IT Management

Privacy compliance checklist for Australian businesses

Your 2025 Privacy Compliance Checklist and What You Need to Know About the New Data Laws

If your business collects names, email addresses, payment details, staff records or information through a website, you need to know what you hold and how it is protected.

Privacy requirements are not the same for every business. They can depend on your size, industry, customers, contracts and where you operate. Start with the Australian rules that apply to you, then check whether overseas laws or industry requirements also apply.

This checklist covers practical areas to review. It is not legal advice, and an IT provider should not decide your legal obligations for you.

Know what personal information you hold

Make a simple record of the personal information your business collects. Include information received through contact forms, email, customer systems, accounting software, staff records, online bookings and cookies.

For each type of information, record:

  • Why you collect it.
  • Where it is stored.
  • Who can access it.
  • Which suppliers receive or process it.
  • How long you keep it.
  • How it will be deleted when it is no longer needed.

This record makes the rest of the privacy review much easier. It can also uncover old spreadsheets, forgotten forms or former suppliers that still hold data.

Make your privacy notice accurate

Your privacy notice should match what the business actually does. It should explain what you collect, why you collect it, how you use or disclose it, how people can contact you and how they can raise a privacy concern.

Avoid copying a policy from another website. A polished document is not useful if it describes systems and practices your business does not have.

Add a review date and update the notice when your collection or use of information changes.

Check consent and choice

Consent is required in some situations, but it is not the only basis on which a business may handle information. Ask a privacy professional which rules apply to your activities.

Where you rely on consent, make the choice clear and keep a record of it. Do not hide optional marketing consent inside unrelated terms. Give people a practical way to withdraw consent where required.

Cookie banners and tracking choices also need to reflect the services on the website. Do not display a generic banner that claims to block optional tracking if it does not.

Review suppliers that handle data

Email marketing, payment, website, support and cloud services may all process personal information for your business.

Keep a list of these suppliers and review:

  • What information each supplier receives.
  • Where the supplier stores or processes it.
  • Which staff and subcontractors can access it.
  • What the contract says about security, breaches and deletion.
  • How you will retrieve or delete the information if you leave.

Using a well-known service does not remove your responsibility to understand how business data is handled.

Give people a clear contact point

Nominate someone inside the business to manage privacy questions. The role does not need a special title unless a law or contract requires one.

Document how the business will respond to requests for access, correction or other rights that apply. Staff should know where to send a request instead of handling it through an informal email chain.

Keep only what the business needs

Holding information forever creates risk and makes a future clean-up harder. Set retention periods that reflect legal, contractual and business needs.

The process should cover normal records, email, cloud storage, backups and information held by suppliers. Secure deletion may take different forms in each system, so document what is possible and who approves it.

Protect the information

Security controls should match the sensitivity of the information and the harm that could follow if it were lost or exposed.

Practical controls include:

  • Strong, unique sign-ins and multi-factor authentication.
  • Limited access based on each person's job.
  • Prompt removal of access when staff or contractors leave.
  • Current device and software updates.
  • Protected, tested backups.
  • Monitoring for unusual access.
  • A process for reporting a lost device or suspicious message.

Encryption can help protect data, but it is not a complete privacy program. Access, staff behaviour and supplier controls matter too.

Prepare for a data breach

Australian businesses covered by the Notifiable Data Breaches scheme may need to assess a breach and notify affected people and the regulator when the legal test is met. Other laws, contracts or insurers may add different duties.

Create a response plan before an incident. It should name the people who will contain the issue, assess what happened, preserve records and obtain legal or privacy advice. Do not put an unverified universal deadline in the plan.

Check special uses of information

Get specific advice if your business handles children's information, health information, identity documents or payment card details. The same applies if software uses personal information to make decisions about people.

If your business serves people overseas, ask whether laws in those locations apply. Do not assume that an Australian privacy policy covers every market.

Review privacy as the business changes

Review this checklist when you add a website form, new supplier, marketing tool, staff system or customer service. A yearly review is useful, but a change in how information is collected or used should trigger a review sooner.

For legal obligations and privacy notices, use a qualified privacy adviser. Need a clear view of which systems and suppliers hold business data? Book a privacy technology consultation to map the technology side, including account access, backups, device protection and supplier handovers.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
Make your website and documents more accessible
Next Article →
3 Simple Power Automate Workflows to Automatically Identify and Terminate Unused Cloud Resources