Published 09 July 2026
Privacy Act for Australian small business: reasonable steps
For years most Australian small businesses sat outside the Privacy Act. The "small business exemption" meant that if you turned over less than $3 million a year, the Act largely didn't apply. That assumption is now out of date. A run of reforms has been narrowing the exemption and raising the stakes for mishandling personal information. Plenty of owners are hearing about it for the first time from their insurer, their lawyer or a clause in a customer's contract.
This guide covers, in plain English, what the Privacy Act expects on security (the "reasonable steps" standard) and how the Essential Eight gives you a practical way to think about it. It's general information, not legal advice. If it's unclear whether the Act applies to your business, a privacy lawyer is worth the fee.
Who the Privacy Act covers now
The Act is built on the Australian Privacy Principles (APPs): 13 principles governing how organisations collect, use, store and disclose personal information. Historically, the small business exemption meant many SMBs weren't "APP entities" at all.
Reform is heading one way, and that's towards bringing more businesses in. Even before the recent changes, plenty of small businesses were already covered because of what they do rather than how big they are. Think businesses that trade in personal information, provide health services, or are contracted service providers to government. If you hold personal information about customers or staff, the safe assumption today is that the Act is relevant to you. Don't lean on the exemption.
The Office of the Australian Information Commissioner (OAIC) publishes guidance on who is covered and how the principles apply. It's the authoritative source if you want to check your own situation.
What "reasonable steps" means for security
For cyber security, the principle that matters most is APP 11: security of personal information. Put simply, an entity must take reasonable steps to protect the personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure.
The word doing the heavy lifting is reasonable. The Act deliberately doesn't give you a checklist. What's reasonable scales with how sensitive the information is, how much harm a breach could cause, and what protections are practical for a business your size. A sole trader with a mailing list is held to a different practical standard than a medical clinic holding health records.
That flexibility helps. It also leaves owners with a fair question: how do I know my steps are reasonable? This is where a recognised security baseline earns its keep.
Where the Essential Eight fits
The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate (ASD) at cyber.gov.au. It was designed for the threats behind most breaches: phishing, malicious attachments, unpatched software and stolen passwords.
To be clear, the Essential Eight is not named in the Privacy Act, and putting it in place doesn't satisfy the Act on its own. But it's widely referenced as a sensible, well-understood baseline for what "reasonable steps" can look like in practice. Several of the eight controls line up directly with the risks APP 11 is worried about:
- Multi-factor authentication cuts the chance that a stolen password leads to someone getting into customer records.
- Regular backups protect against losing personal information to ransomware or hardware failure, and let you recover rather than pay.
- Restrict administrative privileges limits how much data any one compromised account can reach.
Working through the Essential Eight gives you a story you can defend. Not "we hoped for the best", but "we assessed ourselves against a recognised government baseline and wrote down what we do."
The Notifiable Data Breach scheme
Tied to the Privacy Act is the Notifiable Data Breaches (NDB) scheme. If an entity covered by the Act has an "eligible data breach" (one likely to result in serious harm to the people whose information was exposed), it's generally required to notify both the affected individuals and the OAIC.
For a small business, it pays to understand what that means in practice before anything goes wrong:
- You need to be able to detect and assess a suspected breach. Hard to do with no logging, no backups and no idea what data you hold.
- You need a plan for who does what (assess, contain, notify), not improvising mid-crisis.
- Notification obligations and timeframes are specific. Knowing they exist ahead of time matters.
A written incident-response plan and a clear picture of your data are the groundwork. It's the same paperwork that supports a cyber-insurance application.
A sensible sequence for a small business
You don't need a compliance department. Here's a practical order to work in:
- Know what personal information you hold and where it lives: customer records, staff files, email, cloud apps. You can't protect or report on what you haven't mapped.
- Assess your security baseline. Our free Essential Eight self-assessment takes you through the eight controls in about 20 minutes and gives you an indicative maturity level for each, in plain English.
- Close the obvious gaps first. Usually that's MFA everywhere, tested backups, and keeping admin accounts separate from everyday use.
- Write it down. A short information-security policy, an incident-response plan and a record of your controls are what show you've turned "reasonable steps" from an intention into a practice.
- Review periodically. Reasonable steps aren't a one-off. Staff, systems and data change. An annual review keeps your security and your documentation current.
The honest caveats
Two things, said plainly. First, whether the Privacy Act applies to your business, and what counts as "reasonable" for you specifically, are legal questions. This article is general information, and a privacy lawyer can give you an answer fitted to your circumstances. Second, a self-assessment reflects what you know about your own environment. It is not an audit or a certification, and no baseline removes the risk of a breach entirely.
What it does do is get you from "we've never looked" to "we know where we stand and we can show it". That's the shift that matters, both for the people whose data you hold and for the regulators, insurers and customers who increasingly ask.
Start with the 20-minute check: the free Essential Eight self-assessment gives you an indicative maturity snapshot across all eight controls, no account required.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).