Pillar · Privacy Act / APP / NDB

The $3M threshold + the categories where it doesn't matter at all.

Most Australian SMBs assume the Privacy Act only applies above $3M turnover. Half right. Above $3M you are an APP entity. But health service providers + credit providers + TFN handlers + residential tenancy database operators + Commonwealth contractors + anyone who trades in personal information are covered regardless of turnover. Here is the full coverage map.

Why the $3M threshold probably doesn't apply to you

The $3M turnover threshold is a misleading mental model. Most SMBs assume privacy law starts there. The reality: any business handling Tax File Numbers, providing health services, extending credit, or operating a residential tenancy database is covered REGARDLESS of turnover.

If your business runs payroll, you handle TFNs. If you run payroll on XIntelliSync, you're handling TFNs through our automated-payroll-processing and automated-payg-withholding agents — which means you're a TFN recipient under section 6 of the Privacy Act, which means you're covered. The threshold doesn't apply to you.

XIntelliSync makes that structurally visible: every TFN-class data flow passes through XGVS gates, every action gets logged, every retention period gets enforced. You can audit your own coverage trail in your account.

← Privacy Act pillar · See the payroll cluster that handles TFN data →

Seven paths to coverage

Hit any one — you are an APP entity.

$3M turnover threshold

Privacy Act s 6C (definition of organisation) + s 6D (definition of small business operator)

Any business with annual turnover above $3M (in the previous financial year, including related-body-corporate turnover) is an APP entity. Below $3M is generally exempt UNLESS one of the always-covered categories applies. Most XIntelliSync customers cross this threshold within 12-18 months of growth.

Always covered: Health service providers

Privacy Act s 6FA

Any business that provides a "health service" — including GPs, allied health, fitness trainers, mental-health practitioners, dentists, pharmacies, aged-care providers, and complementary medicine — is covered regardless of turnover. Health information is sensitive information per s 6 + APP 3.3.

Always covered: Credit providers + credit reporting bodies

Privacy Act Pt IIIA + s 6 (definition of credit provider)

Mortgage brokers, non-bank lenders, BNPL providers, vehicle finance, asset finance, equipment finance, and credit reporting bodies are covered regardless of turnover. Credit information has its own consent + use regime under Pt IIIA in addition to the 13 APPs.

Always covered: Tax File Number recipients

Privacy Act s 6 (definition of TFN information) + TFN Rule 2015

Any business that handles Tax File Numbers — every employer running PAYG, every super fund handling member TFNs, every accountant + bookkeeper accepting TFN declarations — is covered regardless of turnover. The TFN Rule 2015 adds explicit secondary-use restrictions on top of the 13 APPs.

Always covered: Residential tenancy database operators

Privacy Act s 6 + RTBA / state tenancy database legislation

Any business that operates a residential tenancy database (TICA, NTD, Trading Reference Australia, etc.) is covered regardless of turnover. Real estate agencies that maintain their own tenant records may also fall in scope depending on their database structure.

Always covered: Trade in personal information

Privacy Act s 6D (small business operator exception)

Below $3M turnover but you trade in personal information (e.g. sell mailing lists, run a lead-generation marketplace, operate a data broker)? You lose the small-business exemption and become a covered entity regardless of turnover. Lead-list sale + marketing-list resale both trigger this.

Always covered: Contracted Commonwealth service providers

Privacy Act s 6F + Commonwealth contract clauses

Any business contracted to provide services to or for a Commonwealth agency is covered regardless of turnover, for the personal information handled in connection with that contract. Includes Centrelink contractors, Department of Veterans' Affairs panels, government IT vendors.

All 22+ industries served

Coverage status for every industry XIntelliSync serves.

Always-covered industries are flagged red. $3M-threshold industries are flagged cyan. Partially-covered (e.g. NFPs) are flagged violet.

Construction

$3M turnover threshold

Covered if annual turnover > $3M (APP entity per Privacy Act s 6C). Most builders cross the threshold once they take on residential or commercial projects above ~$2M revenue.

Healthcare

Always covered

Always covered regardless of turnover under Privacy Act s 6FA — health service providers handle health information which is sensitive information per s 6 + APP 3.

Hospitality

$3M turnover threshold

Covered if annual turnover > $3M. Multi-venue groups + franchise operators typically cross the threshold; single-venue cafés rarely do.

Retail

$3M turnover threshold

Covered if annual turnover > $3M. Single-store retailers under threshold may still be covered if they trade in personal information (e.g. mailing-list sale).

Professional Services / Consulting

$3M turnover threshold

Covered if annual turnover > $3M. Most consulting firms cross threshold quickly; even small firms covered if they handle client TFN / TFN declarations on engagement.

Digital / Tech / SaaS

$3M turnover threshold

Covered if annual turnover > $3M. SaaS providers also covered through cross-border data flow rules under APP 8 — must contractually bind any overseas processor to the APPs.

