Important: this is general information, not legal advice.
The author of this article is not a lawyer, and neither is Duelling Pixels. Australian privacy and marketing law is fact-specific and changes regularly — what applies to your business depends on how you collect, use, store and share personal information in your particular circumstances. Use this guide to ask better questions, then talk to an Australian-qualified privacy or commercial lawyer before making decisions that carry legal risk.
If you run a small business in Australia, the conventional wisdom has been that privacy law is something the big end of town worries about. That wisdom expired sometime in 2025. In late 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million over a single data breach — the first major civil penalty under the Privacy Act. In April 2026, the Australian Communications and Media Authority (ACMA) imposed $3.96 million in infringement notices against Latitude Finance over more than 2.7 million breaches of the Spam Act. The Office of the Australian Information Commissioner (OAIC) is running its first-ever proactive compliance sweeps. And on 1 July 2026, many professional service firms that have long sat outside the Privacy Act will be drawn into its orbit by the AML/CTF Tranche 2 reforms.
This guide walks through what’s now expected of an Australian small business that collects customer data — what you can hold, how to ask for it, what you can do with it, and what’s about to change. It’s written for owners and operators, not lawyers, and is a starting point for conversations with both your developer and your solicitor.
Why privacy stopped being a “big-company” problem
The Privacy Act 1988 generally applies to businesses with an annual turnover above $3 million. The trap is the carve-outs. Even under the threshold, the Act still catches you if you provide a health service, trade in personal information, are contracted to the Commonwealth, or run a residential tenancy database — and the OAIC sets these out clearly. Those aren’t edge cases. They capture health, allied health, complementary therapy and wellness businesses that hold health information, and a long tail of suppliers selling into government.

From 1 July 2026, the picture changes again. Tranche 2 of the Anti-Money Laundering and Counter-Terrorism Financing reforms extends the regime to certain designated services typically provided by real estate professionals, lawyers,conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones. The OAIC’s guidance is that the Privacy Act applies to the personal information handling connected with those AML/CTF obligations,even if a business would otherwise sit under the $3 million small business threshold.
Penalties have caught up to the rhetoric. For serious or repeated breaches, courts can impose the greater of $50 million,three times the benefit obtained, or 30% of adjusted turnover. The ACL penalty was the first major civil penalty awarded under the Act. The OAIC’s proceedings against Medibank — over a breach affecting roughly 37% of the Australian population — remain live, with the alleged exposure based on the previous $2.22 million-per-contravention regime. The Notifiable Data Breaches scheme adds reporting obligations: generally, you have up to 30 days to assess a suspected eligible breach, and once a breach is confirmed as eligible, you must notify the OAIC and the people affected as soon as practicable.
Does the Privacy Act apply to your business?
- Annual turnover over $3M → yes
- Provide a health service or hold health information → yes
- Trade in personal information → yes
- Contracted to the Commonwealth → yes
- From 1 July 2026: real estate, legal, conveyancing, accounting, trust and company services, or dealing in precious metals — for the AML/CTF parts of your work → yes
- None of the above → some obligations still apply (especially if you buy marketing lists), and full compliance is the safer commercial position.
The four types of customer data, and why two of them are quietly dangerous
How you got the data matters as much as what’s in it. Marketers typically carve customer information into four categories.
Zero-party data is what a customer tells you on purpose — through a preference centre, an onboarding quiz, a “what do you want to hear about” tick-list, or a feedback form. The customer knows exactly what they’re handing over and why. It’s the cleanest category you can hold.
First-party data is what you collect directly through your own channels — website analytics, purchase histories, abandoned-cart records, your CRM, customer support transcripts. You control the collection point, the notice, and the consent. It’s the foundation of modern marketing in Australia.

Second-party data is another organisation’s first-party data, shared with you under a partnership — a referral partner sending you customers who opted in, or a co-branded promotion. Useful, but every prior consent in the chain has to be inspected. You can’t lawfully use it if the original collection didn’t put your business on notice.
Third-party data is what’s aggregated by external data brokers and ad-tech platforms — purchased lists, broker enrichment files, pixel-fed lookalike cohorts. You can’t see how it was originally collected, whether consent was obtained, whether it’s current, or whether the people on it expected to hear from you. The OAIC’s regulatory priorities for 2025–26 specifically target data brokerage and ad-tech as high-risk vectors.
