Australia's Privacy Act Reforms and Microsoft 365: A Compliance Roadmap for Mid-Market Businesses
Australia's amended Privacy Act is not a future risk. Since December 2024, the new framework has been active. Penalties now reach $50 million for serious breaches, individuals can sue for privacy invasions without going through a regulator, and a deadline for automated decision-making transparency is approaching on 10 December 2026. If your business turns over more than $3 million a year and operates on Microsoft 365, your compliance posture is already partly determined by your tenant configuration. This whitepaper maps every key obligation to the specific Microsoft 365 tools that satisfy it.
What Actually Changed: The Privacy Act Reforms in Plain Language
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. It does not replace the existing Privacy Act 1988. Instead, it layers new obligations, new enforcement tools, and new penalties on top of the existing Australian Privacy Principles (APPs). The rollout has been staged across three dates, each bringing a distinct set of new requirements.
The first wave, which took effect on 11 December 2024, introduced the majority of changes that directly affect how businesses handle personal information. The obligation to implement "technical and organisational measures" to protect personal information (APP 11) was strengthened from a general security duty into a more specific requirement. Overseas disclosure pathways were restructured, requiring businesses to satisfy one of a list of prescribed conditions before transferring personal data to a recipient overseas. The OAIC received expanded public inquiry powers, and a new tiered civil penalty and infringement notice framework replaced the earlier single-tier structure.
The second wave came into force on 10 June 2025. On that date, Australia established a statutory tort for serious invasions of privacy. This is not a regulatory process. It is a private right of action: an individual who has suffered a serious invasion of their privacy can now take a business to court directly, without first going through the Office of the Australian Information Commissioner (OAIC). Courts can award damages for emotional distress and, in cases of intentional or reckless conduct, additional damages. For businesses that handle large volumes of personal information, this represents a genuinely new category of legal exposure that did not exist before June 2025.
The third wave is still ahead. On 10 December 2026, transparency obligations for automated decision-making take effect. We return to this deadline in detail later in this whitepaper, because it is the most immediately actionable item for businesses running Microsoft 365, Copilot, and Power Automate environments.
The New Penalty Structure
The reformed Act operates a three-tier penalty structure that replaces the single serious interference penalty. Tier 1, reserved for serious or repeated breaches, carries penalties for corporations of up to $50 million, or three times the benefit obtained from the breach, or 30 per cent of the company's adjusted turnover for the relevant period, whichever is greatest. Individuals face up to $2.5 million. Tier 2, which applies to any interference with privacy, carries up to $3.64 million for corporations and $728,000 for individuals. Tier 3, for specific listed breaches, carries up to $364,000 for corporations. Infringement notices for listed corporations are fixed at $72,800 per contravention.
The practical shift here is that the OAIC now has graduated tools. Previously, the regulator was reluctant to pursue maximum penalties for anything short of a catastrophic breach. The new structure gives the Commissioner proportionate options that make enforcement action more likely, not less, for mid-sized businesses that fall short on the basics.
The $3 Million Threshold: One Tipping Point, Two Obligations
The small business exemption under the Privacy Act remains in place. As of September 2026, businesses with annual turnover below $3 million are not covered by the Act, with limited exceptions. The August 2026 exposure draft released by the Attorney-General's Department does not propose removing this threshold. So for now, if your business is firmly below $3 million, the reformed Privacy Act does not apply to you directly.
However, there is a detail about this threshold that most growing businesses miss entirely: the Cyber Security Act 2024 uses the same $3 million turnover figure as its compliance trigger. Businesses with annual turnover exceeding $3 million are now required to report ransomware payments to the Australian Signals Directorate within 72 hours of making that payment. The report goes through the ASD's ReportCyber portal. Failure to report attracts a civil penalty of up to $99,000. SOCI-regulated entities must comply regardless of size.
The result is that crossing the $3 million revenue threshold creates two simultaneous legal obligations where none existed before: Privacy Act coverage and Cyber Security Act ransomware reporting. This is not a coincidence of drafting. It reflects a deliberate policy decision to align the two regimes at the same revenue point, creating a single compliance tipping point for Australian businesses.
