Corporate & Commercial

Contracts, structures and governance for businesses that need the paperwork to hold when something goes wrong.

Mergers & Acquisitions

Buying or selling a business, from the term sheet and due diligence through to completion and the restraints that follow.

Litigation & Dispute Resolution

Commercial disputes in the NSW, ACT and Federal courts, resolved early where that is possible and run properly where it is not.

Government and Defence

Supplying government and the defence industry.

Technology and Software

Your product scales digitally. Your contracts have to scale with it.

Financial Services

A regulated business, on solid legal footing.

Legal Administration Assistant, Canberra

Canberra office, full time, on site.

Wahlstation for German Referendare

Sydney or Canberra, open all year.

Articles

Where the law changed, what it now requires, and what a business has to do about it.

Guides

One question worked through end to end, with the provisions and the decisions it rests on.

Case notes

What a judgment decided, and what follows from it for anyone in the same position.

Germany

A German desk for businesses moving between Australia and the German-speaking market.

Singapore

Singapore law where it governs the contract, and the arbitral seat that carries much of the region’s work.

Vietnam

Market entry, supply arrangements and dispute resolution for Vietnam.

Commercial Law Privacy and Data Protection Corporate Governance

European Privacy Law: When the GDPR Reaches an Australian Business

European privacy law reaches an Australian business through what it does, not where it sits. A company with no European office, no EU entity and no European staff is inside the GDPR if it offers goods or services to people in the EU or monitors their behaviour there. The turnover threshold that puts most small Australian businesses outside the Privacy Act has no equivalent in European law.

The European Central Bank tower above the Main in Frankfurt at night
Above. The European Central Bank, Frankfurt am Main. European privacy law reaches an Australian business through what it does, not through where it sits.

In short

The GDPR applies to an Australian business that offers goods or services to people in the EU or monitors their behaviour there, whatever its size and wherever it sits. The Privacy Act's small business exemption has no European equivalent.

  • Payment is irrelevant, and monitoring is a separate trigger from selling.
  • A representative inside the Union must be appointed in writing.
  • Australia is not an adequate country, so transfers need article 46 safeguards.

The test is what you do, not where you sit

European privacy law reaches an Australian business through conduct, not through presence. There is no office test, no subsidiary test and no server test. Article 3(2) of the General Data Protection Regulation fixes the reach by reference to two activities:

This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

Two things follow that are easy to miss. Payment is irrelevant. A free trial, a newsletter, a downloadable white paper and a support portal are all an offering of services. And monitoring is a separate limb, so a business that sells nothing into Europe still engages the Regulation if it tracks European visitors. Analytics, advertising pixels, session recording and cookie-based personalisation will ordinarily amount to monitoring, because what matters is behavioural analysis or profiling and the purpose behind it, not the mere fact that data is collected online.

What the Regulation does not catch is the accidental European. A customer in Munich who finds an Australian site written in English, priced in Australian dollars, shipping only domestically, is not evidence that the business offers goods or services in the Union. The question is whether the business envisaged offering into the Union, and the ordinary indicators are the ones you would expect: a European language, a European currency, European delivery, a European domain, European contact details, or marketing aimed at a member state.

The threshold that does not exist in Europe

The exemption that puts most small Australian businesses outside the Privacy Act has no European equivalent. The Act binds APP entities, meaning Australian government agencies and private organisations other than exempt small businesses. Section 6D of the Privacy Act 1988 (Cth) still turns on turnover:

A business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less.

Privacy Act 1988 (Cth) s 6D(1).

The exemption is also narrower than the headline figure suggests. It does not apply to a business that provides a health service and holds health information, that trades in personal information for a benefit, that is a Commonwealth contracted service provider or a credit reporting body, and under section 6D(9) it does not apply at all to a small company related to a body corporate that is not itself small. Groups are the ordinary case among the businesses reading this.

Nothing in the GDPR corresponds to that. Size affects some obligations at the margin, such as the record-keeping duty in article 30 and the exemption from appointing a representative in article 27(2), but it never affects whether the Regulation applies at all.

So the position that surprises founders is entirely ordinary: an Australian company with turnover under three million dollars can sit outside the Privacy Act and squarely inside the GDPR at the same time. The regime with the smaller penalties does not apply, and the regime with the larger ones does.

