Independent Australian Storage & Infrastructure Authority

Australian Privacy Law and Self-Hosted Personal Data: What You Need to Know

Running your own NAS or self-hosted server in Australia puts you in a different legal position than using commercial cloud services. This guide explains which parts of the Privacy Act 1988 apply to home users vs small businesses, what your obligations are, and where the real risks sit.

Informational Understand

Individuals acting in a personal capacity are generally not covered by the Privacy Act, while business coverage depends on whether the entity is covered by the Act or falls within a statutory exception. Personal home NAS use is generally outside the Act because an individual acting in a personal capacity is not covered; most small businesses are separately outside the Act unless an exception applies. Storing another person’s personal information does not by itself establish Privacy Act coverage. Coverage depends on whether the holder is an APP entity; a small business can be covered where an exception applies, including when it provides a health service and holds health information. This article explains where the lines are, what they mean in practice, and what sensible data hygiene looks like regardless of your legal position.

In short: Personal home NAS use falls outside Privacy Act obligations in most cases. Small businesses with annual turnover of $3 million or less are generally exempt unless a statutory exception applies, such as being a health service provider or having opted in. Above the threshold, the Australian Privacy Principles apply regardless of where data is stored - NAS, cloud, or paper. Self-hosting does not create extra obligations, but it does mean you are responsible for your own security rather than a cloud provider.

Note: This article provides general information, not legal advice. Australian privacy law is under active reform as of 2026. Consult a privacy lawyer for specific compliance questions, particularly if you handle health information, employee data, or data belonging to a large number of individuals.

The Small Business Exemption

The Privacy Act 1988 contains a small business exemption (section 6C) that removes most small businesses from the Australian Privacy Principles. A 'small business operator' is generally an entity with annual turnover of $3 million or less. If your business falls below this threshold, the Privacy Act's core obligations do not directly apply to you.

An individual acting in a personal capacity is generally not covered by the Privacy Act; this is distinct from the small-business rules. A person storing their own family's data on a home NAS has no Privacy Act obligations because there is no 'business' involved at all. Privacy law applies to organisations collecting and handling other people's data in a business context, not to individuals managing their own information.

However, the exemption has important carve-outs that pull some small businesses back in:

  • Health service providers: Any business providing a health service and holding health information is covered, regardless of size. A sole-practitioner GP, physio, or psychologist with a NAS holding patient records has Privacy Act obligations.
  • Businesses that collect or disclose personal information for a benefit: Businesses that trade in personal information may lose the exemption where they collect or disclose it for a benefit, service or advantage, subject to exceptions including consent and conduct required or authorised by legislation.
  • Businesses related to a larger entity: If you are a subsidiary or related entity of a company above $3 million, the exemption may not apply.
  • Businesses that have opted in: Some businesses voluntarily subject themselves to the Privacy Act for commercial or trust reasons.

What the Australian Privacy Principles Require

For organisations covered by the Act, the 13 Australian Privacy Principles (APPs) impose obligations across the data lifecycle. The ones most relevant to a self-hosted environment:

  • APP 1 (Open and transparent management): You must have a Privacy Policy describing what personal information you collect and how you handle it. A covered entity must take reasonable steps to make its APP privacy policy available free of charge and in an appropriate form; its APP 5 collection-notice obligations are separate.
  • APP 6 (Use or disclosure): Personal information collected for one purpose cannot generally be used for another purpose without consent.
  • APP 11 (Security): You must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. This is the most operationally significant APP for a self-hosted setup - it requires active security measures, not just good intentions.
  • APP 12 (Access): Individuals have the right to access personal information you hold about them.
  • APP 13 (Correction): Individuals can request correction of inaccurate information.

Where Self-Hosting Changes the Risk Picture

When you store other people's personal information in a commercial cloud service, the cloud provider's security infrastructure, certifications, and incident response capabilities form part of your security posture. With self-hosting, that responsibility sits entirely with you. This is not a reason to avoid self-hosting, but it is a reason to be deliberate about security measures.

For a covered entity, APP 11 requires 'reasonable steps' to protect personal information. What is reasonable depends on the sensitivity of the data and the size of the organisation. A sole-practitioner health service with a NAS holding patient records has a different 'reasonable steps' standard than a large health network. Depending on the circumstances, reasonable steps may include:

  • Encryption at rest, where the NAS platform and selected storage configuration support it
  • Encrypted transmission (HTTPS for any web access, VPN or Tailscale for remote access rather than plain HTTP)
  • Access controls (separate user accounts with minimal permissions rather than everyone using admin credentials)
  • Backup (a NAS with no backup is a single point of failure for regulated data)
  • Physical security (a NAS accessible to anyone in a building is not secure)

Data Breach Notification Obligations

The Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act) requires covered entities to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if a data breach is likely to result in serious harm. Small businesses exempt from the Privacy Act are also exempt from the NDB scheme.

