I have read a lot of guides on Australian data retention law. Most of them are competent. They explain the Privacy Act, they list the Australian Privacy Principles, they mention the small-business turnover threshold, and then they stop. They stop at exactly the point where a small business owner starts having the real problem, which is not “what does the law say” but “so how long do I keep this customer’s email address, and who deletes it, and when”.

I run into this because I collect customer feedback. Surveys, the occasional Net Promoter Score pulse, contact details attached to a review request. That data piles up quietly. Nobody has ever knocked on my door asking me to prove I had a retention schedule, but I would rather have one before someone does than scramble the day a customer emails and says “delete everything you hold about me”. This piece is the practical version I wanted: a concrete retention schedule for feedback data, a deletion workflow you can actually run, and a template you can copy and adapt.

Why The Generic Guides Leave You Stuck

The law firm and IT-consultancy articles that rank for this topic are written to be safe for every business at once. That is their weakness. A guide that has to cover a hospital, a franchise chain, and a two-person cafe cannot tell any of them how long to keep a specific record, so it retreats to principle: keep data only as long as you need it, then destroy or de-identify it (Sprintlaw, 2024a). True, and useless on a Tuesday afternoon when you are looking at three years of survey exports wondering what to bin.

There is a second gap. Much of this advice assumes the Privacy Act applies to you in full. For a lot of Australian small businesses it does not, at least not automatically. Businesses with annual turnover of $3 million or less are generally exempt from the Act, with important exceptions such as trading in personal information, providing health services, or being a contracted service provider to government (Invotec, 2024; Sprintlaw, 2024b). This exemption is on borrowed time: the Privacy and Other Legislation Amendment Act 2024 removes it, with the change commencing 10 December 2026, after which an estimated 2.5 million additional Australian businesses will need to comply with all 13 Australian Privacy Principles regardless of turnover. Two things follow from that. First, do not assume you are covered, because the exceptions are easy to trip over. Second, and this is the part I want to make the case for, even if you are exempt, a retention and deletion policy is still worth having. Customers increasingly expect it, it limits your exposure if you ever do get breached, and it is far easier to adopt the good habit now than to retrofit it once the exemption disappears entirely on 10 December 2026 and the obligation lands on every small business regardless of turnover.

The Principle You Are Actually Working To

Under the Australian Privacy Principles, once personal information is no longer needed for any purpose for which it may be used or disclosed, and you are not required by law to keep it, you must take reasonable steps to destroy it or de-identify it (Office of the Australian Information Commissioner, n.d.). That is APP 11.2, and it is the single sentence that a retention schedule exists to operationalise. “No longer needed for the purpose it was collected” is the trigger. Your job is to decide, in advance and in writing, when that moment arrives for each type of data you hold, so you are not making the call under pressure or, worse, never making it at all.

The phrase “reasonable steps” matters too. A small business is not expected to run enterprise-grade data governance. Reasonable for a fifteen-person operation means a written policy, a named person responsible, and a habit of actually following it. The business.gov.au guidance for small business lands in the same place: collect only what you need, protect it while you hold it, and get rid of it when you are done (Australian Government, n.d.).

A Retention Schedule For Feedback Data

Here is where I depart from the generic guides and get specific. Feedback and review programs generate a few distinct data types, and they do not all deserve the same treatment. The periods below are a sensible starting point for a small business, not legal advice; adjust them to your own circumstances and check anything unusual with a solicitor.

Raw survey and NPS responses with identifying details attached. This is the highest-sensitivity bucket, because it links an opinion to a person. My default is to keep the identifiable version only as long as you genuinely need to act on it. For most feedback that is the current review cycle plus a short tail, so roughly twelve months. After that, strip the identifiers and keep the response as anonymous data if you still want the content.

Aggregated and de-identified scores. Once a survey response can no longer be traced to an individual, it stops being personal information in the practical sense, and the retention clock effectively stops mattering. Aggregate NPS or eNPS trends, sentiment summaries, and anonymised verbatim comments can be kept as long as they are useful, because they are how you see change over time. This is the key move: separate the insight from the identity, keep the insight, retire the identity.

Customer contact details collected via feedback tools. Names, emails, and phone numbers captured to send a survey or a review request should live only as long as the relationship or consent that justifies them. If someone gave you their email to receive a single review request, keeping it for three years is hard to defend. Tie retention to the consent basis and review it at least annually.

Complaint and service-recovery records. These earn a longer hold, because they can be evidence in a dispute, a warranty claim, or a chargeback. Two to seven years is a defensible range depending on the matter, and some records overlap with other obligations. Note that separate rules can require you to keep certain business and tax records for around five years, so a document may need retaining for a reason unrelated to privacy even after its feedback purpose has passed (Sprintlaw, 2024a).

The anonymised-versus-identifiable distinction is the one I would tattoo on the inside of every small business owner’s eyelids. You almost never need to keep the identity to keep the value. Decouple them early and most of your retention problem disappears.

The Deletion Workflow

A retention schedule tells you what to delete on a timer. A deletion workflow tells you what to do when a customer asks. You want both, and you want the second one written down before you need it, because deletion requests always seem to arrive at the least convenient moment.