The commercial implication: buying or renting a marketing list is high-risk because you have to be able to prove all of it —valid consent, accurate sender details, a working unsubscribe process, and a lawful basis for how the personal information was originally collected and shared. Latitude Finance’s $3.96 million penalty in April 2026 shows how seriously ACMA treats basic spam compliance: the action covered more than 2.7 million breaches of the Spam Act, primarily for marketing messages that lacked accurate sender contact information and a working unsubscribe facility. ACMA has been clear that businesses cannot outsource spam compliance simply because a third party supplied the list.
The takeaway: build for zero- and first-party. Treat anything else as borrowed risk.
The privacy rules that actually shape day-to-day marketing
There are thirteen Australian Privacy Principles (APPs). For everyday marketing operations, six of them carry the load, and three ideas tie them together.
Only ask for what you actually need. APP 3 requires that personal information be “reasonably necessary” for a function or activity of your business. Speculative collection — capturing date of birth, mobile, address and gender when you only need an email — is now an active compliance risk, not just a UX one. Strip your forms down to what the transaction requires.
Tell people what you’re doing at the point you do it. APP 5 requires you to notify individuals at or before the point of collection. A privacy policy linked in your footer is not enough on its own. A compliant collection notice tells the user who you are, what you’re collecting, why, what happens if they don’t provide it, and who you’ll share it with. The OAIC’s January 2026 compliance sweep made the point: about 60 entities across rental agents, pharmacies, licensed venues, car rental, car dealerships and pawnbrokers were assessed against their privacy policies and in-person collection practices. The OAIC has flagged that non-compliant privacy documentation can attract compliance directions, infringement notices, and penalties of up to $66,000.
Use the data only for what you said you’d use it for. APP 6 limits secondary uses unless the customer would reasonably expect them or has separately consented. Quietly enrolling someone on a marketing list after they buy a product is the most common APP 6 breach we see in audits. APP 7 layers extra rules on direct marketing — every communication needs a working, prominent opt-out, honoured promptly across every system.
Direct marketing also has to comply with the Spam Act 2003, administered separately by the ACMA. Express consent under the Spam Act requires affirmative action: a customer-checked box, a verbal yes, or a signed form. Pre-ticked boxes don’t count. Sending a “can we email you?” email is itself an unlawful commercial message. For voice telemarketing, the Do Not Call Register obliges you to “wash” lists regularly before calling — registered numbers must generally be recognised after 30 days.
Six-question review prompt for your sign-up form
- Does it collect anything beyond what we genuinely need today?
- Is there a clear collection notice on the form itself, not just in the footer policy?
- Does the notice name us, the purpose, and any third parties we share with?
- Is marketing consent a separate, unticked box from the main submit?
- Does every marketing email and SMS carry a working unsubscribe?
- Do we honour opt-outs across every system, not just the platform they came in on?

Tracking pixels, hashed emails and the AdTech traps
The Meta Pixel, Google Ads tag and TikTok Pixel have all attracted regulatory attention. In November 2024 the OAIC issued guidance on tracking pixels, making clear that data harvested by tracking pixels — IP addresses, URL data, form inputs,transaction data and hashed email addresses — is personal information under the Privacy Act when it can be reasonably linked to an identifiable individual. The practical risk: tracking pixels can engage APP 3, APP 5, APP 6, APP 7 and APP 8 obligations at the same time, particularly where they collect personal information invisibly, capture or transmit sensitive information, or pipe data to overseas platforms without appropriate notice and controls.
Two specific traps catch a lot of small businesses.
The hashed-email myth. Hashing isn’t anonymisation. Hashes can be matched, replayed and reversed, particularly when the same email is hashed the same way across multiple platforms. If you’re piping hashed emails into Meta or Google to build custom audiences, you are not in a safe harbour. Cleanrooms have the same issue — they limit what your team can see, not what the platform can match.
The set-and-forget pixel. Pixels installed years ago and never reviewed can scrape URL parameters and form data that include sensitive information — health-related searches, cart contents, abandoned form fields. The OAIC has explicitly warned that pixels can transmit sensitive information back to advertising platforms without the operator realising. Sensitive information under APP 3 generally requires the individual’s express opt-in consent, which an unsupervised pixel almost certainly does not have.
Cross-border exposure under APP 8 makes this harder. Using Klaviyo, Mailchimp, HubSpot, Meta or Google involves disclosing personal information overseas, and the Australian business stays accountable for what the overseas recipient does with it. “We outsourced it” is not a defence.
Four-item pixel audit
- Tag-manager review — what’s actually firing on your site, and on which pages?
- Configure pixels to suppress form fields, URL parameters, and any cart content that could reveal sensitive information.
- Add a layered collection notice covering third-party tracking, with a real opt-out — not a “by continuing you agree”banner.
- Check vendor contracts — do they prevent the platform from using your data for its own model training or shadowprofiling?