What triggers each privacy regime The Privacy Act applies to APP entities and exempts small businesses under three million dollars turnover. The GDPR applies on conduct, offering goods or services to people in the Union or monitoring their behaviour, with no turnover threshold at all. PRIVACY ACT 1988 (CTH) GDPR Who it binds APP entities Who it binds Controllers and processors Turnover threshold Exempt at or under $3,000,000 No threshold Size is irrelevant Reach Australian link Reach Conduct aimed at the Union No equivalent Representative in the Union
Select a testThe two regimes are triggered by different things, so an Australian business can be outside one and inside the other.
Figure 1. The two regimes are not a stricter and a looser version of the same rule. They are triggered by different facts.
Table 1. The two regimes on the points that decide whether you are caught.
QuestionPrivacy Act 1988 (Cth)GDPR
What triggers itBeing an APP entityOffering goods or services into the Union, or monitoring behaviour there
Turnover thresholdExempt at or under $3,000,000None
Local presence neededAustralian linkNo
Representative requiredNo equivalentYes, in a member state, unless article 27(2) applies
Sending data outAPP 8, accountability for the recipientAdequacy, or article 46 safeguards
Maximum corporate penaltyGreatest of $50m, 3x benefit, or 30% of adjusted turnover€20m or 4% of worldwide annual turnover, whichever is higher

The obligation most Australian businesses have never heard of

An Australian business caught by article 3(2) must appoint a representative inside the Union, in writing. It is probably the most easily missed GDPR obligation for an Australian company, because it has no analogue in Australian law and no natural trigger in an Australian compliance calendar.

Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.

GDPR art 27(1).

The representative must be established in a member state where the relevant individuals are, must be mandated to be addressed, in addition to or instead of the business itself, by supervisory authorities and by individuals on all issues related to the processing, and must be named where those individuals can find them, which in practice means the privacy notice. Appointing one does not shift liability: article 27(5) preserves every legal action that could be brought against the business itself.

The United Kingdom is a separate exercise. Since Brexit an Australian business targeting the UK is caught by the UK GDPR rather than the EU Regulation, and an EU representative does not answer it: a business serving both markets needs one in each.

There is an exemption, and it is narrower than it first reads. Article 27(2) removes the obligation only where the processing is occasional, does not involve special category data (health, biometrics, race, beliefs, sexual orientation and the like) or criminal data on a large scale, and is unlikely to result in a risk to individuals. A business running continuous analytics on European visitors, or holding a European customer list, is not processing occasionally.

Data coming the other way: Australia is not adequate

Australia has never been the subject of a European adequacy decision, so personal data cannot move from the Union to Australia on that basis. The European Commission's adequacy list runs to Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for organisations in the Data Privacy Framework, Uruguay and the European Patent Organisation. New Zealand is on it. Australia is not.

Absent adequacy, article 46 requires appropriate safeguards, and the ordinary instrument is the standard contractual clauses adopted by the Commission in 2021. Three practical consequences follow for an Australian business receiving European data.

  • The clauses are a Commission decision, so their operative text is not negotiable. What is negotiable, and what matters commercially, is the annexes: the description of the processing, the technical and organisational measures, and the sub-processor list.
  • Signing is not the end of it. The exporter must assess whether the law of the destination country undermines the clauses in practice, and document that assessment.
  • There is a gap that catches exactly the reader this article is written for. The 2021 clauses were drafted for importers outside the EEA whose processing is not itself subject to the GDPR. If your own processing is caught by article 3(2), which is the position sections 1 to 3 above describe, those clauses were not designed for the transfer. The Commission has announced a further set for that case and has not yet adopted it, so in practice exporters continue to require the existing clauses in the meantime. Sign them, but do not treat them as closing the question.
  • For a genuinely one-off transfer, article 49 provides limited derogations, including explicit informed consent and necessity for a contract with the individual. They are exceptions and will not carry a continuing data flow.
  • The obligations bite through your contract chain. An Australian supplier to a European customer will usually meet the clauses as a schedule to the services agreement rather than as a standalone document, and will then need to flow equivalent terms down to its own sub-processors.

What being wrong costs, in both places

One incident can attract two penalties, calculated on two different bases, by two regulators who do not coordinate. On the European side, the upper tier of article 83 is administrative fines up to €20,000,000, or in the case of an undertaking up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Breach of the transfer rules and of the basic principles sits in that upper tier.

