Privacy law compliance and privacy policies
Meet your privacy obligations before a data breach forces the issue.
If your business collects personal information from customers, employees, or other individuals, the Privacy Act 1988 (Cth) imposes obligations on how that information is collected, used, stored, and disclosed. The consequences of non-compliance range from regulator complaints to mandatory data breach notifications and civil penalties. Understanding and meeting your obligations is both a legal requirement and a business risk management issue.
What is privacy law compliance and why does it matter?
Privacy law compliance is the process of ensuring that your business collects, uses, stores, and discloses personal information in accordance with the Privacy Act 1988 (Cth) (the Act) and the Australian Privacy Principles. Any business that handles personal information such as customer data, employee records, health information, or financial details is subject to obligations that govern how that information must be managed and what happens when something goes wrong. The consequences of non-compliance range from regulator investigations and enforceable determinations to mandatory public data breach notifications and, for serious or repeated breaches, civil penalties of up to $50 million.
Does the Privacy Act apply to my business?
The Privacy Act applies to Australian Government agencies and to private sector organisations with an annual turnover of more than $3 million. Certain organisations are covered regardless of turnover, including private health service providers, credit reporting bodies, and organisations that trade in personal information. Even if your business is below the turnover threshold, state and territory privacy legislation may apply. If you are unsure whether the Privacy Act applies to your business, we can advise.
What are the Australian Privacy Principles?
The Australian Privacy Principles (APPs) are 13 principles under the Act that govern how organisations handle personal information. They cover open and transparent management of personal information (including maintaining a current privacy policy), collection, use and disclosure for legitimate purposes, direct marketing obligations, cross-border disclosure, and the rights of individuals to access and correct their personal information. Compliance with all applicable APPs is required for covered entities.
What is the Notifiable Data Breaches scheme?
The Notifiable Data Breaches scheme under the Act requires covered organisations to notify both the Office of the Australian Information Commissioner and affected individuals if a data breach is likely to result in serious harm. Notification must be made as soon as practicable. Failure to notify when required is itself a breach of the Privacy Act. Organisations should have a documented data breach response plan in place before a breach occurs.
What should a compliant privacy policy include?
Obligations understood
Compliant privacy policy
Breach readiness
Get your privacy obligations and policy sorted before a breach forces the issue.
A privacy policy that does not reflect your data practices is a risk, not protection.
- We will advise on whether the Privacy Act 1988 (Cth) applies to your business and which obligations apply to your specific data practices.
- We will review your current privacy policy and advise on the changes needed to meet current requirements.
- We will advise on your data collection, use, disclosure, and storage obligations under the Australian Privacy Principles.
- We will advise on your obligations under the Notifiable Data Breaches scheme.
- We will assist you to prepare or update your privacy policy and internal data handling procedures.
When your business handles personal information and you need to know your obligations
What's included in your privacy law compliance service
- Privacy Act applicability assessment.
- Privacy policy review and update.
- Australian Privacy Principles compliance advice.
- Notifiable Data Breaches scheme obligations advice.
- Data handling procedures guidance.
A privacy policy that does not reflect your actual data practices is a liability.
Most businesses that face privacy complaints or data breach investigations do not have malicious data practices, they have inadequate ones. A privacy policy written years ago that does not mention a key data collection channel. An employee data retention practice that was never reviewed against destruction obligations. A third-party data sharing arrangement that was not disclosed to individuals at collection. These gaps are common and they create real exposure when something goes wrong. The Notifiable Data Breaches scheme means that serious breaches must be reported to both the regulator and affected individuals, and the reputational consequences of a public notification are significant.
From uncertain compliance to documented, defensible data practices
We review how your business actually collects, uses, stores, and discloses personal information, and assess that against the requirements of the Act and the Australian Privacy Principles. We update your privacy policy to reflect both the legal requirements and your actual practices, and advise on the internal procedures needed to handle data lawfully on an ongoing basis. When we are done, you have a policy and practices that hold up to scrutiny.
From uncertain obligations to compliant, documented data practices.
Data mapping and assessment
We review how your business handles personal information and identify the Privacy Act obligations that apply.
Policy and procedures
We update your privacy policy and advise on the internal procedures needed for ongoing compliance.
Ongoing compliance support
We advise on new data practices, third-party arrangements, or changes to the law that affect your obligations.
Commercial lawyers experienced in privacy law compliance, Australian Privacy Principles advice, and data breach response.
We understand that privacy compliance can feel like a technical exercise disconnected from the day-to-day running of a business. Our team advises businesses on privacy obligations regularly and knows how to translate legal requirements into practical policies and procedures that work in a real business environment.
We understand you want to know the cost, before we get started.
We will map out our process, from beginning to end, so you know what the journey will look like before you get started.
We will provide you with a clear and detailed Work Proposal covering each step along the way.
Our fair fees are all-inclusive. No hidden costs for telephone calls, emails, photocopying, couriers, or coffee.
Our great lawyer guarantee
We want to be part of your team over the long term. We achieve this by adhering to these core principles:
Take the time
We listen carefully to understand what you want to achieve. Then we thoroughly explain our advice and step you through the documents. You can be sure you know the full consequences.
Share our knowledge
We will pass on as much knowledge as we can, so you can make your own informed decisions. We want to make you truly independent.
Stick to our knitting
We only do what we're good at. You can be confident that we know what we're doing and don't pass on the cost of our learning.
Work as one team
Someone will always be available to answer your questions, or point you in the right direction. You will also benefit from a range of perspectives and experience.
Fair pricing
For advice and documents, we provide a fixed or capped quote so you don't take price risk. If you're in a dispute, we map out the process and costs so you know what to expect.
It's your show
We're not in this for our egos. We're in it for a front row seat to witness your success.