Can a customer sue your small business for a serious privacy invasion?

Alex Solo
byAlex Solo8 min read

A serious privacy complaint can expose a small business to more than an Australian Privacy Principle investigation. Since 10 June 2025, Schedule 2 of the Privacy Act 1988 has provided a separate court claim for serious invasions of privacy. Being APP exempt does not necessarily remove that risk.

The useful starting point is what actually happened: was private information misused, was someone intruded upon, and could they reasonably expect privacy in the circumstances? A customer must also establish intentional or reckless conduct, seriousness and the required public interest balance. A privacy complaint is not automatically a successful claim.

For a business owner, that distinction changes the response. Preserve the records, stop any ongoing conduct and assess the court-claim elements separately from any APP or data breach questions. The sections below explain that investigation and the limits of consent, lawful authority and other defences. This article is general information only and is not legal advice.

Assess the conduct before answering the customer

When a privacy complaint lands, work through the facts in this order:

  • What exactly is the conduct complained about: intrusion into a private space, misuse of information, or both?
  • Is anything still happening now, such as an online post, shared folder access, staff viewing, or ongoing surveillance?
  • Who did it, who approved it, and what systems, devices or accounts were involved?
  • What records exist, including logs, screenshots, consent wording, notices, policies, CCTV settings, messages and staff instructions?
  • Was the conduct deliberate, or is the allegation really about an accidental error?
  • Could the person reasonably expect privacy in those circumstances?
  • Could the conduct be considered serious, rather than merely upsetting or inconvenient?
  • Is there a separate Privacy Act, APP or notifiable data breach issue to assess as well?

That checklist matters because the new tort is broader than APP coverage, but it does not automatically apply to every privacy complaint.

Being APP exempt does not necessarily end the risk

Most small businesses with annual turnover of $3 million or less are generally exempt from the Australian Privacy Principles (APPs), although exceptions apply because of what they do. For example, some health service providers, businesses that trade in personal information, some Commonwealth contractors and certain other categories can be covered regardless of turnover.

Even so, the OAIC says the statutory tort for serious invasions of privacy is broader in application than the rest of the Privacy Act and can extend to individuals and entities that may not necessarily be APP entities. In practical terms, a genuinely APP exempt business should not assume it is immune from a serious privacy invasion claim.

The reverse is also true. If your business is APP regulated, that does not mean every mishandling of personal information becomes a Schedule 2 claim. A customer might complain to the OAIC about APP issues, or there may be a data breach assessment to make, without the facts meeting the legal elements of the tort.

What a customer would need to prove in court

The tort sits in Schedule 2 of the Privacy Act 1988 and claims are brought through the courts, not decided directly by the OAIC. Clause 7 of Schedule 2 sets out the essential elements. For a business receiving a complaint, those elements are the evidence map you need to investigate.

First, there must be an invasion of privacy by either intruding upon the person's seclusion, misusing information that relates to them, or both. "Seclusion" points to interference with a private space or private activity. "Misuse of information" points to handling, revealing or using information in a way that invades privacy.

Second, a person in the plaintiff's position must have had a reasonable expectation of privacy in all of the circumstances. The law allows the court to look at matters such as the technology used, the purpose of the conduct, the person's attributes, whether they had sought privacy, where an intrusion occurred, and, for information misuse, the nature of the information and whether it was already public.

Third, the invasion must have been intentional or reckless. This is a critical threshold for businesses. A genuine mistake may still create other problems, but the tort is not framed as a catch-all for every careless admin slip.

Fourth, the invasion must be serious. The court can consider likely offence, distress or harm to dignity, what the defendant knew or ought to have known about that impact, and whether intentional conduct involved malice.

Fifth, the public interest in the person's privacy must outweigh any countervailing public interest. The legislation specifically recognises possible countervailing interests such as freedom of expression, media freedom, public health and safety, open justice, government administration, national security, and prevention or detection of crime and fraud.

The claim is actionable without proof of damage. That does not mean liability is automatic. It means a plaintiff does not have to show financial loss before the court can consider the claim.

How the elements play out in business examples

Example one: a staff member deliberately posts a customer's medical or financial details in a business group chat or on social media after an argument. That could raise a misuse of information issue. If the details were obviously private, the conduct was deliberate, and the likely harm to dignity was obvious, the complaint may need urgent legal assessment under Schedule 2 as well as under any other data privacy regime that applies.

Example two: a business owner uses a hidden camera or device to observe a customer in a private fitting area, treatment room or similar private space. That fact pattern may point to intrusion upon seclusion, especially where a person would clearly expect privacy there.

Example three: an employee accidentally sends an invoice or booking email to the wrong recipient. That can still be serious from an operations and customer trust perspective, and it may trigger other privacy analysis if your business is regulated under the APPs. But without evidence of intentional or reckless conduct, an accidental email error does not automatically establish the tort.

These are only examples, not conclusions about liability. Real cases turn on detailed facts, records and context.

Businesses often reach for a Privacy Policy, website terms or a generic sign on the wall and assume that solves the complaint. That is risky. Consent and lawful authority are recognised defences, but whether they apply depends on the facts.

A court may need to examine what the person was actually told, whether the wording covered the specific conduct, whether the consent was express or implied, and whether the later use or disclosure stayed within that scope. Broad boilerplate language may not match what staff actually did.