On the Australian side the exposure was rewritten in 2022 and again in 2024. Section 13G now turns on a single serious interference rather than a serious or repeated one, and the maximum for a body corporate is:

The amount of the penalty for a contravention of subsection (1) by a body corporate is an amount not more than the greatest of the following:

(a) $50,000,000;

(b) if the court can determine the value of the benefit that the body corporate, and any related body corporate, have obtained directly or indirectly and that is reasonably attributable to the conduct constituting the contravention—3 times the value of that benefit;

(c) if the court cannot determine the value of that benefit—30% of the adjusted turnover of the body corporate during the breach turnover period for the contravention.

Privacy Act 1988 (Cth) s 13G(3).

For an individual the maximum is $2,500,000.

A mid-tier civil penalty in section 13H now catches an interference that is not serious, which removes the practical defence that a contravention was not grave enough to be worth pursuing.

The Australian floor moved, and moves again in December

The reform that Australian commentary described as forthcoming for several years has been law since December 2024. Most of it, including the penalty provisions above, commenced on 11 December 2024, the day after assent. Two changes were staged.

Sydney Harbour and the north shore seen from the air in daylight
Above. Sydney Harbour. The Australian floor rose in December 2024 and rises again in December 2026.
Commencement of the 2024 Australian privacy amendments Assent on 10 December 2024, the statutory tort on 10 June 2025, and automated decision-making transparency on 10 December 2026. Assent Statutory tort Automated decisions 6 months 18 months
10 December 2024The Privacy and Other Legislation Amendment Act 2024 received assent. The penalty rewrite and most of the machinery commenced the next day; only two changes were staged.
Figure 2. The 2024 amendments commenced in stages. The third stage has not commenced yet.

Two of the three have already happened. The statutory cause of action for serious invasions of privacy has been available since 10 June 2025, and it runs against any person rather than only against APP entities, so the small business exemption does not answer it.

The third has not. From 10 December 2026, an APP entity whose privacy policy is silent about automated decision-making will be non-compliant where computer programs make, or substantially contribute to, decisions that could reasonably be expected to significantly affect an individual's rights or interests. The policy must say what kinds of personal information those programs use and what kinds of decisions they make. Any business that has introduced automated scoring, triage, eligibility or pricing since it last revised its privacy policy has a document change to make before that date.

What this changes in your documents

What this means for you

Most of the work is documentary rather than technical. The exposure usually comes from a privacy notice that does not describe what the business actually does, a contract chain that never carried the transfer terms, and a representative that was never appointed.

Your review checklist

  • Establish, in writing, whether either limb of article 3(2) is engaged. Record the answer and the reasons, because it is the first thing a supervisory authority asks.
  • If it is, appoint a representative in the Union and name them in the privacy notice.
  • Map where European personal data actually sits, including analytics, marketing platforms, support tools and backups, rather than where you believe it sits.
  • Put the standard contractual clauses into the contract chain, and complete the annexes properly rather than leaving them as templates.
  • Check your consent mechanism against the definition of consent, not against whether a banner exists.
  • Revise the privacy policy for automated decision-making before 10 December 2026.
  • Have an incident response plan that can meet both clocks: 72 hours to the supervisory authority under article 33, and the Australian notifiable data breaches scheme for eligible breaches.
  • Confirm whether the small business exemption still applies to you, and note that it never applied to the GDPR.

Complying with one regime does not discharge the other. The Australian Privacy Principles and the GDPR overlap in subject matter and diverge in mechanism, and a business that meets the Australian Privacy Principles in full can still be in breach of the transfer rules, the representative obligation and the consent standard in Europe.

This article is provided for general information purposes only and does not constitute legal advice. Specialised legal counsel should be sought for specific fact patterns.

Fabian Hoffmann, Principal of Boettcher Law

Fabian Hoffmann

Principal, Boettcher Law · Sydney, Canberra, Frankfurt a.M.

Boettcher Law advises Australian and German businesses on cross-border data and privacy obligations, including GDPR applicability assessments, representative appointments, transfer documentation and Privacy Act compliance. See our areas of expertise, our note on the 2024 Australian privacy amendments, and our guides to offering digital products into the EU market and European cybersecurity obligations.

Law current at 17 August 2026. Next review due 17 February 2027.

What our clients say

Reviews left on Google by the businesses and individuals we act for. Updated automatically, not selected by us.

