Skip to content
Operations HubIT & Cybersecurity

Data Privacy Obligations: What Australian Businesses Must Do

Most Australian business owners have a working understanding of technology and security. You know the basics.

By Andrew Northcott·27 May 2026·5 min read·Last reviewed 8 July 2026

The short answer

Australian businesses covered by the Privacy Act must handle personal information in line with the Australian Privacy Principles: collect only what's needed, secure it, use it for the stated purpose, allow access and correction, and maintain a privacy policy. Eligible data breaches must be reported under the Notifiable Data Breaches scheme. Whether you're covered depends on turnover and activity, so confirm your obligations with the Office of the Australian Information Commissioner.

Data privacy in Australia isn't a single rulebook you tick off once. It's a set of obligations that scale with the kind of information you hold, how you collect it, and what happens when something goes wrong. The good news is that the core of it is practical, not abstract — most of what the law asks is what a careful business would do anyway.

Whether the Privacy Act applies to you

The Commonwealth Privacy Act and its Australian Privacy Principles (APPs) apply to most businesses above a turnover threshold set by the ATO and Office of the Australian Information Commissioner (OAIC), plus certain smaller businesses regardless of size — health service providers, businesses that buy or sell personal information, contractors handling Commonwealth data, and a few others. If you're a small operator today, don't assume you're permanently exempt: the exemption is under active review, and being covered by the APPs is increasingly the expected baseline even where it isn't strictly mandatory. Treat compliance as the sensible default rather than something to avoid.

What the Australian Privacy Principles actually require

The APPs run across the whole lifecycle of personal information. In plain terms, they ask you to:

  • Collect only what you need, by lawful and fair means, and tell people at the point of collection why you're collecting it and who you might share it with.
  • Keep a current privacy policy that's genuinely accessible — not a wall of boilerplate no one can find.
  • Use information only for the purpose you collected it for (or a directly related purpose the person would reasonably expect), and get consent for anything beyond that, particularly direct marketing.
  • Keep it accurate and secure, protecting it from misuse, loss, and unauthorised access.
  • Give people access to their own data and let them correct it when it's wrong.
  • Handle sensitive information — health, biometrics, racial or religious details — to a higher standard, generally requiring express consent.

Sending personal information overseas (including to offshore cloud servers) carries its own obligations: you generally remain accountable for how an overseas recipient handles it, so know where your data actually lives.

The Notifiable Data Breaches scheme

If you're covered by the Privacy Act, the Notifiable Data Breaches (NDB) scheme applies. When a breach is likely to result in serious harm to the people affected and you can't contain it, you must notify both the OAIC and the affected individuals as soon as practicable. The trigger isn't "was there a breach" — small incidents happen — it's "is serious harm likely." That's why you need to be able to assess an incident quickly. Decide in advance who makes the call, what evidence you'll need, and how you'll reach affected customers. A breach discovered at 5pm on a Friday is not the moment to invent your response plan.

Practical steps that keep you compliant and out of trouble

The obligations become manageable when you turn them into a small number of standing habits:

  • Map what you hold. You can't protect or honour requests over data you can't locate. List where personal information lives — CRM, accounting system, email, spreadsheets, that shared drive everyone forgot about.
  • Minimise and delete. The safest data is data you no longer hold. Set retention periods and actually purge information you no longer have a lawful reason to keep.
  • Secure the basics. Multi-factor authentication, patched systems, restricted access, and encrypted backups map neatly onto the ASD's Essential Eight and cover most real-world breach causes. This is where privacy and cybersecurity meet.
  • Train the people who touch data. Most breaches are human — a misdirected email, a reused password, a phishing click. A short, repeated staff briefing does more than a thick policy no one reads.
  • Vet your suppliers. Your payroll bureau, cloud vendor, and email platform all hold your customers' data. Their security is effectively your security.

Privacy work also connects to how your wider back office is set up — clean systems, clear ownership, and good record-keeping make compliance far less painful. If that foundation is shaky, it's worth reading our guide to the modern SME back office alongside this.

Where to keep watch

Australian privacy law is mid-reform. Expect the definition of "personal information" to broaden, the small-business exemption to narrow, and individuals to gain stronger rights. The direction of travel is clear: more accountability, not less. Building good habits now means the changes ask less of you later.

This is general information, not legal advice. Because privacy obligations are regulated and evolving, confirm your specific position with the OAIC's current guidance or a qualified adviser before acting on anything with legal consequences.

About the author

Andrew Northcott

Founder & Chairman, Valont

Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.