The Privacy Act 1988 and its thirteen Australian Privacy Principles set the rules for collecting, using, disclosing and securing personal information, overseen by the OAIC. Under the Notifiable Data Breaches scheme, organisations covered by the Act must notify affected individuals and the regulator of breaches likely to cause serious harm. Some small businesses are currently outside the Act, with important exceptions such as health service providers. Reform of the Act is under way, and customers and investors will ask about privacy regardless, so we advise against relying on that exemption when designing a product.
The principle most relevant to an offshore developer is the one on cross-border disclosure. An Australian organisation that discloses personal information to an overseas recipient generally remains accountable for how that recipient handles it. The practical response is to avoid the disclosure:
- Production systems in an Australian cloud region, in your company’s account
- Development and testing on synthetic data
- Access to production data kept with your own people, with deployments running through an automated pipeline
- Collection limited to what each feature requires, and a privacy policy that matches what the software actually does
- Account deletion, data access and correction built into the product or its admin tools
- Logging and alerting adequate to detect a breach and assess it within the required timeframes
If you are considering fintech features that use the Consumer Data Right, or anything involving health records, the accreditation and regulatory questions need to be answered before the scope is fixed. This is general information and not legal advice. BBR does not hold ISO 27001, SOC 2 or IRAP-related certifications.