If you are covered, notification is required for an eligible data breach involving unauthorised access to or disclosure of personal information, or loss where unauthorised access or disclosure is likely, when serious harm is likely and remedial action has not prevented that risk.

A ransomware attack involving exfiltration of client personal information could trigger NDB obligations; a covered entity must assess whether the eligible-data-breach criteria, including likely serious harm, are met. An attack that encrypts data without confirmed exfiltration may or may not trigger it, depending on the circumstances. If there are reasonable grounds to suspect an eligible data breach, conduct a reasonable and expeditious assessment; notify once there are reasonable grounds to believe an eligible data breach occurred, unless an exception applies.

2026 Privacy Act Reforms

The Australian government has been progressing significant reforms to the Privacy Act. Key proposed changes relevant to small businesses and self-hosters include:

  • Small business exemption review: The $3 million threshold and the exemption itself are under review. Proposed reforms may remove or significantly narrow the exemption, bringing more small businesses under the Act's obligations. As of mid-2026, this has not been legislated but remains a live policy issue.
  • Individuals have had a statutory cause of action for serious invasions of privacy since 10 June 2025; this tort is distinct from the broader direct right of action considered in the Privacy Act Review. This increases liability exposure for covered entities.
  • Children's privacy: Stronger protections for children's personal information are proposed, with direct implications for businesses collecting data from minors.

The OAIC website is the authoritative source for current reform status. Any business that may currently be borderline on the small business exemption should monitor these reforms closely.

Practical Steps for Home and Small Business NAS Users

Regardless of whether you are legally covered by the Privacy Act, good data handling practices protect you and the people whose data you hold:

Encryption at rest Enable Synology Encrypted Shared Folder or QNAP volume encryption for folders holding third-party personal data
Access controls Separate NAS user accounts per person with minimum required permissions. No shared admin credentials.
Remote access Use Tailscale or a VPN rather than direct port forwarding. Avoid HTTP access to NAS from the internet.
Backup Maintain at least one offsite backup of regulated data. A NAS with no offsite backup is a single point of failure.
Audit logging Enable NAS access logging. Where supported, enable file-access logging appropriate to the NAS platform and services in use.
Retention policy Define how long you keep personal data and delete it on schedule. Keeping data indefinitely 'in case it is useful' creates unnecessary risk.
Privacy policy If covered by the Act, publish a Privacy Policy and keep it current. The OAIC publishes guidance for developing an APP privacy policy.

Related reading: our NAS buyer's guide.

Use our free Cloud vs NAS Cost Calculator to compare cloud storage against owning a NAS.

Related reading: our NAS explainer.

Does Australia's Privacy Act apply to a home NAS storing family photos and documents?

No. The Privacy Act applies to organisations handling other people's personal information in a business context, not to individuals managing their own data. A person storing their own family's photos, documents, and personal files on a home NAS has no Privacy Act obligations.

I run a small business with client records on a NAS. Am I covered by the Privacy Act?

It depends on your annual turnover. If your business has turnover of $3 million or less, it is generally not covered unless an exception applies. One exception is a business that provides a health service and holds health information; handling health information alone is not the complete statutory test. If your turnover is above $3 million, the Australian Privacy Principles apply to all personal information you hold, including data stored on a NAS. When in doubt, seek advice from a privacy lawyer or the OAIC.

Is self-hosting more or less legally risky than using a cloud service for business data?

The Privacy Act's obligations are the same regardless of where data is stored. What changes is who is responsible for security. With a cloud service, the provider's security measures form part of your compliance posture. With self-hosting, all security measures are your responsibility. Neither is inherently more or less risky legally - the risk depends on how well you implement security in either case. A well-secured NAS can meet the same 'reasonable steps' standard as a well-configured cloud service.

What should I do if my NAS is breached and I hold client personal data?

If you are a covered entity under the Privacy Act: assess whether the breach is likely to result in serious harm to individuals. Take all reasonable steps to complete the assessment within 30 calendar days; if there are reasonable grounds to believe an eligible data breach occurred, notify the OAIC and affected individuals as soon as practicable. Document your assessment and notification process. If you are exempt from the Act but have contractual obligations to clients, check those contracts for breach notification requirements. Regardless of legal obligations, notifying affected individuals is good practice and builds trust.

Does the Australian Privacy Act cover data stored on a NAS overseas?

The Privacy Act applies to Australian organisations and their data handling practices regardless of where data is stored. APP 8 applies when an APP entity discloses personal information to an overseas recipient, not merely because information is stored offshore. Overseas cloud storage may in limited circumstances be a use rather than a disclosure where the entity retains effective control. You must take reasonable steps to ensure the overseas recipient complies with the APPs. For a small business storing data on a NAS in their home in Australia, this is not relevant - the NAS is in Australia.

Securing a self-hosted setup against data breaches starts with proper remote access controls. For Australian users, especially those on CGNAT-affected NBN connections, Tailscale is the most practical secure remote access solution.

What to read next