1. The Decision in Plain Terms
  2. Five Factors That Should Drive the Decision
    1. The obligations that actually apply to you
    2. Trigger points that change the answer
    3. What getting it wrong costs
    4. The time and expertise you have in-house
    5. How regulated your sector is
  3. Getting the Call Right With Artificer Legal
  4. Where the Decision Usually Turns

The question usually stops being theoretical at a specific moment. It might be the day you hire your fifth employee, the week you launch a new product line, or the morning a client emails a supplier compliance questionnaire with a deadline attached. Sometimes it is a letter from a regulator, or a customer complaint that has escalated further than you expected. At that point, deciding whether to engage a compliance lawyer is a real call with real money attached, and the answer depends on facts you can actually check.

The Decision in Plain Terms

There are three ways to handle compliance, and most growing businesses move between them over time:

  • Do it yourself: templates, checklists and software, run without legal input.
  • Targeted reviews: a lawyer checks your contracts, policies and marketing claims at specific moments, such as a product launch or your first hire.
  • Ongoing counsel: a retainer or a light annual program where a lawyer keeps your documents current and advises as issues come up.

The real question hiding inside the headline one is narrower. It is not "should we buy compliance services?" but "which obligations actually apply to us, and which of them can we manage safely with the time and expertise we have?" Most businesses answer that second question confidently for one or two areas and not at all for the rest.

Two options look like shortcuts but collapse into the same problem. Compliance software automates reminders, training logs and records, but it does not tell you what the law requires; somebody still has to decide what a rule means for your business. And relying on a "small business exemption" from privacy law is riskier than it sounds, because the exemption has exceptions that catch businesses that assume it protects them. Neither replaces a person who can read a requirement and apply it to your operation.

Five Factors That Should Drive the Decision

The factors below are what a lawyer would weigh with you. Work through them honestly and the decision mostly makes itself.

The obligations that actually apply to you

Start by listing the laws that attach to how you sell, market, collect data and employ people. For most Australian businesses the list looks like this:

  • Consumer law: the Australian Consumer Law, Schedule 2 of the Competition and Consumer Act 2010 (Cth), bans misleading or deceptive conduct in trade or commerce (s 18), imposes consumer guarantees on goods and services, and makes unfair terms in standard form contracts void (s 23). Since the reforms that took effect in November 2023, proposing or relying on an unfair term can also attract a penalty, and the small business definition reaches contracts where a party employs fewer than 100 people or has annual turnover under $10 million.
  • Privacy and data: businesses covered by the Privacy Act 1988 (Cth) must meet the 13 Australian Privacy Principles covering collection, use, storage and disclosure of personal information. Most businesses with annual turnover of $3 million or less are exempt, but not if they provide health services, sell or trade in personal information, perform credit reporting functions or contract with the Commonwealth. When a breach happens, the Notifiable Data Breaches scheme gives you 30 days to assess whether it is an eligible data breach, and notification to the Office of the Australian Information Commissioner and affected individuals follows if serious harm is likely.
  • Employment: hiring brings the National Employment Standards under the Fair Work Act 2009 (Cth), including maximum weekly hours, leave entitlements, notice of termination and redundancy pay, and superannuation at 12 per cent of ordinary time earnings from 1 July 2025. Modern awards add industry-specific conditions on top, and the standards cannot be displaced by a contract.
  • Advertising and promotions: your website, ads and social posts must not mislead, and competitions and giveaways carry state-based permit and disclosure rules. Financial product advertising and therapeutic goods advertising sit with ASIC and the Therapeutic Goods Administration respectively.
  • Corporate governance: if you operate through a company, directors owe duties of care and diligence and good faith under ss 180 and 181 of the Corporations Act 2001 (Cth), both enforceable as civil penalty provisions. Records, lodgements and the company's internal rules are part of the same picture.
  • Industry rules: sectors such as financial services, health, alcohol, construction, childcare and food carry licensing, reporting and audit obligations that can dwarf the general laws above.

The list is not the same for every business. A café's obligations run to food safety, alcohol service and basic employment law; a software company's run to privacy, the ACL and intellectual property. Part of what a compliance lawyer does is tailor the general list to your model, and part of what you are paying for is knowing which items on it do not apply to you at all.

