Reader-supported SEO Agency resourceContact us →
By Isla North · 08.10.2026 · 15 min read

There is a simple truth to be had with data privacy obligations for any online business in Australia: once you have a customer’s name, email, payment or delivery details on file, you have responsibilities. Depending on what you do and the data you handle, an Australian online enterprise will have to answer to the Privacy Act 1988, the Notifiable Data Breaches scheme, spam-marketing regulations and the Australian Privacy Principles.

I am Isla North. I have come across my share of small operators who regard privacy as something to put in the footer five minutes prior to a site going live. You might as well take a teaspoon to a bushfire. A sensible privacy programme will put it on record what information is being gathered and why, how it is put under lock and key, who has access, when it is disposed of and the procedure should there be a problem.

Which Privacy Laws Are Applicable

e-commerce inventory packing operations

An Australian online business can have more than one obligation on its hands, making e-commerce compliance in Australia essential. The federal Privacy Act is the law of the land, but then there are consumer and telecommunications laws, state and territory rules, industry regulation and the demands of payment security to consider.

The best way to go about it is to chart out all the places a customer comes into contact with the company, be it the website forms, checkout, analytics, cloud storage or your email marketing and support staff. It is not only the website builder who has to worry about compliance.

Online Operators And The Rules

Under the Privacy Act 1988, organisations are regulated in their handling of personal information. The APPs (Australian Privacy Principles) are the common term for the rules governing everything from collection and use to security, correction, overseas disclosure and governance.

In Australia, that personal information could be anything from an individual’s name, address, phone and email to account logins, IP and device identifiers, purchase records, photographs and location data so long as the person can be put to one. There is a higher degree of protection for sensitive matters like health or biometric data, racial or ethnic origin, sexual orientation and religious beliefs.

For the definitive word on where things stand, one should consult the guidance of the Office of the Australian Information Commissioner. The OAIC, as it is known, is the body that oversees the bulk of the federal framework.

On The Small-Business Exemption

Many owners think the small business privacy exemption in Australia is broader than it is. While a turnover of $3 million a year or under may see a business exempt from some of the Act’s requirements, it is no free pass.

Turnover is only one element. The structure of the business, whether it has chosen to opt in to privacy obligations, the nature of the information at hand and ties to other organisations can all come into play.

When That Exemption Is No Good

A small business dealing in health services or information, or one that is a party to a credit-reporting arrangement, needs to be circumspect. The same goes for those in a regulated sector or acting as a contracted service provider.

It is a mistake to equate “small” with “unregulated”. An online retailer of modest size might not be subject to every tenet of the Privacy Act but customers will want their information handled properly. Then there are the separate concerns of the Australian Consumer Law, security and marketing rules.

Any prudent risk management calls for a data breach response plan in Australia, secure systems and a privacy policy even if the business is exempt. It is cheaper in the long run than having to tell a customer you cannot account for his order records.

The 13 APPs Explained

These 13 principles are what the Australian Privacy Act 1988 is built on. They form a system in which a business must have a lawful basis for the information it collects, make plain what it is up to and ensure its protection.

One does not simply copy a stock policy and leave it at that; the APPs are to be applied to the way the business actually runs.

APPPractical focusExample for an online business
APP 1Openness and transparencyHave an up to date privacy policy and set out your data practices.
APP 2Pseudonymity and anonymityWhere it is practical and within the law, permit anonymous dealings.
APP 3Soliciting of personal informationDo not collect more than is reasonably called for by the business.
APP 4Dealing with unsolicited informationWhere one is not at liberty to collect, assess and put an end to any unexpected information.
APP 5Collection notificationPut in place a notice of collection that makes the purposes and any disclosures clear.
APP 6Use and disclosureThe information is to be used for what it was intended unless there is an exception.
APP 7Direct marketingOne may market only when the requirements are satisfied and an opt-out is on offer.
APP 8Cross-border disclosureManage privacy risks by taking reasonable steps after an assessment of overseas recipients.
APP 9Government-related identifiersTax file numbers and the like are to be handled within the bounds of what is allowed.
APP 10Data qualityCustomer information must be current, complete and accurate.
APP 11Security and destructionGuard data against unauthorised access, loss or misuse; de-identify or destroy once its use has run its course.
APP 12AccessMake personal information available barring a permitted exception.
APP 13CorrectionInaccurate personal information should be put right as the case demands.

