- Who the APPs apply to
- Understand whether you even hold "personal information"
-
The core duties
- Maintain an open and transparent privacy policy
- Notify people when you collect their information
- Use and disclose information only within your stated purpose
- Take reasonable steps to keep it secure
- Manage overseas disclosure carefully
- Handle direct marketing with care
- Give people access and let them correct their data
- Notify eligible data breaches
- Consequences of getting it wrong
- A practical compliance checklist
- Where professional help usually fits in
- The step most businesses get wrong
If your business collects, stores or uses information about identifiable people, privacy law is not optional. The Privacy Act 1988 (Cth) (the Act) is the main federal law, and its 13 Australian Privacy Principles (the APPs) set out how most private-sector businesses must handle personal information. Getting it wrong carries penalties measured in the tens of millions, and since mid-2025 a serious invasion of privacy is also a direct civil wrong an individual can sue for.
This guide sets out who the law applies to, the thresholds that bring a business inside its scope, the core ongoing duties you will need to build into your operations, and what happens if you fail. Read it as a starting map of the obligations, not as legal advice for your specific business.
Who the APPs apply to
The starting position is simple: the APPs bind APP entities (that is, any body, partnership, unincorporated association or trust covered by the Act). The most important carve-out is the small business exemption. Under s 6D of the Act, a business is a "small business" if its annual turnover for the previous financial year was $3 million or less. The turnover test is based on the income the business earns in a year, including sales, commissions, rent, interest and other operating income.
A small business is generally exempt from the APPs. But the exemption disappears, and the APPs apply regardless of turnover, if the business:
- provides a health service and holds health information (other than in an employee record);
- discloses personal information about someone to someone else for a benefit, service or advantage, or collects personal information as part of providing such a benefit;
- is a contracted service provider under a Commonwealth contract; or
- is a credit reporting body.
A business can also lose the exemption if it is related to a body corporate that is not a small business, and a small business can voluntarily opt in to be treated as an APP entity under s 6EA of the Act.
Two things are worth flagging before you self-assess against the $3 million figure. First, the threshold is based on the previous financial year's turnover, so a business that grows past the line in the current year usually steps into coverage the following year. Second, the government has signalled it intends to remove or narrow the small business exemption in future reform, so the "under $3 million, therefore exempt" assumption is not permanent. If you are close to the threshold or expect to grow, treat the exemption as a bridge rather than a permanent shield.
Understand whether you even hold "personal information"
Before the duties make sense, you need to know what the Act protects. Personal information is broadly defined as information or an opinion about an identified, or reasonably identifiable, individual. That includes obvious items like names, email addresses and phone numbers, but it also extends to less obvious data such as a customer's browsing history where it can be tied back to them, unique device identifiers, and the details you hold in a customer relationship management database. The point for Australian businesses is that "personal information" is wider than you might assume, and the APPs attach to all of it.
The core duties
Once you are an APP entity, the principles fall into identifiable duties. These are the ones most SMEs will interact with day to day.
Maintain an open and transparent privacy policy
APP 1 requires you to manage personal information openly and transparently, and to have a clearly expressed, up to date privacy policy. The policy must be free and easy to access, and must explain in plain language:
- what kinds of personal information you collect and hold;
- how and why you collect, use and disclose it;
- how an individual can access and correct their information; and
- how someone can complain about a breach of the APPs and how you will deal with that complaint.
A policy that is buried, out of date, or written in dense legalese does not satisfy the principle. It should reflect what your business actually does with data, not what you would like to be doing.
Notify people when you collect their information
APP 5 requires you to notify an individual at or before the time you collect their personal information, or as soon as practicable afterwards. The notification must cover, to the extent reasonable, who you are and how to contact you, why you are collecting the information, the main consequences if it is not collected, who you usually disclose it to, and whether you are likely to send it overseas (and where, if practicable to say).
In practice this is the short privacy notice on a form, a web page, or at the point of sign-up. It is separate from, and more targeted than, the longer privacy policy. A common compliance failure is treating the policy and the notice as the same document; the notice must reach the person at the moment of collection.
Use and disclose information only within your stated purpose
APP 6 limits what you can do with personal information. You may only use or disclose it for the purpose for which you collected it (the primary purpose) unless one of a set of exceptions applies, most commonly the individual's consent, or a secondary purpose the person would reasonably expect and which is related to the primary purpose. Sensitive information, such as health, racial or political information, is subject to a stricter test: a secondary purpose must be directly related to the primary purpose.
