book a virtual meeting Search Search
brisbane

one eagle – waterfront brisbane
level 30, 1 eagle street
brisbane qld 4000
+61 7 3235 0400

dandenong

40-42 scott st,
dandenong vic 3175
+61 3 9794 2600

melbourne

level 7, 600 bourke st,
melbourne vic 3000
+61 3 8615 9900

sydney

level 21, 20 bond st,
sydney nsw 2000
+61 2 8298 9533

hello. we’re glad you’re
getting in touch.

Fill in form below, or simply call us on 1800 888 966

Privacy law obligations when selling your business

30 January 2018
olivia christensen
Read Time 3 mins reading time

Privacy law is rapidly expanding and impacting how businesses handle individuals’ personal information. We have previously discussed the Australian data breaches scheme and the impact of changes to EU privacy law on Australian businesses. This article will explore a Seller’s privacy obligations under the Privacy Act 1988 (the Act) in a business sale.

What are the obligations?

Trade in personal information commonly occurs when a business sells their customer list as a business asset or discloses personal information of their customers or third party contractors to potential purchasers during due diligence. If a business subject to the Act is trading personal information, they must obtain the concerned individuals’ consent before the trade is made.

Is your business subject to the Act?

All private health service providers must comply with the Act. Additionally, businesses in the private sector and organisations in the not-for-profit sector with an annual turnover of more than $3 million must comply.

A business with an annual turnover of less than $3 million will only be subject to the Act if they:

  • sell or purchase personal information;
  • are related to a larger body corporate that is subject to the Act, for instance if they are a subsidiary company;
  • provide services under a contract with the Australian Government;
  • are credit providers or credit reporting bodies; or
  • operate a residential tenancy database.

Practical recommendations

There are some practical steps you can take to ensure your business is compliant with the Act during due diligence.

Obtain consent

If you are the Seller and your business’s full data set (including personal information) is to be provided on settlement or earlier, you must first obtain the customer’s informed consent.

The consent process might include the Seller informing customers of the sale, the Buyer’s identity, proposed use of information and privacy policy, and seeking the required consent.

Depersonalise

Any personal information database provided to the Buyer as part of due diligence should be depersonalised. Although this will diminish the value to the Buyer, it will enable the Buyer to make an assessment of the credibility of your business.

This article was written by Olivia Christensen, Special Counsel – Commercial. 

stay up to date with our news & insights

Privacy law obligations when selling your business

30 January 2018
olivia christensen

Privacy law is rapidly expanding and impacting how businesses handle individuals’ personal information. We have previously discussed the Australian data breaches scheme and the impact of changes to EU privacy law on Australian businesses. This article will explore a Seller’s privacy obligations under the Privacy Act 1988 (the Act) in a business sale.

What are the obligations?

Trade in personal information commonly occurs when a business sells their customer list as a business asset or discloses personal information of their customers or third party contractors to potential purchasers during due diligence. If a business subject to the Act is trading personal information, they must obtain the concerned individuals’ consent before the trade is made.

Is your business subject to the Act?

All private health service providers must comply with the Act. Additionally, businesses in the private sector and organisations in the not-for-profit sector with an annual turnover of more than $3 million must comply.

A business with an annual turnover of less than $3 million will only be subject to the Act if they:

  • sell or purchase personal information;
  • are related to a larger body corporate that is subject to the Act, for instance if they are a subsidiary company;
  • provide services under a contract with the Australian Government;
  • are credit providers or credit reporting bodies; or
  • operate a residential tenancy database.

Practical recommendations

There are some practical steps you can take to ensure your business is compliant with the Act during due diligence.

Obtain consent

If you are the Seller and your business’s full data set (including personal information) is to be provided on settlement or earlier, you must first obtain the customer’s informed consent.

The consent process might include the Seller informing customers of the sale, the Buyer’s identity, proposed use of information and privacy policy, and seeking the required consent.

Depersonalise

Any personal information database provided to the Buyer as part of due diligence should be depersonalised. Although this will diminish the value to the Buyer, it will enable the Buyer to make an assessment of the credibility of your business.

This article was written by Olivia Christensen, Special Counsel – Commercial.