1. Who must comply: the $3 million turnover test
    1. When small NFPs are covered regardless of turnover
  2. The core duty: a clearly expressed and up-to-date privacy policy
  3. The supporting duties that turn the policy into practice
  4. When a data breach happens: the notification duty
  5. What happens if you do not comply
  6. A privacy compliance checklist
  7. When a lawyer should help
  8. The rule that catches most NFPs out

Charities and not-for-profits (NFPs) collect personal information every day: donor names and card details, member contact lists, volunteer records and, in many cases, sensitive information about the people who use their services. If your organisation is covered by the Privacy Act 1988 (Cth) (the Act), having a privacy policy is not optional. Australian Privacy Principle (APP) 1.3 makes it a legal requirement to maintain a clearly expressed and up-to-date privacy policy, and APP 1.4 prescribes what that policy must contain.

Whether the obligation applies to you at all turns on a $3 million turnover test and a list of exceptions that catch more small NFPs than most people expect. This article sets out who must comply, what the policy must cover, the supporting duties that sit around it, what happens if you breach the Act, and where a lawyer can help.

Who must comply: the $3 million turnover test

The Act binds APP entities, which are agencies and organisations. An organisation is an individual, body corporate, partnership, unincorporated association or trust: see s 6C of the Privacy Act 1988 (Cth). Most charities fit this definition. An incorporated association or a company limited by guarantee is a body corporate, and an unincorporated association is caught by the last limb, so the structure of your NFP rarely takes you outside the Act by itself.

The key carve-out is the small business exemption. An organisation does not include a small business operator, and a business is small if its annual turnover for the previous financial year was $3,000,000 or less: s 6D(1) of the Act. Newly started businesses are tested against their current year figures: s 6D(2).

Three features of the turnover test matter for NFPs in particular:

  • Turnover is gross income, not profit: Annual turnover includes the proceeds of sales, commission, rent and leasing income, interest, royalties and dividends, government bounties and subsidies and other operating income: s 6DA of the Act. The Office of the Australian Information Commissioner (OAIC) puts it simply: annual turnover includes all income from all sources, but not assets held, capital gains or the proceeds of capital sales. For an NFP, that means donations, membership fees and government grants all count towards the $3 million.
  • Once over the line, you stay there: You stop being a small business operator if your turnover exceeded $3 million in any financial year that has ended since you began operating: s 6D(4)(a). A single strong fundraising year is enough to bring your organisation permanently within the Act, even if turnover falls again afterwards.
  • The exemption is on borrowed time: Following the Privacy Act Review, the Commonwealth Government has said it will remove the small business exemption as part of the next tranche of privacy reform. That legislation had not been enacted at the time of writing, so the exemption remains in force, but any NFP close to the threshold should expect to be covered within the next few years.

When small NFPs are covered regardless of turnover

Even a small NFP is not a small business operator if it falls into one of the categories in s 6D(4) of the Act:

  • Health services: If your organisation provides a health service and holds health information, the exemption does not apply. Health services are defined broadly and include assessing, maintaining, improving or managing a person's health, and services provided in the course of aged care, palliative care or disability care: s 6FB. The OAIC notes that an NFP can be caught even when health care is not its primary activity, such as a club that runs an injury or fitness program for members.
  • Trading in personal information: You lose the exemption if you disclose personal information to anyone else for a benefit, service or advantage, or provide a benefit to collect personal information from someone else: s 6D(4)(c) and (d). The OAIC gives the example of a charity that sells or swaps its donor list in exchange for sponsorship benefits. Disclosures made with the individual's consent or as required by law do not count: s 6D(7).
  • Commonwealth contracts: A contracted service provider under a Commonwealth contract is covered even if small, which affects many aged care and disability service providers: s 6D(4)(e).
  • Related bodies corporate: A body corporate related to a larger entity that is subject to the Act is covered too, for example an NFP that is part of a global network whose parent exceeds the threshold: s 6D(9).

Small business operators in certain roles are also treated as organisations, including reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth): s 6E(1A) of the Act. That provision will matter from 1 July 2026, when the expanded anti-money laundering regime brings new classes of businesses within the definition of reporting entity.

Finally, an exempt small business operator can choose to be treated as an organisation by registering a choice with the Commissioner: s 6EA of the Act. Some NFPs opt in deliberately as a public commitment to good privacy practice.

The core duty: a clearly expressed and up-to-date privacy policy

If your NFP is an APP entity, the central obligation is APP 1.3: you must have a clearly expressed and up-to-date policy about how you manage personal information, known as the APP privacy policy.

APP 1.4 requires the policy to contain at least the following:

  • the kinds of personal information your NFP collects and holds;
  • how you collect and hold that information;
  • the purposes for which you collect, hold, use and disclose personal information;
  • how individuals can access their personal information and seek correction of it;
  • how individuals can complain about a breach of the APPs and how you will deal with a complaint; and
  • whether you are likely to disclose personal information to overseas recipients and, where practicable, the countries in which they are located.

"Clearly expressed" means plain language that the people dealing with your NFP can actually follow, with structure and headings rather than dense legal prose. "Up to date" means the policy must reflect what you genuinely do. If your NFP later starts sharing donor data with a fundraising platform, or begins collecting health information for a new program, the policy needs to change at the same time. The OAIC publishes a free guide to developing an APP privacy policy, and its APP 1 guidelines explain how the principle is applied.

The policy is not a standalone document. APP 1.2 requires you to take reasonable steps to implement practices, procedures and systems that ensure your NFP actually complies with the APPs and can deal with inquiries and complaints. A policy that sits on a website while staff and volunteers handle donor records however they like is not compliance.