Finance / Mortgage Brokers

Always covered

Always covered as credit providers (Pt IIIA Privacy Act). Mortgage brokers + non-bank lenders + buy-now-pay-later all under credit reporting code (CR Code) + APPs.

Legal

Always covered

Always covered through TFN handler obligations (s 6) + most firms above $3M turnover. Trust-account client data triggers professional + statutory privacy obligations.

Childcare / Early Learning

Always covered

Always covered — children’s health + immunisation data is sensitive information regardless of turnover. CCS + family payment data adds Centrelink TFN handler obligations.

Education / RTOs

Always covered

Always covered through student TFN handler obligations + ASQA / TEQSA reporting requirements. RTOs handle USIs which are sensitive identifiers under separate regime.

Manufacturing

$3M turnover threshold

Covered if annual turnover > $3M. Most manufacturers operating B2B above threshold; employee data alone (TFNs) places them in TFN handler regime regardless.

Transport / Logistics

$3M turnover threshold

Covered if annual turnover > $3M. Driver TFN handling + Chain of Responsibility records may bring coverage even below threshold for fleets > 12t.

Mining / Resources

$3M turnover threshold

Covered if annual turnover > $3M (most operators cross threshold). FIFO worker rostering + biometric site-access systems trigger broader privacy obligations.

Agriculture / Primary Production

$3M turnover threshold

Covered if annual turnover > $3M. Many farm operations under threshold; covered through TFN handler regime once a single employee is on PAYG.

Fitness / Health Clubs

Always covered

Always covered — fitness assessments + injury history + medical clearance documents are health information per Privacy Act s 6 (regardless of turnover).

Not-for-Profit

Partially covered

NFPs with turnover > $3M are APP entities. NFPs handling health information always covered. Religious + political bodies may have sector-specific exemptions but membership data is still sensitive information.

Events / Conferences

$3M turnover threshold

Covered if annual turnover > $3M. Single-event organisers may fall under threshold; covered when handling attendee dietary + accessibility (health) information.

Creative / Photography / Production

$3M turnover threshold

Covered if annual turnover > $3M. Studios under threshold still covered if they handle model release forms with sensitive details (e.g. minors) or trade in mailing lists.

Marketing / Advertising Agencies

$3M turnover threshold

Covered if annual turnover > $3M. Below threshold but trades in personal information (lead-list resale) → still covered under s 6D Privacy Act.

HR / Recruitment

Always covered

Always covered through TFN handler regime + employee record handling for client placements. Most firms also above $3M turnover.

Insurance Brokers / Underwriters

Always covered

Always covered through health information handling (insurance claims) + credit information regime. Insurance Council of Australia General Insurance Code overlaps with APPs.

Real Estate / Property Management

Always covered

Always covered as residential tenancy database operators + most agencies above $3M turnover. Property management TFN-on-trust-account triggers TFN handler regime.

FAQs

Privacy Act coverage — answered.

How is the $3M turnover threshold calculated?

Annual turnover is the gross revenue earned in the previous financial year, including the turnover of related body corporates (a group test, not a per-entity test). The threshold is set in the Privacy Act + Privacy Regulation 2013. If your group consolidated turnover crosses $3M in the prior year, you are covered for the current year regardless of which entity holds the data.

I am a sole trader with $200K turnover — am I really exempt?

Probably not. Even though you are below $3M, you may be covered through the always-covered categories. Are you handling employee TFNs? Covered. Providing any health service (incl. fitness training)? Covered. Providing credit (e.g. payment plans)? Covered. Trading in personal information (selling a lead list)? Covered. The exemption is narrower than most sole traders realise.

My business is just under $3M — when do I have to start complying?

You become an APP entity on the first day of the financial year following the year you crossed $3M. You should start compliance preparation 6-12 months before crossing the threshold so you have a privacy policy + collection notices + reasonable-security controls in place when the obligation triggers. XIntelliSync handles this automatically once you mark your business as expected-to-cross-threshold.

Do I need to publish a privacy policy if I am exempt under the $3M small-business exception?

Strictly no — APP 1 only applies if you are an APP entity. But: a published privacy policy is best-practice trust signalling, customers expect it, and many B2B buyers require it as a contract term. Most exempt small businesses publish one anyway, voluntarily binding themselves to the APPs. Once you cross the threshold, the policy becomes mandatory.

Does the GDPR apply to Australian businesses?

Only if you offer goods or services to individuals in the EU or monitor the behaviour of individuals in the EU. If you do — GDPR applies in addition to the Privacy Act, and its data-subject rights and breach-notification rules are stricter (72 hours for breach notification vs the Australian 30 days). XIntelliSync flags GDPR exposure on customer onboarding when EU traffic is detected.

How does XIntelliSync determine my coverage status?

During customer onboarding, XIntelliSync asks: industry, turnover band, whether you handle TFNs, whether you provide a health service, whether you give credit, whether you operate a tenancy database, whether you trade in personal information. The answers determine coverage status, which sets the XGVS Privacy Act gate intensity for every action your account takes from that point forward.