Start here

Find your obligations

Read down the list and note every line that describes your business. Most businesses match three or four. Each link jumps to what the obligation asks of you.

If your business turns over more than $3 million a year

Privacy Act and the APPs, notifiable data breaches, ransomware payment reporting

If your business turns over $3 million or less

The Privacy Act can still apply, and the privacy tort applies to everyone

If your business holds any health information in Victoria

Health Records Act 2001 (Vic), with no small business exemption

If your business is a registered tax or BAS agent

Tax Practitioners Board Code, tax file number rules, and possibly the anti-money laundering regime

If your business holds or works under an Australian financial services licence

ASIC cyber resilience expectations, which covers most financial planners and insurance brokers

If your business supplies the Victorian Government

Victorian Protective Data Security Standards, through your contract

If your business supplies the Australian Government

The Privacy Act as a contracted service provider, plus whatever security terms the contract sets

If your business has, or wants, cyber insurance

The insurer's own conditions, set in your policy and renewal questionnaire

If your business is any business at all

Record keeping and the privacy tort

The obligations

What each one asks of you

These are laws and regulator expectations, not frameworks. Each has a primary source you can check, linked at the end of its entry.

Privacy Act 1988 and the Australian Privacy Principles

Applies to Businesses with annual turnover over $3 million, and some smaller businesses regardless of turnover.

The thirteen Australian Privacy Principles govern how you collect, use, store, disclose and secure personal information, including keeping a clear privacy policy. Smaller businesses are covered anyway if, among other things, they provide a health service, trade in personal information, are a contracted service provider to an Australian Government agency, or are a reporting entity under the anti-money laundering laws. That last one now reaches accountants who provide designated services, since the regime expanded on 1 July 2026.

From 10 December 2026, if a computer program uses personal information to make, or substantially help make, decisions that significantly affect people, your privacy policy must say what kinds of information and decisions are involved.

Source: OAIC: small business · Privacy and Other Legislation Amendment Act 2024

Notifiable Data Breaches scheme

Applies to Every business the Privacy Act covers, and any business holding tax file numbers.

If you suspect an eligible data breach, one likely to cause serious harm, you must take all reasonable steps to complete an assessment within 30 calendar days. Once you have reasonable grounds to believe it is an eligible breach, you must notify the OAIC as soon as practicable, then tell the people affected. The OAIC treats 30 days as the maximum, not the target.

Breaches involving tax file numbers are covered by the scheme whatever your turnover, which matters for every accounting practice and every employer.

Source: OAIC: the NDB scheme · TPB: notifiable data breaches

Statutory tort for serious invasions of privacy

Applies to Any person or business. There is no small business exemption.

Since 10 June 2025, individuals can sue for a serious invasion of privacy, meaning intrusion upon their seclusion or misuse of information about them, where it was intentional or reckless. They do not need to prove financial loss. The exemptions cover journalism, government agencies, law enforcement and intelligence bodies, not private businesses of any size.

Source: Privacy Act, Schedule 2

Ransomware payment reporting

Applies to Businesses with turnover of more than $3 million in the previous financial year, and critical infrastructure entities.

If you make a ransomware or cyber extortion payment, or one is made on your behalf, you must report it to the Australian Signals Directorate within 72 hours. The obligation started on 30 May 2025; after an education-first period, regulators moved to compliance and enforcement from 1 January 2026.

Source: cyber.gov.au: payment reporting · Home Affairs factsheet

Health Records Act 2001 (Vic)

Applies to Any organisation that handles health information in Victoria, whatever its size.

This is the Victorian obligation most businesses miss. It covers health service providers, and also other organisations holding health information, which the Victorian Department of Health says includes employers. It sets its own privacy principles for collecting, holding, using and securing that information. Complaints go to the Health Complaints Commissioner.

Source: Victorian Department of Health: Health Records Act

Australian financial services licensees

Applies to AFS licensees and the businesses operating under them, including most financial planners and insurance brokers.

