Back to all postsSecurity

Privacy Act Security Checklist for Migration Practices

Under $3 million turnover, your practice is probably exempt from the Australian Privacy Principles. Four things make that exemption far less comforting than the headline suggests.

LodgeHQ

Compliance Team

9 September 20268 min read

Here is the fact most privacy advice written for migration practices skips: if your practice turns over less than $3 million a year, the Australian Privacy Principles almost certainly do not apply to it.

Section 6D of the Privacy Act 1988 defines a small business as one whose annual turnover for the previous financial year was $3,000,000 or less, and a small business operator as an entity carrying on only small businesses. Small business operators are not APP entities. No APP 11 security obligation, no APP 1 privacy policy requirement, and no notifiable data breach scheme.

That is worth knowing precisely, because four things make the exemption far less comforting than it sounds — and because the file you hold is one of the most sensitive a small business in Australia is ever likely to hold.

Four reasons the exemption is thinner than it looks

It is easier to lose than to keep

Turnover is not profit, and the test looks backwards: a year above $3 million puts you outside the exemption for the following year. Section 6D(4)(a) then makes the loss sticky — an entity is not a small business operator if it carries on a business that has had turnover above the threshold in any financial year ending after it started that business.

Section 6D(9) adds a structural trap: a body corporate is not a small business operator if it is related to a body corporate carrying on a business that is not a small business. A small practice inside a larger group does not get the exemption because of its own size.

Some ordinary arrangements disqualify you

Section 6D(4) lists activities that take an entity outside the exemption regardless of turnover. Two are worth reading against how migration practices actually operate:

  • disclosing personal information about an individual to anyone else for a benefit, service or advantage
  • providing a benefit, service or advantage to collect personal information about an individual from someone else

Referral arrangements sit uncomfortably close to both. Sending a client's details to an education agent, a lawyer, or a finance broker in exchange for a commission is a disclosure for a benefit on its face.

Subsections 6D(7) and (8) provide the answer that usually saves you: neither limb applies where the disclosure or collection is with the individual's consent, or required or authorised by legislation. Which turns your exemption into something that depends on your consent practices being real rather than assumed — and that is a much less restful position than "we are under the threshold".

The statutory tort has no small business exemption

Schedule 2 of the Privacy Act creates a cause of action in tort where a defendant invaded the plaintiff's privacy by intruding on their seclusion or misusing information relating to them, where there was a reasonable expectation of privacy, the invasion was intentional or reckless, it was serious, and the public interest in privacy outweighed any countervailing interest.

It is available against "another person". Nothing in it turns on turnover. And the invasion is actionable without proof of damage.

In deciding whether there was a reasonable expectation of privacy, a court may consider the nature of the information — expressly including whether it related to intimate or family matters, health or medical matters, or financial matters. That describes a migration file almost exactly.

The Code applies either way

Section 35 of the Code of Conduct prohibits disclosing personal information about a client or former client, or their affairs, to a third person without written consent, except as required by law. Section 53 requires documents belonging or relating to a client or former client, held by you or anyone in your business, to be kept securely.

Neither has a turnover threshold. For most practices, the Code — not the Privacy Act — is the instrument that actually governs how client information is handled, which is a good reason to build the control set around it. Our Code compliance checklist covers the surrounding obligations.

You are holding sensitive information by any definition

The Privacy Act's definition of sensitive information covers racial or ethnic origin, political opinions, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, and criminal record — plus health information, genetic information and biometric information.

Now list what a migration matter routinely contains: a passport showing nationality, police certificates from every country of residence, medical examination results, statutory declarations about a relationship, evidence of religious ceremonies, and in protection matters, an account of persecution.

There is no realistic version of a migration file that is not saturated with sensitive information. Whether the APPs technically bind you is a separate question from whether the data warrants that level of care.

A control set worth running regardless

The ASD's Essential Eight is the sensible baseline. Its eight mitigation strategies are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.

For a small practice, the ASD's small business cyber security guide is the more approachable entry point, and three of the eight carry most of the value: multi-factor authentication everywhere it is available, keeping software patched, and backups you have actually restored from.

Layered on top, four practice-specific controls matter more here than in a general business:

  • Collect less. The Code requires you to verify identity and maintain a file; it does not require you to keep every document a client ever sent. A copy of a passport you did not need is pure liability.
  • Separate the client's originals from your record. They are governed by different duties, as our guide to file retention sets out.
  • Know where the data actually lives. Cloud storage, personal devices, an offshore team's access, and every messaging app anyone uses with clients.
  • Dispose deliberately. Indefinite retention is not caution. It is exposure on your oldest and least protected data.

The exemption test

Before assuming you are exempt, confirm all of these:

  • Was turnover $3,000,000 or less last financial year, and in every year since the business started?
  • Is the practice related to a body corporate that is not a small business?
  • Does the practice receive any benefit for referring or disclosing client information — and if so, is there real, recorded consent?
  • Does it provide any benefit to obtain client information from a third party?
  • Is it a contracted service provider under a Commonwealth contract?

Any yes on the last four, or a no on the first, and you should assume the APPs apply.

The controls test

  • Is MFA on email, document storage, case management and ImmiAccount?
  • Does anyone share a login?
  • When did you last restore from a backup rather than confirm one ran?
  • Can you list every place a client's passport scan currently exists?
  • Is there a disposal step at the end of the retention schedule, and a record of it?
  • Would you know within a day if a mailbox were accessed by someone else?

Opting in, and why a client might ask

Section 6EA lets a small business operator choose to be treated as an organisation, bringing itself within the APPs voluntarily.

That is worth knowing because corporate clients increasingly ask. A sponsoring employer conducting vendor due diligence, a university, or a large employer's procurement team may require Privacy Act coverage as a condition of engagement, and "we are exempt" is an unpersuasive answer in that conversation. Opting in is a decision with real consequences and should be taken with advice — but it is a lever, and most practices do not know it exists.

Where a system helps

Privacy exposure in a small practice is rarely a failure of policy. It is sprawl: client documents in an email archive, a shared drive, two personal phones and a messaging thread, with no single place that knows what exists.

Consolidation is the control that makes every other control possible. You cannot secure, minimise, retain or destroy what you cannot enumerate. That is the practical case for moving off email and shared drives, which our guide to modern practice software covers in more detail.

LodgeHQ keeps client documents, correspondence and access in one auditable place. Start a free trial and start by finding out how many copies of one client's passport your practice is currently holding.

Verify before you rely on it

Privacy law is under active reform and the small business exemption has been the subject of review, so the position described here should be checked against the current Act rather than assumed. Read the Privacy Act directly, and the OAIC's data breach guidance for the notification scheme.

This is general information for migration practices, not legal advice. Whether the APPs apply to your practice, and whether a particular arrangement disqualifies you, are questions to put to a lawyer with your actual structure in front of them.

Tags:Privacy ActData SecurityComplianceRisk ManagementClient Data