Pillar · Australian Privacy Act 1988 + APP + NDB

Privacy Act / APP / NDB compliance — every covered SMB. Every collection. Every breach.

The Australian Privacy Act 1988 covers more SMBs than most realise. Above $3M turnover. Or handling health information. Or storing TFNs. Or providing credit. The 13 Australian Privacy Principles set the rules. The Notifiable Data Breach scheme sets the 30-day clock. XIntelliSync prepares; you lodge with OAIC at oaic.gov.au.

Why this lives on XIntelliSync, not on a law firm's blog

XIntelliSync IS an APP entity. APP 11 reasonable security is enforced gate-by-gate, not policy-promised.

Most SaaS reads the Privacy Act once, copy-pastes a privacy policy from a template, and prays nobody at the OAIC reads it. We built the gate engine that enforces it on every action — because we're the system holding the data, and a policy PDF doesn't stop a TFN from leaving the database.

XIntelliSync IS an APP entity. Every TFN, payroll record, customer phone number, ABN, bank account, and superannuation fund detail flowing through the platform is personal information your business is accountable for under APP 1 through APP 13. We don't sell you a privacy-management product — we're the system holding the data. APP 11 reasonable security isn't a quarterly review on our side. It's enforced gate-by-gate, every action, on the production runtime.

XGVS — 42 layers, 6 stages, 356+ gates across 34 compliance frameworks. Every action passes every gate that applies — or the action halts and tells you why. Privacy Act, APP 1 through APP 13, and the NDB scheme are four of those 34. Your data, every action, every time.

Two years of work before you ever logged in. Built in Australia, gate-tested against the regulator your data answers to.

See how the four-system Trust Stack actually works

The four pillars of Australian privacy compliance

Coverage · APPs · Notifiable breach · Privacy by Design.

Every covered Australian SMB must answer the same four questions. Are we covered? What rules apply? What happens if we breach? How do we build privacy in from day one?

APP Coverage + the $3M Threshold

The Privacy Act 1988 covers more SMBs than most realise.

$3M turnover threshold · 4+ permanent-coverage categories · 13 APPs · Privacy Act 1988 (Cth) — verifiable on oaic.gov.au

Most Australian SMBs assume the Privacy Act only applies to big businesses. The truth: any business above $3M annual turnover is an APP entity, plus several categories are covered REGARDLESS of turnover — health service providers (s 6FA), credit providers and credit reporting bodies (Pt IIIA), Tax File Number recipients (s 6), and residential tenancy database operators. If you handle medical records, give credit, store TFNs, or run a tenancy database — you are covered, full stop.

The 13 Australian Privacy Principles

APP 1 to APP 13 — the rules every covered SMB must follow.

13 APPs · APP 1 (open & transparent management) → APP 13 (correction) · Schedule 1 to the Privacy Act

The 13 APPs cover the full lifecycle of personal information: collection (APPs 3-5), use and disclosure (APPs 6-9), data quality and security (APPs 10-11), and access and correction (APPs 12-13). Plus the structural ones — APP 1 (privacy policy and accountable management) and APP 2 (anonymity option). Sensitive information (health, biometrics, racial origin, sexual orientation, religious beliefs) carries an extra explicit-consent overlay under APP 3.3.

Notifiable Data Breach (NDB) Scheme

Eligible breach → notify OAIC + affected individuals within 30 days.

Privacy Act Pt IIIC · 30-day clock from awareness · OAIC + each affected individual · Statement of Notifiable Data Breach

When personal information is lost or accessed without authorisation AND a reasonable person would conclude this is likely to result in serious harm — that is an eligible data breach. From the moment your business becomes aware of facts suggesting an eligible breach has occurred, the 30-day clock starts. Within 30 days you must (1) take reasonable steps to assess if it is eligible, (2) notify OAIC via the Notifiable Data Breach form, and (3) notify each affected individual. Non-compliance: civil penalties up to $50M for serious or repeated interference with privacy.

Privacy by Design

Build privacy into the system. Do not bolt it on after a breach.

APP 11 reasonable security · APP 8 cross-border safeguards · OAIC Privacy Management Framework · ISO/IEC 27701

Privacy by Design is the engineering discipline of building privacy controls into the system from day one. APP 11 requires reasonable steps to protect personal information from misuse, loss, and unauthorised access. APP 8 requires that any cross-border data flow either has substantially-similar protection at the foreign destination OR explicit consent from the individual. The OAIC Privacy Management Framework is the practical playbook — XIntelliSync builds against it.