Collect Information Fairly

There is good privacy practice to be had before a customer ever gets to the “buy” button. An online business would do well to determine what it actually requires, put the rationale in plain terms and resist the temptation to gather superfluous details just because a form is there for the asking.

A collection notice is expected to name the business, set out the purpose of the collection and if it is optional or required, give an account of likely uses and disclosures and the rights to access or correction. It should be there at the point of collection, not hidden away.

For sensitive matters, some secondary uses and optional marketing consent is key. It must be specific, voluntary and informed, and not hard to retract. A box for marketing that is already ticked is no way to make a choice.

Do not conflate promotional consent with what is essential for the service. An order confirmation does not equate to a customer’s agreement to be sent an SMS about a sale down the track.

In my review of the customer journey at a small online shop I was not so much put off by the volume of data as by where it all went: from the checkout and delivery tools to email, analytics, accounting and support. The form was innocuous enough, but the trail the data left was not.

Write A Privacy Policy That Is Of Some Use

The policy an Australian customer of an online business will read should be of real practices, not a recitation of legalisms. Find it easily, have it dated or versioned and see to it that it is reviewed when vendors or products are changed.

It needs to cover what is being collected and why, how it is done, to whom it might be disclosed and if it is going to leave Australia. It should also say how the business goes about protecting it, dealing with complaints and allowing customers to have their information accessed or corrected.

Make Sure The Policy Is True To Life

Look at the software settings, the website, your scripts for customer service and compare them to the policy. Should it claim no third party sharing while a cloud provider and a marketing platform are handling the data, then the wording is wanting.

Cookies and behavioural advertising need to be explained. Do not put forward grand promises of security; an online system is never without risk and a careful description of safeguards is better than trouble.

Secure, Retain And Destroy

APP 11 is clear on the need for reasonable steps to ward off unauthorised access, modification, interference or disclosure of personal information. What constitutes the right measure will vary with the systems employed, the nature of the harm and the size of the operation.

Multi-factor authentication, encryption, secure backups, staff training and logging are all part of it. You would not circulate a spreadsheet of customer particulars at a barbecue as though it were a tinny, nor should you.

Have A Routine For Retention

There should be an end date to data retention. After ascertaining what is to be kept for tax, warranty or legal purposes, anything else should be de-identified or destroyed in a secure fashion. Putting a file in an “Archive – Do Not Touch” folder is no substitute for a policy. Proper destruction means verified deletion from the system and paper records and, where you can, from the backups.

Respond To Eligible Data Breaches

Organisations that fall under the Privacy Act are subject to the Notifiable Data Breaches scheme. Should an eligible data breach come to light, it is incumbent on the business to put the OAIC and any concerned parties on notice when unauthorised access or loss of data is thought to be a probable cause for serious harm.

That harm may be physical, psychological or emotional in nature; it can be economic, financial or reputational, or even identity theft. One should not think of a breach as only a hacking affair of some drama. A misdirected email, a laptop gone missing, an account left open or a cloud folder exposed will do to warrant an investigation.

Put in place a Calm Response Plan

An Australia data breach response plan must make plain who is to be making decisions, preserving evidence, appraising risk and dealing with the OAIC if notification is called for, as well as who has contact with those affected. The incident is to be contained in short order by the business, but not at the expense of any evidence of value.

Those affected deserve to be told in no uncertain terms what has transpired, what information was at issue and what they can do about it. Vague reassurances are of little use to a person with concerns over his or her identity documents being put about on the internet.

While not all privacy incidents amount to an eligible data breach, a suspected one should be put on record and looked into. There is no virtue in a “wait and see” attitude; a minor error can become a matter of trust if one is not careful.

Vendors And Cloud Providers

For an online business there is still an onus to know how third parties are managing customer information. To outsource the processing is not to have the privacy risk vanish, merely to put another piece on the map.

In choosing a supplier, one would do well to enquire as to where data is kept, the security in place, who has access, the use of subcontractors, the reporting of incidents and the return or deletion of information once the association is over.