What changes in 2026 — and what to do before each date
Four moving pieces will reshape obligations over the next eighteen months.
Statutory tort for serious invasions of privacy — already in force. Since June 2025, individuals have been able to bring a civil claim directly in the courts for a serious, intentional or reckless invasion of privacy — including the misuse of private information — where the relevant legal tests are met. Damages can reach $478,550. That stacks on top of regulator action and opens a separate class-action exposure for businesses with poor practices.
AML/CTF Tranche 2 — commences 1 July 2026. Real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones become reporting entities under the AML/CTF regime. The OAIC’s position is that the Privacy Act applies to the personal information handling connected with those AML/CTF obligations, even where the small business exemption would otherwise apply. If that’s you, the work is real: APP 5 notices at every collection point, a current privacy policy, a clear consent and use framework, an incident response plan, and a path to destroying or de-identifying data that’s no longer needed. OAIC and AUSTRAC guidance is explicit that you should stop retaining full copies of identity documents for record-keeping — extract the data points you need, then delete the source images.
Automated Decision-Making transparency — commences 10 December 2026. Under new APP 1.7 and 1.8 (introduced by the Privacy and Other Legislation Amendment Act 2024), an APP entity must include information in its privacy policy where a computer program makes — or does something substantially and directly related to making — a decision that could reasonably be expected to significantly affect an individual’s rights or interests. The kinds of decisions in scope include AI-assisted insurance underwriting, automated CV screening, predictive credit scoring, and automated risk assessments. If you’re using AI in those kinds of decisions, get the disclosure into your privacy policy before the December 2026commencement.
Tranche 2 privacy reforms — proposed, drafting through 2026. A broader package of reforms is under consultation. Proposals include an overarching “fair and reasonable” test for all data handling, the removal of the employee record exemption, and, potentially, the elimination of the small business exemption entirely. These are reform proposals, not settled law — the final shape depends on the legislation that passes Parliament.
Dated action checklist
- Before 1 July 2026 (if you’re a Tranche 2 profession): privacy policy in plain English, APP 5 collection notices at every intake point, a consent register, secure destruction protocol for identity documents, and vendor contracts reviewed.
- Before 10 December 2026 (everyone using AI or algorithms in customer-affecting decisions): privacy policy section on automated decision-making, naming the specific decisions and personal information involved.
For an Australian small business in 2026, the realistic position isn’t panic — it’s pragmatism. The Privacy Act has been on the books for thirty-eight years; what’s changed is that the rules are now properly enforced, the gaps are closing, and the practices that used to be normal — buying lists, set-and-forget pixels, boilerplate privacy policies copied from a template —are now liabilities.
The single highest-leverage move is to audit what you collect and ask why. Strip the unnecessary fields. Fix the collection notices on your forms. Make sure every marketing channel has a working opt-out, and that opt-outs flow back into every system that talks to that customer. Replace any bought lists with consented, first-party programs — they perform better commercially anyway. If you use AI in customer decisions, get the disclosure into your privacy policy before December.
This is where a marketing studio earns its keep, and where the work pays for itself. If you’d like a hand auditing the data side of your website, forms, email program and ad tracking, that’s exactly the kind of work we do at Duelling Pixels. The earlier you start, the lower your bill will be.
References
- Office of the Australian Information Commissioner — Small business and the Privacy Act
- Office of the Australian Information Commissioner — Australian Privacy Principles guidelines
- Office of the Australian Information Commissioner — Tracking pixels and privacy obligations (November 2024)
- Office of the Australian Information Commissioner — Privacy compliance sweep to put privacy policies under thespotlight (January 2026)
- Office of the Australian Information Commissioner — Australian Clinical Labs ordered to pay penalties (2025)
- Office of the Australian Information Commissioner — OAIC takes civil penalty action against Medibank
- Office of the Australian Information Commissioner — Notifiable Data Breaches scheme
- Australian Communications and Media Authority — Latitude Finance pays $3.96m for more spam breaches (April 2026)
- Australian Communications and Media Authority — Avoid sending spam (Spam Act guidance)
- Do Not Call Register — About the Do Not Call Register
- AUSTRAC — About the AML/CTF reforms (Tranche 2)
- Attorney-General’s Department — Privacy reforms (statutory tort and Tranche 1)
- Federal Register of Legislation — Privacy and Other Legislation Amendment Act 2024
- Privacy Act 1988 (Cth); Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth); Privacy Legislation Amendment(Enforcement and Other Measures) Act 2022
Information current as of May 2026. This guide is general in nature and not a substitute for legal advice tailored to your circumstances.




Leave a Reply