What XIntelliSync actually does about the Privacy Act

Three binaries, all backed by real platform behaviour, none of them a marketing claim.

1. Two businesses on the same database cannot read each other's data — the database itself refuses, not a policy promise. Row-Level Security is enforced on every customer table (745 of them, 100% coverage). APP 6 use-and-disclosure and APP 11 reasonable security are enforced at the database layer, not in a try/catch.

2. Sensitive personal information flows through gate-checked agents, not blanket queries. The Bank Reconciliation agent (automated-bank-reconciliation) reads through Basiq's accredited-partner CDR feed — read-only, one direction, no write-back. The payroll agents (automated-payroll-processing, automated-pay-slip-generation, automated-super-calculation) handle TFN-class data inside scoped tenant queries that XGVS supervises in real time.

3. Silent-write failure is the breach class that doesn't show up in penetration tests, doesn't trigger alerts, and doesn't appear in the audit log — because the write returned success. The database receives nothing. The customer thinks the action persisted. On personal-information tables, that exact pattern starts the 30-day NDB clock the moment a regulator or affected individual notices the data isn't where it should be — which can be quarters later. XGVS Stage 0 + Stage 5 gates exist to make that failure mode impossible to hide on this platform. Errors surface immediately or fail loudly. There is no third option.

What XIntelliSync deliberately does NOT do. No Notifiable Data Breach reporting on your behalf — section 26WK of the Privacy Act makes lodgement and affected-individual notification your obligation as the APP entity, and we won't fake an OAIC notification. No privacy-policy authoring. No third-party data-sharing on your customers' behalf without your explicit consent flow. APP 1 governance policy, APP 5 collection notification, APP 6 disclosure consent, and APP 13 correction stay yours. No software writes those for you, and any platform that says otherwise is selling you exposure.

Privacy Act, APP, NDB, CDR — the four frameworks governing personal information in Australia. XGVS gates all four. Your obligations outside the platform stay yours. The data flowing through the platform is on us, every action, every time.

See the agents that touch your personal information

Where to lodge externally

XIntelliSync prepares. You lodge with OAIC. The Commissioner acknowledges.

XIntelliSync is not a registered agent of the Office of the Australian Information Commissioner and does not lodge data breach notifications on your behalf. Once XIntelliSync prepares the Statement of Notifiable Data Breach + the affected-individual notification template, lodge externally at one of these official OAIC portals:

OAIC Notifiable Data Breach Form — oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach

Official online form to lodge a Statement of Notifiable Data Breach with the Australian Information Commissioner. Lodge within 30 days of becoming aware of facts suggesting an eligible breach has occurred. Plus notify each affected individual via the same Statement.

Office of the Australian Information Commissioner — oaic.gov.au

Australia's privacy regulator. Authoritative source on the Privacy Act 1988, the 13 APPs, the NDB scheme, the Privacy Management Framework, and current enforcement actions. Subscribe to OAIC media releases for regulatory change signals.

The 13 Australian Privacy Principles — oaic.gov.au APPs

OAIC's authoritative explainer on each of the 13 APPs. Use as the reference for collection notices (APP 5), use and disclosure (APPs 6-9), data quality and security (APPs 10-11), and access and correction (APPs 12-13).

OAIC Privacy Management Framework — oaic.gov.au privacy-management-framework

The OAIC's practical playbook for embedding privacy throughout an APP entity. Four steps: embed a culture of privacy that enables compliance · establish robust internal practices · evaluate your privacy processes · enhance your response to privacy issues.

AustLII — austlii.edu.au Privacy Act 1988 (Cth)

Free public access to the Privacy Act 1988 and Schedule 1 (the 13 APPs). Use for legal-grade citation when responding to OAIC investigations or drafting privacy contracts. The Act is the underlying source of every APP rule.

All 22+ industries served

Coverage status + the most-likely NDB scenario for every industry XIntelliSync serves.

XIntelliSync serves Australian SMBs across 22+ industries. Each industry below maps to its Privacy Act coverage status (always-covered · turnover-threshold · partially-covered), the industry-specific privacy obligation under the 13 APPs, and the most-likely Notifiable Data Breach scenario for that industry. Coverage rules verifiable on oaic.gov.au.

Construction

$3M turnover threshold

Coverage — Covered if annual turnover > $3M (APP entity per Privacy Act s 6C). Most builders cross the threshold once they take on residential or commercial projects above ~$2M revenue.

APP nuance — Subcontractor TFN + super-fund-membership data triggers TFN handler obligations (always-covered regardless of turnover). White card / induction database under APP 6 — secondary use limits.

