set a data retention schedule, so you're not hoarding information you no longer need.
  • Run a short staff training session on handling personal information.
  • Confirm backups and patching are actually happening, not just scheduled.

Ongoing, annually:

  • Check new projects for privacy risk before launch, not after.
  • Review the policy against how your business actually operates now.
  • Run a tabletop exercise: walk through a mock breach and see where the gaps are.

A Coach's View on Making Privacy Compliance Actually Happen

Most small business owners don't struggle to understand what the Privacy Act wants. They struggle to turn OAIC guidance into something someone on the team actually owns and does. That gap between reading the rules and running them day to day is where coaching earns its place.

Assigning one named person as the "privacy owner" inside a small team, even part time, tends to move a business from "we should probably look at this" to a published policy and a working checklist within weeks rather than months.

Why Most Compliance Advice Gets the Priority Order Backward

Most guides on this topic lead with the legal architecture: the Act, the APPs, the NDB scheme, in that order. It reads thoroughly, but it buries the one decision that actually matters first, whether your business is covered at all, under three layers of legislative detail before the reader gets an answer.

The turnover test and the activity triggers deserve to come first because they determine everything downstream. A five-person bookkeeping firm handling TFNs has the exact same obligations as a $10 million company, yet most owners assume size alone protects them from scrutiny. It doesn't.

The other place conventional advice falls short is treating "reasonable steps" as a fixed checklist rather than a scaled expectation. A solo tradie and a 40-person NDIS provider don't need identical security setups, but plenty of generic guides imply they do, which either scares small operators into paralysis or gives them false confidence that a template policy is enough.

Start with the coverage question, be honest about your answer, then size your security effort to match your actual risk. Everything else in this space is implementation detail.

— Duncan

Get Hands-On Help Turning Privacy Rules Into Daily Habits

Reading the OAIC's guidance is one thing. Actually getting a privacy policy published, a staff checklist adopted, and someone accountable for keeping it current is where most small businesses stall out. That's the gap Championbusinesscoaching works in every week with Australian business owners.

Championbusinesscoaching

Coaching sessions turn the checklist above into an assigned task list with real deadlines, not another document sitting in a shared drive. That includes help drafting the actual policy language, running a short staff training session on handling customer data, and setting up simple accountability systems so compliance doesn't quietly slide once the initial push is over. This isn't legal advice, and nothing here replaces a lawyer for genuinely complex cases, but it closes the distance between "we know what we're supposed to do" and actually doing it. If you want a plan built around your specific business rather than a generic template, book a consultation with Championbusinesscoaching and get your privacy priorities mapped out in your first session.

Official Resources and Practical Templates to Consult Now

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources