Sector guide · E-commerce & retail
The numbers buyers pull apart first in an online business sale
Before a buyer falls in love with your brand, they will interrogate your data. If you know these numbers cold, and they hold up, you are ahead of the vast majority of stores on the market.
Nothing on this page is legal, financial or taxation advice. Free confidential appraisal, no cost and no obligation. Last updated 15 September 2026.
Get my free appraisal, in writingCall 0431 124 128
No obligation. Nothing is published. Nobody is contacted.
Before a buyer falls in love with your brand, they will interrogate your data. If you know these numbers cold, and they hold up, you are ahead of the vast majority of stores on the market. If you do not know them yet, finding out is the first job of your preparation window.
None of these need to be perfect. What matters is that they are known, honest and improving. A seller who presents this dashboard unprompted changes the entire tone of a negotiation, because the buyer's risk perception drops and risk perception is what discounts prices.
The due diligence dashboard
| What a buyer asks for | What it has to show |
|---|---|
| Revenue trend by month, over at least 36 months | Buyers buy the trajectory, not the total. Flat and steady beats a spike that is already fading. |
| Repeat purchase rate and returning customer revenue share | How much of this year's revenue came from customers acquired in previous years. This is the single clearest proof the brand has value beyond its ad spend. |
| Contribution margin after all selling costs | Gross margin minus fulfilment, freight, platform fees and advertising. Plenty of stores with healthy gross margins make almost nothing per order once acquisition cost is counted, and buyers find this in the first week. |
| Marketing efficiency ratio | Total revenue over total marketing spend, across all channels. A business drifting from a MER of five toward two is buying its own revenue, and the price will reflect it. |
| Traffic and revenue mix by channel | Organic search, direct, email, paid social, paid search, marketplaces. Concentration above roughly 70 per cent in any single paid channel gets priced as fragility. |
| Email and SMS revenue share | Owned channels typically driving 20 to 30 per cent of revenue signals a real customer asset, not a rented audience. |
| Inventory turns and aged stock position | Capital sitting in slow movers is capital the buyer must fund at settlement, and they will discount accordingly. |
| Refund, chargeback and review metrics | Return rates, dispute rates and review velocity are read as proxies for product quality and operational health. |
Every line here can be evidenced from a system rather than asserted in a meeting, which is the whole advantage of selling an online business well prepared.
The small business exemption, the $3 million threshold, and why it is easier to lose than to keep
The Privacy Act 1988 (Cth) exempts small business operators from the Australian Privacy Principles. The OAIC defines a small business operator as one with an annual turnover of $3 million or less. Annual turnover for this purpose includes all income from all sources, and does not include assets held, capital gains or proceeds of capital sales. That last point matters at sale, because the proceeds of selling the business do not themselves push you over the line.
The threshold is a one way ratchet. The OAIC states that if your small business has had an annual turnover of more than $3,000,000 in any financial year since 2002, you must comply with the Australian Privacy Principles. Falling back below $3 million in a later year does not restore the exemption. For an online retailer that had one exceptional year, in a demand surge or a viral product cycle, the obligation is permanent even though the revenue was not.
A buyer will test this by looking at your full trading history rather than the last two years. Reconstruct it before you go to market. If you crossed $3 million in any year since 2002, you are inside the Australian Privacy Principles and the Notifiable Data Breaches scheme now, and the answer to a buyer’s privacy questionnaire is different.
Exceptions that remove the small business exemption regardless of turnover
| Exception | Why it matters to an online retailer |
|---|---|
| Businesses that trade in personal information without the required consent | This is the exception that catches online retailers. Selling or disclosing a customer database in a business sale is precisely the conduct that raises it. A business that believed itself exempt on turnover can be brought inside the Act by the structure of the transaction itself. |
| Health service providers | Relevant where the storefront sells health related goods with any consultation, assessment or practitioner service attached rather than pure retail supply. |
| Commonwealth contract service providers | Relevant where any part of the revenue comes from supplying under a Commonwealth contract, including through a reseller arrangement. |
| Reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 | Relevant where the business offers designated services rather than ordinary retail sales. |
| Credit reporting bodies, residential tenancy database operators, employee associations under the Fair Work Act, protected action ballot operators | Narrow categories, listed here because the exception list is exhaustive and a buyer’s adviser will work through it line by line. |
| Consumer Data Right accredited businesses | Relevant where the business has sought accreditation to receive data under the Consumer Data Right. |
| Businesses that have opted in voluntarily | Some sellers opted in to reassure enterprise customers or platform partners. If you did, the exemption is gone by your own choice and the opt-in is a disclosable fact. |
Exception categories are from the OAIC small business page, current as at August 2026. I have not been able to verify any committed timetable or mechanism for removing the small business exemption entirely. The OAIC page still presents the $3 million threshold as operative, and the 2024 reform materials describe the changes as a first step without setting a date, so this page does not state that the exemption is ending.
