No doubt you’ve been inundated at some point with a bunch of “We’re updating our privacy policy” emails, from every website you’ve ever signed up to. This was largely triggered by the introduction of the General Data Protection Regulation (GDPR), which formally took effect in Europe on 25 May 2018.
What is the GDPR?
The GDPR was introduced across Europe to counter some of the more insidious data collection and online surveillance techniques out there. At a very basic level, the GDPR applies if you collect the personal data of any EU citizen. It includes a range of provisions and has severe penalties for breaches.
How does this apply to Australian website and business owners?
In Australia, privacy policy and handling of customer data is regulated by the Australian Privacy Act 1988 which includes 13 Australian Privacy Principles (APPs). The good news for Australians is that the GDPR and the Australian Privacy Act are compatible, in that both promote transparency and accountability in information handling, and both require businesses to notify of any privacy breaches. However, the GDPR contains several differences which do not currently have an equivalent right under the Australian Privacy Act.
Note: the Australian Privacy Act has been under review since 2022, with proposed reforms that may extend its reach to smaller businesses. It’s worth keeping an eye on oaic.gov.au for updates.
Does the GDPR apply to me?
Just because a website may be accessible in the EU does not necessarily mean it will be forced to comply with the GDPR. The important questions to consider are:
- Is your business a legal entity in Europe?
- Do you have employees in Europe?
- Do you sell goods or services to customers in Europe?
If your answer is YES to any of these, then your business is subject to the GDPR and, depending on the type of business you conduct, you may need to make changes to:
- Privacy Policy
- Terms and Conditions
- Website forms that collect information from or about customers – forms must now obtain explicit consent from customers regarding use and retention of any information about them
- Your site may need new facilities for customers to view, delete, export and request updates to any information your site holds about them
If your answer is NO, then keep reading!
Does the Australian Privacy Act apply to me?
The Privacy Act includes 13 Australian Privacy Principles. The OAIC provides a quick reference outline of all 13 APPs. These APPs outline how certain organisations must handle, use and manage personal information.
The Australian Privacy Act does not apply to all organisations, and individual organisations must decide how they apply to their own organisation. Make sure you do some research to see if your organisation is included or not.
Consider this – due to the requirements of the GDPR, and the number of people in the world it applies to, there is now increased focus on data privacy, collection and management. With that in mind, it may be reasonable to assume:
- There will be changes in the way things are done going forward.
- It’s not difficult to envisage a time when – above and beyond the legal requirements – businesses that do demonstrate a commitment to data privacy, may be preferenced over those that don’t.
What to do right now
- If you don’t have a Privacy Policy, outlining how data is collected and managed – consider getting one. This can be combined with a website notice highlighting the existence of the policy. While this does not make a website GDPR-compliant, it does help meet APP1 – “open and transparent management of personal information”.
- Consider your current and future data collection processes:
- Do you provide the option of anonymity or pseudonymity (APP2)?
- Do you handle sensitive information appropriately (APP 3-6)?
- Do you understand the rules around how you can use or share the data you collect, including for direct marketing purposes and overseas? (APP 7-9)
- The GDPR requires a business to ONLY collect the data required for the task at hand – do you really need to ask for an address if you’re not posting goods to customers?
- Should you pre-tick boxes in forms? (GDPR – no).
- Should you provide people with the option to opt-out or opt-in? (GDPR – opt-in).
- Encryption of backup files. APPs 10-13 relate to the quality, security, access to and correction of personal information by an individual. The GDPR goes further, with a “right to be forgotten” requirement – which means if an individual wins the right to be forgotten, their personal data needs to be removed not just from existing systems but from un-encrypted backups too. To preempt this as a possibility, consider encrypting backup files now.
If you need assistance with determining your requirements or implementing new privacy policies or processes, get in touch.







