Black Shard

Privacy Act uplift in Australia.

A data map of what you hold and where it travels, a gap review against the Australian Privacy Principles, and the engineering work that closes the gaps.

Privacy Act work starts with what the organisation holds. Personal information accumulates through exports, integrations, backups, analytics tools, and development environments seeded from production, and most of those copies do not appear in the privacy policy.

Uplift work starts with the current environment: a data map derived from the systems, each of the thirteen Australian Privacy Principles identified as met, partial or missing against that map, gaps prioritised against your target and date, and evidence collected as the changes land.

What the Privacy Act asks of you

The Privacy Act 1988 sets thirteen Australian Privacy Principles that govern the whole life of personal information: whether you should have collected it, what you told people at the time, how you use and disclose it, how you secure it, whether it goes overseas, and what happens when somebody asks to see or correct it. Sitting alongside them is the Notifiable Data Breaches scheme, which sets what you must do when it goes wrong.

The principles are written as obligations on an organisation rather than as a control framework, and that is why they are easy to agree with and hard to evidence. APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Nothing in that sentence says whether your current access model qualifies. That judgement is made against what you hold, how sensitive it is, and what it would cost the people it belongs to if it leaked.

The obligations most often found unmet are the unglamorous ones. Retention and destruction under APP 11.2, because deleting data properly is harder than keeping it. Overseas disclosure under APP 8, because the third-party tools in a modern stack move data across borders. Access and correction under APP 12 and APP 13, because most systems were never built to answer the question of everything held about one person.

It starts with a data map

A data map records what personal information you hold, where each copy lives, how it got there, who and what can reach it, how long it stays, and where it leaves the organisation. It is derived from the systems, since interviews miss the copies.

The copies are the point. Production databases are the easy part. What surfaces is a reporting warehouse holding a full history that production purges, a shared drive with a decade of exports, a support tool retaining ticket attachments containing identity documents, an analytics pipeline that ingests more of the record than intended, a backup set that will restore data deleted last year, and a development environment seeded from a production snapshot nobody has refreshed or scrubbed. Every copy is located, the flows out of the organisation are named, including which processors are offshore, and retention as it runs is recorded next to retention as written, since the two usually differ.

The map is used in three separate situations. It scopes the gap review. It makes a breach assessment fast under a thirty-day clock. And it turns an access request from a project into a query.

The gap review against the Australian Privacy Principles

With the map in hand, each principle is assessed against what your systems do. Collection is checked for necessity and for whether the notice given at the time matches the use that followed. Use and disclosure is checked against the primary purpose and the exceptions relied on. Security is assessed as a control question: who can reach this data, is that enforced, is access logged, would you know afterwards.

Each gap comes back with the principle it sits under, what we observed in the system, and the specific change that closes it, written for the team who will make the change.

Where a judgement is legal rather than technical, we say so and stop. Black Shard provides engineering advice; legal advice stays with your lawyer. Whether a particular secondary use falls within an exception is your legal adviser's call, and we build the factual record that call rests on.

  • A gap review against all thirteen Australian Privacy Principles, assessed against the systems as they run
  • Each gap tied to the specific configuration, code or process change that closes it
  • A privacy policy and collection notices that describe what the systems do
  • A clear line where a question is legal, with the factual record your advisers need

Closing the gaps

The gaps that matter close in systems. Retention becomes a scheduled deletion job with proof that it ran, applied to the warehouse, the exports and the backups as well as the production table. Access becomes least privilege that is enforced and reviewed, with the review evidenced. Collection minimisation becomes fields removed from a form and columns dropped from an ingest.

Overseas disclosure under APP 8 becomes an inventory of processors with the jurisdictions named and the contractual position recorded, and, where it matters, a workload moved to an Australian region. The services that host our client data sit in Australian regions, and Aurii, clinical software Black Shard built and operates, carries live tenant health data on Azure in Australia behind row-level isolation and an audit trail.

Access and correction under APP 12 and APP 13 become a repeatable procedure with the queries written and tested, so a request is answered inside the statutory timeframe by someone following a runbook. The GRM LAW portal runs the same way: every state change lands in an append-only audit ledger, so who did what to a record can be answered from the system.

The Notifiable Data Breaches scheme, before you need it

The scheme requires you to assess a suspected eligible data breach expeditiously, and in any case within thirty days, and to notify the Information Commissioner and affected individuals where serious harm is likely and cannot be prevented through remedial action. Most of that window is spent establishing what was held in the affected system.

