Businesses that experience a breach may have specific obligations depending on whether the Privacy Act applies to them, the type of personal data involved, and the risk of serious harm resulting from the breach. Serious harm does not have to be explicitly financial, it can be psychological, physical or reputational harm.
A small business is defined under the Privacy Act 1988 (Cth) as one which has an annual turnover of less than 3 million Australian dollars (Section 6D(1)). This value is inclusive of income from all sources and does not include assets held, capital gains or the proceeds of capital gains (Office of the Australian Information Commissioner OAIC).
If your small business falls under the Privacy Act and experiences a breach, there are obligations under the Notifiable Data Breach scheme. However, some small businesses that are not covered by the Privacy Act still must report a data breach event irrespective of their turnover, these include businesses:
You must notify the OAIC and any affected individuals of:
IDCARE can offer your business additional support in drafting and preparing data breach notifications and supporting impacted individuals.
For additional support or information, contact IDCARE by submitting a Get Help Form or call 1800 595 160 (Aus) or 0800 121 068 (NZ).
If you would like to provide feedback please use our Feedback Form.
Join the global list of organisations making a real difference in people’s lives by supporting our service.
















































Copyright © 2025, IDCARE. All Rights Reserved.
ABN 84 164 038 966