Legal, Risk & Compliance

Privacy & Customer Data

What you can and can't do with customer details under Australian privacy law.

Notes from Randall Harper. Thirty years working alongside owner-operators, executives and boards — companies of all types and sizes — across entertainment & media, hospitality, service based business, lifestyle businesses, financial services, retail and not-for-profit, in Australia, Asia, the United Kingdom and the United States. What follows is the thinking I keep returning to.

Privacy obligations apply to more businesses than you think

The Australian Privacy Act applies to all businesses with turnover above $3 million, plus certain smaller businesses regardless of size — including health service providers, credit providers, and businesses that trade in personal information. But even where the Act doesn't formally apply, customers increasingly expect proper handling of their data, and the reputational damage from a breach is often worse than any regulatory penalty.

The principles to operate by

  • Only collect personal information you actually need.
  • Tell people what you are collecting and what you will use it for.
  • Use it only for the purposes you collected it for.
  • Store it securely — encrypted where possible, access-controlled always.
  • Allow customers to access and correct their information on request.
  • Don't share it with third parties without permission.
  • Delete it when you no longer need it.

The practical privacy policy

A privacy policy is a public document on your website that explains how you handle personal information. It does not need to be a legal masterpiece, but it does need to be honest and current. Template policies are fine as a starting point; customise them to reflect what you actually do, not generic boilerplate. Out-of-date policies are worse than no policy at all.

Data breaches: what to do

If you experience a data breach — lost laptop, hacked email, accidental disclosure — assess whether it meets the threshold for notification under the Notifiable Data Breaches scheme. If it does, you have specific obligations to notify both affected individuals and the OAIC within 30 days. Get legal advice early; the wrong response can compound the original problem significantly.

Marketing consent matters

Spam Act compliance is separate from privacy law, and it bites small businesses regularly. You need explicit or inferred consent to send marketing emails or SMS, you need an unsubscribe mechanism, and you need to honour unsubscribes promptly. The penalties for getting this wrong have increased significantly in recent years, and the regulator is increasingly willing to apply them.

Want this as a PDF?

Tell us where to send it and we'll email you a copy to keep.

The contents of this paper are the opinion of Clear Point Advisory only. Readers should rely on their own judgement and obtain professional advice appropriate to their circumstances.

Clear Point Advisory · Randall Harper · randall@clearpointcollective.com.au · 0402 416 266
© 2026 The Clear Point Collective. All rights reserved.