The data map answers what was held, the access model answers who could reach it, and the logging answers what was touched. Without those three, the assessment consumes the window and ends in an estimate.

Our boundary is the same here. We support the assessment by establishing the facts of what was accessed, who is affected, and what remediation has been done, and by producing the factual record the assessment and any notification rest on. Where the judgement is legal, your legal advisers make it from that record. If you are in an incident now, our breach page is the place to start.

What the reforms change

The Privacy and Other Legislation Amendment Act 2024 began a staged reform of a statute written before most of the systems it now governs existed. Some of it is already in force. A statutory tort for serious invasions of privacy commenced in June 2025, so individuals can bring an action directly in addition to complaining to the regulator. New criminal offences target doxxing. The Commissioner gained tiered civil penalty provisions, so conduct short of a serious or repeated interference is now actionable.

More is scheduled. Transparency obligations around automated decision-making require privacy policies to disclose where automated systems make or substantially inform decisions that significantly affect an individual's rights or interests, with the obligation commencing in December 2026. A Children's Online Privacy Code is being developed by the Commissioner on a comparable timeline.

Further tranches remain under consideration, including proposals affecting the small business exemption and a fair and reasonable test for collection and use. Those remain proposals. The work that prepares for any of them is the same: a current data map, minimised holdings, enforced access, and evidence of each.

What does a Privacy Act uplift cost?

Compliance work runs as a defined program with milestones, quoted before it starts. The drivers are the volume and sensitivity of what you hold, since sensitive information carries stricter obligations; system sprawl, meaning how many places hold a copy, including analytics, support tooling and non-production environments; third parties and offshore processing, which drive the APP 8 work; whether existing logging can answer who accessed what or has to be built first; and whether we execute the remediation or hand your team a plan to execute. The mapping stage is the most variable, because it is the stage that discovers how many copies exist.

Send a brief describing roughly what personal information the business handles and what prompted the question: a contract clause, an insurer, a regulator, or an incident. If it is an incident, say so, and we treat it as one.

Questions, answered

Does the Privacy Act apply to our business?
It applies to Australian Government agencies and to organisations with an annual turnover above three million dollars, plus categories that are covered regardless of turnover, including private health service providers and businesses that trade in personal information. The small business exemption has been under review for some time, and building toward compliance is the safer commercial position even where the exemption currently applies. Whether a specific entity is covered is a legal question and your adviser's call.
What is the difference between a privacy policy and a collection notice?
The policy is the standing document describing how the organisation handles personal information generally. A collection notice is what you tell someone at the point you collect their information: what you are collecting, why, and who you may disclose it to. Organisations commonly have the first and not the second, and the gap review records it.
How long do we have to respond to a data breach?
You must assess a suspected eligible data breach expeditiously, and in any case within thirty days, then notify the Commissioner and affected individuals where serious harm is likely and remedial action cannot prevent it. The thirty days is an outer limit. Most of that window is spent establishing what was held in the affected system, which is what a data map answers.
Do you give legal advice on privacy?
No. Black Shard provides engineering. We map what you hold, review it against the Australian Privacy Principles, close the technical gaps, and build the factual record. Where the question is legal, such as whether a secondary use falls within an exception or whether serious harm is likely, your legal advisers make the call from that record.
Can our data stay in Australia?
Usually yes, and it is often simpler than expected once the processors are inventoried. APP 8 does not prohibit overseas disclosure; it makes you accountable for it. The uplift names every processor and jurisdiction so the decision is deliberate. The services hosting our client data sit in Australian regions.
We already have a privacy policy. Is that enough?
A policy is a description. The obligations are about what the systems do. The common failure is a policy that promises retention limits, access controls and correction rights that no system implements: a documented statement contradicted by the organisation's own configuration.
How does this relate to the Essential Eight or SMB1001?
They overlap where security is concerned. APP 11 asks for reasonable steps to protect personal information, and an Essential Eight uplift or an SMB1001 tier produces much of the evidence that reasonable steps were taken. Privacy uplift goes further in the directions those frameworks do not cover: collection, notice, retention, overseas disclosure, and individual access rights.
Do you work with organisations outside Brisbane?
Yes. An Australian firm, head office in Brisbane, delivering Australia-wide. Mapping and gap review run against your cloud tenancies, databases, and third-party tooling, so location rarely changes the shape of the engagement.

Tell us what personal information the business handles.

Brisbane head office. Work delivered across Australia.

Open a brief[email protected]