Trigger points that change the answer

The obligations stay roughly constant; the risk does not. Compliance failures concentrate around change, so treat these events as the moments to get a fresh look:

  • Launching a product or service: when claims, pricing, refunds and terms first face the Australian Consumer Law.
  • Hiring your first employees or contractors: when Fair Work obligations and employment documents begin.
  • Collecting customer data at scale: especially the first time you use analytics, an email platform or a customer database.
  • Scaling quickly or winning a large contract: when clients and partners start auditing your policies before they sign.
  • A regulator contact or an incident: including a suspected data breach, a complaint escalated to a regulator, or a product safety issue.
  • Crossing a threshold: such as $3 million in turnover, which moves you inside the Privacy Act's main regime.

Each trigger is an argument for a targeted review rather than a standing retainer. The two are different products. A trigger-based model suits most growing businesses, because the review happens when the risk is actually elevated, not on a calendar date chosen by someone else.

What getting it wrong costs

The enforcement numbers matter because they set the scale of the downside:

  • Australian Consumer Law: a body corporate can face a pecuniary penalty of up to the greater of $100 million, three times the benefit gained, or 30 per cent of adjusted turnover for contraventions such as misleading conduct or unfair terms (s 224 of the ACL), with individuals exposed to up to $2.5 million. The ACCC and state and territory fair trading regulators enforce these provisions and can also seek injunctions and redress for customers.
  • Privacy: serious or repeated interference with privacy can attract penalties up to the greater of $50 million, three times the benefit, or 30 per cent of adjusted turnover (s 13G of the Privacy Act 1988), with the OAIC able to investigate and accept enforceable undertakings.
  • Employment: the Fair Work Ombudsman can investigate, issue compliance notices and take court action for underpayments, with back-pay exposure for directors in some cases.
  • Governance: breaching director duties exposes directors personally to civil penalties, compensation orders and disqualification from managing companies.
  • Commercial: beyond regulators, a compliance failure can void a contract term, trigger a customer refund claim, or cost you a client whose audit you fail.

These are maximums, and regulators exercise judgment about when to pursue them. But the direction of travel matters: the law now treats a systematic compliance failure as a serious matter, not a paperwork slip.

The time and expertise you have in-house

Compliance is only as good as the person who owns it. Ask who in your team would actually implement a policy, update a privacy notice or run a refund check. If the answer is "nobody has time", a drawer full of documents will not reduce risk. A lawyer cannot fix that by drafting more; they fix it by building lightweight systems that fit the hours you realistically have. Software helps with reminders and records, but it is a tool, not a decision-maker, and it still needs someone to configure it against the right legal requirements.

How regulated your sector is

Some sectors treat compliance as a licence condition rather than an optional extra:

  • Financial services: providing financial product advice or dealing generally requires an Australian financial services licence from ASIC, with conduct and disclosure obligations attached.
  • Health: private health service providers must comply with the Privacy Act 1988 regardless of turnover, and handle health information under strict rules.
  • Alcohol, construction, childcare and food: each carries state-based licensing, safety and reporting obligations, and regulators can suspend or cancel licences for breaches.

For a business in one of these sectors, the answer to "do we need a compliance lawyer?" is usually yes, at least at licensing and renewal time. For a general retailer or service business, targeted reviews at trigger points are usually enough.

A conversation with an Artificer Legal practitioner is designed to settle the decision rather than sell you a retainer. In a focused session we would:

  • Map the obligations that actually apply: we tailor the general list to your business model, sector and turnover, so it stops being generic.
  • Stress-test the assumptions: we test the claims the decision rests on, such as "we are under $3 million so privacy does not apply" or "our terms were fine last time".
  • Model the downside: we quantify the gaps we find, so you can see which risks are worth fixing now and which can wait.
  • Draft the documents the chosen path needs: from customer terms and privacy policies to employment contracts and a data breach response plan.
  • Stand by for incidents: the first 30 days after a suspected breach or the first regulator letter is the worst time to be looking for a lawyer.

Whether you need one review or a light annual program depends on the factors above. Either way, the aim is to keep compliance sized to your business rather than imported from a bigger one.

Where the Decision Usually Turns

For most small and medium businesses the answer is not "never" and not "always". It is "at trigger points". The decision usually turns on two things: whether you have crossed a threshold such as $3 million in turnover or your first employees, and whether a change is happening in your business right now. A product launch, a new hire, a data incident or a regulator contact is the moment a targeted review pays for itself. The mistake to avoid is treating compliance as a once-off purchase; it is a set of obligations that move when your business moves.

The obligations themselves are stable and knowable: fair dealing and consumer guarantees under the ACL, the privacy principles and breach notification rules, the National Employment Standards, and director duties if you operate through a company. What changes is how much of that machinery your business has engaged. Map the obligations, watch the triggers, and bring in a compliance lawyer when a threshold is crossed or a change lands. That is the decision, and it is easier to make with the facts in front of you.