Back to GDPR

Australian Privacy Principles for Small Business: Does the Privacy Act Apply to You?

Sydney Opera House at the harbour, representing the Australian Privacy Principles for small business Photo: Unsplash

Short answer: Most businesses with an annual turnover of $3 million or less are exempt from the Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles. The exemption does not apply if you provide a health service and hold health information, trade in personal information, work under a Commonwealth contract or opt in. So most HealthTech companies are covered.

Related guides:

Key takeaways

  • The Privacy Act 1988 (Cth) applies to Australian Government agencies and to organisations with an annual turnover above A$3 million. Smaller businesses are generally exempt, but the exceptions are wide. The OAIC's small business guidance explains how turnover is measured and lists every exception.
  • If you provide a health service and hold any health information, the APPs apply to you whatever your turnover. This catches many HealthTech startups, clinics and allied health providers.
  • Covered businesses must follow all 13 Australian Privacy Principles (APPs) and the Notifiable Data Breaches (NDB) scheme, which requires notifying the OAIC and affected individuals about eligible data breaches.
  • Removing or narrowing the small business exemption has been proposed as part of further reform, so building privacy controls now is a sensible hedge.
  • If you already run ISO 27001 or GDPR, most APP obligations map onto controls you already have.

Does the Privacy Act apply to small businesses?

Usually not, if your annual turnover is $3 million or less and no exception applies. The Privacy Act regulates "APP entities", meaning Australian Government agencies and organisations, and small business operators are carved out of that definition.

Details that matter:

  • Turnover is the test, not headcount or profit.
  • Group structure counts. A small business related to a larger one generally cannot rely on the exemption.
  • Growth ends the exemption. Once turnover exceeds the threshold you become an APP entity, so plan ahead.
  • Foreign companies can be caught. The Act can apply to overseas organisations that carry on business in Australia.

Being exempt does not remove every obligation. Contracts and customer security questionnaires often expect APP-level practices regardless of size.

Which small businesses are covered regardless of turnover?

Several categories of small business must comply with the APPs even if their turnover is under $3 million. The most relevant for SaaS and HealthTech companies are:

Exception What it means in practice
Provides a health service and holds health information Any business that provides a health service to individuals and holds health information (other than in employee records) is covered. This includes GPs, allied health, pharmacies, and many digital health and telehealth products.
Trades in personal information Businesses that disclose personal information for a benefit or service, or pay others for it, are covered unless consent or the law allows it.
Contracted service provider to the Commonwealth If you deliver services under a Commonwealth contract, you are covered for that work.
Related to a larger business A small business related to an organisation that is not itself small is covered.
Opted in A small business can choose to be treated as an APP entity by registering with the Office of the Australian Information Commissioner (OAIC).

Why the health service exception matters for HealthTech

"Health service" is defined broadly. It covers activities intended to assess, record, maintain, improve or manage an individual's physical or psychological health. A symptom checker, remote monitoring platform, telehealth app or practice management tool that records clinical information can fall within it. Health information is also "sensitive information" under the Act, which means stricter rules on collection (generally consent) and use.

If you run a small digital health startup, assume the APPs apply until a lawyer tells you otherwise. Our guide to GDPR for healthcare covers the equivalent special category rules if you also serve European patients.

What do the 13 Australian Privacy Principles require?

The 13 APPs are principles-based rules on how covered entities collect, use, disclose, secure and give access to personal information.

APP Title Plain-English summary
APP 1 Open and transparent management of personal information Have practices, procedures and a clear, up-to-date privacy policy.
APP 2 Anonymity and pseudonymity Let people deal with you anonymously or under a pseudonym where practicable.
APP 3 Collection of solicited personal information Only collect what is reasonably necessary, and get consent for sensitive information such as health data.
APP 4 Dealing with unsolicited personal information If you receive information you did not ask for, decide whether you could have collected it, and destroy or de-identify it if not.
APP 5 Notification of the collection of personal information Tell people at or before collection who you are, why you collect their data and who you share it with.
APP 6 Use or disclosure of personal information Use and disclose data only for the purpose you collected it, unless an exception applies.
APP 7 Direct marketing Only use personal information for direct marketing in limited cases, and always offer a simple opt-out.
APP 8 Cross-border disclosure of personal information Take reasonable steps so overseas recipients handle data consistently with the APPs. You may remain accountable for them.
APP 9 Adoption, use or disclosure of government related identifiers Do not use government identifiers, such as a Medicare number, as your own customer identifier.
APP 10 Quality of personal information Keep personal information accurate, up to date and complete.
APP 11 Security of personal information Protect data from misuse, interference, loss and unauthorised access, and destroy or de-identify it when no longer needed.
APP 12 Access to personal information Give individuals access to the information you hold about them on request.
APP 13 Correction of personal information Correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

For engineering teams, APP 11 is where most of the work sits. It is outcome-based, so the question is whether your steps were reasonable for the sensitivity of the data.

How does the Notifiable Data Breaches scheme work?

If you are covered by APP 11, you must notify the OAIC and affected individuals when you have an eligible data breach. An eligible data breach happens when:

  1. There is unauthorised access to, unauthorised disclosure of, or loss of personal information you hold.
  2. That breach is likely to result in serious harm to one or more individuals.
  3. You have not been able to prevent the likely risk of serious harm with remedial action.

