Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Protecting Beneficiary Data: What Australian NFPs Must Know Under the Privacy Act

The Privacy Act 1988 (Cth) applies to more Australian charities and not-for-profits than most realise. For those that handle health information, financial records, or other sensitive personal details about the people they serve, the obligations apply regardless of organisation size. The consequences of getting this wrong have increased significantly under recent reforms, with penalties now reaching up to $50 million for serious or repeated breaches.

Understanding what data you hold, who it applies to, and what the law requires is not just a compliance exercise. It is a core governance responsibility, and one that the ACNC expects NFP boards and leadership to address.

Does the Privacy Act Apply to Your NFP?

The general rule is that the Privacy Act applies to organisations with annual turnover above $3 million. Many smaller charities assume this exempts them entirely. That assumption is often wrong.

The small business exemption does not apply if your NFP:

  • Collects or holds health information (including mental health, disability, or medical conditions)
  • Trades in personal information, for example selling donor or beneficiary lists
  • Is a contracted service provider to a Federal Government agency
  • Is related to a body corporate that is covered by the Act

For most NFPs working in community services, health support, disability care, family services, or crisis housing, these categories apply directly. Even if your turnover sits below $3 million, there is a strong likelihood your data practices are covered.

What Counts as Sensitive Beneficiary Data?

The Privacy Act draws a distinction between personal information and sensitive information. Sensitive information carries stricter obligations, and most NFPs hold it. Sensitive information includes:

  • Health and medical records
  • Information about a person's disability or mental health
  • Racial or ethnic origin
  • Religious beliefs or affiliation
  • Sexual orientation or gender identity
  • Financial hardship information collected as part of service eligibility assessments
  • Criminal history records held in connection with support programs

In practice, this covers intake forms, case notes, support plans, referral records, and client databases that NFPs use every day. The way this data is collected, stored, accessed, and disposed of is governed by the 13 Australian Privacy Principles (APPs) under the Act.

Key Obligations Under the Privacy Act

The Australian Privacy Principles set out what covered organisations must do. The most relevant for NFPs working with beneficiary data are:

  • Collection notice (APP 5): Beneficiaries must be told why their data is being collected, who will have access to it, and whether it will be disclosed to third parties, at or before the time of collection.
  • Consent for sensitive information (APP 3): Sensitive information can only be collected with the individual's consent, or where a specific exception applies such as a legal obligation.
  • Secure storage and access controls (APP 11): Personal information must be protected from misuse, interference, loss, and unauthorised access. This includes appropriate IT security controls, not just physical file security. See our cybersecurity services for not-for-profits.
  • Data breach notification (Part IIIC): If a breach is likely to cause serious harm to an individual, it must be notified to the OAIC and the affected individuals as quickly as practicable. Having a tested backup and recovery process in place before a breach occurs is essential.
  • Access and correction rights (APPs 12-13): Individuals can request access to information you hold about them, and ask for it to be corrected if it is inaccurate.

What a Breach Means for an NFP

The Privacy and Other Legislation Amendment Act 2024 significantly increased penalties for serious or repeated privacy breaches: up to $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover, whichever is greater.

Regulatory action from the OAIC can include enforceable undertakings, public findings, and civil penalties.

Beyond regulatory penalties, a breach involving beneficiary data carries a distinct reputational risk. The people who trust an NFP with their most sensitive personal information, including people experiencing homelessness, family violence, health challenges, or financial hardship, have few avenues to protect themselves if that trust is broken. The ACNC expects boards to take this seriously as a governance matter, regardless of whether the organisation is legally obligated under the Privacy Act.

Protecting Beneficiary Data in Practice

Strong data protection for NFPs is built on three foundations: policy, access controls, and the right IT systems.

On the policy side: a data retention and disposal policy, a privacy policy accessible to beneficiaries, a documented breach response plan, and regular privacy awareness training for staff and volunteers.

On the access control side: role-based access to beneficiary records, multi-factor authentication on all systems holding sensitive data, and regular reviews of who has access to what. The ACSC Essential Eight provides a practical baseline: patching operating systems, restricting admin privileges, and enabling MFA are all directly relevant here.

On the IT systems side: cloud platforms with Australian data residency, secure backups tested for recovery, and endpoint protection on all devices that access client records. For many NFPs, these controls are within reach, but only if the IT infrastructure supporting them is properly configured and maintained.

All IT works with not-for-profit organisations across Australia to put these controls in place without overcomplicating it. If you are unsure where your data protection sits right now, our NFP IT team can give you a straight assessment.


Frequently Asked Questions

The general exemption applies to organisations with annual turnover under $3 million, but it does not apply if your NFP collects health information, provides services under a government contract, or trades in personal information. Most NFPs working in health, disability, family services, or crisis support are covered regardless of size.
Sensitive information includes health and medical records, mental health information, disability status, racial or ethnic origin, religious beliefs, sexual orientation, and financial hardship details. NFP intake forms and case notes almost always contain one or more of these categories. Sensitive information requires explicit consent to collect and stricter protections than general personal information.
If a data breach is likely to cause serious harm to an affected individual, the NFP must notify both the OAIC and the individuals affected as soon as practicable under the Notifiable Data Breaches (NDB) scheme. A documented breach response plan and tested backup and recovery process are the two most important controls to have in place before a breach occurs.
The most directly relevant controls are: multi-factor authentication on all systems holding beneficiary data, role-based access so staff only see records relevant to their role, encrypted backups with tested recovery, and endpoint protection on all devices. The ACSC Essential Eight provides a practical baseline that does not require enterprise-level spending to implement.

Written by Tom Buckley, All IT Services. All IT is a Sydney-based managed IT provider supporting not-for-profit organisations, hospitality groups, and financial services businesses across Australia.

Not Sure Where Your Data Protection Stands?

All IT works with not-for-profit organisations across Australia. If you would like a straight assessment of where your data protection sits right now, get in touch. Monthly contracts, no lock-in.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →
Posted in Not-For-Profits