Home › Services › Privacy Act & data breaches
Privacy Act & data breachesKnow what data you hold, and what you must do if it leaks.
The Privacy Act does not apply to every small business — but the exemption is narrower than most owners think. We work out where you stand, then make sure you could meet the 30-day breach assessment deadline.
There are two separate questions here and most businesses conflate them. First: does the Privacy Act apply to you at all? Second: if it does, could you actually meet your obligations if something went wrong tomorrow? We answer both.
Does the Privacy Act apply to you?
The Privacy Act generally does not apply to businesses with an annual turnover of $3 million or less. That exemption is narrower than most owners assume, because a long list of exceptions pulls small businesses back in regardless of turnover:
- Private sector health service providers — which includes allied health, psychology, dental, and businesses holding health information they may not think of as clinical.
- Businesses that buy or sell personal information.
- Contracted service providers under an Australian Government contract.
- Credit reporting bodies, and businesses accredited under the Consumer Data Right.
- Residential tenancy database operators, and reporting entities under anti-money laundering law.
- Businesses related to another business that is covered, and businesses that have opted in.
The full list is on the OAIC's rights and responsibilities page. We check this first, because it determines whether the rest is a legal obligation or good practice.
The Notifiable Data Breaches scheme
If the Act applies to you and you suspect an eligible data breach — personal information lost, or accessed or disclosed without authorisation, in a way likely to cause serious harm — you must carry out a reasonable and expeditious assessment. You must take all reasonable steps to complete it within 30 calendar days of becoming aware of the grounds for that suspicion (s 26WH(2) of the Privacy Act). If it is an eligible data breach, you notify the affected individuals and the OAIC.
The OAIC has stated it expects entities to treat 30 days as a maximum rather than a target, because the risk of serious harm grows with time. Source: OAIC — Part 4: Notifiable Data Breach scheme.
The practical problem is earlier than the deadline. To assess a breach in 30 days you first have to know it happened. Businesses without logging, without alerting and without a named decision-maker do not start the clock until a customer tells them — and by then the 30 days have been running for a while.
What we map
- What personal information you hold — and where it actually lives, including the spreadsheet on someone's laptop and the inbox nobody has cleaned out since 2019.
- Who can reach it — staff, contractors, former staff whose accounts are still live, and third-party systems with an integration token.
- Whether you would notice — logging, alerting, and whether anyone reads the alerts.
- Whether you could respond — a breach response plan with named roles, decision criteria, notification templates and a realistic 30-day timeline.
- What you should not be keeping — data you have no reason to hold is the cheapest risk to remove, which leads into data destruction.
Recent changes worth knowing about
The Privacy and Other Legislation Amendment Act 2024 introduced a statutory tort for serious invasions of privacy, giving individuals a direct cause of action in certain circumstances. The OAIC's explanation is here: statutory tort for serious invasions of privacy. Reform of the small business exemption itself has been under discussion for some years; we tell you what the law requires today and flag what is in train, not what a vendor would like you to fear.
What we are not
We are not lawyers and this is not legal advice. What we provide is a technical and operational readiness assessment against published OAIC guidance. Where a question is genuinely legal — whether a specific breach is notifiable, or how the statutory tort applies to your circumstances — you need a privacy lawyer, and we will say so.
Not sure where you stand?
The security check is free and takes 30 minutes. You will leave it knowing your three biggest gaps.
Book a free security check