When you suspect an eligible breach, you must carry out a reasonable and expeditious assessment, and the scheme expects that assessment to be completed within 30 days. If the breach is eligible, you must give the OAIC a statement describing the breach, the information involved and recommended steps, and notify affected individuals as soon as practicable.

Health information often tips a breach into "likely serious harm", so HealthTech teams should build NDB steps into their incident response plan: who assesses, who decides and who notifies. Our incident response plan template gives you a starting structure.

What is changing with Privacy Act reform?

Australia is reforming the Privacy Act in stages, and the first tranche is law. The Privacy and Other Legislation Amendment Act 2024 introduced changes including:

  • A statutory tort for serious invasions of privacy.
  • A tiered penalty regime, with infringement notices available for less serious breaches.
  • Clarification that reasonable security steps under APP 11 include technical and organisational measures.
  • Transparency requirements about automated decision-making that uses personal information, which start on 10 December 2026.

Further reforms are expected. The most significant proposal for small businesses is removing or narrowing the small business exemption. This has been proposed as part of the broader Privacy Act review and has not been enacted. Timing and design are uncertain, but if it goes ahead, many businesses under $3 million will need to comply for the first time. Starting now spreads the effort and helps with enterprise buyers today.

APPs compliance checklist for a small SaaS or HealthTech business

Use this checklist whether the APPs apply to you now or you expect them to soon.

  1. Confirm your status. Record your turnover assessment and check each exception, especially the health service test. Revisit it yearly.
  2. Map your personal information. What you collect, why, where it lives, who can access it and which vendors receive it. Flag health data.
  3. Publish an APP privacy policy covering what you hold, how you use it, overseas disclosures, and how people can access, correct or complain.
  4. Add collection notices (APP 5) to signup flows, intake forms and apps.
  5. Get and record consent for health and other sensitive information.
  6. Review cross-border disclosures to offshore hosting, support and subprocessors, with contractual privacy terms.
  7. Harden security under APP 11: MFA, least-privilege access, encryption, logging, backups and vulnerability management.
  8. Set retention rules to delete or de-identify data you no longer need, including backups.
  9. Handle access and correction requests with a simple intake, identity checks and tracking.
  10. Document your NDB process, with notification templates and a tabletop exercise.
  11. Manage vendors and keep a current subprocessor list.
  12. Train your team on privacy basics and breach escalation.

If you are designing new features, bake these steps into product development using privacy by design principles so compliance is not bolted on later.

How do the APPs line up with ISO 27001 and GDPR?

Closely enough that one control library covers most of all three. GDPR and the APPs share core privacy concepts, and ISO 27001 supplies the security machinery behind APP 11 and the NDB scheme.

APP area GDPR equivalent ISO 27001 support
APP 1 privacy policy and governance Transparency and accountability Policies, roles and management review
APP 3 and 5 collection and notice Lawful basis and privacy notices Asset and information inventory
APP 6 and 7 use, disclosure, marketing Purpose limitation and consent Information classification and handling
APP 8 cross-border disclosure International transfer rules Supplier relationships and agreements
APP 11 security and destruction Security of processing, storage limitation Annex A controls for access, cryptography, logging, deletion
APP 12 and 13 access and correction Rights of access and rectification Documented procedures and records
NDB scheme Personal data breach notification Incident management controls

The differences are in the details: GDPR has rights and a lawful basis model the APPs do not mirror exactly, and breach triggers and timelines differ. If you already run ISO 27001 or GDPR, do a gap assessment and add Australia-specific items such as APP privacy policy content, government identifier rules and NDB templates.

How SecureSlate helps

SecureSlate helps SMBs and HealthTech teams run privacy and security compliance from one place. Track the APPs as a custom framework and map them onto the controls you already run for ISO 27001, GDPR, HIPAA and SOC 2, so each control is written once and reused. Automated evidence collection from your cloud and SaaS stack keeps proof of your security controls current, while policies, a risk register and vendor risk workflows cover privacy policies, cross-border disclosures and subprocessor reviews. Audit-ready exports let you answer customers and auditors without a scramble.

Start your free SecureSlate trial

FAQ

Does the Privacy Act apply to a business with turnover under $3 million?

Generally no, because of the small business exemption. However, the exemption does not apply if you provide a health service and hold health information, trade in personal information, are a Commonwealth contracted service provider, are related to a larger business or have opted in. Check each exception before relying on the exemption.

Is a HealthTech startup covered by the Australian Privacy Principles?

Very often, yes. If your product or service provides a health service to individuals and you hold health information, the APPs apply regardless of turnover. Health information is also sensitive information, so stricter consent and handling rules apply.

Has the small business exemption been removed?

Not at the time of writing. Removing or narrowing the exemption has been proposed as part of further Privacy Act reforms, but it has not been enacted. Small businesses should monitor reform progress and consider adopting APP-aligned practices early.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Jun 25, 2026 · GDPR

Data Privacy Week

Jun 25, 2026 · GDPR

GDPR Certification

Jun 25, 2026 · GDPR

CCPA Checklist

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?