Privacy compliance · Melbourne, Australia
The obligation started on 1 July. Most businesses it applies to still don't know.
AML/CTF Tranche 2 made real estate agencies, conveyancers, accountants, solicitors, buyer's agents and property developers reporting entities. With it came something quieter: the Privacy Act small business exemption stopped covering the personal information handled in that work — whatever your turnover.
ComplyHub builds your privacy program in four weeks, for a fixed fee, without a law firm's hourly rate.
No obligation. We'll tell you if you don't need us.
Where the law actually stands
Three dates matter. Only one has already passed.
We sell what is in force. Plenty of people will tell you every small business is about to fall under the Privacy Act — that isn't law yet, and saying otherwise is how you end up buying something you don't need. Here is what is in force, what is scheduled, and what is still only proposed.
General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.
Who this applies to
Six professions, one commencement date.
The obligation attaches to the service you provide, not to the size of your business. Find the one that describes you.
Real estate agencies & property managers
Tenancy applications, 100-point checks and every unsuccessful applicant still sitting in the CRM.
Conveyancers & settlement agents
Certified identity documents and settlement files that nobody has decided when to destroy.
Accountants & bookkeepers
Tax file numbers, bank feeds, payroll and director identity documents — mostly moving by email.
Solicitors & small law firms
You can read the legislation. The implementation is the project nobody has time for.
Buyer's agents & developers
Small teams, full borrowing capacity on file, and the same obligations as a national franchise.
Finance & mortgage brokers
A long disclosure chain, and December's automated decision-making rules land right on your software.
What we do
Four ways to work with us.
Start small if you want to see how we work. Start with the foundations if you already know where this is heading.
Privacy health check
$750 + GST, one-off
A half day of our time and a written answer to one question: how exposed are you?
- Review of your current policy, forms and file handling
- Written findings memo against the Australian Privacy Principles
- Prioritised list of what to fix first
- Credited in full against foundations if you proceed within 60 days
Privacy foundations
$4,500 – $7,500 + GST, one-off
A complete privacy program, built and handed over in four weeks.
- Data map of every place personal information lives
- Gap assessment against the 13 Australian Privacy Principles
- Privacy policy and collection notices written for your practice
- Notifiable data breach response plan
- 60-minute staff training session
Most clients choose this
ComplyHub annual
from $10,500 + GST, per year
Foundations plus twelve months of maintenance, bundled.
- Everything in Privacy foundations
- Quarterly compliance review
- Policies and registers updated as the law changes
- Breach response line — call us first, not your lawyer
- Annual staff training refresher
Ongoing privacy officer
$400 – $800 + GST, per month
Maintenance only, for businesses whose program is already built.
- Quarterly reviews and register upkeep
- Regulatory change monitoring
- Breach response line
- If someone else built your program, we'll assess it first ($1,500)
How we work
Three things we'd want to know if we were buying this.
We don't sell the proposal
The blanket removal of the small business exemption is not law and may not be for some time. We'll never quote you a deadline that doesn't exist. Everything we sell is tied to an obligation already in force, and the ledger above is on every page for exactly that reason.
Fixed fee, fixed scope
You get a scope and a number before we start, and the number doesn't move unless you ask for something outside it. No hourly billing, no six-minute units, no invoice for the phone call.
Onshore, and we'll show you
Our work is delivered from Melbourne and your information stays in Australia. We can name every system that touches it — which is the same question we're about to ask you about your own business.
We are not a law firm. We don't provide legal advice, and our engagement letter says so plainly. What we do is implementation: mapping data, writing operational documents, training staff and maintaining registers. Where a question is genuinely one of legal interpretation, we tell you and refer you to someone who can answer it.
Find out where you stand.
Twenty minutes on the phone. We'll walk through what you collect and where it goes, and tell you plainly whether you have a problem. If you don't, we'll say so — that call has happened before and it will happen again.