Security
Personal information you did not mean to collect
Analytics, forms and embedded widgets can each independently collect personal information a business never deliberately decided to hold.
A website can collect personal information a business never deliberately decided to hold at all — not through a form someone consciously filled in, but incidentally, through analytics scripts, embedded third-party widgets, and server logs quietly recording details nobody explicitly asked for. This page sets out the general shape of that risk. It is not a substitute for advice from a qualified privacy adviser, and the specifics of Australian obligations here should be confirmed against current legislation and guidance rather than this page alone.
What actually counts as “personal information”: the reasonably identifiable individual test
The Privacy Act’s own test is whether information is about an identified individual, or an individual who is reasonably identifiable — a lower bar than requiring a name attached. An IP address, a device identifier or a combination of otherwise-unremarkable details is not automatically personal information, and it is not automatically excluded from being personal information either; it depends on whether it could reasonably be used, alone or combined with other information a business holds or can access, to identify someone. This is genuinely a case-by-case question rather than a fixed list, which is exactly why the sweeping claim made on some competitor pages — that an IP address “is” or “is not” personal information — is itself an overstatement in either direction. What this page can say plainly is the test being applied; what any specific tool’s specific data actually satisfies is a question for a privacy adviser looking at the real configuration.
Where incidental collection commonly happens
Analytics tools can capture more than a business realises by default — IP addresses, device details, and sometimes far more depending on configuration. Embedded third-party widgets — chat tools, booking systems, review platforms, social media embeds — each bring their own separate data collection, frequently to servers outside Australia, that a business may never have reviewed in detail. Server access logs, kept by nearly every hosting provider by default, record visitor IP addresses and browsing activity as a matter of course.
Why this matters under Australian privacy law, in general terms
The Australian Privacy Principles govern the collection, use, storage and disclosure of personal information by entities the Privacy Act applies to. A small-business exemption currently exists for many smaller operators, though its future status is a live and shifting question — see website terms and a privacy policy are different documents for the fuller detail on that exemption and its reform status, and confirm the current position with a privacy adviser rather than assuming it will remain unchanged. Even where an exemption currently applies, collecting more personal information than a business intended, without knowing it, is a genuine business risk independent of the exemption’s legal reach.
Why the small-business exemption does not reach every small business
The turnover-based exemption discussed above does not apply at all to a defined set of entities, regardless of size, and this list is fixed by the Act rather than a judgement call: health service providers, of any size, that provide a health service and hold health information otherwise than as an employee record; businesses that trade in personal information for a benefit or consideration; credit reporting bodies; recipients of tax file number information; and providers of services under a Commonwealth contract. A business in any of these categories is bound by the Australian Privacy Principles in full, however small its turnover.
This matters more here than the general caution above suggests, and it is worth being direct about why. A clinic, an allied health practice, or a hearing care provider reading a general page about a turnover exemption would reasonably conclude that turnover is what determines its position — for a health service provider, turnover almost never does, because the health-provider carve-out applies regardless of size. And the exact tools this page is about — a booking widget, an intake form, a contact form asking what someone needs help with — are precisely where a health-adjacent business collects health information incidentally, often without the collection ever being framed internally as “holding health information” at all. A booking form asking why an appointment is needed, or a contact form inviting a description of a hearing concern, is collecting exactly the category of information this carve-out is about.
What a general audit looks like
Listing every tool embedded on the site that could plausibly collect visitor data — analytics, chat, booking, marketing pixels, forms — and checking, for each one, what it actually collects and where that data is stored. This is a genuinely worthwhile exercise for any business, regardless of its current exemption status, because the practical exposure exists whether or not the law currently reaches it.
What this page does not attempt to resolve
Whether a specific business currently falls under the small-business exemption, what its specific obligations are if it does not, and what a specific incident or gap would require under notification obligations, are all questions for a qualified privacy adviser, informed by a business’s actual circumstances rather than a general web page.
One thing worth checking today, specifically
If any form on the site asks what a visitor needs help with, or what symptom or concern brings them in, that field is worth reviewing against the health-provider carve-out above before assuming turnover settles the question.
Where to go from here
The wider legal and privacy content on this site, and a qualified privacy adviser, are the appropriate next step for anything specific to a business’s own data-handling position — see industries for sector-specific privacy considerations where they exist.
Evidence for this page
This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.
- Entity this page targets
- personal information collected without meaning to
- Measured Google volume
- no data
- Keyword difficulty
- no data
- Advertiser cost per click
- no data
- AI assistant volume
- no data
- Advertiser competition
- no data
- Measured on
- 3 August 2026
- Search results inspected for intent
- No
Source: research/outer-volume-au.json · DataForSEO Google Ads search_volume and Labs bulk_keyword_difficulty, location_code 2036 (Australia), language en · pulled 3 August 2026.
Provenance
Written by Australian Website Design. Published 2026-08-03, last updated 2026-08-04. Reviewed by legal-compliance on 2026-08-04.
Sources
- Outer-cluster demand measurement (this site) —
research/outer-volume-au.json - Privacy Act 1988 (Cth), including the Australian Privacy Principles and the small-business exemption and its carve-outs (accessed 2026-08-03)