Cyber help · Part 4

What's coming, and what you can do now

A series on what businesses really owe you.

Over the last two weeks I've painted a fairly bleak picture, so let me start this one by owning that. Most small operators out here are exempt from the federal Privacy Act. There's no state law behind it for private business. The local layer is the thinnest of the lot. If you've been reading along thinking "well, that's a bit grim, Brian" — you're right, and I wasn't going to sugar-coat it.

But grim isn't the same as hopeless. So this week is the turn: what's actually changing, what's already landed, and — the part that matters most — what you can do about it right now, whether you're the customer handing over your details or the small operator being handed them. (Usual note: general information, not legal advice. I read the source documents. I'm not a solicitor.)

First, the change everyone's talking about — and the one it's easy to get wrong.

The exemption might not last forever. Back in early 2023, a big government review of the Privacy Act recommended getting rid of the small-business exemption altogether — the very $3-million line we've been circling for two weeks. The government agreed with the idea in principle and said it would come back with a second round of reforms to deal with it.

Here's the part I need you to hear clearly, because a lot of websites out there have got it wrong: that has not happened. The exemption is still in force. No law removing it has passed Parliament. The Attorney-General says the next tranche is "progressing," but there's no Bill, and no firm date. So if you read a blog somewhere telling you small businesses are "now covered" — they're not. The honest way to say it is this: the exemption is on borrowed time. Reform is coming. But it isn't law yet, and nobody can tell you when it will be. Anyone who tells you otherwise is guessing.

Now the thing that has landed — and this one's a genuine shift.

Since the tenth of June last year, Australians have a personal right to sue over a serious invasion of their privacy. For the first time. It's a new statutory tort, and the reason it matters so much for us out here is one detail: it doesn't care about the small-business exemption. The exemption is a shield against the federal Act and its regulator. This is different. This is you, personally, taking someone to court. That exempt caravan park, that little operator who's outside the Privacy Act entirely — they are not outside this.

It's not a free-for-all, and I don't want to oversell it. To get up, you'd have to show a few things: that you had a reasonable expectation of privacy; that what they did was intentional or reckless, not just careless or unlucky; that it was genuinely serious; and that your privacy outweighs any public-interest reason for what happened. That's a real bar to clear. But where a court is satisfied, the damages for the hurt and distress of it are capped at the greater of about $478,550 or the ceiling that applies in defamation cases — which is to say, not trivial money. For the first time, the little bloke has a door into the courtroom that doesn't depend on how much money the business turns over.

And for the businesses that are covered by the federal Act, the penalties got a lot heavier a few years back too — for a company, up into the tens of millions at the top end. That's not the caravan park's problem. But it tells you which way the wind is blowing.

So that's the lay of the land. Let me leave you with something you can actually use, because that's the whole point of Cyber Bushies.

If you're the customer, handing your details over:

  1. Ask why. "What do you need that for, and how long do you keep it?" A straight operator won't mind the question. Hesitation tells you something.
  2. Give less. If the form asks for your date of birth and there's no real reason for it, leave it blank and see if it still goes through. Most of the time it does.
  3. Assume the exempt shop won't have a privacy policy — and don't assume that means they're careless. It usually just means the law never asked them to have one. You can still ask how they store things.
  4. If something goes wrong and it's serious, know that the courtroom door I mentioned is now open to you, exemption or not. Get proper advice before you walk through it — but know it's there.

If you're the small operator, holding other people's details:

  1. You may be legally exempt. You are not morally exempt, and your customers don't know the difference — a breach feels the same to them either way.
  2. Collect less. The data you never gathered is the data that can never leak. This is the single cheapest security control there is, and it's free.
  3. Lock down the basics: strong, unique passwords; two-factor on anything with customer data in it; and know which app or service you're trusting with that data, because — as we saw in the very first post — that's usually where it goes wrong.
  4. Doing this well is a selling point, not a cost. "We look after your information properly" is a thing you can say out loud in a small town, and people remember it.

That's the series. Three weeks, one honest answer: the law protecting your data out here has real gaps, the strongest new protection is a courtroom door that only just opened, and a fair bit of your safety still comes down to good habits — yours, and the habits of the people you hand your details to. That's exactly the gap Cyber Bushies exists to close. If any of this raised a question about your own setup, that's the right instinct — the silliest question is the one you don't ask.

The full series

  1. Who actually has to protect your data? (Most small businesses don't.) — 27 July
  2. Out here, the safety net has a hole in it — 3 August
  3. What's coming, and what you can do now — 10 August (you're here)

Sources

General information, not legal advice. Everything above is drawn from the regulators' own published guidance and the legislation itself. Where something is proposed rather than law, I've said so plainly — you can check the status yourself at the links below.

  • OAIC — Statutory tort for serious invasions of privacy (the right to sue, in force 10 June 2025): oaic.gov.au
  • OAIC — Small business (the $3 million exemption, and who is covered regardless): oaic.gov.au
  • Attorney-General's Department — Privacy Act Review Report (the 2023 review that recommended abolishing the exemption): ag.gov.au
  • Attorney-General's Department — Government response to the Privacy Act Review Report (agreed in principle; second tranche still to come): ag.gov.au
  • Privacy Act 1988 (Cth) — the Act itself, as currently in force: legislation.gov.au