Data privacy used to be a big-company problem. If you ran a law firm or a bank, you worried about it. If you ran a plumbing business on the Bellarine or a clinic in Geelong, you mostly did not. That has changed. The 2026 reforms to Australian privacy law are bringing more small businesses into scope, and the rules around data breaches already apply regardless of your size.
This guide is a plain-English walk-through of what data privacy means for a small business in Australia today: what the law actually requires, what counts as personal data, your main obligations, and the practical steps that keep you on the right side of it. It is not legal advice - if you have a specific situation, seek legal advice for your situation.
What data privacy actually means
Personal information is any information or opinion about an identified individual, or someone who is reasonably identifiable, whether it is true or not. A name and a phone number is personal information. So is a photo, a purchase history, an IP address, or a note a staff member wrote about a customer.
Privacy is not the same as security, even though people use the words interchangeably. Security is about protecting information from unauthorised access - locks, passwords, encryption, firewalls. Privacy is about whether you should have collected it in the first place, what you can do with it, who you can share it with, and how long you keep it. You can have excellent security and still breach privacy - for example, by holding customer data for years after you stopped needing it.
The Privacy Act and the Australian Privacy Principles
The Privacy Act 1988 is the main federal law that governs how personal information is handled in Australia. Sitting underneath it are the Australian Privacy Principles (APPs), a set of 13 principles that cover the full life cycle of personal information: collecting it, using and disclosing it, keeping it accurate and secure, and eventually destroying it.
In plain English, the APPs say things like: only collect what you actually need; tell people you are collecting it and why; do not use it for something unrelated without consent; keep it secure; let people see and correct their own information; and do not keep it forever if you no longer need it.
The small business exemption
Historically, small businesses with an annual turnover of $3 million or less have been exempt from most of the Privacy Act. That exemption has never been absolute. It does not apply if you trade in personal information, hold health records or tax file numbers, or are a contractor handling personal information for the government.
The 2026 reforms narrow this exemption and bring more small businesses into scope. The exact thresholds and transition arrangements matter, so check current thresholds against your own turnover and activities rather than assuming you are still exempt. Even where the Act itself does not apply, the Notifiable Data Breaches scheme and state-based privacy and health records laws can still catch you.
What counts as personal data
For a typical Geelong small business, personal data is hiding in plain sight across systems you use every day. It includes:
- Names, email addresses, phone numbers, and postal or street addresses.
- Health information - appointments, treatment notes, even a casual remark about a customer's condition.
- Financial details like credit card numbers, bank accounts, and invoices.
- Biometric data such as fingerprints or facial recognition used for access.
- Online identifiers - IP addresses, device IDs, and website cookie data tied to a person.
- Employment records for your own staff, including performance notes and payslips.
Concrete examples from local businesses: a tradie's client database with names, addresses, and job notes; a clinic's patient records; a quote sent by email that includes a customer's mobile and home address; a spreadsheet of staff with dates of birth and superannuation details. All of it is personal information, and all of it is your responsibility.
Your main obligations
Stripped back, your obligations under the APPs look like this:
- Collect only what you need. If a quote does not require a date of birth, do not ask for one.
- Store it securely. Encryption, access controls, and backups that are themselves protected.
- Limit access. Staff should only see the personal information they need for their role.
- Keep it accurate. Update records when things change and have a process for corrections.
- Allow correction. If a customer says their address is wrong, fix it.
- Retain only as long as needed. Set a retention period and stick to it.
- Destroy securely. Shred paper, wipe or destroy drives, and confirm cloud copies are deleted.
The Notifiable Data Breaches scheme
The Notifiable Data Breaches (NDB) scheme sits inside the Privacy Act and applies to entities covered by the Act. A notifiable data breach happens when there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and the breach is likely to result in serious harm to any of the individuals it is about.
Serious harm is not defined to a dollar figure. It can be financial, psychological, physical, or reputational. A lost laptop with unencrypted customer details is more likely to be serious harm than a misplaced flyer with a first name on it.
If you suspect a notifiable breach, the scheme gives you 30 days to assess whether it qualifies. Once you are satisfied it does, you must notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals as soon as practicable, with a statement describing the breach, the information involved, and what you recommend people do.
Practical steps to comply
Compliance does not need to be complicated, but it does need to be deliberate. The businesses that handle this well do the same handful of things. A good starting point is a proper cybersecurity posture built on the Essential Eight, because privacy and security overlap heavily.
- Build a data inventory. List where personal information lives - your CRM, accounting software, email, shared drives, paper files. You cannot protect what you do not know about.
- Apply least-privilege access. Give each staff member access to only the records they need. Review it when roles change.
- Encrypt at rest and in transit. Full-disk encryption on laptops, encrypted backups, and HTTPS on anything customer-facing.
- Turn on multi-factor authentication. MFA on email, accounting, and any system holding personal data is the single biggest breach control you can apply.
- Set a retention and destruction schedule. Decide how long each data type is kept, and run a quarterly clean-up to destroy what is no longer needed.
- Train your staff. Most breaches come from people, not malware. Short, regular training on phishing, sharing, and what counts as personal data goes a long way.
- Do vendor due diligence. If a supplier holds personal data on your behalf, confirm they handle it to a reasonable standard and that your contract covers it.
If you run Microsoft 365, a lot of this is already available to you. Sensitivity labels let you tag and protect documents by how sensitive they are, and data loss prevention (DLP) policies can stop personal information like tax file numbers from being emailed out of the organisation by mistake. Our Microsoft 365 services can help you turn these controls on properly rather than leaving them as defaults nobody touched.
What happens if you get it wrong
The OAIC can investigate suspected breaches of the Privacy Act, require you to fix problems, and accept enforceable undertakings. Serious or repeated interference with privacy can attract significant civil penalties. There is also the practical fallout: customers who no longer trust you, time spent on breach response instead of running the business, and the cost of credit monitoring or remediation.
This is not meant to sound doom-laden. Most small businesses that take reasonable steps never face an investigation. The point is that ignoring privacy is a real risk with real consequences, and a modest amount of upfront work removes most of it.
Getting help
Better Networks works with small and mid-sized businesses across Geelong, the Bellarine, and the Surf Coast to get data privacy and security right. We can help you map the personal information you hold, tighten access, set up retention and destruction, and put the Microsoft 365 controls in place that do most of the heavy lifting for you.
Start with our cybersecurity services or an Essential Eight compliance review if you want a structured baseline. When you are ready to talk through your specific situation, get in touch and we will walk you through what good looks like for your business.
