
The Australian privacy law landscape is changing rapidly and small businesses can’t afford to ignore it.
With cyber threats on the rise, consumer expectations evolving and the government expanding regulatory oversight, it is essential that small business owners understand how privacy reforms affect them.
Most Australian small businesses with under $3 million in annual turnover assume privacy laws don’t apply to them.
In many cases, they do. Changes to the Privacy Act 1988 (Cth) (Privacy Act) and increasing cyber risks mean that even the smallest operators need to understand their legal obligations when handling personal information.
Here are the 7 essential things small businesses need to know about the privacy reforms:
Most (but not all!) small businesses are currently exempt.
Turnover is only one factor; the nature of your business also matters.
Handling personal information triggers legal duties.
If you collect or trade in personal data, you likely have obligations under the Privacy Act.
Consumer expectations are changing fast.
84% of Australians want more control over their personal data (OAIC Australian Community Attitudes to Privacy Survey 2023).
Cyber threats are escalating.
Small businesses faced an average cybercrime cost of $49,600 in FY2023-24 (ASD Annual Cyber Threat Report 2023-2024).
Breaches have reputational and legal risks.
47% of Australians were notified of a data breach last year; 76% experienced harm to their business as a result of the breach (OAIC Australian Community Attitudes to Privacy Survey 2023).
Trading data without consent brings obligations.
Selling or exchanging customer data, even indirectly, means you may fall under the Privacy Act.
Cyber hygiene is your legal and commercial shield.
Adopting the Essential Eight and incident response planning is critical.
While currently businesses with under $3 million in annual turnover are generally exempt from the Privacy Act, many small businesses may have obligations based on the type of services they offer. This means, despite the small business exemption your business might currently be required to comply and you might not even realise it.
If your business fits into any of these categories, you aren’t exempt, regardless of turnover:
Health service provider;
Trades in personal information;
Provides services to the Commonwealth;
Operates a residential tenancy database; or
Is part of a larger related body corporate.
(OAIC Privacy Guidance for Organisations and Government Agencies - Small Business)
If your business collects or uses personal information, including names, addresses, phone numbers, emails or tax file numbers, you may be subject to the Australian Privacy Principles (APPs).
This includes situations where personal data is exchanged for:
Discounts or benefits;
Marketing lists; or
Analytics tools that store customer data.
Even if you're not "selling" data, offering a benefit in exchange for personal information may classify your business as trading in personal data under the Privacy Act (OAIC Privacy Guidance for Organisations and Government Agencies - Small Business).
Public sentiment around privacy is shifting. According to the OAIC’s Community Attitudes to Privacy Survey 2023:
84% of Australians want more control over how their personal information is collected and used.
62% say privacy is a major concern in their lives.
70% consider privacy extremely or very important when choosing a product or service.
In short, customers expect businesses, including small ones, to respect and protect their data. This means your privacy practices are now a competitive differentiator.
Small businesses are increasingly targeted by cybercriminals and the financial consequences are growing:
The average cost of a cybercrime incident for small businesses was $49,600 in FY2023-24, an 8% increase from the previous year (ASD Annual Cyber Threat Report 2023-2024).
ASD responded to over 1,100 cyber incidents and received over 87,400 cybercrime reports, averaging one every 6 minutes.
Business email compromise, ransomware and fraud were the top threats (ASD Annual Cyber Threat Report 2023-2024).
This environment makes Data management and protection both a legal and an operational challenge for all businesses.
Privacy breaches come with serious consequences:
47% of Australians reported being affected by a data breach in the past year.
76% said they suffered harm as a result, ranging from scams to identity theft to emotional distress (OAIC Australian Community Attitudes to Privacy Survey 2023).
52% received more scam/spam messages.
29% had to replace key identity documents.
12% experienced psychological harm.
Almost half (47%) of consumers say they would stop using a service after a breach.
If your small business is covered by the Privacy Act, a breach can lead to OAIC investigations, determinations or enforcement (OAIC Privacy Guidance for Organisations and Government Agencies - Small Business).
You may think you're not a data trader, but if you:
Exchange customer lists;
Share personal data for advertising partnerships; or
Collect emails through pop-ups in exchange for a benefit.
…then you may be "trading in personal information" under the Privacy Act.
And if you do so without the individual’s consent, you're automatically covered by the Act and must comply with all APPs (OAIC Privacy Guidance for Organisations and Government Agencies - Small Business).
Consent must be informed and voluntary. An opt-out box isn’t enough.
The Essential Eight mitigation strategies from the ASD offer a practical and effective baseline for protection. All businesses, regardless of size, should implement:
Multi-factor authentication;
Regular backups;
Application and user control; and
System patching and updates.
ASD’s Protective DNS blocked 82 million malicious domains last year (+21% YoY) and the number of critical infrastructure compromises is growing. 11% of cyber incidents responded to in FY2023-24 were tied to this sector (ASD Annual Cyber Threat Report 2023-2024).
Feedback shows that 93% of Australians think they should have the right to ask a business to delete their personal information and 90% want to object to certain data uses Transparency also boosts consumer trust; 70% say privacy is a key decision factor when choosing products (OAIC Australian Community Attitudes to Privacy Survey 2023).
Meeting those expectations now can future-proof your operations and reduce the shock of regulatory changes later. Whether you operate a clinic, small online store or a trades service, investing in cyber hygiene minimises risk and improves your customer confidence.
Small businesses can no longer afford to think of privacy laws as “big business” problems. The Privacy Act reforms and growing cyber threats make it clear: if you handle personal information, you need to take privacy seriously.
Between escalating cyber risks, evolving consumer expectations and the legal grey zones many small operators fall into, now is the time to review your data practices and seek professional advice.
Empirical Legal is a corporate advisory and technology law firm for startups, scaleups and SMEs.
We combine legal, technology, and business experience and expertise to deliver practical, actionable advice and solutions.
Contact us to discuss your data practices, or have us review your privacy policy to ensure your business is compliant with the new Privacy Act amendments.
Reach out to Empirical Legal today.