Posted on Google Google
Mick d profile picture
14 September 2026
Trustindex verifies that the original source of the review is Google.
When people think of lawyers, they always think expensive,money grabbing,aggravated or only concerned in winning for ego,cash,clout. Boettcher law firm, breaks the bread and is willing to plough the field right next to you all the way. Their work ethics & stead fast approach as a team is commendable. Annie Jin (solicitor) went above and beyond for me, from the gecko. Her relaxed but assertive demeanour was top notch. I was in a real quick sand conundrum,where I was stuck.I’m on a disability pension, I’m scraping by and was pushed into the corner, with the plaintive hoping I’d never be able to get my rightfully owed money. She was banking on expenses of a lawyer I wouldn’t be able to fight,She was right, I’d won $16,063 on a poker machine, I had my landlords bsb & acc number saved as a screenshot right next to my own account. Heat of the moment & didn’t have glasses. I accidentally chose the wrong account. The club, my bank ANZ,Police can’t do a thing about this. You’ll need to fight in court,and lawyers fees to go after that amount, you’ll be lucky if you can even afford the lawyer let alone get any moneys back. Annie spoke to Fabian and they saw,not an easy payout, more importantly they saw me as a human struggling that made an innocent mistake that’s cost me dearly. Boettcher law ;choose not to kick me to the kirb,making me feel weak & insignificant,but instead represent me,and show a lady with a gluten for greed and questionable motives & morals a thing or two. This lady played it out for 18months, yet Fabian had said, like Brad Pitt in Snatch. F#%k it , I’ll do the fight for free. I was contacted by Mason who was my representative 3 days ago to inform me he’d get my money back, and Boettcher Law say as they do, do as they say. I’m pleased to say the small amount of money they got from my payout,was not only very fair,but I insisted for I believed it was a moral thing to do considering the 18months of watching a lady trying to claim her so called cake & eat it too. I couldn’t recommend a better law firm,but also a team of highly proficient humans, who will draw the line in the sand for equality,When humans take advantage of others dignity,bullying ,discrimination,disingenuous,dishonest & show little respect to a fellow human, look out cause you’ve woken a team, that are in it for you, not ego,money,fame. Boettchers there for your pride & giving you back your dignity.rare to find a Law firm all about the community & respect the reality of life & are prepared to help the helpless. Annie Jin, Mason ,Fabian You restored my faith in humanity for me, I’ll never forget your commitment & compassion in helping a wounded soldier out of the quick sand to now having faith in our justice system🙏if your looking for a loyal lawyer don’t look any further, if your looking to lose, Go to another firm, 🙏
Posted on Google Google
K profile picture
K
11 September 2026
Trustindex verifies that the original source of the review is Google.
I am extremely grateful to Fabian and Mason for their outstanding assistance during a very stressful and time-sensitive matter. I was facing extremely tight deadlines, and Fabian took the time to carefully review a substantial amount of material. His advice and responses were consistently clear, precise and thoughtful. His attention to detail gave me enormous confidence that important issues would not be overlooked. Within only one or two days, Fabian assisted me through a difficult negotiation under significant pressure. What I appreciated most was not only his legal expertise, but also his patience, persistence and strong sense of fairness. When I was faced with demands that I felt were unreasonable and considerable pressure to make decisions quickly, his calm and careful guidance gave me the confidence to stay focused, not lose perspective, and make considered decisions. I genuinely believe that this contributed greatly to the outcome we ultimately achieved. I would also like to sincerely thank Mason for stepping in and coordinating matters at very short notice. His prompt assistance and responsiveness were greatly appreciated, particularly given the urgency of the situation. The assistance I received from Fabian and Mason went far beyond what I had expected. Fabian’s professionalism, care, patience and commitment to helping his client were exceptional. It is difficult to put into words how much his support meant to me during such a challenging period. Thank you, Fabian and Mason. I am truly grateful for everything you did for me.
Posted on Google Google
Xiao Yuan Tang profile picture
31 March 2026
Trustindex verifies that the original source of the review is Google.
Fabian and Annie were both great to deal with. Annie was especially very dedicated, always quick to respond, and explained everything really clearly. They made the whole process much easier and less stressful. Really appreciate all their help, and I’ll definitely keep working with them in the future.
Posted on Google Google
Yurica Oh profile picture
22 January 2026
Trustindex verifies that the original source of the review is Google.
I cannot thank Fabian Hoffmann and the team at Boettcher Law enough for their outstanding support. We were given sudden notice of lease expiry right before the Christmas–New Year period, and Fabian responded promptly and professionally throughout what could have been a very stressful situation. His advice was clear, strategic, and commercially sensible, and he guided us through negotiations with confidence and precision. Thanks to Fabian’s expertise, we were able to successfully resolve the matter and recover our bond (with only the agreed rent adjustment deducted), avoiding unnecessary escalation. Highly recommend Fabian to anyone needing reliable, sharp, and responsive commercial leasing advice. Truly a pleasure to work with.
Posted on Google Google
Salim Bio Tchane profile picture
28 November 2025
Trustindex verifies that the original source of the review is Google.
Mr Hoffmann and his team were professional and cordial in helping me attaining my objective even though I live in Africa. I stronngly recommend them to others as their assistance was top notch.
Posted on Google Google
Hannelore Federspiel profile picture
19 September 2025
Trustindex verifies that the original source of the review is Google.
The team at Boettcher Law has been nothing short of brilliant to deal with. They have been my trusted partner when I needed legal services and advice. I can highly recommend Fabian Hoffmann and his team!
Posted on Google Google
Robert Yifu Wei profile picture
4 September 2025
Trustindex verifies that the original source of the review is Google.
Fabian and the team were extremely responsive and helpful with our matter.
Posted on Google Google
Channelle profile picture
3 August 2025
Trustindex verifies that the original source of the review is Google.
I was referred to Mason at Boettcher Law by a friend as I needed help with a property matter. Mason and Annie were brilliant - they were professional, super responsive and lovely to deal with. They sorted my matter quickly (having become unexpectedly urgent) and their rates were great, especially given the excellent service. Would 100% use them again if needed. Highly recommend.
Posted on Google Google
Maryana Sedarous profile picture
16 July 2025
Trustindex verifies that the original source of the review is Google.
Fabian worked patiently and attentively with us, and helped us prepare our affidavits and paperwork for our hearings. He went out of his way to ensure everything was properly prepared and on time. I have since recommended him to other family members and would recommend him to anyone else who asks.
Posted on Google Google
armando fernandez profile picture
7 July 2025
Trustindex verifies that the original source of the review is Google.
Excellent work, earnest, committed and responsible. Annie and Fabian are highly recommended Grear solicitors