Likely NDB scenario — Site supervisor laptop with subcontractor TFNs lost on site → eligible data breach if 2+ individuals affected. Notify OAIC + each affected sub within 30 days of awareness.

Healthcare

Always covered

Coverage — Always covered regardless of turnover under Privacy Act s 6FA — health service providers handle health information which is sensitive information per s 6 + APP 3.

APP nuance — Health information requires explicit consent under APP 3.3 + APP 6.2(c). My Health Record interactions, AHPRA registration data, Medicare claims all carry overlapping consent regimes.

Likely NDB scenario — Practice-management-system breach exposing patient appointments + Medicare numbers = always notifiable. Clinical notes leak adds AHPRA professional reporting obligations on top of OAIC NDB.

Hospitality

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Multi-venue groups + franchise operators typically cross the threshold; single-venue cafés rarely do.

APP nuance — Loyalty programme data + booking-system PII + employee TFNs all in scope when above threshold. POS data with card-on-file triggers PCI-DSS overlap (separate from Privacy Act but related).

Likely NDB scenario — Booking-system breach exposing customer names + dietary requirements (health info) + phone numbers — sensitive-information element triggers NDB regardless of turnover for the affected venue.

Retail

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Single-store retailers under threshold may still be covered if they trade in personal information (e.g. mailing-list sale).

APP nuance — E-commerce capture of address + payment + browsing history all in scope above threshold. APP 5 collection notice required at point of capture; APP 1 privacy policy must be findable on the site.

Likely NDB scenario — POS / e-commerce platform breach exposing card data + customer PII = NDB-eligible. Loyalty database breach with email + purchase history = also eligible if 2+ individuals affected.

Professional Services / Consulting

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Most consulting firms cross threshold quickly; even small firms covered if they handle client TFN / TFN declarations on engagement.

APP nuance — Client-confidential information sits under both Privacy Act + common-law confidentiality. APP 11 reasonable-security standards extend to engagement files at rest + in transit.

Likely NDB scenario — Engagement-server breach exposing client business plans + TFNs + employee data. Hard-drive theft from a client site visit is a frequently-cited NDB scenario for consulting.

Digital / Tech / SaaS

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. SaaS providers also covered through cross-border data flow rules under APP 8 — must contractually bind any overseas processor to the APPs.

APP nuance — Cookie / analytics / session data all PII in scope. APP 8 cross-border transfer requires either same-or-substantially-similar protection by the foreign recipient OR explicit consent.

Likely NDB scenario — Database-credential leak via misconfigured cloud bucket or compromised dev token = high-volume NDB. SaaS vendor breach can cascade NDB to every customer (downstream notification).

Finance / Mortgage Brokers

Always covered

Coverage — Always covered as credit providers (Pt IIIA Privacy Act). Mortgage brokers + non-bank lenders + buy-now-pay-later all under credit reporting code (CR Code) + APPs.

APP nuance — Credit information has stricter rules than general personal information — separate consent regime under Pt IIIA. APP 12 access requests carry credit-specific response time limits.

Likely NDB scenario — Credit-application database breach exposing credit scores + financial position = always notifiable. Mortgage broker laptop with client tax returns + bank statements lost is the classic case.

Legal

Always covered

Coverage — Always covered through TFN handler obligations (s 6) + most firms above $3M turnover. Trust-account client data triggers professional + statutory privacy obligations.

APP nuance — Client legal-privilege information sits above Privacy Act protection but APP rules still apply to handling. Conflict-check databases under APP 11 reasonable-security standards.

Likely NDB scenario — Email-account compromise exposing privileged-matter content = NDB + Law Society reporting. Practice-management-system breach exposes trust-account ledgers — financial + identity exposure.

Childcare / Early Learning

Always covered

Coverage — Always covered — children’s health + immunisation data is sensitive information regardless of turnover. CCS + family payment data adds Centrelink TFN handler obligations.

APP nuance — Parent ID + child medical records + emergency contacts under APP 3.3 explicit-consent regime. Photo/video consent forms require granular specificity per APP 5 collection notices.

Likely NDB scenario — Centre-management-software breach exposing CCS records + child immunisation status + parent IDs = always-notifiable. Photo album leak with identifiable children is a high-profile NDB.

Education / RTOs

Always covered

Coverage — Always covered through student TFN handler obligations + ASQA / TEQSA reporting requirements. RTOs handle USIs which are sensitive identifiers under separate regime.

APP nuance — Student record systems carry both APP and federal Education and Training Reform Act obligations. Disability-support records are sensitive information under APP 3.3.