For a business approaching that threshold, this has real planning implications. If you wait until the year your revenue crosses $3 million to begin building compliance infrastructure, you are already behind. Privacy Act compliance, in particular, requires foundational work: mapping where personal data lives, implementing technical controls, updating privacy notices, training staff, and establishing response procedures for access and correction requests. None of that happens overnight. Microsoft 365 configuration, specifically the deployment of Sensitivity Labels, DLP policies, retention schedules, and audit logging, typically takes several weeks even with expert support.
There are also businesses that are already covered by the Privacy Act regardless of size. If your organisation handles health information, operates as a contracted service provider to a government agency, is a reporting entity under the Anti-Money Laundering Act, or is incorporated under the Corporations Act, you are subject to the Privacy Act whether your turnover is $500,000 or $500 million. Many small professional services firms, allied health practices, financial advisers, and not-for-profits sit in this category without realising it.
Where Personal Data Lives in Your Microsoft 365 Tenant
Before you can protect personal information under the amended Privacy Act, you need to know where it is. For most businesses in 2026, the answer to that question runs through Microsoft 365. Email in Exchange Online contains customer contact details, employee records, financial information, and in many cases health or legal information shared in correspondence. SharePoint holds documents: contracts, HR files, client files, compliance records. OneDrive holds staff working documents, often including the kind of personal information that ends up in files because it is convenient rather than necessary. Teams conversations and meeting recordings increasingly contain personal information exchanged in chat and discussed verbally.
Copilot for Microsoft 365 adds a further layer. The AI assistant processes content from across your tenant: emails, documents, Teams conversations, calendar data. It uses this content to generate responses and summaries. If personal information is present in your tenant and accessible to a user, Copilot can surface it in response to a prompt. This is not a security flaw. It is the intended behaviour. But it means that any personal information that is over-shared or inadequately protected within your tenant becomes reachable through AI-assisted queries, raising both Privacy Act obligations and new questions about automated processing.
Data Residency: Where Does Microsoft Store Your Data?
Australia has two Microsoft Azure regions: Sydney (Australia East) and Melbourne (Australia Southeast). Microsoft committed to storing core customer data for Microsoft 365 services at rest in Australian datacentres for tenants that select Australia as their country or region when provisioning their tenant. For many services, including Exchange Online mailbox data and SharePoint documents, this commitment is met without any additional configuration.
However, not all Microsoft 365 data rests in Australia by default. Certain services, including some telemetry data, customer support interactions, and newer AI-powered features, may be processed in other Microsoft regions such as Singapore or the United States. This matters for Privacy Act compliance because APP 8, which governs cross-border disclosure of personal information, requires that a business either satisfy one of the prescribed conditions for overseas transfer or be liable for the overseas recipient's Privacy Act breaches as if they were its own.
Microsoft's Advanced Data Residency (ADR) add-on, available as a paid licence, expands the at-rest data residency commitment to cover additional workloads and services within the Australian region. For businesses that handle significant volumes of personal information and want to simplify their overseas disclosure analysis, ADR is the technical mechanism that reduces the scope of the problem. Without it, legal teams must assess which Microsoft 365 services process data offshore and whether the Microsoft Customer Agreement satisfies the applicable APP 8 conditions for each of those services. Microsoft's Product Terms and Data Processing Addendum set out these arrangements in detail and should form part of your privacy documentation.
Microsoft Purview: Your Privacy Act Compliance Engine
Microsoft Purview is the compliance and information protection suite within Microsoft 365. It is included at various levels across Microsoft 365 Business Premium, E3, and E5 licences. The tools within Purview map directly to the reformed Privacy Act obligations, though the mapping is not always obvious from the product names. Here is how each key tool addresses specific APP requirements.
Compliance Manager
Compliance Manager provides a scored assessment of your Microsoft 365 environment against a library of regulatory frameworks. It includes pre-built assessments for over 360 standards, including frameworks aligned to Australian requirements such as APRA CPS 234, ASD controls, and ISO 27001. For Privacy Act purposes, Compliance Manager helps you identify configuration gaps in your tenant, prioritise remediation actions, and generate evidence of compliance posture for audit purposes. It is the logical starting point for any business beginning a structured Privacy Act compliance programme. The score it produces is not a legal certification, but it gives compliance leads and external auditors a structured, evidence-backed view of the tenant's security controls.
