Published 09 July 2026
Privacy Act for Australian small business: reasonable steps
For years, most small businesses in Australia sat outside the Privacy Act thanks to the "small business exemption" — if you turned over less than $3 million a year, the Act largely didn't apply. That assumption is now out of date. A wave of reforms has been narrowing that exemption and raising the stakes for mishandling personal information, and many owners are hearing about it for the first time from their insurer, their lawyer, or a customer's contract.
This guide explains, in plain English, what the Privacy Act expects around security — the "reasonable steps" standard — and how the Essential Eight gives you a practical way to think about it. It is general information, not legal advice; if the Act's application to your business is unclear, a privacy lawyer is worth the fee.
Who the Privacy Act covers now
The Act is built around the Australian Privacy Principles (APPs) — 13 principles governing how organisations collect, use, store and disclose personal information. Historically the small business exemption meant many SMBs weren't "APP entities" at all.
The direction of reform is to bring more businesses into scope. Even before recent changes, plenty of small businesses were already covered because of what they do rather than their size — for example, businesses that trade in personal information, provide health services, or are contracted service providers to government. If you hold personal information about customers or staff, the safe assumption today is that the Act is relevant to you, and the exemption is not something to lean on.
The Office of the Australian Information Commissioner (OAIC) publishes guidance on who is covered and how the principles apply; it's the authoritative source if you want to check your specific situation.
What "reasonable steps" means for security
The principle that matters most for cyber security is APP 11 — security of personal information. In plain terms, it says an entity must take reasonable steps to protect the personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure.
The word doing the work is reasonable. The Act deliberately doesn't hand you a checklist — what's reasonable scales with the sensitivity of the information, the harm that a breach could cause, and what protections are practical for a business your size. A sole trader holding a mailing list is held to a different practical standard than a medical clinic holding health records.
That flexibility is helpful, but it leaves owners with a fair question: how do I know if my steps are reasonable? This is exactly where a recognised security baseline helps.
Where the Essential Eight fits
The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate (ASD) at cyber.gov.au. It was designed for exactly the threats that cause most breaches — phishing, malicious attachments, unpatched software and stolen passwords.
The Essential Eight is not named in the Privacy Act, and implementing it does not, by itself, satisfy the Act. But it is widely referenced as a sensible, well-understood baseline for what "reasonable steps" can look like in practice. Several of the eight controls map directly onto the risks APP 11 is worried about:
- Multi-factor authentication reduces the chance that a stolen password leads to unauthorised access to customer records.
- Regular backups protect against loss of personal information from ransomware or hardware failure — and let you recover rather than pay.
- Restrict administrative privileges limits how much data any one compromised account can reach.
Approaching security through the Essential Eight gives you a defensible story: not "we hoped for the best," but "we assessed ourselves against a recognised government baseline and documented what we do."
The Notifiable Data Breach scheme
Tied to the Privacy Act is the Notifiable Data Breaches (NDB) scheme. If an entity covered by the Act experiences an "eligible data breach" — one likely to result in serious harm to the people whose information was exposed — it is generally required to notify both the affected individuals and the OAIC.
For a small business, the practical implications are worth understanding before anything goes wrong:
- You need to be able to detect and assess a suspected breach, which is hard if you have no logging, no backups and no idea what data you hold.
- You need a plan for who does what — assess, contain, notify — rather than improvising during a crisis.
- Notification obligations and timeframes are specific, so knowing they exist in advance matters.
A written incident-response plan and a clear picture of your data are the groundwork here — the same documentation that supports a cyber-insurance application.
A sensible sequence for a small business
You don't need a compliance department. A pragmatic order of operations:
- Know what personal information you hold and where it lives — customer records, staff files, email, cloud apps. You can't protect or report on what you haven't mapped.
- Assess your security baseline. Our free Essential Eight self-assessment walks through the eight controls in about 20 minutes and gives you an indicative maturity level for each, in plain English.
- Close the obvious gaps first — usually MFA everywhere, tested backups, and separating admin accounts from everyday use.
- Write it down. A short information-security policy, an incident-response plan, and a record of your controls are what demonstrate you've turned "reasonable steps" from an intention into a practice.
- Review periodically. Reasonable steps aren't a one-off; staff, systems and data change. An annual review keeps both your security and your documentation current.
The honest caveats
Two things worth stating plainly. First, whether your business is covered by the Privacy Act, and what counts as "reasonable" for you specifically, are legal questions — this article is general information, and a privacy lawyer can give you an answer tailored to your circumstances. Second, a self-assessment reflects what you know about your own environment; it is not an audit or a certification, and no baseline eliminates the risk of a breach entirely.
What it does do is move you from "we've never looked" to "we know where we stand and we can show it" — which is the difference that matters, both for the people whose data you hold and for the regulators, insurers and customers who increasingly ask.
Start with the 20-minute check: the free Essential Eight self-assessment gives you an indicative maturity snapshot across all eight controls, no account required.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).