In short
The GDPR applies to an Australian business that offers goods or services to people in the EU or monitors their behaviour there, whatever its size and wherever it sits. The Privacy Act's small business exemption has no European equivalent.
- Payment is irrelevant, and monitoring is a separate trigger from selling.
- A representative inside the Union must be appointed in writing.
- Australia is not an adequate country, so transfers need article 46 safeguards.
The test is what you do, not where you sit
European privacy law reaches an Australian business through conduct, not through presence. There is no office test, no subsidiary test and no server test. Article 3(2) of the General Data Protection Regulation fixes the reach by reference to two activities:
This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
Two things follow that are easy to miss. Payment is irrelevant. A free trial, a newsletter, a downloadable white paper and a support portal are all an offering of services. And monitoring is a separate limb, so a business that sells nothing into Europe still engages the Regulation if it tracks European visitors. Analytics, advertising pixels, session recording and cookie-based personalisation will ordinarily amount to monitoring, because what matters is behavioural analysis or profiling and the purpose behind it, not the mere fact that data is collected online.
What the Regulation does not catch is the accidental European. A customer in Munich who finds an Australian site written in English, priced in Australian dollars, shipping only domestically, is not evidence that the business offers goods or services in the Union. The question is whether the business envisaged offering into the Union, and the ordinary indicators are the ones you would expect: a European language, a European currency, European delivery, a European domain, European contact details, or marketing aimed at a member state.
The threshold that does not exist in Europe
The exemption that puts most small Australian businesses outside the Privacy Act has no European equivalent. The Act binds APP entities, meaning Australian government agencies and private organisations other than exempt small businesses. Section 6D of the Privacy Act 1988 (Cth) still turns on turnover:
A business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less.
Privacy Act 1988 (Cth) s 6D(1).
The exemption is also narrower than the headline figure suggests. It does not apply to a business that provides a health service and holds health information, that trades in personal information for a benefit, that is a Commonwealth contracted service provider or a credit reporting body, and under section 6D(9) it does not apply at all to a small company related to a body corporate that is not itself small. Groups are the ordinary case among the businesses reading this.
Nothing in the GDPR corresponds to that. Size affects some obligations at the margin, such as the record-keeping duty in article 30 and the exemption from appointing a representative in article 27(2), but it never affects whether the Regulation applies at all.
So the position that surprises founders is entirely ordinary: an Australian company with turnover under three million dollars can sit outside the Privacy Act and squarely inside the GDPR at the same time. The regime with the smaller penalties does not apply, and the regime with the larger ones does.
| Question | Privacy Act 1988 (Cth) | GDPR |
|---|---|---|
| What triggers it | Being an APP entity | Offering goods or services into the Union, or monitoring behaviour there |
| Turnover threshold | Exempt at or under $3,000,000 | None |
| Local presence needed | Australian link | No |
| Representative required | No equivalent | Yes, in a member state, unless article 27(2) applies |
| Sending data out | APP 8, accountability for the recipient | Adequacy, or article 46 safeguards |
| Maximum corporate penalty | Greatest of $50m, 3x benefit, or 30% of adjusted turnover | €20m or 4% of worldwide annual turnover, whichever is higher |
The obligation most Australian businesses have never heard of
An Australian business caught by article 3(2) must appoint a representative inside the Union, in writing. It is probably the most easily missed GDPR obligation for an Australian company, because it has no analogue in Australian law and no natural trigger in an Australian compliance calendar.
Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.
GDPR art 27(1).
The representative must be established in a member state where the relevant individuals are, must be mandated to be addressed, in addition to or instead of the business itself, by supervisory authorities and by individuals on all issues related to the processing, and must be named where those individuals can find them, which in practice means the privacy notice. Appointing one does not shift liability: article 27(5) preserves every legal action that could be brought against the business itself.
The United Kingdom is a separate exercise. Since Brexit an Australian business targeting the UK is caught by the UK GDPR rather than the EU Regulation, and an EU representative does not answer it: a business serving both markets needs one in each.
There is an exemption, and it is narrower than it first reads. Article 27(2) removes the obligation only where the processing is occasional, does not involve special category data (health, biometrics, race, beliefs, sexual orientation and the like) or criminal data on a large scale, and is unlikely to result in a risk to individuals. A business running continuous analytics on European visitors, or holding a European customer list, is not processing occasionally.
Data coming the other way: Australia is not adequate
Australia has never been the subject of a European adequacy decision, so personal data cannot move from the Union to Australia on that basis. The European Commission's adequacy list runs to Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for organisations in the Data Privacy Framework, Uruguay and the European Patent Organisation. New Zealand is on it. Australia is not.
Absent adequacy, article 46 requires appropriate safeguards, and the ordinary instrument is the standard contractual clauses adopted by the Commission in 2021. Three practical consequences follow for an Australian business receiving European data.
