1. Who has to comply with what
  2. Identify what is actually confidential
  3. Put the obligations in writing
  4. Protect the personal information you hold
  5. Have a plan for when information gets out
  6. Plan for the day an employee leaves
  7. What happens if you get it wrong
  8. A practical confidentiality checklist
  9. When to call a lawyer
  10. Confidentiality is a practice, not a document

Confidentiality at work is not one obligation but several, and they pull in different directions. Employees owe duties about the information they handle. The business owes duties about the personal information it holds. Company officers and employees owe statutory duties about information they get through their position. And everything can be shaped by what is written into contracts. For an Australian small or medium business, the useful question is not whether you are bound by confidentiality obligations, but which ones apply to you and what you actually have to do to meet them.

This guide sets out who is caught by each duty, what the law requires you to do to protect confidential information, what happens when information gets out, and the consequences of getting it wrong.

Who has to comply with what

The obligations come from four directions: contract, equity, the Privacy Act 1988 (Cth) and the Corporations Act 2001 (Cth). Whether a particular duty binds your business depends on the type of information and the situation.

  • Contract: any confidentiality clause or non-disclosure agreement (NDA) you sign binds whoever signed it, whatever the size of the business.
  • Equity: the equitable duty of confidence applies to every business and every person, with or without a signed document.
  • Privacy Act: the Australian Privacy Principles (APPs) apply to APP entities. A business is generally outside the APPs as a small business operator if its annual turnover was $3 million or less in the previous financial year (s 6D). The exemption is narrower than it sounds. Even a business under that threshold is caught if it provides health services and holds health information, trades in personal information, is a contracted service provider for a Commonwealth contract, is a credit reporting body, or is related to a body corporate that is not a small business (s 6D(4) and (9)).
  • Corporations Act: under s 183, every director, officer and employee of a corporation must not improperly use information obtained because of their position, and the duty continues after they stop being an officer or employee.

There is also an important carve-out for employee records. The APPs do not apply to an employer's acts that are directly related to a current or former employment relationship and an employee record (s 7B(3)). Employee information is still protected, but through the employment contract, the implied duty of fidelity and confidentiality law, rather than the Privacy Act.

Identify what is actually confidential

The starting point for any confidentiality program is deciding what information counts. In a typical SME this falls into three groups: customer personal information, employee information, and proprietary business information such as pricing, client lists, supplier arrangements and product know-how. The law protects each group differently, so the categories matter.

The equitable duty of confidence, which operates without any signed document, requires four things: the information must be identified with specificity; it must have the necessary quality of confidence; it must have been received in circumstances importing an obligation of confidence; and there must be actual or threatened misuse without consent (Optus Networks Pty Ltd v Telstra Corporation Ltd [2010] FCAFC 21 at [39], applying Smith Kline & French Laboratories (Aust) Ltd v Secretary, Department of Community Services and Health (1990) 22 FCR 73).

Two practical consequences follow. First, information that the business itself does not treat as confidential, by marking it, restricting access to it or otherwise signalling its secrecy, is unlikely to have the necessary quality of confidence. Second, during employment every employee already owes an implied duty of good faith and fidelity that stops them using or disclosing confidential information, even if their contract says nothing about it (Plus One International Pty Ltd v Ching (No 3) [2020] NSWSC 1598). The content of that duty grows with seniority: an employee with deeper access to confidential information owes more than a junior one (Del Casale v Artedomus (Aust) Pty Ltd [2007] NSWCA 172 at [32]).

Put the obligations in writing

Contract does what equity leaves uncertain: it defines the information, the conduct prohibited, and what survives the end of the relationship. Three documents do most of the work.

  • A confidentiality clause in every employment contract: The clause should define confidential information (customer lists, pricing, know-how, personal information), prohibit use outside the business's purposes, require the return of materials on departure, and state that the obligation survives termination. In Optus Networks v Telstra, the agreement's confidentiality clause did exactly this: it restricted use and copying to the purposes of the agreement, prohibited disclosure to third parties, and required procedures adequate to protect the information.
  • NDAs with third parties: Contractors, consultants, prospective buyers or partners, and suppliers who see your systems should sign an NDA before they receive anything sensitive. The same clause that protects your information also protects information about your customers and staff that flows through commercial discussions.
  • A workplace confidentiality policy: A written policy tells staff what counts as confidential, how to handle it, how requests from third parties are dealt with, what the rules are for email, electronic communications and social media, and what happens if the policy is breached. A policy that sits unread on a server does little. Training at onboarding and regular refreshers are what make it real, and consistent enforcement is what makes it credible.

Protect the personal information you hold

If you are an APP entity, the APPs impose specific duties that go beyond the general law of confidence.

  • APP 1: you must have a clearly expressed and up-to-date APP privacy policy, and take reasonable steps to implement practices, procedures and systems that ensure the business complies with the APPs and can deal with complaints.
  • APP 6: you must not use or disclose personal information for a purpose other than the purpose for which it was collected, unless the individual consents or an exception applies.
  • APP 11: you must take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include technical and organisational measures, and extend to destroying or de-identifying information you no longer need.

