Privacy is turning into one of those compliance jobs small health and fitness businesses can no longer wave away. This month AUSactive has been telling gym operators, studio owners and personal trainers to review how they handle client information before Australia's privacy rules tighten further through 2026. The same warning lands just as squarely on physiotherapy clinics, dietitians and exercise physiologists, who hold some of the most sensitive data of anyone their clients deal with.

For years the working assumption for a lot of small operators was straightforward: the Privacy Act is a big-business problem, and we sit under the threshold. That assumption is on its way out. It's worth understanding why before it costs someone a very bad week.

What has actually changed

The first round of reforms became law in late 2024 as the Privacy and Other Legislation Amendment Act, which received Royal Assent on 10 December 2024. A few parts of it matter to anyone holding client records.

The one to know is the new statutory tort for serious invasions of privacy, which commenced on 10 June 2025. In plain terms, an individual can now sue over a serious invasion of privacy that was intentional or reckless, where they had a reasonable expectation of privacy. The detail that catches operators out: this right sits outside the usual size thresholds, so being a small business does not put you beyond its reach.

Alongside it, the privacy regulator (the OAIC) picked up stronger enforcement powers and a tiered set of penalties, and the security obligation in the Australian Privacy Principles was sharpened. Businesses covered by the Act are expected to take reasonable technical and organisational steps to protect the information they hold, not just promise to in a policy nobody reads.

The "we're too small" gap is closing

Most small operators have leaned on the small business exemption, which currently keeps organisations under roughly three million dollars in annual turnover outside much of the Act. The government has flagged a second round of reforms expected to remove or wind back that exemption, and the OAIC has said publicly it no longer sees a blanket carve-out as appropriate given the data risks businesses of every size now carry.

There's no firm commencement date for that second round yet, so this isn't a reason to panic. It is a reason to build sensible habits now rather than scramble when a bill lands. The businesses that will struggle are the ones treating good data practice as something they'll sort out later.

Three questions worth answering this month

AUSactive boils the preparation down to three questions. They happen to be the right ones for a clinic too, and you can work through them without a lawyer on retainer:

  • What client information do you actually collect, and why do you collect each piece of it?
  • Where is that information stored, and who in your business can get to it?
  • Does your privacy policy still describe what you genuinely do with data, or was it written years ago and forgotten?

If you cannot answer those cleanly today, that gap is the work. Most operators find the second question is the uncomfortable one, because the honest answer is "in a few different places, and more people than I'd like".

Practical data hygiene without a compliance project

You don't need a consultant and a six-week programme of work to make real progress. A handful of habits do most of the heavy lifting.

Collect less. Every field you capture is something you then have to store, secure and eventually delete. If you're not using a piece of information for a clear reason, stop asking for it.

Get client data into one place. The genuine risk for small operators is not a sophisticated hacker. It's client details scattered across a spreadsheet, a booking tool, a messaging app, a personal notes app and a filing cabinet, where nobody can say with confidence what is held or where. Consolidation is a privacy win before it's a convenience win.

Control who can see what. Shared logins are the classic weak point. When staff come and go, the account details often stay behind. Individual access, removed promptly when someone leaves, closes off a lot of quiet exposure.

Decide how long you keep things. Data you no longer need is pure liability. Set a rough retention rule and actually delete to it, rather than hoarding old records indefinitely.

Have a plan for the bad day. If something does go wrong, a one-page note covering who you call and what you do first beats improvising under pressure. You hope never to use it.

None of this is legal advice, and if you hold detailed health records it's worth a proper review with someone qualified. But the groundwork above is operational, not legal, and it's the part only you can do.

Give client data a single, tidy home

Kinecta keeps each client's intake, notes, check-ins, messages and progress in one record instead of five apps, so you can actually answer what you hold and where it sits. Free for your first 14 days.

Start Free Trial

Where the data lives is half the answer

Go back to those three questions and notice how much easier they get when client information has a single home. When intake forms, session notes, check-ins, messages and progress history all sit in one client record rather than spread across personal phones and spreadsheets, "what do we hold and where" stops being a guessing game. Messaging that happens inside the system stays out of a trainer's personal chat history. Access follows the person, not a shared password.

We built Kinecta that way because practitioners and trainers kept telling us their real problem was fragmentation: the same client existed in four tools and no single source of truth. That fragmentation is also, it turns out, the thing that makes privacy hard. Fixing one quietly helps the other.

Trust is the upside, not just risk

It's easy to read all of this as another cost of doing business. Framed the other way, handling client data well is one of the few compliance jobs that clients notice and reward. People are increasingly wary about where their health and personal details end up. Being the operator who can say clearly what you collect, where it lives and who can see it is a genuine mark of trust, and trust is what keeps clients booking.

The rules will keep moving. Operators who get the basics right now, one tidy system and a few sensible habits, will barely feel the next change when it comes.

Related Reading

How to Choose Practice Management Software for Your Allied Health ClinicKeeping Clients Engaged Between Sessions: What Actually Works