Common questions about European privacy law

Each answer is complete in its first sentence.

Does the GDPR apply if we have no office or company in Europe?

Yes, if you offer goods or services to people in the EU or monitor their behaviour there. Article 3(2) fixes the reach by conduct rather than by establishment, so an Australian business with no European presence at all can be fully within the Regulation.

Does turnover under $3 million exempt us?

It may exempt you from the Privacy Act, and it never exempts you from the GDPR. Section 6D turns off the Privacy Act for a business with annual turnover of $3,000,000 or less, but not for health service providers, businesses trading in personal information, credit reporting bodies, or a small company related to a larger group. European law has no turnover threshold at all.

What is an EU representative, and do we need one?

It is a person or firm inside the Union, appointed in writing, whom regulators and individuals can address in addition to or instead of you, and you need one whenever article 3(2) applies to you. The only exemption is for processing that is occasional, low risk and involves no large-scale special category or criminal data.

Is Australia recognised as adequate by the European Commission?

No. Australia has never been the subject of an adequacy decision. New Zealand has, which is why data can move from the Union to New Zealand without further safeguards but not to Australia.

What are standard contractual clauses?

They are a set of transfer terms adopted by the European Commission, in force since 2021, which supply the safeguards article 46 requires. Beyond choosing the module and the options, their operative text cannot be varied, and the annexes are what parties negotiate. Note that they were drafted for importers not themselves subject to the GDPR; a further set for importers who are has been announced but not yet adopted.

What is the maximum GDPR fine?

For the upper tier, the higher of €20 million or 4% of total worldwide annual turnover for the preceding financial year. Breaches of the basic principles and of the transfer rules sit in that tier.

Has Australian privacy law changed recently?

Yes, in stages. The Privacy and Other Legislation Amendment Act 2024 received assent on 10 December 2024, the statutory tort for serious invasions of privacy commenced on 10 June 2025, and automated decision-making transparency obligations commence on 10 December 2026.

Does complying with the Privacy Act make us GDPR compliant?

No. The two regimes overlap in subject matter and diverge in mechanism. A business meeting the Australian Privacy Principles in full can still breach the European rules on transfers, on consent and on appointing a representative.

Speak to someone who works on cross-border privacy

We advise Australian and German businesses on GDPR compliance, from the applicability assessment through representative appointments and transfer documentation to the Privacy Act obligations that sit alongside it, from offices in both markets.

Sydney+61 2 8201 6400 Canberra+61 2 6232 0600 Frankfurt a.M.+49 69 9675 9832

Related reading

The most recent articles in the same area of law, updated automatically.

Sydney

Canberra

Frankfurt a.M.