Skip to main content
DEADLINE · 10 DECEMBER 2026

Six Privacy Act obligations. One working call. Sorted before 10 December 2026.

Most owners only know about one of the six things regulators, insurers and courts now expect. I sort all six with you, on one working call. AU$5,997 one-time, with 3 months of Titanos Monitor included free — versus ~AU$18,000+ for a comparable Vanta-plus-consultant setup in year one.

Built for Australian SMBs (5–50 staff) on Squarespace, WordPress, Microsoft 365, and Google Workspace. Plain English on the call. No jargon, no PDF-only hand-off. Health providers — clinic, allied health, pharmacy, any size — are already covered by the Privacy Act. There is no small-business exemption for health.

GET COMPLIANT · AU$5,997BOOK A FIT CALL FIRST

14-day refund if no deliverable has been issued. Monitoring cancellable any time. Read full terms ›

Scoped enquiry → invoice within 1 business day → pay by card via Stripe · 14-day refund if no deliverable has been issued

ABN 34 318 502 254 · Australian-owned · 3,600+ unique AU/NZ/SG businesses in the scan corpus · Methodology

See the kind of documentation this engagement produces — my own evidence pack, published in full →

Not sure you have a problem? The free scan doubles as a compliance gap snapshot — start there, no card, no commitment. Free scan →

What Happens on the Call

90 minutes. Screen-share. I apply every change with you, live — not a PDF you have to figure out later.

1
I walk you through your gap report

The findings I prepared for your business — in plain English, no jargon. You'll know exactly what's missing and why it matters before I touch a single setting.

2
I apply every change together with you, on screen

Privacy policy live. Breach plan drafted. SPF/DKIM/DMARC records in your DNS. Two-factor rolled out. Data map completed. AI disclosure added. All six obligations — done by the end of the call, not homework for later.

3
You leave with your evidence pack scoped

Every gap assigned and the fixes underway. The signed attestation letter lands at your 30-day review, once the fixes are verified — a one-page proof you can hand to a regulator, your insurer, or an enterprise client asking for it.

4
3 months of Titanos Monitor, free

Your business's exposure changes every month. You keep watching it without lifting a finger for 3 months, then AU$149/mo only if you choose to continue — and I'll flag anything new that needs attention.

Five Legal Pressure Points

Ordered by what hits an SMB owner soonest, not chronologically. The compliance pack covers all five in one pass.

LIVE NOW

Your customers can sue you directly

Since 10 June 2025, an individual whose data you seriously mishandle can sue you under the new privacy tort — no regulator, no OAIC queue. It applies even if your turnover currently exempts you from the rest of the Act.

LIVE NOW

Your insurer can refuse the claim

Cyber insurers increasingly deny breach claims when baseline controls weren’t in place — things like two-factor login and keeping software up to date (the Australian government’s Essential Eight checklist). Policies commonly condition cover on documented security hygiene. Without a signed record, you’re relying on goodwill at the worst possible moment.

10 DECEMBER 2026

ADM disclosure required in your privacy policy

Automated decision-making — including AI tools your business uses — must be disclosed in your privacy policy with affected-decision categories, types of personal information used, and process explanation. Penalties up to AU$50M for serious or repeated interference.

TRANCHE 2 · COMING

Small-business exemption disappears

The second reform tranche is positioned to remove the AU$3M turnover exemption, pulling roughly 2.3M additional AU SMBs into Privacy Act scope. If you’re currently exempt, that protection has a sunset on it.

LIVE NOW

The regulator is now checking proactively

Since January 2026 the OAIC has run compliance sweeps across sectors including real estate, pharmacies, and licensed venues — examining businesses before any complaint is made. “We’ve had no problems” is no longer the same as “we won’t be looked at.”

Also on the calendar
· 4 March 2026 — Mandatory IoT security standards live. Cascades to any business reselling or operating connected devices.
· 2 August 2026 — EU AI Act enforcement begins. Applies to AU companies with EU customers.