For a small business below the $3 million threshold, check the exceptions in s 6D(4) before assuming the APPs do not apply. Health providers, information brokers and Commonwealth contractors are commonly surprised to find themselves caught.

Have a plan for when information gets out

Every confidentiality program eventually faces a leak, so the plan for responding matters as much as the prevention.

For APP entities, the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act sets out the steps. An eligible data breach is unauthorised access to, unauthorised disclosure of, or loss of, personal information that is likely to result in serious harm to affected individuals. Where there are reasonable grounds to suspect an eligible data breach, the entity must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. Where there are reasonable grounds to believe an eligible data breach has happened, the entity must notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.

If the leaked information is business confidential information rather than personal information, the NDB scheme does not apply, but the equitable duty and any contract still do. Preserve evidence, identify the source, and consider whether an injunction is needed to stop further use while the matter is investigated.

Plan for the day an employee leaves

Confidentiality obligations do not automatically end at the exit interview, but they do change shape.

During employment the implied duty of good faith and fidelity applies, and its scope depends on seniority (Del Casale v Artedomus at [32]). After employment ends, the position is different: absent a valid contractual restraint, a former employee is free to compete with you and to use their general skill, knowledge and experience, including client names they know from memory (Plus One International v Ching; Del Casale v Artedomus). What they cannot do is use or disclose information that remains confidential, whether under a clause that survives termination, under the equitable duty, or under s 183 of the Corporations Act, which continues to bind former officers and employees.

Restraint clauses, such as non-compete and non-solicit terms, are only as strong as the legitimate business interest they protect. Courts have refused to use injunctions to give an employer a restraint the contract never created (Plus One International v Ching), so the drafting needs to be done properly before the employee signs, not when you need to rely on it. The exit process matters too: collect devices and documents, cancel system access, and confirm ongoing obligations in writing.

What happens if you get it wrong

The consequences of a confidentiality failure escalate quickly.

  • Privacy penalties: For serious or repeated interference with privacy, the maximum civil penalty for a body corporate is the greatest of $50 million, three times the value of any benefit obtained, or 30% of the adjusted turnover during the breach period. For other entities the cap is $2.5 million (s 13G). Other interferences with privacy carry a penalty of up to 2,000 penalty units (s 13H). The OAIC can investigate, make determinations and pursue civil penalties in the courts.
  • Corporations Act: Improper use of information by an officer or employee is a civil penalty provision (s 183), and dishonest use can be a criminal offence (s 184).
  • Equitable and contractual remedies: A successful claim for breach of confidence can produce injunctions to stop further use, damages, or an account of profits (Plus One International v Ching). Agreements commonly acknowledge that a breach can cause irreparable damage for which money is not an adequate remedy, which is why courts will act quickly with interlocutory injunctions.
  • Employment consequences: Breach of confidentiality during employment can be misconduct that justifies discipline or dismissal.
  • The non-legal cost: Usually the largest, comprising lost client trust, damaged reputation, and competitors who learn your playbook.

A practical confidentiality checklist

Run through these steps in order to cover the main bases:

  • Confirm whether you are an APP entity: apply the $3 million turnover test in s 6D and then the exceptions, and reassess as turnover grows.
  • Put a confidentiality clause in every employment contract and an NDA in front of every third party who sees your information.
  • Adopt a written confidentiality and privacy policy, and train staff on it at onboarding and regularly afterwards.
  • Restrict access to confidential information on a need-to-know basis, and label and store it securely.
  • If you are an APP entity, keep your APP privacy policy up to date and implement the technical and organisational security steps APP 11 requires.
  • Have a data breach response plan: who assesses a suspected breach, and how you will notify the OAIC and affected individuals if it is eligible.
  • Run exit interviews: collect devices and documents, cancel access, and confirm ongoing obligations in writing.

When to call a lawyer

Work out your obligations before an incident, not after. A lawyer can advise whether the Privacy Act applies to your business and what the APPs require in practice, draft confidentiality clauses, NDAs, policies and restraint clauses that are enforceable, run or advise on a data breach response, and move quickly for an injunction when information has been misused. Restraint clauses and data breach notifications are two areas where the cost of a mistake is far higher than the cost of advice.

Confidentiality is a practice, not a document

The obligation most often missed is the one that follows the employee out the door. Most businesses remember the confidentiality clause at recruitment, then forget that the real exposure sits in the exit interview, the devices that come back, and the former employee's ongoing obligations under contract, equity and the Corporations Act.

The misstep that costs the most is treating confidentiality as paperwork. When a dispute reaches court, the first question is whether the information had the necessary quality of confidence, which depends on how the business actually treated it: whether it was marked, restricted and handled as secret. A clause in a drawer will not save information the business itself never treated as confidential.

Two things you can do this week: confirm whether the Privacy Act applies to your business, and put a confidentiality clause into the next employment contract or NDA you sign.