Start by checking coverage. The Privacy Act generally covers Australian Government agencies and organisations with annual turnover above $3 million, subject to exceptions. Many smaller businesses are exempt, but exceptions include health service providers and some other activities. Holding client or employee data alone does not settle the question. Use the OAIC's small-business guidance to check your circumstances; other laws and contractual duties may also apply.
01The obligation that matters most: APP 11
APP 11 requires covered entities to protect the personal information they hold through measures reasonable for their circumstances. This includes technical and organisational measures, assessed against factors such as information sensitivity and possible harm. It is an ongoing duty. Assign responsibility, assess risks and review controls before an incident occurs.
02The Notifiable Data Breaches scheme starts the clock early
The NDB scheme generally requires an organisation covered by the Privacy Act to notify the OAIC and affected individuals when an eligible data breach is likely to result in serious harm. The assessment clock starts when the organisation becomes aware of reasonable grounds to suspect an eligible data breach, and reasonable steps must generally complete that assessment within 30 calendar days. That is an assessment deadline, not an automatic 30-day delay before notification.
03Where sector obligations stack on top
Sector duties depend on the entity and its activities. APRA CPS 234 applies to APRA-regulated entities; AML/CTF requirements depend on designated services. Health providers should check applicable health-record and professional requirements, including My Health Record duties where relevant. Legal practices should consider confidentiality and privilege. Map the requirements that actually apply rather than assuming every rule applies to an entire industry.
04How a technical incident becomes a compliance failure
Consider a business that contains an intrusion but does not establish what information was accessed or document its assessment. Technical containment alone does not resolve its notification duties. A response plan should include an accountable decision-maker, an evidence record and a process for obtaining appropriate advice and communicating when required.
05What “reasonable steps” looks like in practice
Useful measures to consider include MFA, appropriate endpoint protection, access reviews, tested backups, staff training and a rehearsed response plan. Record the decisions and test results. This is a starting point for a risk-based review, not a checklist that certifies APP 11 compliance.
If you operate in a regulated industry and have never mapped your specific obligations to your actual controls, that gap is worth closing before a regulator — or an attacker — closes it for you.
Sources
Where this leaves you
Knowing the risk is not the same as knowing your own exposure.
The Cyber Readiness Assessment gives you a written, prioritised answer in ten business days — enquire for scope and terms.