ASIC treats cyber resilience as part of the general licence obligations, including having adequate risk management systems. In February 2026 the Federal Court ordered FIIG Securities to pay a $2.5 million penalty, which ASIC describes as the first civil penalty for cyber security failures under those general obligations. On 8 May 2026 ASIC wrote to all licensees calling for urgent cyber uplift, describing cyber resilience as a core licensing obligation rather than an IT issue.

Source: ASIC 26-021MR · ASIC 26-092MR

Registered tax and BAS agents

Applies to Registered tax and BAS agents, and their practices.

The Code of Professional Conduct requires you to keep client information confidential and to run a documented system of quality management, which includes protecting that confidentiality. The Tax Practitioners Board expects sufficient IT controls to protect client records and names specific ones, such as multi-factor authentication, patching and encryption. New sanctions powers start on 1 October 2026, including civil penalties for breaching the Code.

If your practice provides designated services under the anti-money laundering regime, which expanded to accountants on 1 July 2026, you also verify client identity and keep those records.

Source: TPB: protect your practice · TPB: sanctions reforms · TPB: AML/CTF factsheet

Victorian Government suppliers

Applies to Businesses contracted to Victorian public sector organisations that handle their information.

The Victorian Protective Data Security Standards bind Victorian public sector organisations, and those organisations must make sure their contracted service providers do not breach the Standards when handling public sector information. In practice the obligation reaches you through your contract, so read the security clauses before you sign.

Source: OVIC: the Standards

Record keeping

Applies to Every business.

The ATO requires most business records to be kept for five years, and companies must keep financial records for at least seven. How long you keep information is also a security decision: records held beyond their purpose are still records that can leak.

Source: ATO: record keeping · ASIC: company records

Frameworks

What you will be asked about, even though it is not law

Frameworks are how insurers, clients and assessors check that the obligations above are met in practice. None is a legal requirement for a private business, but you will meet all three.

ASD Essential Eight

Eight technical controls from the Australian Signals Directorate. Mandatory at Maturity Level Two for non-corporate Commonwealth entities, voluntary for everyone else. The maturity model was last updated in November 2023, and ASD consulted partners in mid-2026 on evolving it into a broader “Essentials” series.

The Essential Eight explained

SMB1001

An Australian cyber security standard written for small and medium businesses, published by Dynamic Standards International and updated each year. It has five levels, certified through a scheme that names them Bronze to Diamond, and it covers policy and people as well as technology.

The SMB1001 standard

Cyber insurance conditions

Not a law, but a contract. Insurers set their own requirements, and renewal questionnaires commonly ask about multi-factor authentication, backups, patching and incident response. An inaccurate answer can matter as much as a missing control.

Answering renewal questions

And what does not

Three things you may hear about that probably do not apply

The small business exemption is not being removed, yet. The draft Privacy Act bill released on 31 August 2026 leaves it in place, so businesses turning over $3 million or less remain outside the Privacy Act unless one of the categories above applies.

The Scams Prevention Framework places its obligations on designated sectors, starting with banks, telecommunications providers and digital platforms, not on ordinary businesses.

Critical infrastructure laws apply to owners and operators of designated critical infrastructure assets. A professional practice is very unlikely to be one.

Knowing what does not apply is part of compliance. It stops a business spending on the wrong thing while the obligations that do apply go unmet.

What is changing

The dates that matter, 2024 to 2026

These are the changes that affect a business like yours, in order, including two that are still to come.

