An Australian website is not automatically subject to every privacy law wherever a visitor lives. Nor is a small business automatically outside the Australian Privacy Act merely because its turnover is below a threshold.
Privacy scope begins with facts: which entity performs which activity, involving what information, about whom, in which places and for what purpose? Only then can an organisation identify applicable law, notices, contracts, technical controls and review obligations.
This article compares three common questions for Australian online businesses: the Australian Privacy Act 1988, the European Union General Data Protection Regulation (GDPR), and California's Consumer Privacy Act as amended by the CPRA (collectively referred to here as the CCPA framework). It is general information, not legal advice.

Build a processing and disclosure map first
Create a plain-language record of:
- the legal entities, contractors and brands involved;
- types of personal information collected or inferred;
- whose information it is and where those people are located;
- websites, forms, applications, analytics, advertising and support channels;
- purposes, decisions and retention periods;
- systems, cloud regions, recipients and subprocessors;
- disclosures, sales, sharing and international transfers; and
- who decides the purpose and means of processing.
Do not treat a cookie banner, privacy-policy generator or plugin inventory as a complete map. Server logs, email delivery, backups, payment providers, security services, customer-relationship systems and human support processes can all matter.
Australia: the small-business exemption has important exceptions
The Australian Privacy Principles (APPs) apply to Australian Government agencies and many private-sector organisations. Most small-business operators with annual turnover of $3 million or less are not covered by the Privacy Act, but there are important exceptions. Coverage can arise from the nature of the entity or activity—for example, some health-service providers, businesses that trade in personal information, Commonwealth-contracted service providers and related corporate structures (OAIC — Small business).
An organisation can also opt in. State or territory laws, surveillance, direct-marketing, telecommunications, employment, consumer, health-record and contractual obligations may remain relevant even where the federal small-business exemption applies.
Questions to record include:
- Is each relevant entity an APP entity, exempt small-business operator or covered for only a particular activity?
- Does it provide a health service or handle health information?
- Does it disclose personal information for a benefit, service or advantage, or collect it for that purpose?
- Does a Commonwealth contract or another regulated relationship change the position?
- Is an overseas recipient handling information on its behalf?
Do not publish a blanket statement that “the Privacy Act does not apply” without checking the entity and activity.
Notifiable Data Breaches
The Notifiable Data Breaches (NDB) scheme applies to entities covered by the Privacy Act. A notification decision is not triggered by every security event. It requires assessment of the statutory criteria, including whether there has been unauthorised access to, disclosure of, or loss of personal information likely to result in serious harm, and whether remedial action prevents the likely harm.
Prepare an evidence-preserving response process and obtain appropriate legal advice rather than relying on an automatic 30-day countdown or a generic breach template. The OAIC provides a current response guide (OAIC — Responding to data breaches).
Automated decisions from 10 December 2026
For covered APP entities in scope, Privacy and Other Legislation Amendment Act provisions introduce additional privacy-policy transparency about certain substantially automated decisions from 10 December 2026. The organisation should identify decisions that use personal information and have a significant effect on people's rights or interests, then check the final statutory wording and OAIC guidance before the commencement date (OAIC — APP 1 guidance).
That is a transparency requirement with defined scope—not a statement that all analytics, workflow automation or AI is prohibited.
European Union: GDPR territorial scope is more specific than “EU visitors”
The GDPR can apply outside the EU, but an Australian website does not enter scope merely because it is technically accessible by someone in Europe.
Article 3 addresses processing:
- in the context of the activities of an establishment in the EU, regardless of where processing occurs; or
- by a controller or processor not established in the EU where the processing relates to offering goods or services to people in the EU, or monitoring their behaviour insofar as that behaviour takes place in the EU.
Whether an Australian organisation is offering goods or services to people in the EU requires a fact-specific assessment. Relevant indicators can include intentional targeting rather than mere accessibility. Behavioural monitoring also needs analysis of the actual processing and purpose. Consult the official text and obtain qualified advice (EUR-Lex — Regulation (EU) 2016/679, Article 3).
If the GDPR applies, determine the organisation's role and processing basis before copying a generic checklist. Obligations can include transparent information, rights handling, processor terms, security, records, breach assessment and international-transfer controls.
Neither a data-protection officer nor a data-protection impact assessment is universally mandatory for every business. Their requirements depend on defined conditions, including the nature, scale and risk of processing. The need for an EU representative also has conditions and exceptions. Treat each as a scoped legal question.

