Built By Base Code
Built By Base Code
Secure. Automate. Scale.
Self-audit
Privacy Act 1988 · small business
builtbybasecode.com/audit/privacy

Is your business Privacy Act ready?

Eighteen yes/no questions covering the Privacy Act 1988, the Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme. Ten minutes to complete. A common myth is that small business is exempt: the $3 million turnover threshold is narrower than most owners assume. Score at the bottom, interpretation and next steps on the reverse.

How to score. Tick Yes (2 pts) if you are confident this is in place and could evidence it. Tick Not sure (1 pt) if you think so but haven't checked, or if only part of the business meets the standard. Tick No (0 pts) if you know this is not currently the case.

01Know your obligations 3 questions

1.1
You know whether your business is covered by the Privacy Act 1988. If under $3M turnover, you have checked whether you fall into any of the specific inclusions (health services, contracted service providers, credit reporting, trading in personal information).
1.2
You have read (or have a summary of) the 13 Australian Privacy Principles and can name the ones that apply to your business (typically: collection, use and disclosure, quality, security, access, correction).
1.3
You have a written, public-facing privacy policy that reflects what your business actually does with personal information, and it has been reviewed in the last 12 months.

02Data map & consent 4 questions

2.1
You know where customer personal information lives across your systems (CRM, spreadsheets, email attachments, forms, third-party services). You could produce that inventory on request.
2.2
Every form, sign-up, and booking your business uses tells the customer what information you collect and why, in plain language, at the point of collection.
2.3
You only use collected personal information for the purposes stated at collection (or a related and reasonably expected secondary purpose). Marketing email lists were built with clear consent, not scraped or assumed.
2.4
Sensitive information (health, financial, biometric) is collected only with explicit consent, and only where genuinely required for the service.

03Access, retention, disposal 3 questions

3.1
If a customer asked for a copy of the personal information you hold about them, you could produce it in a reasonable format within 30 days.
3.2
You have a written retention schedule (how long you keep each category of customer data) and a defined trigger to delete data once its business purpose ends.
3.3
Old customer data is disposed of securely (shredded, cryptographically wiped, permanently deleted). Old laptops, USB drives, and paper files are not stored indefinitely in an office cupboard.
Built By Base Code
Built By Base Code
Secure. Automate. Scale.
Self-audit · continued
Privacy Act 1988 · small business
builtbybasecode.com/audit/privacy

04Third parties & offshore 3 questions

4.1
You have a list of every third party that has access to your customer data (accountant, CRM vendor, email marketing tool, hosting, booking platform, contractors).
4.2
Every third party that stores or processes personal information has a written agreement, terms of service, or DPA in place that commits them to appropriate privacy handling.
4.3
You know whether any customer data leaves Australia (US-based SaaS, cloud storage regions). If so, you have taken reasonable steps under APP 8 to ensure it stays protected.

05Breach preparedness 3 questions

5.1
You know that the Notifiable Data Breaches scheme requires an assessment of a suspected eligible data breach within 30 days, and notification to affected individuals and the OAIC where the breach is likely to cause serious harm.
5.2
You have a written data breach response plan (even a single page) that names the person responsible, the containment steps, and the notification template.
5.3
You maintain a log of security incidents (attempted and actual) so a pattern is visible before it becomes a notifiable breach.

06Roles & training 2 questions

6.1
One person in the business is nominated as the point of contact for privacy questions, access requests, and breach coordination. Their contact details are on the privacy policy.
6.2
Your team has had basic privacy training in the last 12 months. They can recognise what counts as personal information and know who to escalate a request or suspected breach to.
Built By Base Code
Built By Base Code
Secure. Automate. Scale.
Score & next steps
Privacy Act Self-Audit
builtbybasecode.com/audit/privacy
Add your ticks · Yes = 2, Not sure = 1, No = 0 Maximum possible: 36. Write your total in the box.
/ 36

What your score means

Compliant and evidenced 28 to 36

Your privacy posture is where it should be. You have the policy, the data map, the retention schedule, and a breach plan. The value of a review at this level is confirming the plan actually holds under pressure and keeping documentation current as your systems change.

Policy exists, evidence is thin 15 to 27

You have some of the moving parts, likely a privacy policy and a rough sense of where data lives, but the connective tissue is missing. In a real breach or an OAIC enquiry, the gaps show up quickly. A short project can turn a scattered set of documents into a coherent, evidenced program.

Exposed to compliance risk 0 to 14

You are handling personal information without the safeguards the Privacy Act expects. This is not a judgement, it is a common starting point for a small business that grew organically. The good news is that the highest-impact items (a data map, a retention policy, a breach plan) are inexpensive to establish and dramatically reduce your exposure.

Wherever you scored, do these three things this month

  1. List every place customer data lives. One column: system name. Second column: type of data. Third column: who has access. A spreadsheet is fine. This one page opens every other conversation.
  2. Read your privacy policy end to end. Circle anything that no longer matches how the business actually operates. That is the shortlist for your next update.
  3. Write a one-page breach response plan. Who assesses. Who notifies. Who talks to media. What the notification email looks like. Save it somewhere you can access if your main email is compromised.
Need a partner for the compliance program?

Book a free 30-minute discovery call.

Thirty minutes to walk through your current privacy posture and what the Privacy Act actually asks of you. No obligation. Fixed-price scope within 5 business days if a project fits.

Book at builtbybasecode.com/contact Or email services@builtbybasecode.com · We reply within one business day.
About Built By Base Code. We are a local IT consultancy based in Ballina, serving small businesses across Ballina, Byron, Lismore, Casino, and Tweed. We build cybersecurity, process automation, and cloud infrastructure. Every project is quoted at a fixed price in writing, and you own the end result outright, with documentation, credentials, and training at handover. No lock-in contracts. Privacy compliance work is scoped as a small, fixed project, not an ongoing retainer.