Likely NDB scenario — Student information system (SIS) breach exposing TFNs + USIs + assessment records. Email-list leak of student email addresses is a frequently-cited low-severity NDB.

Manufacturing

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Most manufacturers operating B2B above threshold; employee data alone (TFNs) places them in TFN handler regime regardless.

APP nuance — Supplier portal capture + customer-relationship data + employee biometric (timeclock) data all in scope. APP 1 privacy policy + APP 5 collection notice required at customer onboarding.

Likely NDB scenario — ERP system breach exposing customer payment terms + supplier ABNs + employee records = NDB-eligible. Biometric timeclock vendor breach cascades NDB to the manufacturing customer.

Transport / Logistics

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Driver TFN handling + Chain of Responsibility records may bring coverage even below threshold for fleets > 12t.

APP nuance — Telematics / GPS / ELD data is personal information about the driver. APP 5 collection notice required at driver onboarding; secondary use restricted under APP 6.

Likely NDB scenario — Telematics-vendor breach exposing driver routes + work diary entries + license details = NDB. Customer delivery-address database leak compromises customer privacy at scale.

Mining / Resources

$3M turnover threshold

Coverage — Covered if annual turnover > $3M (most operators cross threshold). FIFO worker rostering + biometric site-access systems trigger broader privacy obligations.

APP nuance — Biometric site-access data is sensitive information under APP 3.3 — explicit consent required. FIFO worker family-contact data carries higher-than-baseline privacy risk.

Likely NDB scenario — Site-access system breach exposing biometric templates + employment records is high-severity (biometrics cannot be re-issued). NDB notification triggers AS/NZS 4360 risk review.

Agriculture / Primary Production

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Many farm operations under threshold; covered through TFN handler regime once a single employee is on PAYG.

APP nuance — Seasonal worker data + WHM (working holiday maker) records carry overlap with immigration data-handling regime. Drone footage capturing neighbouring properties may breach others’ privacy.

Likely NDB scenario — Farm-management-software breach exposing yield data + soil tests + worker PII. Seasonal worker payroll system breach exposing WHM passport copies is the classic agriculture NDB.

Fitness / Health Clubs

Always covered

Coverage — Always covered — fitness assessments + injury history + medical clearance documents are health information per Privacy Act s 6 (regardless of turnover).

APP nuance — Member health screening + biometric access (gym entry fingerprints) + personal training records all sensitive information under APP 3.3 explicit-consent regime.

Likely NDB scenario — Gym-management-software breach exposing member health screening + DD payment details = always-notifiable. Photo-leak from PT video sessions adds image-based privacy harm.

Not-for-Profit

Partially covered

Coverage — NFPs with turnover > $3M are APP entities. NFPs handling health information always covered. Religious + political bodies may have sector-specific exemptions but membership data is still sensitive information.

APP nuance — Donor data + beneficiary case files + volunteer working-with-children-check records all sensitive. APP 1 privacy policy must address donor + beneficiary + volunteer separately.

Likely NDB scenario — CRM breach exposing donor giving history + beneficiary case notes — beneficiary harm risk is often higher than donor harm. NDB notification to beneficiaries needs trauma-informed handling.

Events / Conferences

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Single-event organisers may fall under threshold; covered when handling attendee dietary + accessibility (health) information.

APP nuance — Attendee dietary + accessibility data is sensitive information under APP 3.3. Photo / video capture at events requires APP 5 collection notice + opt-out signage.

Likely NDB scenario — Ticketing-platform breach exposing attendee names + dietary needs + payment details. Speaker contract database breach exposes speaker fees + bank details = financial harm NDB.

Creative / Photography / Production

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Studios under threshold still covered if they handle model release forms with sensitive details (e.g. minors) or trade in mailing lists.

APP nuance — Model release + image rights consent under APP 5 + APP 6 secondary-use rules. Capture of minors requires parental consent + sensitive-information regime under APP 3.3.

Likely NDB scenario — Image-archive breach with identifiable minors or sensitive-context shots = high-severity NDB. Cloud-storage credentials leak exposing client deliverables triggers contract + privacy harm.

Marketing / Advertising Agencies

$3M turnover threshold

Coverage — Covered if annual turnover > $3M. Below threshold but trades in personal information (lead-list resale) → still covered under s 6D Privacy Act.

APP nuance — Email-marketing under Spam Act 2003 + APP 7 (direct marketing) overlap. Lead-generation forms must satisfy APP 5 collection notice + APP 1 privacy policy linkage.