Does the ADM rule apply to you?

Two questions. No data collected, nothing submitted.

Is your business a health service provider (clinic, allied health, pharmacy, any size)?

What the Engagement Looks Like

Six steps from scan to signed attestation. No PDF-only deliverable, no opaque hand-offs.

Intake + External Scan

You complete a 10-minute intake form (company, hosting, identity provider, MFA + backup state, what’s driving compliance). I run an external scan on your domain — a look at what an attacker can see about your business from the outside, with version-by-version CVE matching against the public NVD database. Output: scan JSON plus a documented record of what you affirmed about internal posture.

Evidence Pack

Within 3 business days I send your draft pack (~17pp, 13 sections) — your privacy policy + ADM disclosure draft, your NDB runbook (the step-by-step plan for the day you get breached, so you hit the mandatory notification deadline instead of panicking), vendor risk register (a one-page record of every third-party service that touches your customer data), and scan findings split by what I directly verified vs what you affirmed. The final evidence pack — with everything we applied together — lands within 24 hours of the working call, regulator-ready as a single PDF.

90-Minute Implementation Call

Screen-shared working session. I apply changes live: SPF / DKIM / DMARC / CAA records, Microsoft 365 or Google Workspace security defaults, MFA enabled across team, privacy policy + ADM disclosure deployed to your live site, breach-response runbook saved to your shared drive. You keep admin access throughout — every change is yours.

What You Control vs Your Host

Some controls live on Squarespace / Shopify / Xero / Cliniko — not in your hands. You get a one-page escalation list: exactly what to ask your host to fix, with template wording. Anything they decline gets documented as 'reasonable steps taken' for your attestation.

30-Day Review Call + Attestation

I audit what shipped: policy is live, MFA is enforced, runbook is shared. Anything that drifted gets re-applied. You receive a signed letter you can hand to a regulator, insurer, or enterprise client stating exactly what was checked and fixed against the Australian government’s baseline security checklist (Essential Eight, Maturity Level 1), plus a Privacy Act compliance posture letter.

Months 1–3 · Titanos Monitor Free

Monthly external scan with delta report, CVE alerts matched to your stack, and a regulatory-update briefing — same product as Titanos Monitor, included free for 3 months covering your 30-day review and beyond. After month 3 it continues at AU$149/mo only if you opt in — no silent continuity. I'll email you the exact date before any meter would start.

You Control Some · Your Host Controls the Rest

Your hosting service controls some things. I give you exactly what to ask them to fix, and document the rest as "reasonable steps taken."

You Control

I apply these with you on the working call.

  • Privacy policy — written plain English, covering what you hold, why, who sees it, plus the AI/automated tools disclosure
  • Breach-response runbook — a step-by-step plan for the day you get hacked (legally required under NDB)
  • DNS hygiene (SPF, DKIM, DMARC, CAA records) — so scammers can't impersonate your domain
  • Microsoft 365 / Google Workspace security defaults + MFA enabled across your team
  • Vendor risk register — one page mapping every third-party service that touches customer data
  • Signed government security checklist (Essential Eight, Maturity Level 1)
  • Staff access management

Your Hosting Provider Controls

I give you exactly how to escalate.

  • TLS/SSL certificate management on hosted sites
  • HSTS headers on Squarespace / Shopify / Wix
  • Server-side security configurations
  • DDoS protection on hosted infrastructure
  • Database security on SaaS like Xero, Cliniko, Vend

One Engagement · Done With You

No tiers. No PDF-only option. One done-with-you engagement where I apply the changes together with you on a 90-minute working call — 3 months of monitoring included, plus regulatory briefings through the engagement whenever the rules move.

DONE WITH YOU

Privacy Act + Government Security Checklist — Done With You

Comparable Vanta + DPO contractor: ~AU$18,000+ in year 1

AU$5,997one-time · 3 months of Monitor included freeDrafting before the call · 90-min implementation working call · 30-day review + attestation signed · 3 months of monitoring + quarterly re-scans. Not 90 minutes total — 90 minutes is the central session.