  1. 11 December 2024New privacy penalty tiers and OAIC infringement notices begin.
  2. 1 January 2025Updated Tax Practitioners Board Code obligations apply to practices with more than 100 employees; the rest follow on 1 July 2025.
  3. 30 May 2025Ransomware payment reporting starts for businesses turning over more than $3 million.
  4. 10 June 2025The statutory tort for serious invasions of privacy commences.
  5. 1 January 2026Ransomware payment reporting moves from education to compliance and enforcement.
  6. February 2026First Federal Court civil penalty for cyber failures under general AFS licence obligations ($2.5 million).
  7. 8 May 2026ASIC writes to all financial services licensees calling for urgent cyber uplift.
  8. 1 July 2026The anti-money laundering regime expands to accountants who provide designated services.
  9. 31 August 2026Draft Privacy Act bill released, proposing breach notification to the OAIC within 72 hours. Still a draft.
  10. 1 October 2026New Tax Practitioners Board sanctions powers, including civil penalties for Code breaches.
  11. 10 December 2026Privacy policies must explain automated decision-making that significantly affects people.

Penalties, briefly

Privacy penalties now come in three tiers

For a serious interference with privacy, a company faces up to the greatest of $50 million, three times the benefit obtained, or, where the benefit cannot be determined, 30 per cent of adjusted turnover. A second tier covers any interference with privacy, serious or not. The third lets the OAIC issue infringement notices for administrative failures such as an inadequate privacy policy, currently 60 penalty units per contravention for an ordinary company.

Penalty units are indexed: a Commonwealth penalty unit has been $364 since 1 July 2026, so 60 units is $21,840. Figures quoted elsewhere at the old rate are out of date.

Source: Privacy Act, ss 13G, 13H, 13K · ASIC: penalty units

The penalties are real, but they are rarely the first cost. The first cost is the breach itself: the investigation, the downtime, the notifications and the clients who leave.

Where we fit

We make the controls real and keep the evidence

We are not lawyers, and this page is not legal advice. Our part is the technical side of these obligations: putting the controls in place, keeping them working, and holding the evidence you need when an insurer, a client or a regulator asks.

Security that is managed, not bought

AgileSECURE covers identity, email, endpoints, data and governance, aligned to SMB1001 and delivered as part of AgileMANAGED.

A plan and a paper trail

AgileSTRATEGY keeps a roadmap, reviews it quarterly, and tracks renewals and vendors, so compliance is planned rather than rushed.

Know where you stand

Start with the three-minute Cyber Health Check, or book a free 30-minute Security Review with a senior member of the team.

Questions

Common questions about compliance obligations

Does the Privacy Act apply to my small business?
If your annual turnover is more than $3 million, yes. If it is $3 million or less, it can still apply: the OAIC lists health service providers, businesses that trade in personal information, contracted service providers to the Australian Government, reporting entities under the anti-money laundering laws, credit reporting bodies and several others. Tax file number rules and the Victorian Health Records Act apply regardless of turnover.
How long do we have to report a data breach?
If you suspect an eligible data breach, you must take all reasonable steps to assess it within 30 calendar days. If you then have reasonable grounds to believe it is an eligible breach, you must notify the OAIC as soon as practicable, and then the affected individuals. The 30 days is a maximum for the assessment, not a deadline for notifying.
Is the Essential Eight mandatory?
Only for non-corporate Commonwealth entities, which must reach Maturity Level Two. For private businesses it is voluntary, although insurers, larger clients and government contracts often ask about it.
Do we have to report a ransomware payment?
If your business turned over more than $3 million in the previous financial year and makes a ransomware or cyber extortion payment, you must report it to the Australian Signals Directorate within 72 hours of paying, or of becoming aware that a payment was made on your behalf.
What changes in 2026?
Tax practitioners face new Tax Practitioners Board sanctions powers from 1 October 2026. Privacy policies must explain automated decision-making from 10 December 2026. The Government has also released a draft Privacy Act bill that proposes notifying the OAIC within 72 hours of a breach; it is a draft, not law.
Is this legal advice?
No. This page is general information, reviewed on 26 September 2026, with a link to the official source for each obligation. For advice on your specific situation, speak to your lawyer or accountant. Our role is making the technical controls real and keeping the evidence.

Not sure which of these apply to you?

The free 30-minute Security Review works through your obligations and where your controls stand against them. Plain English, no system access needed.

Book a Security Review
1300 859 910 Book a Conversation