Likely NDB scenario — Email-marketing platform breach exposing subscriber lists + segmentation tags. Audience-data marketplace acquisition may trigger derivative NDB across the bought lists.

HR / Recruitment

Always covered

Coverage — Always covered through TFN handler regime + employee record handling for client placements. Most firms also above $3M turnover.

APP nuance — Resume + background-check + reference data all PII. Background checks involving police records are sensitive information under APP 3.3 — explicit consent required.

Likely NDB scenario — ATS (applicant tracking system) breach exposing candidate resumes + reference checks + bank details for placed candidates = NDB across multiple employers.

Insurance Brokers / Underwriters

Always covered

Coverage — Always covered through health information handling (insurance claims) + credit information regime. Insurance Council of Australia General Insurance Code overlaps with APPs.

APP nuance — Medical reports + claim histories + financial-position data all sensitive information. APP 8 cross-border data flow common in re-insurance — disclosure regime applies.

Likely NDB scenario — Claims-management-system breach exposing medical reports + claim payouts = high-severity NDB. Re-insurance data flow breach via overseas processor cascades responsibility back to AU broker.

Real Estate / Property Management

Always covered

Coverage — Always covered as residential tenancy database operators + most agencies above $3M turnover. Property management TFN-on-trust-account triggers TFN handler regime.

APP nuance — Tenancy applications carry the heaviest collection notice requirements per APP 5 + tenancy-database-specific rules. Bond data + utility account references all in scope.

Likely NDB scenario — Property-management-software breach exposing tenant applications + bank statements + landlord trust-account records. Utility-data integration creates derivative NDB across multiple tenants.

FAQs

Privacy Act, APPs, and the NDB scheme — answered.

Is XIntelliSync covered by the Australian Privacy Act 1988?

Yes. As a SaaS platform that handles personal information for paying Australian SMBs (including TFNs through the payroll preparation flow + health information through the appointment + scheduling agents in some industries), XIntelliSync is an APP entity. We publish a Privacy Policy on /privacy-policy and operate against the OAIC Privacy Management Framework.

Does my business have to comply with the Privacy Act?

You are covered if any of the following apply: (1) annual turnover above $3M, (2) you provide a health service (regardless of turnover), (3) you handle Tax File Numbers, (4) you provide credit or are a credit reporting body, (5) you operate a residential tenancy database, or (6) you trade in personal information. Most Australian SMBs we serve fall into at least one of these categories.

What is an "eligible data breach" under the NDB scheme?

An eligible breach is: unauthorised access to or unauthorised disclosure of personal information (or loss of personal information likely to lead to such access or disclosure) AND a reasonable person would conclude this is likely to result in serious harm to one or more affected individuals. Examples: ransomware encrypting customer records, an emailed spreadsheet sent to the wrong recipient, or a stolen laptop with unencrypted client files.

How long do I have to notify OAIC after a data breach?

You have 30 days from the moment you become aware of facts suggesting an eligible breach has likely occurred. Within that window: (1) carry out a reasonable assessment, (2) prepare a Statement of Notifiable Data Breach, (3) submit it to OAIC via the online NDB form at oaic.gov.au, and (4) notify each affected individual. The 30-day clock is for the assessment AND notification — do not wait until day 29 to notify if you confirm the breach earlier.

Does XIntelliSync lodge data breach notifications with OAIC on my behalf?

No. XIntelliSync prepares a Statement of Notifiable Data Breach template populated with the facts of the incident, but the customer must submit it via the OAIC NDB online form at oaic.gov.au. We are not acting as an agent of the customer for the purposes of OAIC reporting. The customer retains lodgement authority and accountability.

What is the maximum penalty for a Privacy Act breach?

For serious or repeated interference with privacy by a body corporate: the greater of $50M, three times the benefit derived from the breach, or 30% of adjusted turnover for the relevant period. For individuals: up to $2.5M. Plus reputational damage, customer trust loss, and OAIC investigations that can take 12+ months to close.

How does XIntelliSync help with Privacy Act compliance?

Through XGVS (XIntelliSync Global Verification System), every action that touches personal information passes Privacy Act + APP gates before it executes. APP 11 reasonable-security checks, APP 8 cross-border-flow checks, APP 5 collection-notice presence, and APP 1 privacy-policy linkage are all enforced at runtime. Customers see a Statement of Verification Pass on every covered action.

Continue reading

Cluster spokes + related pillars.

Each spoke is a deep-dive on one of the four pillars above. The related pillars (AI Verification, Payroll, BAS / GST) all tie back to Privacy Act compliance through XGVS.