Illustration of a laptop surrounded by shield, envelope, bell, padlock, clock and accessibility icons representing Australian website compliance

Australian businesses running WordPress deal with a familiar set of rules: the Privacy Act for personal information, the Notifiable Data Breaches scheme when something goes wrong, the Spam Act for commercial email, and disability discrimination law for accessibility. Most of the technical work behind them is plain good maintenance.

Here is what each rule means for a WordPress site, and a short routine to keep it in order.

Does the Privacy Act Apply to Your Business?

The Privacy Act 1988 covers organizations with annual turnover of more than A$3 million, and some smaller ones, such as health service providers and businesses that trade in personal information. Covered businesses must follow the Australian Privacy Principles, including having a clear privacy policy on the site.

Privacy reforms passed in late 2024 are being phased in, so check the OAIC’s updates each year even if the Act didn’t apply to you before.

Securing Personal Information on WordPress

Australian Privacy Principle 11 requires reasonable steps to protect personal information from misuse, loss and unauthorized access. On a WordPress site, that comes down to a few habits: keep plugins and themes patched, use two-factor authentication for every admin, limit who can see form entries and orders, and delete what you no longer need.

Backups need the same care as the live site. They hold the same personal information, so keep them encrypted, off-site and access-controlled, and test that you can restore them. Our 3-2-1 backup guide explains a reliable setup.

The Notifiable Data Breaches Scheme

Since 2018, businesses covered by the Privacy Act must report eligible data breaches, meaning those likely to result in serious harm, to the OAIC and to the people affected. If you suspect a breach, you must take reasonable steps to assess it within 30 days. The OAIC’s guidance explains what counts.

Fast assessment depends on knowing what happened: activity logs, security monitoring and recent backups. If your site is ever compromised, our guide to the first two hours after a hack helps you act quickly.

The Spam Act and Your Forms

The Spam Act 2003 requires consent before you send commercial emails or texts, clear identification of your business in every message, and a working unsubscribe that you honor within five working days. On WordPress, the weak point is the connection between your forms and your email platform. Test a sign-up and an unsubscribe after every plugin update.

Accessibility and the Disability Discrimination Act

The Disability Discrimination Act 1992 applies to websites that provide goods and services, and WCAG 2.1 Level AA is the usual benchmark. Our practical WCAG guide covers the common WordPress fixes: form labels, contrast, keyboard navigation and alt text.

Frequently Asked Questions

My turnover is under A$3 million. Can I ignore the Privacy Act?

Not always. Some small businesses are covered regardless of turnover, such as health service providers. The OAIC website has a checklist to confirm.

What counts as a notifiable data breach?

One that is likely to result in serious harm to the people whose information was involved, such as exposed identity or financial details.

Is a pre-ticked newsletter box acceptable?

It is risky. Consent should be clear and active, so leave the box unticked and record when people sign up.

How often should I check my site?

Apply security updates weekly, and review forms, backups and accessibility at least once a quarter.

What to Do This Week

  1. Confirm whether the Privacy Act covers your business.
  2. Test your newsletter sign-up and unsubscribe links.
  3. Restore a recent backup to a staging copy to prove it works.
  4. Write down who would assess a breach and how you would contact customers.

Our managed WordPress maintenance keeps updates, backups and monitoring running for you, or start with a free site audit.

This article explains the technical side for website owners. It isn’t legal advice; for decisions about your own obligations, talk to a qualified adviser.

Filed under
Tags
Is your WordPress site as healthy as it should be?

Get a free audit covering security, updates, backups, and performance gaps. Takes 60 seconds to request and costs nothing.

Get your free audit