California: check the statutory business thresholds and the activity
The CCPA framework applies to a for-profit business doing business in California that meets statutory conditions. As summarised by the California Privacy Protection Agency, a business generally falls within scope if it meets at least one of the applicable thresholds, including:
- annual gross revenue above the indexed threshold—$26.625 million effective 1 January 2025;
- buying, selling or sharing the personal information of 100,000 or more California consumers or households; or
- deriving 50% or more of annual revenue from selling or sharing California consumers' personal information.
Associated entities and contractual roles can also affect the analysis. A Californian IP address or one customer does not itself establish that every CCPA obligation applies. Confirm current thresholds and definitions directly with the regulator or counsel (California Privacy Protection Agency — CCPA FAQs).
Where in scope, map collection, use, disclosure, sale and “sharing” for cross-context behavioural advertising. Consumer notices and rights, opt-out mechanisms, service-provider/contractor terms, sensitive-personal-information rules and reasonable security may apply according to the activity.
California's regulations continue to evolve. The CPPA's current regulations include phased requirements concerning risk assessments, cybersecurity audits and automated decisionmaking technology for entities meeting defined conditions and timelines. Do not assume every small online business has the same duties or implementation date (CPPA — Laws and regulations).
Scope comparison
| Question | Australia | EU GDPR | California CCPA framework |
|---|---|---|---|
| First scope check | Entity and activity; turnover plus statutory exceptions | Establishment, offering goods/services to people in the EU, or monitoring behaviour in the EU | For-profit business doing business in California plus statutory thresholds/relationships |
| People covered | “Individuals” under the Privacy Act and relevant APP activity | Data subjects in the territorial and material scope | California consumers/households under the statutory framework |
| Key role concepts | APP entity; contracted service provider; overseas recipient | Controller, processor, joint controller, representative | Business, service provider, contractor, third party |
| Breach question | NDB eligible-data-breach criteria for covered entities | Personal-data-breach duties and risk-based notification tests | CCPA private right/action and other California breach/security laws require separate analysis |
| Cross-border issue | APP 8 and accountability/exceptions where applicable | Chapter V transfer mechanisms and conditions | Disclosure/sale/sharing, contracts and other applicable transfer requirements |
This table is an orientation aid, not a legal crosswalk. Definitions and exemptions are not interchangeable.
Cross-border processing is more than a region selector
For a cloud, analytics, email or support service, ask:
- Which legal entity receives the information?
- In which countries can staff and subprocessors access it?
- Where are primary data, logs, backups and support records stored?
- Is the transfer a disclosure, outsourced handling, sale or sharing under the applicable framework?
- Which contract terms, transfer mechanisms, notices and risk assessments are required?
- Can the organisation meet deletion, access and export obligations across copies?
For APP entities, APP 8 can make an Australian entity accountable for some acts or practices of an overseas recipient, subject to the legislation's structure and exceptions (OAIC — APP 8). Australian hosting alone does not prove all access and subprocessors are domestic; overseas hosting is not automatically unlawful.

A defensible sequence for a small business
- Inventory entities, people, purposes, systems, recipients and retention.
- Determine Australian coverage and exceptions by entity and activity.
- Check whether the business intentionally offers goods or services to, or monitors, people in the EU.
- Check California business thresholds, relationships, sale and sharing definitions.
- Align notices and consent choices with the actual processing.
- Put appropriate contracts and access controls around providers.
- Establish rights, deletion, breach and evidence procedures.
- Review material changes, new markets and regulator updates.
Collect less information where possible. A smaller, well-understood dataset is generally easier to secure, explain, retain and delete than a broad “collect now, decide later” pool.
Where Ozlin can help
Ozlin can help map website and application data flows, document technical configurations, reduce unnecessary collection, review WordPress integrations and prepare an evidence pack for a client's legal or privacy adviser. Ozlin does not provide legal advice, determine that a client is compliant or replace qualified counsel.
See Privacy-aware web services or contact Ozlin to discuss a scoped technical review.
Related reading: WordPress privacy for Australian SMEs.
AI-assistance disclosure
AI tools assisted with source discovery, outlining and copyediting. A qualified human reviewer must verify every legal statement, threshold, source and publication decision before release. This article must not be used as a substitute for legal advice.

Primary sources checked
- OAIC — Small business
- OAIC — APP 1: open and transparent management
- OAIC — APP 8: cross-border disclosure
- OAIC — Responding to data breaches
- EUR-Lex — Regulation (EU) 2016/679
- California Privacy Protection Agency — CCPA FAQs
- California Privacy Protection Agency — Laws and regulations
Source access date: 29 August 2026.


Leave a Reply