The Office of the Australian Information Commissioner (OAIC) publishes statistics on notified data breaches twice a year, and the count has run into the hundreds every six-month reporting period for years. A consistent share of those breaches, often around a third in recent reports, come down to human error rather than hacking. An email sent to the wrong address. A customer spreadsheet on a laptop left in an Uber.
That detail matters for small business owners, because human error is the one category that doesn’t care how small you are. This post walks through the practical privacy obligations we see Brisbane and Australian owners overlook when they collect customer information. It’s general information, not legal advice, and privacy is an area where the detail of your specific business genuinely changes the answer.
Does privacy law apply to a small business?
Whether Australia’s federal privacy regime formally applies to a small business generally depends on its annual turnover and the kind of work it does. Some smaller businesses are commonly covered regardless of size, including those providing health services or trading in personal information, and reform in this area has been moving toward covering more small businesses, not fewer.
Here’s the practical reality though. Even a business that sits outside the formal regime still faces customer expectations, contract clauses that require certain data handling, platform terms (every ad network and payment provider has them), and the plain commercial damage of a breach. In our experience the businesses that treat privacy as “not applicable to us” are the ones with the messiest data when someone finally looks.
Working out where your business actually sits is exactly what our legal and governance advisors will look at, and it’s worth getting a firm answer rather than an assumption. business.gov.au has a plain-language starting point on privacy obligations for businesses.
What counts as customer personal information?
Personal information is generally any information about an identified person, or a person who is reasonably identifiable. Names, emails, phone numbers and addresses are the obvious examples, but the definition reaches further than most owners expect.
Purchase histories tied to a customer account. Custom audience lists uploaded to Meta or Google. Call recordings. CCTV footage of your shopfront. Quote requests sitting in an inbox from 2019. Health-related information is generally treated as sensitive and held to a higher standard, which catches allied health clinics, gyms with injury questionnaires, and NDIS providers who often don’t think of themselves as data businesses.
If a person could be picked out from it, treat it as personal information until someone qualified tells you otherwise.
Collect less than your forms currently ask for
The simplest privacy improvement most small businesses can make is deleting fields from their forms. Every piece of customer data you collect is something you now have to store, secure and eventually dispose of. If it isn’t needed for the job, it’s pure liability.
A pattern we keep seeing: a quote form built years ago asks for date of birth, home address and how the person heard about the business, when the actual quoting process only ever uses the suburb and a phone number. Nobody remembers why the other fields are there. The data piles up anyway.
Our growth team builds lead forms for a living, and the tension is real. More fields can mean better qualified leads. But the general principle in Australian privacy guidance is to collect what’s reasonably necessary for what you actually do, and that principle happens to be good marketing practice too. Shorter forms convert better.
Where customer data hides in a small business
Customer data in a small business almost never lives in one tidy system. When we map data as part of an operations review, it typically turns up in six or more places, most of them forgotten.
| Where it hides | Common problem | Lower-risk habit |
|---|---|---|
| Email inboxes | Years of attachments, no cleanup | Move data to systems, archive old mail |
| Spreadsheet exports | Copies on personal laptops | Keep exports in shared, access-controlled storage |
| Marketing platforms | Old lists nobody audits | Review lists and remove stale contacts |
| Ad platform audiences | Uploaded lists with unclear consent | Document what each upload was based on |
| Ex-staff accounts | Access never revoked | Offboarding checklist that cuts access same day |
| Old POS or CRM systems | Retired software still holding records | Export what’s needed, then close it properly |
The ex-staff row is the one owners wince at. In reviews we regularly find former employees who still have live logins to the CRM or the shared drive months after they left. It costs nothing to fix and almost nobody has a process for it.
What a privacy policy is actually supposed to do
A privacy policy is meant to describe, accurately, what your business collects, why, how it’s held, and who it’s shared with. It is a description of reality, not a decoration for the website footer.
The most common failure we see is a template policy that contradicts what the business actually does. The policy says data never leaves Australia, while the business runs its email, bookings and accounting on overseas-hosted platforms. That mismatch is worse than useful, because a policy generally functions as a representation to your customers, and misdescribing your practices can create problems of its own under consumer law.
The fix isn’t a better template. It’s mapping what you actually collect and where it flows, then having the policy written to match. The OAIC publishes guidance on what a policy should cover, and a lawyer reviewing yours will start by comparing it to how the business really operates.
What happens if customer data is lost or stolen?
Australia runs a notifiable data breaches scheme, which generally means that covered businesses may need to notify affected individuals and the OAIC when a breach is likely to cause serious harm. The assessment of whether a breach crosses that line is fact-specific, and it’s a call to make with proper advice, quickly.
What matters before any of that is having a plan. The businesses that handle breaches well are the ones that already know who to call, which systems hold what, and who has authority to act. The ones that handle it badly spend the first 48 hours working out what data they even hold. Given that a third of notified breaches involve simple human error, assume it can happen to you and write the one-page response plan now.
Why customer data comes up when you sell the business
Buyers and their advisors increasingly ask hard questions about customer data during due diligence, and a customer list collected without clear consent is worth less than one collected properly. This surprises owners every time.
In our Sale Ready work with business brokers, the customer database is often listed as a headline asset. Then someone asks whether the marketing consent attached to those contacts actually transfers to a new owner, whether the privacy policy permits the sale, and how the list was built. If the answers are vague, the buyer discounts the asset or asks for warranties the seller doesn’t want to give. Cleaning this up twelve months before a sale is cheap. Cleaning it up mid-negotiation is not.
Common questions about small business privacy obligations
Do I need a privacy policy on my website?
Businesses covered by the federal privacy regime generally need one, and even businesses that aren’t formally covered usually need one anyway, because ad platforms, app stores and payment providers commonly require it in their terms.
Can I send marketing emails to past customers?
Australian spam rules generally require consent, which may be express or inferred from an existing relationship, plus a working unsubscribe option and accurate sender details. Bought lists and scraped emails are where businesses commonly get into trouble.
How long should I keep customer data?
The general principle is to keep personal information only as long as it’s needed for the purpose it was collected for, then destroy or de-identify it. Some records carry separate retention obligations (tax and employment records, for instance), so this is worth mapping properly rather than guessing.
What about customer data stored in overseas cloud tools?
Most small businesses use overseas-hosted software, and that’s generally workable, but your privacy policy should reflect it and there may be obligations around how overseas disclosure is handled. Don’t claim data stays in Australia if your stack says otherwise.
Is a free template privacy policy good enough?
A template is better than nothing only if it matches what you actually do. In our experience most templates don’t, and an inaccurate policy can create more exposure than it removes.
Who regulates privacy in Australia?
The Office of the Australian Information Commissioner is the federal privacy regulator, and its website is the best free resource for guidance written for businesses.
Getting a straight answer on your setup
Privacy compliance for a small business in Australia usually comes down to a handful of practical questions. What do you collect, where does it live, who can touch it, does your policy tell the truth, and what happens on a bad day. Most owners can’t answer all five, and that’s normal, because nobody built the business around data.
The legal side of our practice, working with partner counsel, can map your customer data alongside the marketing and operations picture, since the three are never really separate. If you’d like a clear read on where you stand before it becomes a due diligence problem or a breach notification, book a first conversation with us. Thirty minutes usually tells you which of the five questions need real work.