Lawful authority also needs care. If you say the conduct was required or authorised by law, you need to identify the real legal basis and keep records showing how the conduct stayed within it. The legislation also recognises other defences in some situations, including where conduct was reasonably believed necessary to prevent or lessen a serious threat to life, health or safety, or was incidental to lawful defence of persons or property and proportionate, necessary and reasonable.

The practical point is simple: do not make confident statements to the customer before you have checked the documents, footage, logs and staff accounts.

First steps after a serious privacy complaint

First, contain any continuing intrusion, access or disclosure while preserving proof of what happened. Capture the post or access trail before removing it where safe, then restrict sharing links, isolate devices, pause the surveillance practice or remove staff permissions as needed.

Second, preserve evidence. Save logs, screenshots, audit trails, device settings, email headers, CRM notes, staff messages, consent records, and versions of any notices or scripts used at the time. Do not clean up the evidence trail before advice.

Third, identify the actual conduct. Separate what you know from what is assumed. Was there a disclosure, an observation, a recording, a search, or an internal misuse of customer data? Which people were involved?

Fourth, assess whether you also have Privacy Act obligations. Ask whether your business is covered by the APPs despite being small, and whether the incident raises a notifiable data breach question. Those are separate analyses from the Schedule 2 tort. One does not automatically prove the other.

Fifth, contain communications. Tell staff not to argue with the complainant, speculate in messages, or post defensive explanations online. Public responses can repeat the private information, suggest recklessness, or create new evidence against the business.

Sixth, acknowledge the complaint calmly and narrowly. You can say you are reviewing the matter, preserving records, and will respond once you have investigated. Avoid admissions, blame or broad denials until the facts are clear.

Who deals with the complaint, and what could a court order?

The OAIC does not directly administer the statutory tort. That matters because some businesses assume every privacy issue stays with the regulator. A customer may still raise regulatory complaints where relevant, but the Schedule 2 tort itself is a court cause of action.

If proceedings are brought, the court has a range of remedies. It may grant an injunction, including at an early stage, to restrain conduct. It may award damages, including for emotional distress, and in exceptional circumstances exemplary or punitive damages. The court may also order other relief, including an apology.

There is no safe business response based on guessing claim value, assuming no loss means no case, or assuming that a regulator process is the only path open to the complainant.

Keep the response practical and get advice early

A serious privacy allegation can affect customer trust, staff conduct, customer contracts, complaints handling and insurance notifications. If your business is small, do not let the APP threshold become a false sense of safety. The better approach is to investigate against the actual Schedule 2 elements, preserve records, stop any ongoing conduct and separate the court claim question from any APP or data breach question.

Key Takeaways

  • Being a small business or APP exempt does not necessarily stop a customer from bringing a Schedule 2 privacy claim.
  • The claim is aimed at intrusion upon seclusion, misuse of information, or both, not every privacy complaint.
  • A plaintiff still needs to establish a reasonable expectation of privacy, intentional or reckless conduct, seriousness and the public interest balance.
  • Consent, lawful authority and other statutory defences may matter, but generic wording or assumptions are not enough.
  • Your first response should be practical: stop any ongoing conduct, preserve evidence, and assess APP or data breach issues separately.
  • The OAIC does not directly decide this tort, and courts can order remedies such as injunctions, damages and an apology.

If you need help assessing a customer complaint, preserving evidence or working out whether Schedule 2, the APPs or a breach-response duty applies, Sprintlaw can provide Australian privacy advice. Call 1800 730 617 or email team@sprintlaw.com.au.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Leaving an AI vendor? Secure your data and access before you terminate

Leaving an AI vendor? Secure your data and access before you terminate

Leaving an AI vendor can create real operational risk if your prompts, records or workflows are trapped in the platform. Before you terminate, check what your contract says about export, access, transition help and deletion, and test the handover in practice.

5 Oct 2026
Read more
Before a software vendor handles your customer data, ask for proof

Before a software vendor handles your customer data, ask for proof

Before a software vendor gets access to customer or employee data, ask for proof that matches the real product, data flows and subcontractors. Learn what to test in a vendor security questionnaire, how APP 11 can still apply after outsourcing, and which answers must become contract terms.

2 Oct 2026
Read more
Using AI Call Transcription Tools: Privacy, Security And Contract Checklist

Using AI Call Transcription Tools: Privacy, Security And Contract Checklist

Using AI to transcribe business calls? One wrong setting could expose personal information, breach privacy rules or lock you into risky provider terms.

30 Sept 2026
Read more
"Reject All Cookies" Buttons in Australia: Legal, Clear Consent

"Reject All Cookies" Buttons in Australia: Legal, Clear Consent

Do Australian businesses need “reject all cookies” buttons? This guide explains when clear cookie consent matters, the risks of misleading banner design

29 Sept 2026
Read more
"Reject All Cookies" Buttons: Making Them Legal & Clear

"Reject All Cookies" Buttons: Making Them Legal & Clear

A clear “reject all cookies” button is more than a design choice. Learn how Australian businesses can make cookie banners fair, accurate and aligned with

29 Sept 2026
Read more
Data Retention for Online Course Platforms in Australia

Data Retention for Online Course Platforms in Australia

Online course platforms often collect more personal information than founders expect. This guide explains how Australian businesses can set sensible data

29 Sept 2026
Read more
Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.