Data Loss Prevention
DLP policies enforce rules that prevent personal information from being shared in ways that breach your policies or the APP. Microsoft 365 DLP includes built-in sensitive information types for Australian data: Tax File Numbers, Medicare card numbers, passport numbers, and bank account numbers. You can extend these with custom types for data specific to your business or industry. DLP policies can be applied across Exchange Online, SharePoint, OneDrive, Teams chats, and Copilot interactions. A policy might block an email containing a list of TFNs from being sent to an external recipient, alert a compliance officer when health information is posted in a Teams channel, or prevent a SharePoint document containing personal data from being shared externally. This directly supports the reformed APP 11 obligation to implement technical measures to protect personal information from misuse, interference, loss, and unauthorised access.
Sensitivity Labels
Sensitivity Labels classify information by category and apply protection controls to it automatically or on user selection. A label such as "Confidential: Personal Information" can encrypt a document, prevent it from being shared externally, add a watermark, and apply a retention policy, all in a single user action or automatic policy trigger. For Privacy Act compliance, Sensitivity Labels are the mechanism by which you demonstrate that personal information is identified, classified, and protected at the document and email level. A well-designed labelling taxonomy, at minimum Public, Internal, Confidential, and Restricted, gives staff a practical framework for handling personal information correctly, which is what the "organisational measures" limb of reformed APP 11 actually requires.
Retention Policies and Records Management
APP 11.2 requires businesses to take reasonable steps to destroy or de-identify personal information when it is no longer needed for the purpose for which it was collected. Retention policies in Microsoft Purview automate this obligation. You can set policies that delete emails older than a defined period, archive SharePoint content that has not been accessed in a specified number of years, or trigger a review workflow before deletion occurs. Records Management provides a more granular tool for business-critical records that must be retained for legal or regulatory reasons. Together, these tools let you demonstrate to the OAIC that you do not hold personal information indefinitely out of convenience, which is the kind of basic housekeeping that has attracted regulatory attention in breach investigations.
Audit Logs and eDiscovery
The audit log in Microsoft Purview records user and administrator activity across every Microsoft 365 service: who accessed what, when, from where, and what they did with it. This log is the primary evidence trail for demonstrating accountability under the Privacy Act. When the OAIC investigates a complaint or conducts an audit, the audit log is the first thing a forensic review examines. Enable unified audit logging for your entire tenant and retain audit records for at least 12 months (Microsoft 365 E5 or Audit (Premium) licences extend this to 10 years for specific record types).
eDiscovery and Content Search provide the tools to respond to individual access requests under APP 12. When an individual asks what personal information you hold about them, you have 30 days to respond. Running a Content Search across Exchange, SharePoint, OneDrive, and Teams for a specific individual's name, email address, or other identifiers is how you find that information at scale. The same tools support correction requests under APP 13 and assist with responding to legal proceedings under the new statutory tort.
Entra ID: Identity-Based Privacy Protection
Personal data is only as secure as the identities that can access it. Microsoft Entra ID (formerly Azure Active Directory) is the identity platform underpinning every Microsoft 365 tenant. Its configuration is among the highest-impact areas for Privacy Act compliance and often the most neglected in mid-market environments.
Conditional Access
Conditional Access policies define the conditions under which a user can authenticate and access Microsoft 365 resources. Policies can require multi-factor authentication for all access, block sign-ins from non-compliant devices, restrict access to specific geographic locations, require a managed device to access SharePoint, or elevate authentication requirements when a user's sign-in risk score is elevated. For Privacy Act purposes, Conditional Access is the technical mechanism that enforces the principle of least privilege: only users who meet the defined conditions can reach personal information stored in Microsoft 365. This is one of the clearest examples of a "technical measure" within the meaning of reformed APP 11.
Multi-Factor Authentication
MFA is not optional for businesses with Privacy Act obligations. Regulatory guidance from the OAIC, combined with the ACSC's Essential Eight framework (which requires phishing-resistant MFA at Maturity Level 2 and above), makes clear that an account protected only by a password does not meet the standard of "reasonable steps" required by APP 11. Entra ID Conditional Access can enforce MFA for every sign-in, or for higher-risk scenarios only, depending on your approach. Microsoft Authenticator, FIDO2 hardware keys, and certificate-based authentication are all available options. Passkeys, supported through Microsoft's authenticator apps and FIDO2 devices, represent the strongest available form of phishing-resistant MFA and are now the recommended standard for sensitive data access.
