Why a buyer now asks about your customer data
Data breach notifications hit an all time high in 2025. Here is what that changed about due diligence, and the three questions an owner should be able to answer before a buyer asks them.
General information only, not financial, legal or taxation advice. Tony Pope holds Queensland Office of Fair Trading licence 4963575.
The short version
- The OAIC received 1,205 data breach notifications in 2025, the highest since the scheme began in 2018 and 8 per cent above 2024.
- Malicious or criminal attack caused 716 of those 1,205, so the majority were not an accident by a staff member.
- A buyer is not auditing your IT. They are pricing the chance of inheriting a problem they cannot see and did not create.
- Three answers cover most of it: what personal information you hold, where it is, and who can still get to it who should not.

The Office of the Australian Information Commissioner received 1,205 data breach notifications in 2025, the highest number since mandatory reporting started in 2018 and 8 per cent up on the 1,112 notified in 2024. 716 of them were caused by malicious or criminal attack. The figures were published on 6 July 2026.
That is the background noise a buyer is now working against. It is why a question that did not appear in a due diligence list three years ago appears in one now.
What the buyer is actually asking
Not whether your systems are good. They are asking a narrower and more commercial question: if I buy this business, am I buying a problem that has already happened and nobody has noticed yet.
It is the same instinct behind asking for the PPSR search and the lease. A buyer cannot inspect everything, so they look for the categories where an unpleasant surprise is both plausible and expensive. Customer data has moved into that category because the notification figures say it is plausible, and because the cost lands on whoever owns the business when it surfaces, not on whoever caused it.
Three answers worth having ready
What personal information do you hold, and why. Names and contact details for quoting and invoicing is one answer. Identity documents, dates of birth, bank details, health information or copies of licences is a different answer with a different risk attached. Most owners are surprised by how much has accumulated in an inbox.
Where does it live. The accounting package, the CRM, the quoting tool, a shared drive, a personal laptop, a filing cabinet in the shed. Name them. A buyer who hears a confident list is being told something about how the business is run generally, not only about data.
Who can still get to it. This is the one that trips people up. Former employees whose logins were never disabled, a former bookkeeper still on the file, a contractor who built the website four years ago and still holds the hosting login. Every one of those is a live access path and every one is fixable in an afternoon.
Why it is worth fixing before you go to market
Not because a buyer will pay more for tidy access controls. They will not.
It is that a discovery in due diligence costs you more than the thing itself. A buyer who finds an ex employee still holding an active login has not just found a login. They have found evidence about how carefully the business is administered, and they will apply that to everything they have not checked. That is the expensive part, and it is entirely avoidable.
What this does not mean
It does not mean buying a security product. It does not mean a compliance certificate, and it does not mean you need to be inside the Privacy Act for any of this to matter. Many businesses with turnover of $3 million or less sit outside the Act under the small business exemption, and the exemption is lost in several situations including health service providers and businesses that trade in personal information. Either way the commercial exposure is the same, because a buyer prices what they might inherit rather than what the Act requires.
The work is mostly administrative: a list, a location, and a clean out of access that should have ended when somebody left.
The short version
Data has become a due diligence line item because the notification numbers made it one. The answer is not a product, it is a list you can hand over without going and finding out first.
If you are eighteen months out from selling, this is a cheap thing to fix now and an awkward thing to be asked about later.
Common questions
Does a small business have privacy obligations in Australia?
It depends on turnover and activity. Many businesses with annual turnover of $3 million or less are outside the Privacy Act under the small business exemption, but the exemption is lost in a number of situations, including where the business provides a health service, trades in personal information, or is a contracted service provider under a Commonwealth contract. The exemption also does not stop a buyer asking, and it does not stop a breach damaging the business.
What does a buyer actually want to know about data in due diligence?
Usually three things. What personal information the business holds and why, where it is stored and who hosts it, and who has access including former staff and former contractors. A clear answer to all three is worth more than a certificate.
Will a past data breach stop a sale?
Rarely on its own. What causes problems is a breach a buyer discovers rather than one they are told about, because it changes what else they assume is undisclosed. Raise it early, show what was done about it, and it becomes a fact rather than a discovery.
Keep reading






All notes on selling a business · All seller guides · What is my business worth?
Check it yourself
Primary sources, none of them affiliated with me and none of them endorsing this site. Where anything here differs from an official source, the official source is right.
Links open on external government and industry websites. The full list sits on licensing, registers and official sources.
Ask what it is worth
Free, in writing, and nobody finds out you asked. Tell me the trade and the suburb and I will do the rest.
Nobody finds out you are selling. This goes to me only, into my own database in Sydney. I will not contact your accountant, your landlord, your bank or your staff, ever, unless you ask me to.
If you would rather not put anything in writing yet, ring 0431 124 128. Prefer to pick a time yourself? Book a time in my diary.
Thinking about selling?
Thirty minutes, on the phone or in person, at a time that suits you including evenings. You will get a straight read on where the business sits today and what would move the number. It costs nothing, there is no obligation, and nobody finds out you asked.