Take reasonable steps to keep it secure
APP 11 is the security duty. If you hold personal information, you must take such steps as are reasonable in the circumstances to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure. "Reasonable in the circumstances" is judged against the size of your business, the sensitivity of the information, and the likely risk of harm. It is deliberately not a one-size-fits-all standard, but for most businesses it will involve access controls, staff training, encryption where appropriate, and a policy for destroying or de-identifying information you no longer need under s 11.2 of the Act.
Manage overseas disclosure carefully
If you disclose personal information to a recipient outside Australia, APP 8 requires you to take reasonable steps to ensure that recipient will handle the information consistently with the APPs, unless an exception applies (for example, where you reasonably believe the recipient is subject to a law or binding scheme providing substantially similar protection). The reason this matters is s 16C of the Act: if you disclose to an overseas recipient and that recipient breaches the APPs, the disclosure is treated as your breach. You remain accountable for what happens to the data after it leaves your control.
Handle direct marketing with care
APP 7 governs direct marketing. You may generally use or disclose personal information for direct marketing only in limited circumstances, and you must always give the individual a simple way to opt out. If you send marketing by email or SMS, you need to keep this in mind alongside the separate consent and unsubscribe requirements of the Spam Act 2003 (Cth): those two laws run in parallel and both must be satisfied.
Give people access and let them correct their data
APP 12 generally requires you to give an individual access to the personal information you hold about them on request, subject to limited exceptions, and APP 13 requires you to correct that information where it is inaccurate, out of date, incomplete, irrelevant or misleading. Both duties rest on you acting within a reasonable timeframe.
Notify eligible data breaches
Separate from the APPs, under Part IIIC of the Act (the Notifiable Data Breaches scheme), you must notify the Office of the Australian Information Commissioner (the OAIC) and affected individuals if there is an eligible data breach. A breach is eligible where there is unauthorised access to, or unauthorised disclosure or loss of, personal information that is likely to result in serious harm to any affected individual. Notification must happen as soon as practicable. This requirement has no small business carve-out, so it applies even to an exempt small business that suffers a qualifying breach.
Consequences of getting it wrong
The compliance burden is one thing; the price of failure is now substantial. Since the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth), the Act distinguishes serious interference with privacy from ordinary interference.
For a serious interference, under s 13G of the Act the maximum civil penalty for a body corporate is the greatest of: $50 million; three times the value of any benefit obtained from the conduct; or if that cannot be determined, 30% of adjusted turnover. For an individual, the maximum is $2.5 million. An ordinary interference under s 13H carries a lower cap of 2,000 penalty units.
There is also a new individual-level risk. From 10 June 2025 the Act creates a standalone tort of serious invasion of privacy. Under that cause of action, an individual whose privacy is invaded, for example by intrusion upon seclusion or misuse of their information, can sue where the invasion was intentional or reckless, serious, and where their reasonable expectation of privacy outweighed the countervailing public interest. Damages are recoverable without proof of financial loss.
The OAIC is the regulator. It investigates complaints and data breaches, and for serious or repeated interferences it may apply to the Federal Court for civil penalties. For most businesses the practical consequences of a breach are a regulatory investigation, reputational damage, the cost of remediating the breach, and potentially a compensation claim to the individual affected.
A practical compliance checklist
On an ongoing basis, work through the following:
- Confirm whether the APPs apply to you at all, given turnover and the exceptions.
- Identify every way your business collects, uses, discloses and stores personal information.
- Maintain a current, plain-language privacy policy that reflects what you actually do.
- Provide a privacy notice at the point of collection.
- Put in place reasonable security for the information you hold.
- Map where information is disclosed, including any overseas recipients, and confirm each is protected.
- Confirm direct marketing has a working opt-out and, for electronic messages, satisfied the Spam Act.
- Have a process that lets people access and correct their information.
- Have a data breach response plan so you can assess and notify an eligible breach as soon as practicable.
Where professional help usually fits in
An experienced privacy lawyer's value here is practical, not just defensive. A lawyer can help you work out whether the small business exemption actually applies to your structure, draft a privacy policy and collection notices that accurately describe your data flows, review contracts with third parties and overseas processors so that APP 8 accountability is addressed, and build a data breach response plan that lets you act quickly if something goes wrong. Given how fast Australian privacy law is changing, a practitioner can also help you weigh upcoming reform rather than waiting until a breach forces the issue.
The step most businesses get wrong
If there is one place compliance typically fails, it is the privacy notice at the point of collection. Many businesses maintain a policy that satisfies a website checklist, but never actually tell people what they are collecting at the moment the data is handed over, and never check whether that collected data is being sent somewhere it should not go. That gap is exactly what APP 5 and APP 8 target, and it is where both regulator complaints and the new tort most often find their footing. This week, the single most useful thing you can do is list the concrete places your business collects personal information, confirm each has a notice that says what is being collected and why, and confirm where that data ultimately travels.