- The clauses are a Commission decision, so their operative text is not negotiable. What is negotiable, and what matters commercially, is the annexes: the description of the processing, the technical and organisational measures, and the sub-processor list.
- Signing is not the end of it. The exporter must assess whether the law of the destination country undermines the clauses in practice, and document that assessment.
- There is a gap that catches exactly the reader this article is written for. The 2021 clauses were drafted for importers outside the EEA whose processing is not itself subject to the GDPR. If your own processing is caught by article 3(2), which is the position sections 1 to 3 above describe, those clauses were not designed for the transfer. The Commission has announced a further set for that case and has not yet adopted it, so in practice exporters continue to require the existing clauses in the meantime. Sign them, but do not treat them as closing the question.
- For a genuinely one-off transfer, article 49 provides limited derogations, including explicit informed consent and necessity for a contract with the individual. They are exceptions and will not carry a continuing data flow.
- The obligations bite through your contract chain. An Australian supplier to a European customer will usually meet the clauses as a schedule to the services agreement rather than as a standalone document, and will then need to flow equivalent terms down to its own sub-processors.
What being wrong costs, in both places
One incident can attract two penalties, calculated on two different bases, by two regulators who do not coordinate. On the European side, the upper tier of article 83 is administrative fines up to €20,000,000, or in the case of an undertaking up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Breach of the transfer rules and of the basic principles sits in that upper tier.
On the Australian side the exposure was rewritten in 2022 and again in 2024. Section 13G now turns on a single serious interference rather than a serious or repeated one, and the maximum for a body corporate is:
The amount of the penalty for a contravention of subsection (1) by a body corporate is an amount not more than the greatest of the following:
(a) $50,000,000;
(b) if the court can determine the value of the benefit that the body corporate, and any related body corporate, have obtained directly or indirectly and that is reasonably attributable to the conduct constituting the contravention—3 times the value of that benefit;
(c) if the court cannot determine the value of that benefit—30% of the adjusted turnover of the body corporate during the breach turnover period for the contravention.
Privacy Act 1988 (Cth) s 13G(3).
For an individual the maximum is $2,500,000.
A mid-tier civil penalty in section 13H now catches an interference that is not serious, which removes the practical defence that a contravention was not grave enough to be worth pursuing.
The Australian floor moved, and moves again in December
The reform that Australian commentary described as forthcoming for several years has been law since December 2024. Most of it, including the penalty provisions above, commenced on 11 December 2024, the day after assent. Two changes were staged.

Two of the three have already happened. The statutory cause of action for serious invasions of privacy has been available since 10 June 2025, and it runs against any person rather than only against APP entities, so the small business exemption does not answer it.
The third has not. From 10 December 2026, an APP entity whose privacy policy is silent about automated decision-making will be non-compliant where computer programs make, or substantially contribute to, decisions that could reasonably be expected to significantly affect an individual's rights or interests. The policy must say what kinds of personal information those programs use and what kinds of decisions they make. Any business that has introduced automated scoring, triage, eligibility or pricing since it last revised its privacy policy has a document change to make before that date.
What this changes in your documents
What this means for you
Most of the work is documentary rather than technical. The exposure usually comes from a privacy notice that does not describe what the business actually does, a contract chain that never carried the transfer terms, and a representative that was never appointed.
Your review checklist
- Establish, in writing, whether either limb of article 3(2) is engaged. Record the answer and the reasons, because it is the first thing a supervisory authority asks.
- If it is, appoint a representative in the Union and name them in the privacy notice.
- Map where European personal data actually sits, including analytics, marketing platforms, support tools and backups, rather than where you believe it sits.
- Put the standard contractual clauses into the contract chain, and complete the annexes properly rather than leaving them as templates.
- Check your consent mechanism against the definition of consent, not against whether a banner exists.
- Revise the privacy policy for automated decision-making before 10 December 2026.
- Have an incident response plan that can meet both clocks: 72 hours to the supervisory authority under article 33, and the Australian notifiable data breaches scheme for eligible breaches.
- Confirm whether the small business exemption still applies to you, and note that it never applied to the GDPR.
Complying with one regime does not discharge the other. The Australian Privacy Principles and the GDPR overlap in subject matter and diverge in mechanism, and a business that meets the Australian Privacy Principles in full can still be in breach of the transfer rules, the representative obligation and the consent standard in Europe.
This article is provided for general information purposes only and does not constitute legal advice. Specialised legal counsel should be sought for specific fact patterns.
Sources
- Regulation (EU) 2016/679 (GDPR), arts 3, 27, 45, 46, 83
- Commission Implementing Decision (EU) 2021/914, standard contractual clauses
- European Commission, adequacy decisions
- Privacy Act 1988 (Cth), ss 6D, 13G, 13H, Schedule 1 (APP 1.7) and Schedule 2
- Privacy and Other Legislation Amendment Act 2024 (Cth), commencement table
- OAIC, Australian Privacy Principles


