Australian privacy obligations in plain English, for a business with a dozen staff
A starting point, not legal advice. The Australian Privacy Principles as a lifecycle, why relying on an exemption is a poor strategy, and what good looks like.
A starting point, not legal advice
If you run a business with around a dozen staff, you’ve probably had a moment where someone asks “are we allowed to do that with customer information?” and nobody in the room is quite sure. This article is meant to give you a plain-English orientation to Australian privacy obligations, so that conversation is easier next time. It isn’t legal advice. Privacy law in Australia has been under active reform, thresholds and specifics move, and the right move for your situation should always be checked with the Office of the Australian Information Commissioner (OAIC) or a professional adviser.
Think of it as a lifecycle, not a rulebook
The Australian Privacy Principles can feel like a long list of legal clauses, but underneath them is a fairly simple idea: personal information has a lifecycle, and you have obligations at each stage of it.
- Collect only what you need. If you don’t need a piece of information to do the job, don’t ask for it.
- Tell people what you’re collecting and why. A clear, honest explanation at the point you collect something, not just a dense document nobody reads.
- Use it for that purpose. Information collected for one reason generally shouldn’t quietly get used for something else.
- Keep it secure. Reasonable steps to protect it from misuse, loss, and unauthorised access.
- Let people see and correct it. Individuals generally have the right to ask what you hold about them and to have mistakes fixed.
- Delete it when you no longer need it. Holding on to information “just in case” is a liability, not an asset.
If you can honestly describe your business’s practice at each of those six stages, you’re most of the way to a defensible privacy position, regardless of the finer legal detail.
The small business exemption, and why it’s not a strategy
Australia has historically had an exemption from parts of the Privacy Act for small businesses below a certain turnover. If you’ve ever heard someone say “we’re too small for privacy law to apply to us”, this is probably what they’re thinking of.
Two things are worth knowing about that exemption. First, it has never applied to everyone, regardless of size. Businesses that provide health services, businesses that trade in personal information, contractors delivering services under an Australian Government contract, and a number of other categories are generally excluded and treated as covered regardless of turnover. If any of that describes part of what you do, don’t assume you’re exempt without checking.
Second, relying on an exemption is a poor strategy even where it technically applies. This area has been under reform, and the settings around who is covered can change. More practically, your customers, the schools you work with, your funders and your insurers increasingly ask about your privacy practices regardless of whether the law technically requires it of you. Being able to say “we handle personal information properly” is becoming a basic expectation, not a bonus. Exactly where the current threshold sits is worth checking directly with the OAIC or a professional adviser, rather than relying on anything printed here that could be out of date.
If in doubt about whether an exemption applies to your business, treat yourself as covered. It costs little to run good privacy practice, and it costs a great deal to explain to a client why you didn’t.
What a data breach means in plain terms
A notifiable data breach, in plain language, is a situation where personal information your business holds is accessed, disclosed, or lost in a way likely to cause serious harm to the people it’s about, and you’re unable to prevent that harm through quick action. Think a stolen laptop with client files on it, an email sent to the wrong list of recipients, or a system that gets broken into.
The general obligation, where it applies, is to assess the situation properly and, where it meets that threshold, notify both the affected individuals and the OAIC. The exact criteria are worth understanding properly if it ever happens, rather than guessed at in the moment, so it’s worth knowing beforehand which information you hold would be most serious if exposed.
What good looks like in practice
For a business your size, you don’t need a large compliance department. You need a handful of practical things done properly and kept up to date.
| What good looks like | Why it matters |
|---|---|
| A written record of what personal information you hold and where | You can’t protect or respond to a request about something you can’t locate |
| A privacy notice people can actually read | Meets your obligation to explain collection, and builds trust with clients |
| Access controls on staff systems and files | Limits who can see sensitive information to those who genuinely need it |
| A proper offboarding process for departing staff | Closes off access before it becomes a risk, not after |
| A simple plan for if something goes wrong | Means a stressful moment doesn’t also become a chaotic one |
Knowing what you hold and where
Most small businesses are surprised, once they look, at how many systems hold personal information: the practice management system, the accounting software, an old spreadsheet, a shared inbox, a folder someone set up years ago and never revisited. A simple written inventory, even a one-page list, is one of the most useful documents a small business can have.
A privacy notice people can actually read
A privacy notice that’s three pages of dense legal language technically exists, but it doesn’t really achieve the purpose of telling people what you’re doing with their information. A short, honest explanation, in language a customer would actually read, does more work than a long one nobody opens.
Access controls and offboarding
Not everyone in a twelve-person business needs access to everything. Client files, financial records and staff records are worth restricting to people who need them for their role. When someone leaves, closing off their access promptly is one of the simplest, most overlooked pieces of good practice.
A plan for when something goes wrong
You don’t need an elaborate incident response document. You need to know, in advance, who makes the call about whether something is serious, who you’d contact for advice, and how you’d let affected people know. Working that out during an actual incident is much harder than working it out beforehand.
A short practical checklist
- Write down what personal information you collect, why, and where it’s stored
- Check whether any part of your business falls outside the small business exemption
- Make sure your privacy notice is genuinely easy to read
- Review who has access to sensitive files and tighten it where you can
- Confirm your offboarding process actually removes access, not just email
- Write a one-page plan for what you’d do if something went wrong
- Check the current position with the OAIC or a professional adviser, since this area continues to change
None of this needs to happen in a single afternoon. Working through it steadily gets most businesses to a solid position, and gives you something honest to say next time a client, school or funder asks how you handle their information.