Cyber help · Part 2

Who actually has to protect your data? (Most small businesses don't.)

A series on what businesses really owe you.

Last week I wrote about two medical data breaches in a single month, and how the weak link wasn't the clinic — it was an app the clinic used. A few of you wrote back with the same question, more or less: "Alright Brian — so whose job is it to protect my details in the first place? What are they actually obligated to do?"

It's a fair question. And the honest answer surprised me when I went and checked it properly, so I want to walk you through it the way I'd want it explained to me — plainly, no lawyer-speak. (And just so we're square: this is general information, not legal advice. I'm a bloke who reads the source documents, not a solicitor.)

Let's start at the top, because that's where most of the muscle is.

The main law is federal. It's called the Privacy Act 1988, and it's run by a mob called the OAIC — the Office of the Australian Information Commissioner. Underneath it sit thirteen rules called the Australian Privacy Principles. Don't let the number scare you; in plain English they add up to a fairly sensible list. A business covered by the Act is meant to: only collect what it actually needs, and tell you why. Not quietly use your details for something else, or flog them off. Keep what it holds accurate. Take reasonable steps to keep it secure, and get rid of it when it's no longer needed. Let you see what they've got on you and fix it if it's wrong. And have a clear, up-to-date privacy policy so you can check all of that.

That's a genuinely decent set of obligations. If every business that held your details had to follow it, I'd have a lot less to write about.

Here's the catch — and it's a big one.

The Privacy Act only binds businesses turning over more than three million dollars a year. Under that line, a business is generally exempt. Not "lightly regulated." Exempt. The rules I just listed don't apply to them at all.

Now stop and think about what that means out here. Three million in turnover sounds like a lot, and for most of the operators in a town like Dalby, it is — comfortably more than they'll ever see. The caravan park. The mechanic. The little retailer on the main street. The bloke doing your books. The footy club with a spreadsheet full of members' phone numbers and birthdays. On the numbers from the government's own review, businesses under that threshold make up around 2.3 million of them — about 95% of every business in the country. The overwhelming majority of the places that hold a piece of you are, legally speaking, outside the Act.

That's not a loophole somebody snuck in. It's called the small business exemption, and it's been deliberate policy for years — the idea being not to bury tiny operators in red tape. I understand the intent. But I want you to feel the flip side of it, because nobody spells it out: when a small business loses your data, in a lot of cases it wasn't breaking a privacy law, because no privacy law applied to it in the first place.

Which brings me to the one exception that matters most — and it's why last week's post connects to this one. There are a handful of carve-ins: businesses that trade in personal information, government contractors, credit reporting outfits, and a few others are pulled in no matter how small they are. But the big one, the one you should tuck away, is this: health service providers are covered regardless of turnover. A tiny one-room clinic, a solo physio, your local GP — all bound by the Privacy Act, all the way down.

So when I told you my Dalby GP's company had a sister clinic lose 25,000 people's details, that clinic was firmly inside the rules. It had every obligation to protect those records. The corner shop two doors down, holding your name and card details? Very likely outside them. Same street, same town, completely different legal footing for the exact same information about you.

And there's a bit of extra teeth worth knowing about, because it changed recently. For the businesses that are covered, there's a data-breach scheme that forces them to tell you and the regulator when a breach could seriously harm you. On top of that, since June last year, Australians have — for the first time — a personal right to sue someone for a serious invasion of their privacy. That one's important enough that I'll come back to it properly later in this series.

So here's where I want to leave you sitting, the same way this question left me: the strongest protection you've got is one federal law with a hole in it big enough to drive a road train through — and whether you're covered depends less on how sensitive your information is, and more on how much money the business holding it happens to make.

Which raises the obvious next question. If the federal Act doesn't reach the small operator down the road — does anything else? Does the state pick up the slack? Does the council?

That's where it gets interesting for us out here. And I'll be honest with you in the next part: the answer isn't the one I was hoping to find.

Next in this series

Part 2 — "Out here, the safety net has a hole in it." Monday 3 August: what Queensland law actually covers, what it doesn't, and why a Queenslander sits differently to someone in New South Wales or Victoria.

Sources

General information, not legal advice. Everything above is drawn from the regulator's own published guidance and the government's Privacy Act Review. Where reform has been proposed but not legislated, I've said so plainly — the small business exemption is still in force today.

  • OAIC — Australian Privacy Principles quick reference: oaic.gov.au
  • OAIC — Small business (the turnover threshold and the carve-ins): oaic.gov.au
  • OAIC — About the Notifiable Data Breaches scheme: oaic.gov.au
  • IAPP — Amending Australia's Privacy Act: small businesses, bigger responsibilities: iapp.org
  • Norton Rose Fulbright — Parliament passes major privacy law reform: nortonrosefulbright.com