Founding offer: save 20% for life, only 50 places·14-day free trialClaim yours →

Client data and privacy for Australian agencies: what the Privacy Act means day to day

Australian privacy law is principles-based, which makes it flexible and a little vague. Here is how the Privacy Act and the APPs translate into everyday agency habits.

The Crewqo team Published Updated 6 min read
On this page
  1. Does the Privacy Act apply to your agency?
  2. The APPs that shape agency work
  3. Offshore tools and APP 8
  4. Notifiable Data Breaches: what to do
  5. Reforms: what changed recently and what is next
  6. Day-to-day habits that cover most of it
  7. Checklist for Australian agencies
  8. Frequently asked questions

The short answer: the Privacy Act 1988 and its 13 Australian Privacy Principles (APPs) govern how covered organisations collect, use, store and disclose personal information. It generally applies to businesses with annual turnover above $3 million, and to some smaller ones, and it is regulated by the Office of the Australian Information Commissioner (OAIC). Even if your agency is under the threshold, larger clients will often require you to handle their data to APP standards by contract. Day to day, that means collecting only what you need, telling people what you do with it, being careful with offshore tools, keeping it secure, and knowing what to do if a breach happens.

This is general information, not legal advice. Privacy law changes, and how it applies depends on your agency, your clients and where everyone is. For decisions about your own obligations, speak to a qualified adviser in the relevant country.

Does the Privacy Act apply to your agency?#

The Act applies to “APP entities”: Australian Government agencies and most private sector organisations with annual turnover over $3 million. Smaller businesses are generally exempt, but not all of them. A small business is still covered if, for example, it provides a health service and holds health information, trades in personal information, is a contracted service provider under a Commonwealth contract, or chooses to opt in.

For agencies, the more practical question is whether your clients are covered. A client that is an APP entity remains responsible for the personal information it shares with you. It will usually protect itself by contract: requiring you to follow the APPs, restricting how you use the data, and requiring notice of any breach. So even an exempt agency often ends up working to the APPs in practice.

Across the TasmanNew Zealand agencies: the Privacy Act 2020 and its information privacy principles apply, overseen by the Office of the Privacy Commissioner. Many of the habits below carry straight across.

The APPs that shape agency work#

Not all 13 principles bite equally in agency work. These are the ones you meet most weeks.

Australian Privacy Principles most relevant to agencies
PrincipleWhat it coversWhat it means for an agency
APP 1Open and transparent managementA clear, current privacy policy, and internal practices that match it
APP 3Collecting solicited informationOnly collect what is reasonably necessary, for example in briefs and forms
APP 5Notifying people about collectionTell people who you are and why you collect their details, such as on enquiry forms
APP 6Use and disclosureUse information for the purpose it was collected for, not for your own side projects
APP 7Direct marketingGive an easy opt-out; the Spam Act 2003, regulated by ACMA, also applies to marketing emails
APP 8Cross-border disclosureTake reasonable steps before sending information overseas; the discloser can stay accountable
APP 11Security of personal informationProtect it from misuse and loss, and destroy or de-identify it when no longer needed
APP 12 and 13Access and correctionBe able to find and correct someone’s information when asked

Offshore tools and APP 8#

Most agency software stores data somewhere, and often not in Australia. APP 8, together with section 16C of the Act, means that when a covered organisation discloses personal information to someone overseas, it generally has to take reasonable steps to make sure the recipient handles it in line with the APPs, and it can remain accountable if the recipient doesn’t.

That is why Australian clients ask agencies where their tools store data. You should be able to answer for each tool that holds client personal information:

  • Which country or region the data is stored in, where the vendor says so.
  • Whether the vendor’s terms commit it to appropriate security and confidentiality.
  • Who can access it, including the vendor’s own staff.

Where you control the storage, you control part of the answer. With object storage you can usually choose the region your bucket sits in. With Crewqo, files go to the storage you connect, so you pick the provider and, where it offers a choice, the region. Our guide to choosing agency file storage compares the options.

Notifiable Data Breaches: what to do#

Under the Notifiable Data Breaches scheme, a covered organisation must notify the OAIC and the affected people of an “eligible data breach”: unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm, where remedial action hasn’t prevented that risk. If you suspect a breach, you must carry out a reasonable and quick assessment, which should be done within 30 days.

If your agency is handling a client’s data, the client may be the one who must notify, so it needs to hear from you fast. Put the notice period in your contract, and prepare:

  1. Contain. Revoke access, reset credentials, pull shared links.
  2. Assess. What information, whose, how many people, what harm is likely.
  3. Tell the client within the time your contract sets, with what you know so far.
  4. Record what happened and what you did, whether or not it is notifiable.

Reforms: what changed recently and what is next#

The Privacy and Other Legislation Amendment Act 2024 made the first round of changes from the long-running review of the Privacy Act. Among other things, it gave the OAIC stronger enforcement tools, created a statutory tort for serious invasions of privacy, set up work on a Children’s Online Privacy Code and added transparency requirements for some automated decisions. Further proposals, including the future of the small business exemption, have been discussed but were not part of that first round.

For agencies the direction is clear even where the detail isn’t: clients will expect more care, not less. Building good habits now is cheaper than retrofitting them later. Check the OAIC’s website for the current position.

Day-to-day habits that cover most of it#

  • Collect less. Trim briefs and forms to what the job needs. No licence numbers or dates of birth “just in case”.
  • Keep client data off personal phones. Group chats on personal messaging apps are hard to secure and impossible to offboard. A team chat inside your workspace solves that.
  • Give access by need. Designers don’t need the payroll; clients should see only their own work. See how Crewqo handles access by area.
  • Offboard the same day. Remove access when people or freelancers leave.
  • Delete on schedule. Agree retention with clients and actually delete, including old exports.
  • Keep backups safe. Encrypted, tested, and with clear key custody. See encrypted backups explained.

Checklist for Australian agencies#

Privacy basics, whether or not you are over the threshold

Frequently asked questions

Is my small agency covered by the Privacy Act?

Businesses with annual turnover of $3 million or less are generally exempt, with exceptions such as health service providers, businesses that trade in personal information and Commonwealth contracted service providers. Covered clients will often require APP standards by contract anyway.

Is there an Australian version of a GDPR data processing agreement?

There is no set form in the Privacy Act. Clients usually rely on contract clauses covering APP compliance, security, overseas disclosure, breach notice and deletion, which do a similar job.

Do we have to report every data breach?

Only eligible data breaches, meaning those likely to result in serious harm that remedial action hasn’t prevented, must be notified to the OAIC and affected people. You should still record every incident and tell affected clients as your contract requires.

Can we use software hosted overseas?

Yes, but under APP 8 a covered organisation should take reasonable steps to make sure the overseas recipient handles information in line with the APPs, and it may remain accountable. Know where each tool stores data and what its terms promise.

Written by the Crewqo team. Spotted something out of date? Tell us at hello@crewqo.com.

Founding offer · first 50 agencies

Claim one of 50 founding spots

Save 20% for as long as you stay, start with a 14-day free trial, and cancel any time.

14-day free trialNo card neededCancel any time