Journal/Business

Data Breaches Are Now an SMB Problem: Privacy Act Reforms and Your Web Forms

Big breaches make the news, but the Privacy Act reforms reach the contact form on a ten-page site. Here is where customer data actually leaks from a small business website, and an afternoon of fixes.

Feature image for data-breaches-are-now-an-smb-problem-privacy-act-reforms-and-your-web-forms

Breaches are not just a big-company problem any more

When a data breach makes the news it belongs to a telco, a health insurer or a retailer with millions of customers. That coverage has taught a lot of small business owners that breaches happen to someone else. The Privacy Act reforms say otherwise, and so does the way most small business websites handle customer data day to day.

We covered what the Privacy Act reforms mean for Australian websites when they landed: the new tort for serious invasions of privacy, the tiered penalties, the pressure on the small business exemption. This piece is about what happens after someone fills in a form on your site. Where does that information go, and how many copies of it exist by the end of the month?

This is practical guidance from people who build websites, not legal advice, so if you handle health records or financial details, talk to a privacy lawyer as well.

Where customer data leaks on an ordinary site

Almost nobody running a small business site is losing data to a sophisticated attack. They're losing it to habits nobody has looked at since the site went live. When we take over an existing site, the same few things come up again and again.

The most common is the contact form that emails every submission in plain text. Name, phone number, address, and whatever the customer wrote in the message box, all landing in an inbox that is shared, forwarded, and synced to three phones. Each of those is a copy you don't control. Meanwhile the form plugin is usually storing every submission in the website database as well. Years later the site holds a searchable list of everyone who ever enquired, and most owners have no idea it's there.

Then there are the exports. Someone pulled the customer list to build a mailout or fix a spreadsheet, and it's still on their laptop, on the backup of that laptop, and possibly in a personal cloud drive. Exports feel temporary. They never are.

Session recording tools, heatmaps and advertising pixels can capture what people type before they hit submit, depending on how they're configured. Owners install them to understand conversions and don't realise form contents may be going to a third party.

And then there's access. One login for the CMS, the booking system, the email tool and the payment dashboard, with the password in a group chat. Nobody can tell who did what, and you can't remove one person without resetting it for everybody. People leave and their logins don't. The receptionist who left in March still has a working CMS account.

None of that needs a hacker. A lost phone or a phishing email will do.

What the law now expects of you

Under the notifiable data breaches scheme, if personal information you hold is lost or accessed without authorisation, and that's likely to cause serious harm to the people involved, you're expected to assess it quickly and notify both the affected individuals and the regulator. The reforms sharpened the penalties and made it easier for individuals to take action themselves.

So if the shared inbox with three years of enquiries is compromised, you may be legally obliged to contact every person in it and explain what happened. That conversation costs far more, in time and in trust, than fixing the form would have.

The small business exemption doesn't change much here. It's under review, your larger clients are already asking about data handling in their procurement questionnaires, and your customers don't care about turnover thresholds. They care whether you looked after their details.

The afternoon checklist

Most of this is fixable in one working session with your developer. This is the order we go through it.

  • Collect less. Go through every form and remove fields nobody acts on. If the booking form asks for a date of birth and nobody uses it, delete the field.
  • Keep it for less time. Turn on automatic deletion of stored submissions after thirty or ninety days, depending on how you use them. If the tool can't do that, it's the wrong tool. The same goes for the inbox: an archive folder is still a copy.
  • Stop emailing the whole submission. Have the form send a notification with a link to the secure record instead of the customer's details. If your platform can't, at least route submissions to a dedicated mailbox with restricted access.
  • Find every copy. Website database, CRM, mailing list tool, accounting system, personal laptops, shared drives. Write the list down.
  • Mask your pixels. Check session recording and analytics tools and make sure form fields are masked. Most tools support it. It's rarely on by default.
  • One login per person, two-factor on everything. Every system that holds customer data, including email, hosting and the domain registrar. Then delete the shared accounts. This one step blocks most of the ordinary account compromises we deal with.
  • Run an access audit. Who has access to what, remove anyone who has left, cut back anyone with more than their role needs. Put a quarterly reminder in the calendar.
  • Write the bad-day plan. One page: who gets called, how you work out what was exposed, who decides whether it's notifiable, who contacts the affected people. Much easier to write while calm.

Most of these are settings, not development work. The ones that need code, like changing how forms deliver submissions, are small jobs on a well-built site.

How a well-built site handles this from the start

When we build a site or a custom application, the data path gets decided up front. Forms deliver to a controlled destination. Retention is set on day one. Access is per person from the first login, and session recording is configured with masking before it's switched on. The site ends up compliant because it was built that way, rather than because someone remembered later.

It also helps when a bigger client sends a security questionnaire. Being able to answer "where does customer data live and who can see it" in two sentences puts you ahead of most businesses your size.

If your site is older, this is the kind of work that belongs in an ongoing support and maintenance arrangement. Retention windows drift, plugins change their defaults, staff come and go, and a quarterly check stops an afternoon of fixes from turning back into a year of accumulated risk.

If you only do one thing after reading this, open the inbox that receives your contact form and see how far back it goes. That's your exposure. We review existing sites for exactly this as a fixed piece of work, and we build it into every new site from the first form. If you'd like a plain look at where your customer data lives and what it would take to tidy it up, get in touch.

Filed under: Business. Last edited 8 October 2026. Send corrections.
§ Read next
/ Business
Should You Vibe-Code Your Own MVP? An Honest Answer
/ Business
Google Zero-Click and AI Overviews: Why Your Traffic Fell and What Still Works
§ Business services we offer

§ Subscribe

One letter,
once a month.

Studio essays, postmortems and the occasional Risograph print drop. No tracking pixels, no automation funnels.