by Paul Quealey
Prepared in association with Eugénie Michael of Eugenie Michael Legal
Most small to medium businesses (SME’s) assume data protection and privacy are something only large-scale companies need to worry about, though, this isn’t correct.
The digitisation of our business systems and records means that almost every business collects, stores and shares confidential (proprietary) and personally identifiable (customer details, staff records, payment data, email lists etc) information. If this is you; data protection and privacy are your problem too.
The good news is that getting the basics right is simpler than most people fear, and it doesn’t take a big budget either. Here’s what you actually need to know, and what to do about it.
Data Protection and Information Security: The Missing Link
Data protection rules focus on the information held, no matter the size of business: what type of data you hold, why you have it, where it’s stored, who you share it with, how long you keep it, and whether any of it goes overseas. Driving these rules is data privacy, which is the legal and ethical right of individuals to maintain control over their personal information.
Information security is about the systems: the networks, devices and controls that keep that data safe from outside threats like hackers, scams and leaks.
Too often these get treated as the same thing, or as areas that never touch. That is where businesses get caught out. They are separate roles, but they depend on each other to form one working system that decides how you gather, use and protect the data you hold. Strong security around data you were never allowed to collect still lands you in trouble. Well-governed data with a lack of secure systems anyone could breach is just as exposed.
So, your business needs both pulling in the same direction: a clear handle on the data you hold, and a strong security posture protecting it.
Where The Law Comes In
In Australia, privacy requirements are mandated by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). They cover how you collect, use, store, disclose and correct personal information. If a serious data breach happens that’s likely to cause harm, the Notifiable Data Breaches scheme says you must tell the regulator (the OAIC) and the people affected.
These rules apply to businesses with annual turnover over $3 million, and to some smaller ones (for example, health providers). If you’re under that threshold you may not be directly caught, yet, however there is a growing consumer expectations that all businesses, no matter the size, adequately obtain, hold, and protect private information.
Whilst Australian data protection regulations trail behind the European Union and United Kingdom, it is more important now than ever that SME’s consider how they manage information assets. With penalties for serious or repeated breaches now run into the tens of millions for companies, so this is not a “corner” worth cutting.
What To Put In Place Now
A roadmap for getting across the data you hold and its use and security includes:
- Know your data. Map what confidential and personal information you hold, where it lives, and where it goes. You can’t protect what you haven’t mapped.
- Tighten your contracts. Every time you hand data to a supplier, or a client hands data to you, someone is responsible for protecting it. Don’t leave that to chance. Build clear data protection and security terms into your vendor and client agreements, so the obligations are set in writing, not assumed.
- Get your internal policies in place. A Data Protection Policy, an Information Security Policy, and a Data Breach Response Plan tell your staff, and contractors and agents how to handle and classify data, and exactly what to do if something goes wrong. These are your first line of defence in a breach and decide who does what, and how fast, before a breach happens, not during one.
- Check your external policy. Your Privacy Policy which sits on your website is the promise you make to the public. Make sure it’s accurate, current, and actually matches what you do.
- Employee Training. Your team is your biggest risk and your best defense, as human error drives the vast majority of data breaches. Security issues almost always start with a person falling a phishing/scam email, not a hacker cracking a firewall. Regular cyber security training is a must.
- Set a security baseline. At a minimum, work with your internal IT team or third-party IT provider to ensure multi-factor authentication is turn on for all available software’s and systems used, and patches and updates are deployed regularly. Your data should also be subject to regular backups.
Your Next Step
If you do one thing this quarter, review your privacy policy, update your vendor and client agreements, and make sure a breach response plan is in place. Know your data, put the right policies and governance around it, and you’ll go a long way towards being protected.
If you are unsure of your next steps, or require assistance and direction on understanding you data protection and privacy requirements in Australia, please contact Paul Quealey of Lambourne Partners below or on (02) 4969 6600 for more guidance and details or Eugenie Michael of Eugénie Michael Legal.

