Privacy and data breaches, ready before you need it.
When a breach happens, the clock starts. We put your privacy program in place, build a breach response plan your team can follow, and keep the record of how each incident was handled.
More firms are covered than think they are.
- The Privacy Act and the Australian Privacy Principles apply to firms with annual turnover above $3 million. The small business exemption below that is still in place, though some smaller firms are covered for other reasons.
- AML/CTF changes that. Under section 6E(1A) of the Privacy Act, any reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) must comply with the Privacy Act for personal information it handles for the purposes of, or in connection with, its AML/CTF obligations, regardless of turnover. The $3 million threshold does not apply to a reporting entity. For law firms providing designated services, that has applied since 1 July 2026. Identity documents and due diligence records are exactly the information a breach exposes.
- The Notifiable Data Breaches scheme applies wherever the Privacy Act does. If you suspect an eligible data breach, you must assess it quickly, and within 30 days at the latest. If it's likely to cause serious harm, you must notify the OAIC and the people affected as soon as practicable.
- Automated decisions. From 10 December 2026, firms covered by the Privacy Act must say in their privacy policy when personal information is used in automated decisions that significantly affect people.
- Confidentiality to your clients applies whatever your size.
The next round of changes is already drafted.
The government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 in September 2026, and expects to introduce it to Parliament before the end of the year. It isn't law yet, and it may change. As drafted, it proposes a new "fair and reasonable" test for how personal information is collected, used and disclosed; tighter consent rules for direct marketing and trading in personal information; a wider definition of sensitive information; stronger security duties, including identifying all the personal information you hold, reducing harm from every data breach (not only notifiable ones) and a 72-hour notification window; a framework that separates the organisations that control personal information from those that process it for them; and a formal complaints process with a 60-day response time. It does not remove the small business exemption. We track the bill, and can update your program when it becomes law.
What you'll be able to prove
- A privacy policy that matches what your firm actually does with personal information.
- A map of the personal information you hold, where it's kept and why.
- Retention and destruction periods set in your Microsoft 365, not left to memory.
- A breach response plan that names who does what, with the assessment steps and 30-day limit, OAIC notification and client communications drafted in advance.
- A breach register that records every incident, including the ones that turn out not to be notifiable.
- Staff who know how to report a suspected breach, and a simple way to do it.
How the evidence is captured
A suspected breach is reported through a form that opens a register entry, records when the firm became aware, and tracks the 30-day limit with reminders to the responsible person. Retention settings are applied in your tenant, so destruction happens on schedule and leaves a record. Access and sharing reports show who could see what, which is the first question in any breach assessment.
Where a breach touches AML/CTF records, notification has to be handled with the AML/CTF Act's tipping-off rules in mind. The plan covers that.
What can be included
- Privacy coverage review: the facts your firm and its advisers need to confirm how far the Privacy Act applies
- Personal information map
- Privacy policy review
- Retention and destruction settings in Microsoft 365
- Breach response plan and pre-drafted communications
- Breach reporting form and register
What this isn't
We put the program, records and processes in place. We don't give legal advice on whether a particular incident is notifiable; that decision stays with your firm.
Frequently asked questions
-
If your annual turnover is above $3 million, generally yes. If it's below, the Act still applies to personal information you handle for your AML/CTF obligations if your firm is a reporting entity (section 6E(1A)), and other exceptions can apply. We map the facts that decide it as part of the privacy review.
-
Unauthorised access to or disclosure of personal information, or its loss where that is likely to follow, that a reasonable person would conclude is likely to result in serious harm to someone, and where remedial action hasn't removed that risk.
-
No, only eligible data breaches. But record every incident and your assessment of it, because that record is your evidence of how it was handled.
-
Assess a suspected breach quickly, and within 30 days at the latest. If it's eligible, notify the OAIC and affected people as soon as practicable.
Be ready before the clock starts.
Fixed scope, fixed fee, and a plan your team can follow on the worst day.