Six obligations sorted in one pass: privacy policy, breach plan, email security, login security, data mapping, and AI disclosure. Everything you need to demonstrate “reasonable steps” under the Privacy Act and the Australian government's baseline security checklist (Essential Eight, Maturity Level 1), applied together with you in a single working call — then maintained for the 3-month monitoring window.

  • A proper privacy policy written and deployed live — covers what customer data you hold, why, how it's stored, who it's shared with (not a copy-paste from 2015)
  • A breach-response runbook integrated into your shared drive — the step-by-step plan for the day you get hacked, so you hit the mandatory NDB notification deadline instead of panicking
  • Email security records applied on the call (SPF, DKIM, DMARC) — so scammers can't impersonate your business domain
  • Login security hardening applied with you (Microsoft 365 / Google Workspace security defaults + MFA across your team)
  • Vendor risk register — a one-page record of every third-party service touching your customer data, so you know exactly what you hold and where it lives
  • AI + automated tools disclosure added to your privacy policy — the new rule: if you use AI on customer info, you have to say so
  • 90-minute implementation working call — I apply all six with you on a screen-share, no PDF-only hand-off
  • Signed letter documenting the reasonable steps you've taken under the Privacy Act and the Australian government's security checklist (Essential Eight, Maturity Level 1) — the evidence trail a regulator, insurer, or enterprise client looks for (not a guarantee against complaints — those are decided on the facts of an incident)
  • 30-day review call to re-audit anything that drifted, then sign the attestation
  • 13-section evidence pack documenting all of the above (~17pp) — proof of work for your insurer or regulator
  • External scan with you-vs-host responsibility split (same engine as the free scan)
  • Sample of the pack shape — my own, published in full at /our-evidence-pack
  • 3 months of Titanos Monitor included free (then optional at AU$149/mo — opt-in, no auto-charge)

14-day refund if no deliverable has been issued. Monitoring cancellable any time. Read full terms ›

Scoped enquiry → invoice within 1 business day → pay by card via Stripe · 14-day refund if no deliverable has been issued

How the Monitoring Works After the Pack

The first 3 months of Titanos Monitor ship with the pack — automatic, no extra charge. What happens at the end of month 3 is the part most vendors get wrong.

Months 1–3

Free + automatic

Monthly external scan, delta report, CVE alerts matched to your stack, and a regulatory briefing land in your inbox. Same product as Titanos Monitor — included with the pack.

7 days before month 4

I email you the exact date the meter would start

Plain-English email: "Your 3 included months end on {date}. If you want it to continue at AU$149/mo, subscribe here. If you do nothing, it simply stops — no charge, no action needed."

After month 3

Opt-in continues, silence stops it

Default mode: no charge unless you affirmatively subscribe. No auto-charge unless you choose to keep it. No retention sequence. No coupon games.

Questions I Get

Want to see your current security exposure first? Free scan →

Need an AI build instead? AI Implementation for Business →

Ship Compliance Before the Deadline

One engagement, one outcome: all six obligations sorted together — privacy policy, breach plan, email security, login security, data mapping, and AI disclosure — with every change applied on the 90-minute working call, a signed Privacy Act + Essential Eight ML1 attestation letter, and the 13-section evidence pack as proof of work.

GET COMPLIANT · AU$5,997BOOK A FIT CALL FIRST

14-day refund if no deliverable has been issued. Monitoring cancellable any time. Read full terms ›

Scoped enquiry → invoice within 1 business day → pay by card via Stripe · 14-day refund if no deliverable has been issued

Built with AI assistance. Every document, every scan finding, and every attestation is reviewed and signed off by Kyle Deligny (ABN 34 318 502 254) before it reaches you. My ABN is on every page — the accountability is mine.

Book Free AI Audit Call