  1. Log the request. Record who asked, when, and what they asked for. Date-stamp it. If you are covered by the Privacy Act you are expected to respond within a reasonable period, so a clock starts here.
  2. Verify identity. Confirm the request genuinely comes from the person whose data it concerns. Deleting or disclosing data to the wrong person is itself a privacy problem.
  3. Check for holds before you delete anything. This is the step people skip. Is there an ongoing dispute, a live complaint, an insurance or warranty matter, or a legal or tax obligation that requires you to retain the record? If yes, you may need to keep it and tell the customer why, rather than delete on request.
  4. Delete or de-identify across every location. Remove the identifying data from your feedback tool, your email or SMS lists, any spreadsheet exports, and any backups you can practically reach. If the underlying insight is worth keeping, de-identify rather than destroy.
  5. Confirm back to the customer. Tell them in plain language what you deleted and what, if anything, you have retained and why. Closing the loop in writing is both good manners and a record that you acted.

Step four is where scattered data quietly defeats you. If a customer’s details live in a survey tool, a Mailchimp list, three CSV exports, and a shared inbox, a “delete me” request is not one action, it is a treasure hunt, and treasure hunts get done badly or not at all. This is the honest operational case for a single system. When feedback data lives in one place with one policy applied to it, retention and deletion become something you can actually enforce, which is a large part of why I built Business Review 360 to centralise this rather than leave it strewn across tools. It is also why I keep returning to the theme in pieces like closing the loop on customer feedback: the loop only closes if the data is somewhere you can find it.

A Policy Template You Can Copy

Adapt the bracketed parts and you have a working first draft. Keep it short. A one-page policy that gets followed beats a ten-page one that lives in a drawer.

[Business name] Customer Data Retention and Deletion Policy

A Note On Breaches, Because Retention Reduces The Blast Radius

There is a bonus to holding less data: when something goes wrong, there is less to lose. If you are covered by the Notifiable Data Breach scheme and a breach is likely to result in serious harm, you have obligations to assess and notify (OAIC, n.d.-a; OAIC, n.d.-b). Every record you have already deleted on schedule is a record that cannot be exposed. Good retention discipline is quiet security work you do in advance.

References

Australian Government. (n.d.). Protect your customers’ information. business.gov.au. https://business.gov.au/online-and-digital/cyber-security/protect-your-customers-information

Invotec. (2024). Australian privacy laws: A practical guide to customer data compliance. https://www.invotec.com.au/australian-privacy-laws-a-practical-guide-to-customer-data-compliance/

Office of the Australian Information Commissioner. (n.d.). Australian Privacy Principles guidelines: Chapter 11, APP 11, security of personal information. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information

Office of the Australian Information Commissioner. (n.d.-a). Notifiable data breaches. https://www.oaic.gov.au/privacy/notifiable-data-breaches

Office of the Australian Information Commissioner. (n.d.-b). Part 4: Notifiable Data Breach (NDB) scheme. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme

Sprintlaw. (2024a). Data retention laws in Australia: Essential guide for businesses. https://sprintlaw.com.au/articles/data-retention-laws-in-australia-essential-guide-for-businesses/

Sprintlaw. (2024b). Protecting customer privacy: Compliance for Australian businesses. https://sprintlaw.com.au/articles/protecting-customer-privacy-compliance-for-australian-businesses/

FAQ

How long should a small business keep customer survey and NPS responses?

As a practical default, keep the identifiable version only as long as you need to act on it, which for most feedback is around twelve months. After that, strip the identifying details and keep the response as anonymous data if the content is still useful. The de-identified score or comment can be retained indefinitely, because once it can no longer be traced to a person it is no longer personal information in the sense the privacy rules care about.

Does the Privacy Act even apply to my small business?

Often not automatically, and not for much longer either. Businesses with annual turnover of $3 million or less are currently generally exempt, but there are important exceptions, including trading in personal information, handling health information, and being a contracted service provider to a government agency (Invotec, 2024). That exemption is being repealed: the Privacy and Other Legislation Amendment Act 2024 removes it from 10 December 2026, after which turnover will no longer be a factor. Because the exceptions are easy to trip over today and the exemption disappears entirely soon, do not assume you are exempt, and adopt a retention policy anyway.

What do I do when a customer asks me to delete their data?

Log the request with a date, verify the request genuinely comes from that person, and check for any legal hold or obligation that requires you to keep the record before you delete anything. Then remove the identifying data from every place it lives, de-identifying rather than destroying if the underlying insight is worth keeping, and confirm back to the customer in writing what you deleted and what, if anything, you retained and why.

Can I keep NPS or eNPS scores longer than the customer details attached to them?

Yes, and you generally should. The value of feedback data is in the aggregate trend, not the individual identity. Once you de-identify a response so it can no longer be linked to a person, you can keep it as anonymous data for as long as it is useful, while deleting the name, email, or phone number on a much shorter schedule. Decoupling the insight from the identity early is the single most useful move for keeping retention manageable.

Where should feedback data live to make retention and deletion easier?

In one place, with one policy applied to it. When survey responses, contact details, and complaint records are scattered across spreadsheets, email lists, and separate survey tools, actioning a deletion request or a scheduled purge becomes a hunt across systems that tends to get done badly or skipped. Centralising feedback data means a retention review or deletion request is a few minutes of work rather than an afternoon, which is a large part of the reason to use a dedicated tool rather than a shared inbox and a folder of exports.