Illustration of interconnected secure devices, documents, and data analytics around a central security shield.

Unifying customer data and complying with the Australian Privacy Act

Discover a practical three-stage framework to unify customer data across legacy systems and stay compliant with the Australian Privacy Act.

state of data analytics report for leaders and businesses
Get the State of Data and Analytics report.

See why improving data quality is the #1 priority for leaders. Get this and other strategic insights from 10,000+ business, analytics, and IT professionals.

The Australian privacy principles that matter most for data unification

Principle What it means in practice
APP 3 (Collection) Often called data minimisation, this means you can only collect personal information that's reasonably necessary for what you're doing. 

"It might be useful one day" isn't a good enough reason to bring data into your unified system.
APP 5 (Notification) Customers need to be told what you're collecting and why, generally before or at the point you collect it. 

Your privacy policy must also align with how you’re using the data.
APP 6 (Use and disclosure) Information collected for one purpose can't just be reused for a different one unless the customer would reasonably expect it.
APP 8 (Cross-border disclosure) If personal information is stored or processed outside Australia, including by an offshore vendor or cloud provider, your business is still responsible for what happens to it.
APP 10 (Data quality) Information you hold has to stay accurate, up-to-date, and complete for the purpose you're using it.
APP 11 (Security) You have to take reasonable data protection steps to prevent misuse, loss, and unauthorised access. 

This is where added layers like Salesforce Shield typically come in.

Questions to ask when comparing data unification vendors

Question to ask Why it matters
Can you track what data is being collected and why? (APP 3) If requested, you should be able to quickly and easily explain the information you’re holding.
How easy is it to update privacy policies and data collection notices? (APP 5) Customers need to be notified when you’re collecting data and how it will be used.

If your use of data changes, it should be easy to revise the wording of those notices.
How is user access managed? (APP 6 and APP 11) You should be able to restrict access to customer data based on teams and employee roles.
Where will the vendor store and process data? (APP 8) Offshore processing of data can become a compliance issue. Confirm whether this is a potential issue and how it’s managed.
How is inaccurate or duplicate data managed? (APP 10) Drawing information from multiple sources increases the risk of inaccuracy. 

A unified system should provide only the most up-to-date information and eliminate duplicate records.
Would the vendor be able to produce a full record of who accessed or changed a piece of data and when? (APP 11) This capability determines how fast you can investigate and respond if something goes wrong, which matters under the Notifiable Data Breaches scheme.
What's the vendor's track record with projects of a similar scale? Ask for examples and references of similar-sized projects. This is one of the strongest indicators of a vendor’s capabilities with respect to privacy laws.
What does a realistic implementation timeline look like, and can it be phased? If you're working to a fixed deadline, ask for a detailed plan of how the vendor can meet your end date.
Data 360 platform in a ssot dashboard
Say hello to Data 360.

Data 360, the only data platform native to Salesforce, unlocks and harmonises data from any system — so you can better understand your customers and drive growth.

The Salesforce Professional Services team is extremely knowledgeable and did a great job of meeting our timeline

Michael Xu
Head of Marketing Technology & Performance, Latitude
build a data culture with a data and ai playbook
Put data at the centre of every decision.

Transform your company by infusing your data with AI and building a thriving data culture.

FAQs

Unifying customer data means that you connect the information held across your sales, service, marketing, and digital channels into one consistent, accurate view of each customer. This means every team works from the same picture instead of piecing it together from separate systems.

Most businesses with an annual turnover under $3 million are currently exempt from the Australian Privacy Act, though some are covered regardless of turnover, depending on what they do. Health service providers and businesses dealing with credit reports, for example, must comply with the Act. That exemption is under review as part of ongoing government reform, so check your specific position.

You don’t always need explicit consent, but you do need a lawful basis and a use that a reasonable customer would expect based on your privacy policy. If unifying data creates a use case that wasn't previously disclosed, update your notice or seek consent before proceeding.

APP 8 means that if personal information is stored or processed outside Australia, whether through an offshore vendor, a specific cloud region, or an AI tool, your business remains responsible for ensuring the recipient handles it in line with the APPs. Check how vendors handle this requirement.

The platform itself usually isn't the risk. The risk comes from what you put into it. The risks develop when you collect more than you need, lose track of where data came from, or connect records for a purpose customers never agreed to. A well-governed platform makes these risks easier to manage, provided the underlying data practices are sound.