Expert-reviewed · Australian-owned · ABN-verified. New privacy laws take effect 11 December 2026. Penalties up to AU$50 million.
We do the diagnostic, give you the evidence pack, and apply the changes together on a 90-minute working call. Built for Australian SMBs on Squarespace, WordPress, Microsoft 365, and Google Workspace.
ABN 34 318 502 254 · Australian-owned · 3,600+ unique businesses in our scan corpus · Methodology
No tiers. No PDF-only option. One done-with-you engagement where we apply the changes together on a 90-minute working call — and stay with you for 12 months of regulatory briefings and quarterly re-scans.
Everything you need to demonstrate “reasonable steps” under the Privacy Act and Essential Eight ML1, applied together with you in a single working call — then maintained for 12 months.
Four legal pressure points stack between now and 11 December 2026. The compliance pack covers them all in one pass.
Already in effect. Individuals can sue directly for serious invasions of privacy — no need to wait for the OAIC.
Connected-device makers and importers face baseline security requirements. Cascades to any business reselling or operating IoT.
Applies to AU companies with EU customers. Transparency, risk-classification, and conformity obligations.
Automated Decision-Making used in any business process must be disclosed in your privacy policy with affected-decision categories, types of personal information used, and process explanation. Penalties up to AU$50M.
Pulls ~2.3M additional AU SMBs into Privacy Act scope. The current AU$3M turnover exemption is expected to be repealed in the second reform tranche.
Six steps from scan to signed attestation. No PDF-only deliverable, no opaque hand-offs.
We map your external attack surface and feed the findings into the engagement pack.
We send your evidence pack (~17pp, 13 sections) for your records — a regulator-ready artifact.
We apply the changes together: DNS hygiene, M365/Workspace hardening, privacy policy + ADM disclosure deployed, NDB runbook integrated.
Every 90 days we re-scan and send a delta report. New exposures get flagged; remediated items get logged.
We audit what shipped, confirm policy changes are live in customer-facing surfaces, and tune the runbook.
Signed compliance attestation letter plus 12 months of industry-specific regulatory briefings.
Your hosting service controls some things. We tell you what to ask them to fix, and document the rest as “reasonable steps taken.”
We apply these together on the working call.
We tell you exactly how to escalate.
Built by an Australian operator. Reports stay in Australia. No US-headquartered data processors. Kyle Deligny, ABN 34 318 502 254.
Want to see your current security exposure first? Free scan →
Need an AI build instead? AI Implementation for Business →
One engagement, one outcome: an evidence pack a regulator accepts as “reasonable steps,” with the changes already applied together on the working call.
Buy Done-With-You · AU$5,997 Book a 15-min first