The supporting duties that turn the policy into practice

The other APPs give the policy its content. The ones NFPs most often need to build into their operations are these:

  • Collect only what you need, and say so: Under APP 3 and APP 5, collect only the personal information you genuinely need, collect it from the individual where that is reasonable, and notify people at or before collection of what you are collecting and why.
  • Handle sensitive information carefully: Sensitive information includes health information and information about religious beliefs and political opinions. Collecting it generally requires consent: APP 3.3. This matters for charities that hold client health records or membership data revealing religious affiliation.
  • Use and disclose for the primary purpose only: Under APP 6, personal information should only be used or disclosed for the purpose it was collected, unless an exception applies. Sharing a donor list with another NFP for its own appeal is an unrelated purpose and requires consent.
  • Direct marketing and fundraising: APP 7 restricts using personal information for direct marketing, which covers fundraising appeals. You must provide a simple way to opt out, honour opt-out requests and, if asked, tell a person where you got their information from. Communications caught by the Spam Act 2003 (Cth) or the Do Not Call Register Act 2006 (Cth) are dealt with under those laws.
  • Secure what you hold: APP 11.1 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. The OAIC's NFP guidance points to staff and volunteer training, multi-factor authentication on important accounts, access controls and keeping systems patched.
  • Do not keep donor records forever: APP 11.2 requires you to destroy or de-identify personal information once it is no longer needed. The OAIC has flagged indefinite retention of supporter data as a key compliance issue for NFPs, and recommends written retention periods for each category of donor data.
  • Give people access and correction: Under APPs 12 and 13, individuals can ask to see the personal information you hold about them and have it corrected, and you must respond within a reasonable period.
  • Know where data goes overseas: APP 8 makes your NFP accountable for personal information disclosed to overseas recipients, including cloud platforms that store donor data outside Australia. This is why the policy must state whether overseas disclosure happens and where.

When a data breach happens: the notification duty

The Act's Part IIIC creates a separate, time-critical duty. If there are reasonable grounds to believe an eligible data breach has occurred, your NFP must notify affected individuals and the OAIC as soon as practicable: s 26WL of the Act. An eligible data breach is, broadly, unauthorised access, disclosure or loss of personal information that is likely to result in serious harm to any of the individuals concerned: s 26WE. The Commissioner can also direct an entity to notify if it has not done so: s 26WR.

For an NFP, a hacked donor database containing names, addresses and card details is the classic scenario, but so is a lost laptop holding client health records or an email sent to the wrong distribution list. The OAIC recommends having a data breach response plan in place before anything goes wrong.

What happens if you do not comply

The consequences sit at two levels: the OAIC can investigate complaints, attempt conciliation and make determinations, and the Federal Court can order civil penalties.

  • APP 1.3 and APP 1.4 are themselves civil penalty provisions for which the OAIC can issue infringement notices or compliance notices: s 13K of the Act. Failing to have a policy at all is therefore a direct, enforceable breach, not merely an administrative gap.
  • A serious interference with privacy attracts a maximum penalty for a body corporate of the greater of $50,000,000, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover during the breach period: s 13G(3). For other entities the maximum is $2,500,000: s 13G(2). Whether an interference is "serious" depends on factors such as the sensitivity of the information, the number of people affected and whether children or vulnerable people were involved: s 13G(1B).
  • Interferences that are not serious still carry penalties of up to 2,000 penalty units: s 13H(3).

There is also the reputational dimension, which for a donation-funded NFP can be the most damaging of all. The OAIC's guidance to NFPs notes that a privacy failure can jeopardise funding and public support, in addition to causing real harm to the clients, donors and supporters whose information is exposed.

A privacy compliance checklist

Work through these steps to put your NFP on a sound footing:

  • Confirm whether the Act applies: apply the turnover test, then check the s 6D(4) exceptions, related bodies corporate and any reporting entity status. Reassess at least once a year.
  • If covered, draft the APP privacy policy to the APP 1.4 contents list and publish it where people can find it, free of charge.
  • Build the APP 1.2 practices behind the policy: assign someone to own privacy, train staff and volunteers, and set up a channel for privacy inquiries and complaints.
  • Map the personal information you hold, where it is stored and how long you keep it, and write retention and destruction processes for donor, member and client data.
  • Check your fundraising practices against APP 7, including opt-out mechanisms and the handling of donor lists.
  • Prepare a data breach response plan covering detection, containment, assessment and the Part IIIC notification steps.
  • If you are exempt but want to signal good practice, consider opting in under s 6EA, and keep an eye on the tranche 2 reforms that will remove the small business exemption.

When a lawyer should help

The threshold questions are where legal advice earns its keep. Working out whether the exemption applies can be genuinely difficult when an NFP provides some health services, exchanges data with sponsors, or sits inside a larger network. A lawyer can map your activities against s 6D(4) and advise on whether you are an APP entity.

Once you know you are covered, a lawyer can draft the APP privacy policy so it satisfies APP 1.4 and, just as importantly, matches the practices your organisation actually follows. Where state and territory health records laws apply alongside the federal Act, a lawyer can coordinate the two. And when a data breach happens, legal input on whether notification is required, and to whom, can prevent a bad situation from becoming a regulatory one.

The rule that catches most NFPs out

The small business exemption gives many NFPs a false sense of security, because two of its exceptions are so easy to trip. A community club that runs an injury program, or a charity that swaps a donor list for sponsorship benefits, is within the Act regardless of how small its turnover is, and the health services exception applies even where care is not the organisation's main activity. Add a single financial year above $3 million, and the exemption is gone for good.

The first action this week is to decide which side of the line your NFP is on. If you are covered, the policy is a legal requirement, not a best-practice extra, so check that it exists, that it meets the APP 1.4 contents, and that it describes what your organisation actually does with the personal information it holds.