Empirical
← articleshomecontact

articles

7 Tips for Businesses on Data Privacy and Cybersecurity

DataPrivacy

The increasing use of websites and e-commerce platforms across businesses in Australia reflect the growing need for compliance with the Privacy Act 1988 (Cth).

Small and medium enterprises (SMEs) and businesses in Australia are becoming more reliant on digital platforms to operate, market and deliver their products or services. If this sounds like you, staying on top of the data privacy requirements in the Privacy Act 1988 (Cth) (Privacy Act) and adopting cybersecurity best practices is essential to protect customer data, maintain trust and avoid consequences.

Empirical Legal advises startups, scale-ups and SMEs on their privacy obligations. Our team understands the legal obligations around data protection and the practical steps needed to ensure compliance. We can help you address both immediate risks and plan for long-term and sustainable compliance.

Key Summary: The 7 Things SMEs Need to Know

To protect customer data and comply with your obligations, you should:

  1. Understand and limit the personal data you collect.
    Only gather the customer data you need and keep a clear, up-to-date record of what you hold, where it’s stored and why, to reduce breach risk.

  1. Delete unused data or when you’re asked.
    Remove personal data as soon as it’s no longer required. Use secure deletion methods to limit exposure and meet customer expectations for control over their information.

  1. Consolidate and secure data storage.
    Store personal data in fewer, centralised locations with consistent security measures to simplify protection and reassure customers who are concerned about overseas storage.

  1. Control and monitor access.
    Restrict data access to those who need it for their role and implement monitoring to detect misuse or unauthorised access.

  1. Encrypt data in storage and in transit.
    Use encryption on devices, files and data transfers to reduce the impact of theft, loss or interception.

  1. Maintain secure backups.
    Keep recent, secure and tested backups separated from live systems to recover quickly from ransomware, system failure or disaster.

  1. Know and comply with breach reporting obligations.
    In the event of a breach, understand and follow the Notifiable Data Breaches scheme to meet Privacy Act requirements and maintain customer trust after a breach.

1. Understand and Limit the Personal Data You Collect

Only collect the personal data you genuinely need for your operations. The more information you hold, the more there is to lose in a breach. Australians are already concerned about over-collection: 81% believe they should not be asked for more information than necessary to provide a product or service (OAIC, Australian Community Attitudes to Privacy Survey 2023). If you cannot clearly explain why you need to collect each piece of data, you should not be collecting it.

A good first step is creating a data register, a record of all personal data you hold, where it’s stored and why you have it. Keep it up to date and standardised so you can identify and address risks quickly.

2. Delete Unused Data or When You’re Asked

Holding unnecessary personal data creates risk without much benefit. The data has already served its purpose. Policies should set retention timeframes and deletion procedures tailored to the sensitivity of the data and your business risk profile. The Privacy Act requires customers’ personal data to be deleted immediately once it’s no longer required with proper data sanitisation to prevent recovery. Unnecessary duplicates, such as multiple copies of the same customer database, should also be removed.

In the European Union, the GDPR has a right to erasure, sometimes called a right to be forgotten. If you serve customers in Europe, you must give them the ability to request their personal data be deleted and facilitate that request. Although not required in Australia, Australians expect control over their information, with 93% believing they should have the right to ask a business to delete their personal information (OAIC, Australian Community Attitudes to Privacy Survey 2023). Allowing your customers to do so would be best practice and will build trust with Australian customers to operate under the right to be forgotten, even if you don’t have any European customers.

3. Consolidate and Secure Data Storage

Australians are wary of where their data is stored, 91% are concerned about their personal information being sent overseas (OAIC, Australian Community Attitudes to Privacy Survey 2023). Choosing secure, local storage options where possible can improve customer trust.

Storing data in fewer, centralised locations makes it easier to protect. By consolidating personal data repositories, you can apply stronger security controls and reduce the complexity of managing multiple storage points. Whether you use on-premises servers, cloud services or a combination, ensure security standards are consistent across all storage systems.

4. Control and Monitor Access to Data

Not every employee needs access to all data. Access should be on a “need to know” basis, with permissions limited to what is necessary for each role (Australian Signals Directorate, Securing Customer Personal Data). Privileged accounts should have additional restrictions and oversight to reduce the risk from stolen credentials or malicious insiders.

Monitoring is equally important. Implement logging systems to detect and investigate unusual activity, whether from cybercriminals or internal misuse.

Only 46% of Australians trust organisations to store their data securely and just 42% trust that it will be used only for the stated purpose (OAIC, Australian Community Attitudes to Privacy Survey 2023). Strong access controls and monitoring are essential to address this trust gap.

5. Encrypt Data in Storage and in Transit

Encryption is a key safeguard. Full disk encryption on devices such as laptops and servers helps protect data if hardware is lost or stolen. File-based encryption adds an extra layer if systems are compromised.

Data should also be encrypted when transmitted, for example, between your systems and customer devices, to reduce interception risks. While encryption is not a complete defence, it can significantly reduce the impact of a breach. Customers expect you to use such protections; data security is rated “extremely important” by 60% of Australians when choosing a product or service (OAIC, Australian Community Attitudes to Privacy Survey 2023).

6. Maintain Secure Backups

Backups are vital to recover from ransomware, accidental deletion or physical damage. They should be recent, uncorrupted and stored securely, ideally segregated from your main systems to prevent malware from infecting them.

Test your ability to restore data regularly and back up configuration settings as well as customer information. According to the Australian Signals Directorate, ransomware attacks are increasingly targeting SMEs. A robust backup strategy can mean the difference between a quick recovery and business-ending downtime.

7. Know and Comply with Breach Reporting Obligations

If you experience a data breach involving personal information, you may need to notify the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme in the Privacy Act.

An “eligible data breach” occurs when:

  1. Personal information is accessed, disclosed or lost without authorisation;

  2. It is likely to result in serious harm; and 

  3. You cannot prevent the risk of serious harm with remedial action.

Failing to report can lead to legal penalties and further reputational damage. With 92% of Australians believing businesses should do more to protect personal information (OAIC, Australian Community Attitudes to Privacy Survey 2023), transparency during a breach is critical for trust.

Key Takeaways

Australian SMEs cannot afford to treat data privacy and cybersecurity as afterthoughts. The statistics are clear: customers expect transparency, security and control over their information and the law is moving towards tighter regulation.

By understanding what data you collect, reducing what you store, controlling access, encrypting, backing up securely and knowing your legal obligations, you reduce the risk of breaches, avoid penalties and protect your reputation.

We urge that you audit your current data handling practices as soon as you can.


Empirical Legal is a corporate advisory and technology law firm for startups, scaleups and SMEs.

We combine legal, technology, and business experience and expertise to deliver practical, actionable advice and solutions.

If you’re unsure where to start, contact us for a practical, compliance-ready review tailored to your business.

Reach out to Empirical Legal today.