Your business is handed a list of potential customers. It might come from a referral partner, a marketing provider or a database seller promising “qualified leads”.
It looks valuable. But can you actually use it?
Maybe. The real issue is not whether someone is willing to sell or share the data. It is whether the information was collected lawfully, whether your business has a proper reason to use it and whether the individuals involved were told what would happen to their details.
Before you upload the list, send the campaign or contact a single person, there are several privacy risks worth checking.
In this article, Prosper Law’s data and privacy law team, explains the key privacy issues to check before collecting personal information from a third party.

What is personal information?
Personal information is information or an opinion about an identified person, or someone who can reasonably be identified.
It can include a person’s name, phone number, email address, date of birth, financial details, employment information or online identifiers.
Some information is considered sensitive and requires greater care. This includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records and certain biometric information.
Does the Privacy Act apply to your business?
The Privacy Act 1988 (Cth) generally applies to businesses with annual turnover above $3 million.
Some smaller businesses are also covered, including certain health service providers, businesses that trade in personal information and some Commonwealth contractors.
If your business is covered, it must comply with the Australian Privacy Principles, commonly called the APPs.
Even if your business falls outside the Privacy Act, good privacy practices still matter. Customers, suppliers and online platforms increasingly expect businesses to explain how personal information is collected and used.
Can you collect personal information from someone else?
In some circumstances, yes. However, businesses covered by the Privacy Act are generally expected to collect personal information directly from the individual unless doing so would be unreasonable or impracticable.
The information must also be reasonably necessary for your business and collected by lawful and fair means.
Before accepting third-party data, ask:
- Why do we need this information?
- Why can’t we collect it directly?
- How did the third party obtain it?
The answer may be straightforward where information comes from an authorised representative, recruitment agency or referral partner.
It is more complicated where you are buying a database containing details of people who have never dealt with your business.
Do you need consent?
Consent may be required, particularly where sensitive information is involved. However, consent is not simply a box that can be ticked in a long privacy policy.
It should be informed, voluntary, current and specific enough to cover the proposed collection and use.
You should check whether the individual agreed to:
- the original business collecting the information;
- the information being shared with another organisation;
- your business receiving it; and
- the way your business intends to use it.
These are not always the same thing.
For example, someone who gives their email address to enter a competition may not expect their details to be sold to unrelated businesses for ongoing marketing.
What must you tell the individual?
If your business receives personal information from a third party, you may still need to notify the individual.
Depending on the circumstances, they may need to know:
- who your business is;
- why you collected their information;
- how you will use or disclose it;
- how they can access your privacy policy;
- how they can request access or correction; and
- whether the information may be disclosed overseas.
Do not assume the original business has already provided a sufficient notice on your behalf.
Ask to see the wording used when the information was collected. It should clearly cover the disclosure to your business and your intended use.
Can you use the information for a different purpose?
Not automatically. Personal information is generally collected for a particular purpose. Using it for something substantially different may require consent or another lawful basis.
Suppose a customer gives their details to a retailer so an order can be processed. They would reasonably expect the retailer to use that information to complete the sale and communicate about delivery.
They may not expect their details to be passed to an unrelated insurance business for marketing.
The further your proposed use moves away from the original purpose, the greater the privacy risk.
Can you buy an email list?
Buying an email list can be risky. Before using one, you should investigate how the addresses were collected, what people agreed to and whether the list is accurate and current.
You also need to consider the Spam Act 2003 (Cth).
Commercial electronic messages generally need appropriate consent, clear sender identification and a working unsubscribe facility. You must not use a list created through prohibited address-harvesting software.
Even where a purchased list appears lawful, it may still be poor value. The addresses may be outdated, irrelevant or connected to people who have no interest in your business.
Sending unsolicited messages can also damage your reputation and increase spam complaints.

What should you ask the third party?
Before accepting or purchasing personal information, ask the provider:
- Where did the information come from?
- What were individuals told when it was collected?
- Did they agree to the information being shared?
- Does their consent cover your intended use?
- Is the information accurate and up to date?
- Have any individuals withdrawn consent or opted out?
- Was address-harvesting software used?
Request copies of collection notices, privacy statements and consent wording where appropriate.
If the provider cannot clearly explain where the data came from, that should be treated as a warning sign.
Use a written agreement
A written agreement can help manage the risks of receiving third-party data.
The agreement may require the provider to confirm that the information was collected lawfully, that appropriate notices were given and that any required consent was obtained.
It may also address accuracy, complaints, withdrawn consent, privacy breaches and responsibility if the provider’s conduct exposes your business to a claim.
A contract cannot make unlawfully collected information lawful. However, it can help establish expectations and provide protection if something goes wrong.
Protect the information after collection
Once the information reaches your business, you are responsible for handling it appropriately.
Only collect the information you genuinely need. Limit access to relevant employees and store it securely. You should also decide how long it needs to be retained and when it should be deleted or de-identified.
Avoid importing an entire database into your systems where only a small amount of information is needed. The more data your business holds, the greater the consequences of a privacy or cyber security breach.
A practical example
Imagine a referral partner sends your business the names and phone numbers of prospective customers.
The partner says each customer agreed to receive offers from “selected business partners”. Before contacting them, ask to see the wording the customers were shown.
Did it clearly explain that their details would be disclosed? Did it identify the types of businesses that might contact them? Was the consent optional and easy to understand?
You should also consider whether your contact is consistent with the original purpose and whether any email or text marketing complies with the Spam Act.
The fact that another business holds the information does not automatically mean you can use it.
Check the source before using the data
Third-party information can help your business generate leads, assess applications and deliver services more efficiently.
It can also create privacy complaints, spam risks and reputational damage if it was collected improperly or used for an unexpected purpose.
Before accepting the data, check where it came from, what the individual was told and whether your intended use is lawful and fair.
Prosper Law assists Australian businesses with privacy policies, third-party data arrangements, commercial contracts and marketing compliance.
Contact Prosper Law’s privacy and commercial law team before purchasing or using a third-party database. Early advice can help prevent a privacy issue from becoming a complaint or regulatory investigation.

Frequently asked questions
Can I collect customer details from a referral partner?
Possibly. Check what the customer was told, whether they agreed to the referral and whether your proposed use is consistent with that explanation.
Is a privacy policy enough to prove consent?
Not always. Consent should be clear, informed and specific. A broad statement hidden in a lengthy privacy policy may not authorise every future use or disclosure.
Can I collect information from public websites?
Public availability does not automatically mean information can be collected and used without restriction. Privacy, spam and other laws may still apply.
Can I buy a marketing database?
Potentially, but it carries risk. Check the source, consent process, accuracy and whether address-harvesting software was used. It might be the case that the content is not worth the value you are asked to pay.
Do I need to notify someone if their information came from a third party?
In many cases, yes. Your business may need to tell the individual who you are, why you collected their information and how it will be handled.
Does the Privacy Act apply to small businesses?
Many businesses with turnover below $3 million are exempt, but important exceptions apply. Small businesses that provide health services or trade in personal information may still be covered.
About the Author

Farrah Motley
Contact an Australian Business Lawyer Today.
Contact us for a free consultation