Privileged Identity Management
Privileged Identity Management (PIM) in Entra ID provides just-in-time access to high-privilege roles. Instead of a Global Administrator having permanent standing access to all data in your tenant, PIM requires them to activate their elevated role for a defined period, with approval if needed, and logs every activation. For Privacy Act compliance, PIM reduces the standing attack surface available to a compromised administrator account, and generates an evidence trail showing that privileged access to sensitive personal information was controlled and audited. It is the practical implementation of access control at the role level.
The December 2026 Countdown: Automated Decision-Making Transparency
The third wave of Privacy Act reforms takes effect on 10 December 2026. From that date, businesses must be transparent with individuals about significant decisions made about them using automated processes. This obligation is newer and less understood than the security and penalty changes, but for businesses running Microsoft 365 with Copilot and Power Automate, it has immediate practical consequences.
What Counts as Automated Decision-Making
The legislation captures decisions that are made about individuals using an automated process where personal information about that individual is a material factor. The definition is intentionally broad. In a Microsoft 365 environment, the following are likely to qualify: Power Automate workflows that route, escalate, or close support tickets based on customer data; Copilot-generated summaries or recommendations used by staff to make decisions about clients; recruitment workflows that use AI-assisted screening to shortlist or reject candidates; any automated system that denies or grants access to services based on personal information; and Conditional Access policies in Entra ID that deny a user's request to access systems based on their risk profile.
Not every automated process qualifies. The obligation applies to significant decisions: those that affect an individual's rights, interests, opportunities, or obligations in a meaningful way. Automated email sorting is unlikely to qualify. An automated workflow that determines whether a loan application proceeds to human review almost certainly does.
What You Need to Do Before December 2026
First, audit your automated workflows. In Microsoft 365, this means reviewing the Power Automate run history and looking at every flow that inputs personal information from your tenant data sources. Check which flows make or feed into decisions about identifiable individuals rather than simply moving or transforming data. For Copilot, review which departments are using it and in what decision-making contexts. Second, update your privacy notices. If any of your automated processes qualify, your privacy notice must disclose this, including the categories of personal information used and how individuals can request human review of an automated decision affecting them. Third, document your assessment. The obligation includes the right of individuals to request a review of an automated decision. You need a process to receive and respond to those requests.
Microsoft 365's audit logs, Power Automate run history, and Compliance Manager are the practical tools for conducting this audit. The work involved is not trivial for organisations with mature Power Automate deployments, but it is manageable with a structured approach and three months remaining.
The Cyber Security Act Overlap: Ransomware Reporting
The Cyber Security Act 2024 adds a separate layer of obligation that intersects with Privacy Act compliance in an important way. Businesses with annual turnover exceeding $3 million must now report ransomware payments to the Australian Signals Directorate (ASD) within 72 hours. The report is made through ASD's ReportCyber portal. Penalties for non-reporting reach $99,000.
The challenge identified by legal practitioners is the reporting overlap a single ransomware incident now triggers. A significant breach involving personal information can simultaneously require: Privacy Act notification to affected individuals and the OAIC (within a reasonable timeframe under NDB scheme requirements); Cyber Security Act ransomware payment reporting to ASD (within 72 hours of payment); APRA CPS 234 notification if you are a regulated financial services entity; SOCI Act reporting if you are an operator of critical infrastructure; and ASX continuous disclosure if you are a listed company. These overlapping deadlines need to be pre-mapped in your incident response plan before an incident occurs, not worked out in the immediate aftermath of an attack.
Microsoft Defender for Business and Microsoft Defender XDR (available in Microsoft 365 E5 and Business Premium licences) provide the detection, containment, and evidence-gathering capabilities that support ransomware response and reporting. Microsoft Sentinel, a cloud-native SIEM, provides centralised security event logging across your environment. The logs Sentinel captures become the evidentiary record for your incident report to ASD and your notification to affected individuals under the NDB scheme. Configuring these tools correctly before an incident is the difference between a structured, defensible response and a reactive scramble to reconstruct what happened.