Examine The Contract And Your Settings

Relevant contracts ought to cover matters of confidentiality and security, audit rights, overseas disclosures, access requests and how to handle notification of an incident or deletion. Default settings are worth a review too; a platform can be inclined to share or collect more than is necessary.

Forgotten integrations are a common pitfall. An erstwhile marketing platform could be sitting on contact lists, a plug-in may have undue access to customer information or an administrator account from years back is still in play.

The Spam Act 2003 governs direct marketing consent for SMS and email in Australia. As a rule, marketing requires consent, a way to opt out and that the sender is properly identified.

There are limited cases for inferring consent, but a simple purchase is not carte blanche for every campaign to come. It is better to have an opt-in on file than to rely on the notion that the customer would not mind. Unsubscribe mechanisms need to be easy to use and opt-outs acted on without delay; suppression lists should be in place to prevent an import from re-adding a contact.

Service Messages

Do not conflate a promotional message with a transactional one like a receipt or a password reset. Some branding is acceptable on a delivery update, but a sales pitch will alter the assessment.

Keep a record of the opt-out process and of consent, including its date and source and the wording presented at sign-up. With good records at hand, a complaint is not so hard to put right and any deficiencies will be seen before the regulator has a chance to.

A Practical Compliance Checklist

You can put together a checklist in a day that will turn up the obvious shortcomings. Of course, if your business has a large customer base or works with multiple vendors and sensitive data, full compliance is something of a longer process. The way to do it is to start at the customer journey and trace the information as it moves through your systems.

Where time is of the essence, one would do well to put first things first: the privacy policy and collection notices, marketing consent, administrator access, multi-factor authentication, your vendor list and breach contacts. Small issues have a way of turning costly at these access points.

  1. Take stock of the personal information you are collecting and its destination.
  2. See if the Privacy Act and APPs are relevant.
  3. Put the privacy policy and collection notices in order.
  4. Have a look at the unsubscribe processes and consent on file.
  5. Revoke any superfluous access and close old accounts.
  6. Make sure there is documentation for retention, secure destruction and how to respond to a breach.

In the case of health or children’s information, identity documents or sizeable databases, legal counsel of a more tailored nature is in order. This guide is meant to be practical; it does not stand in for advice on an incident or a given business model.

FAQ

The Internet And Privacy Laws In Australia

At the federal level there is the Privacy Act 1988 with its 13 Australian Privacy Principles. One might also come under the Spam Act 2003 or the Notifiable Data Breaches scheme. Then there are obligations from industry rules, contracts, consumer law and state or territory legislation.

Is A Digital ID Refusable?

That is a matter apart from what an online business is obliged to do in terms of privacy. It comes down to the organisation, the service and the rules in force as to whether a digital-ID process can be turned down. A business ought to spell out any alternatives for access and not be in the habit of needlessly gathering identity data.

Small Business And The Privacy Act

An annual turnover of $3 million or under could see some businesses make use of the small business exemption, though there are notable exceptions. If credit activities are part of the business, or it is engaged in trading personal information, contracted services or other regulated work, the Act will still apply.

The 13 APPs

From the point of collection to deletion the APPs are in charge of the whole information lifecycle. They deal with security, data quality, government identifiers, overseas and direct marketing disclosure, unsolicited information, anonymity and open management of privacy, to name a few.

Stolen Customer Data

One must contain the situation, keep the evidence and determine the extent of the harm to those affected. Should it be an eligible data breach, the OAIC and the individuals in question may have to be notified.

To Have Privacy In The Business

It is not a document to be left in the website footer. Proper compliance is a matter of habit: be quick to respond to problems, vet your suppliers, be forthcoming in your explanations and in what you collect, and give due regard to marketing preferences.

For an e-commerce operation in Australia the message is plain. Do the legwork to understand the APPs and confirm your coverage, have an honest policy, get the consent documented and run through the breach plan. That is how you put compliance on firmer ground and earn the trust of the customer.

Isla North
I grew up in a house where the windows were always rattled by salt winds and my mother kept a perpetually damp collection of gardening boots by the back door.