What the Privacy and Other Legislation Amendment Act 2024 changed, and when
The Privacy and Other Legislation Amendment Act 2024, No. 128 of 2024, introduced five changes that matter to an online retailer. A statutory tort for serious invasions of privacy, giving individuals a route to seek redress in the courts. Expanded OAIC enforcement and investigation powers, including new tiers of civil penalties and the ability to issue infringement notices. A mandate for the OAIC to develop a Children’s Online Privacy Code covering not only social media platforms but any online services likely to be accessed by children. A mechanism to prescribe a list of countries and binding schemes with adequate privacy protections to facilitate cross-border data transfers. And a requirement that privacy policies include information about automated decisions affecting individual rights.
The statutory tort commenced on 10 June 2025. It is the change that reaches sellers who assume the Privacy Act does not apply to them. The OAIC states that the tort applies more broadly than the Privacy Act itself, reaching individuals and other entities that may not necessarily be an Australian Privacy Principle entity. A business under the $3 million threshold is exempt from the Australian Privacy Principles and still exposed to the tort.
The grounds are intruding upon the individual’s seclusion, or misusing information that relates to the plaintiff. The plaintiff must show that the public interest in protecting their privacy outweighs any countervailing public interest. The OAIC does not have a direct role in administering the tort, so actions are brought in court rather than through a complaint to the regulator. The limitation period is 1 year after the plaintiff became aware of the invasion, or 3 years after it occurred, whichever is earlier, with different rules for minors.
The Children’s Online Privacy Code is not yet registered as at August 2026, and it must be finalised and registered by 10 December 2026. A draft was released by the Attorney-General on 31 March 2026, and Phase 3 consultation concluded in June 2026 with 425 submissions from children, young people, parents and carers and 135 unique written submissions. The Code applies to social media services, relevant electronic services and designated internet services as defined under the Online Safety Act 2021, targeting services likely to be accessed by children or that primarily concern the activities of children. Online retail is not an explicitly listed category, and designated internet services is drafted broadly. If you sell children’s products, treat this as a live compliance item landing inside the horizon of a sale completing in 2026, and say so to your buyer rather than leaving them to find it.
The Notifiable Data Breaches scheme, and the two clocks a buyer will check
The Notifiable Data Breaches scheme applies to entities that have an obligation under Australian Privacy Principle 11 to protect the personal information they hold, under section 26WE(1)(a) of the Privacy Act 1988 (Cth). Coverage includes government agencies, and private sector and not-for-profit organisations with annual turnover exceeding AU$3 million. It also covers businesses that trade in personal information regardless of size, private sector health service providers, credit reporting bodies and credit providers, tax file number recipients, Consumer Data Right accredited entities and Digital ID Act accredited entities.
An eligible data breach has three limbs. Section 26WE(2) requires unauthorised access to, unauthorised disclosure of, or loss of personal information that an entity holds. The breach must be likely to result in serious harm to one or more individuals, where serious harm encompasses serious physical, psychological, emotional, financial or reputational harm. Section 26WF then asks whether the entity has been able to prevent the likely risk of serious harm with remedial action.
Two clocks follow. Section 26WH(2) requires the entity to take all reasonable steps to complete the assessment within 30 calendar days after the day the entity became aware. Section 26WL(3) requires notification as soon as practicable after completing the statement prepared for notifying the Commissioner. There are three ways to notify. All individuals to whom the information relates, under section 26WL(2)(a). Only those at risk of serious harm, under section 26WL(2)(b). Or, where neither is practicable, publishing a copy of the statement on the website and taking reasonable steps to publicise its contents, under section 26WL(2)(c). A statement also goes to the Commissioner.
For a sale, the question is not only whether you have had a breach. It is whether the incident file shows the date you became aware, the assessment completed within 30 calendar days, the decision recorded with reasons, and the notification made or the reason it was not required. A documented incident handled to the statute costs far less in a negotiation than an undocumented one, and a gap in the record invites a warranty and an indemnity that a clean file would not.
Shares in a private company are a financial product under the Corporations Act 2001. Tony Pope does not hold an Australian Financial Services Licence and does not give financial product advice. Nothing on this page is a recommendation to buy or sell shares.
Where a sale is structured as a share sale, the share transfer itself is handled by your solicitor and your accountant. This page explains why the structure matters to your licence, your accreditation or your registration. It does not tell you which structure to choose.
This explains how the rules generally work on a business sale. It is not advice about your situation, and nothing here should be acted on without your accountant running your actual numbers.
Tony Pope is not a registered tax agent and does not give tax advice. Deal structure changes what you keep, sometimes by more than the negotiation does, so get that advice before you sign anything.
Tony Pope is a licensed business broker, not a solicitor. This explains how these rules and clauses usually work so you can have a better conversation with your lawyer.
Your contract should be drafted and reviewed by a solicitor. Where anything on this page differs from an official source or from your own legal advice, that source and that advice are right.
Ask what it is worth
Free, in writing, and nobody finds out you asked. Tell me the trade and the suburb and I will do the rest.
Nobody finds out you are selling. This goes to me only, into my own database in Sydney. I will not contact your accountant, your landlord, your bank or your staff, ever, unless you ask me to.
If you would rather not put anything in writing yet, ring 0431 124 128. Prefer to pick a time yourself? Book a time in my diary.
Find out what your online business is worth
Thirty minutes, on the phone or in person, at a time that suits you including evenings. You will get a straight read on where the business sits today and what would move the number. It costs nothing, there is no obligation, and nobody finds out you asked.
