Customer and contract access
Australian enterprise and government buyers ask suppliers how personal information is protected. Weak answers slow deals and renewals.
Australia has tougher privacy penalties, a right to sue for serious invasions and new transparency duties arriving in December 2026. Show the OAIC and your customers that personal information is protected in practice.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting Australia Privacy Act wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Australian enterprise and government buyers ask suppliers how personal information is protected. Weak answers slow deals and renewals.
Top penalties reach A$50M, three times benefit or 30% of adjusted turnover. Individuals can also sue for serious invasions of privacy.
Notification goes to the regulator and to customers. How quickly and clearly you explain what happened shapes how they judge you.
Automated decision transparency is due 10 December 2026 and the children’s code is in development. Board-level ownership of privacy and security should be clear.
Most larger private organisations are covered, along with government agencies.
They are covered regardless of size and hold especially sensitive information.
The Act can apply to foreign entities that carry on business in Australia and collect data there.
High volumes of customer data make them frequent targets and frequent subjects of breach notices.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
We compare your safeguards with APP 11 and OAIC guidance and rank gaps by the risk to personal information.
Human-led testing of the applications, APIs, cloud and networks that hold or process personal information.
We check that access, encryption, logging and retention controls work as documented.
Scope, methods, findings and results organised for regulators, insurers and customers who ask.
Practical fix guidance for your engineers and a retest to confirm each finding is closed.
A clear summary of exposure, progress and decisions for directors and executives.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
List the data you hold, where it sits, who can reach it and which suppliers process it.
Compare your safeguards with APP 11 expectations and the OAIC’s guidance on reasonable steps.
Run penetration testing of systems that hold personal information and validate key controls.
Test your breach assessment and notification process with a tabletop exercise.
Close findings and retest, review automated decision use and update privacy policy wording and records.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Ask for a current inventory including suppliers and overseas locations.
Ask for dated test results and fixes, not just policies.
Ask when the breach process was last rehearsed and who decides.
Ask for the list before 10 December 2026.
Confirm a named executive owns privacy and security reporting.
The Privacy Act 1988 regulates how Australian Government agencies and many private organisations handle personal information. Its core is the 13 Australian Privacy Principles (APPs). Most businesses with annual turnover above A$3 million are covered, and some smaller ones are too, such as health providers and businesses that trade in personal information. It can also reach overseas organisations that carry on business in Australia.
APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, and to destroy or de-identify it when no longer needed. The 2024 reforms made clear that reasonable steps include both technical and organisational measures. The Notifiable Data Breaches (NDB) scheme then requires notification to the OAIC and affected people when a breach is likely to cause serious harm.
The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy, new enforcement tools and penalty tiers, and a Children’s Online Privacy Code. Automated decision transparency rules are scheduled for December 2026. Further reform stages are still being discussed, so treat dates and detail as something to confirm before relying on them.
Not every principle is about security, but several decide what regulators ask after an incident. These are the ones that matter most to boards and security teams.
Take reasonable steps to protect personal information and to destroy or de-identify it when no longer needed. The OAIC’s guidance expects steps that fit the sensitivity and volume of the data, covering governance, access, systems, testing and supplier controls.
If you suspect an eligible breach, complete an assessment within 30 days. If it is confirmed, notify the OAIC and affected individuals as soon as practicable. Your ability to answer what happened rests on logs and tested response plans.
APP 8 makes you accountable in many cases when you send personal information overseas, such as to a cloud provider. The reforms also add a mechanism to recognise countries with comparable protections.
Organisations that use automated decision-making that significantly affects individuals’ rights or interests must describe it in their privacy policy. The requirement is due to start on 10 December 2026. The OAIC can now issue infringement notices for some policy failures.
The OAIC is developing a Children’s Online Privacy Code for services likely to be accessed by children. Separately, individuals have been able to sue for serious invasions of privacy since June 2025, which adds litigation risk after a breach.
The Act does not name penetration testing, but APP 11 asks for reasonable steps. After a breach, regulators and courts look for proof that you tested and fixed known weaknesses.
Testing evidence shows you looked for weaknesses in systems holding personal information and acted on them.
Prior testing and clear system documentation make breach assessment faster and more accurate.
Test results and retest letters help show that the systems you rely on, or hand data to, were checked.
Reports translate technical results into a record that directors have asked the right questions.
Health providers, data traders and others are covered at any size, and customers will ask regardless.
APP 11 includes destruction and de-identification. Old data is old risk.
A 30 day assessment window is short when no one knows who decides.
Automated decision wording and records take time to compile across business units.
Probably, if you have annual turnover above A$3 million, handle health information, trade in personal information or are a government agency. It can also apply to overseas entities carrying on business in Australia.
Reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, and to destroy or de-identify it when it is no longer needed. Reasonable steps include technical and organisational measures.
If you suspect an eligible breach, assess it within 30 days. If likely to cause serious harm, notify the OAIC and affected individuals as soon as practicable.
A statutory tort for serious invasions of privacy, new penalty tiers and infringement notices, a Children’s Online Privacy Code, a mechanism for comparable overseas privacy regimes, and automated decision transparency duties.
For serious or repeated interference with privacy, the maximum is the greater of A$50M, three times the benefit obtained or 30% of adjusted turnover. Lower tiers and infringement notices apply to less serious failures.
They are due to apply from 10 December 2026. Check the latest OAIC guidance as that date approaches.
No. It is general education. Confirm obligations with qualified Australian counsel.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.