12-Step Privacy Act Compliance Checklist for Microsoft 365
Use this checklist to assess your current Microsoft 365 Privacy Act compliance posture. Each item maps to a specific obligation under the reformed Privacy Act or an associated framework.
- Map personal information across your M365 tenant. Run Content Search in Microsoft Purview to identify where personal information, including sensitive categories such as health and financial data, is stored across Exchange, SharePoint, OneDrive, and Teams.
- Assess your data residency posture. Review your Microsoft 365 tenant data location settings and determine which services process data in Australian datacentres. If you handle significant volumes of personal information, evaluate whether the Advanced Data Residency (ADR) add-on is appropriate.
- Deploy Sensitivity Labels with a clear classification taxonomy. At minimum: Public, Internal, Confidential (Personal Information), and Restricted (Sensitive Personal Information). Apply auto-labelling policies for common personal data patterns.
- Configure Data Loss Prevention (DLP) policies. Enable built-in Australian sensitive information types (Tax File Number, Medicare, passport) and add custom types relevant to your business. Apply policies across Exchange, SharePoint, OneDrive, and Teams.
- Set retention policies that match your data retention schedule. Delete or archive personal information once the retention period expires. Document the schedule and the policy configuration as evidence of APP 11.2 compliance.
- Enable unified audit logging across all M365 workloads. This is switched off by default in some older tenants. Verify it is on and retain logs for at least 12 months. Consider Microsoft 365 Audit (Premium) for extended 10-year retention of high-value record types.
- Enforce MFA for all users via Entra ID Conditional Access. Prioritise phishing-resistant MFA (passkeys, FIDO2, certificate-based) for users with access to sensitive personal information or administrative roles.
- Implement Privileged Identity Management (PIM). Convert standing Global Administrator and other high-privilege roles to just-in-time activation with approval workflows and full audit logging.
- Run a Compliance Manager assessment. Use Microsoft Purview Compliance Manager to assess your tenant against relevant Australian frameworks. Address the highest-priority improvement actions first.
- Document your overseas data transfer posture. Review Microsoft's Product Terms and Data Processing Addendum to confirm which APP 8 conditions apply to each Microsoft 365 service that processes data outside Australia. Update your privacy documentation to reflect this.
- Audit Power Automate and Copilot for automated decision-making before December 2026. List every flow or AI-assisted process that inputs personal information and influences a decision about an identifiable individual. Update your privacy notice to disclose any that qualify.
- Test your incident response plan against overlapping reporting obligations. Confirm your plan addresses Privacy Act notification, Cyber Security Act 72-hour ransomware reporting, and any sector-specific requirements (APRA, SOCI, ASX) simultaneously. Verify that Microsoft Defender and Sentinel logs would support each report.
How All IT Helps
All IT is a Sydney-based managed IT services provider with more than a decade of experience supporting Australian businesses across financial services, professional services, strata, hospitality, and not-for-profit sectors. Our managed Microsoft 365 service covers the configuration, monitoring, and ongoing management of the Purview compliance tools, Entra ID policies, and Defender security controls described in this whitepaper. We do not sell lock-in contracts: our engagements are month-to-month, and our average client relationship runs more than 10 years. Our team answers chat enquiries within three minutes and email within 14 minutes on average, which matters when a compliance deadline or an incident is putting pressure on your timeline.
If you are unsure whether your Microsoft 365 tenant meets the reformed Privacy Act obligations, or if the December 2026 automated decision-making deadline has created an audit task you need support with, contact us for a no-obligation conversation. We will tell you plainly what needs to change and what you are already doing well.
Cyber Security Act 2024, Department of Home Affairs, Australian Government
Privacy Act 1988 guidance, Office of the Australian Information Commissioner (OAIC)
Microsoft Purview compliance solutions, Microsoft Learn
Essential Eight Maturity Model, Australian Signals Directorate
Data sovereignty and data residency in Australia: what Microsoft 365 customers need to know, Frontrow Technology
All IT Services is a Sydney-based managed IT provider supporting businesses across Australia in financial services, professional services, strata, hospitality, and not-for-profit sectors.
Frequently Asked Questions
Not Sure Where Your Microsoft 365 Tenant Stands?
We will assess your tenant's Privacy Act compliance posture and tell you plainly what needs to change. No lock-in, no jargon: just a clear picture of your risk and a practical path forward.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
