← All articles

12 August 2026

The Privacy Act Small Business Exemption: Who Lost It on 1 July, and Why the Rest Shouldn't Relax

The Privacy Act Small Business Exemption: Who Lost It on 1 July, and Why the Rest Shouldn't Relax

The $3 million small business exemption hasn't been repealed — but real estate agents, accountants, lawyers and conveyancers lost it on 1 July 2026, and a tort that commenced in 2025 already ignores it entirely. What actually changed, and the six things to fix in order.

The small business exemption is the most quietly relied-upon rule in Australian business. Turnover of $3 million or less and the Privacy Act mostly doesn't apply to you — no privacy policy obligation, no Australian Privacy Principles, no notifiable data breach scheme. Most owners under that threshold have never had to think about it, and a fair few don't know the exemption exists at all. They've just never been told they had a problem.

For a large group of those businesses, that ended on 1 July. Not with a transition period or a grace year — with a commencement date that passed about six weeks ago while everyone was reading about something else.

And for everyone still exempt, there's a second development that matters more than the exemption does: since June last year, an individual can sue you directly for a serious invasion of privacy, and that action doesn't care about your turnover at all.

Here's what's actually true, what isn't, and what to fix in what order.

What The Exemption Actually Is

A small business under the Privacy Act is one with an annual turnover of $3 million or less. Turnover here means all income from all sources — not profit — though it excludes assets, capital gains and proceeds from capital sales.

What most people don't realise is how long the list of exceptions already was. Even before this year, you were covered regardless of turnover if you were any of the following:

  • A health service provider — and that's read broadly: medical and allied health practitioners, pharmacists, gyms, and anyone else providing a health service and holding health records.
  • A business that trades in personal information — buying or selling it.
  • A Commonwealth contract service provider.
  • A residential tenancy database operator, or a credit reporting body.
  • A reporting entity under the anti-money laundering legislation.
  • A related entity of a larger business that is itself covered.
  • A Consumer Data Right accredited business, a telecommunications data retention provider, or an employee association.
  • Anyone who has voluntarily opted in.

That second-to-last category — related entities — catches more small businesses than people expect. If your small company sits in a group with a parent over the threshold, the exemption may not be yours to claim.

The OAIC publishes a small business guidance page with a checklist for working out which side of the line you're on. It's worth ten minutes, because a good number of readers will find they've been covered for years.

What Changed On 1 July 2026

The anti-money laundering exception is the one that just did a lot of work.

From 1 July 2026, a new group of businesses became reporting entities under the AML/CTF Act — the group generally referred to as Tranche 2:

  • Real estate professionals
  • Dealers in precious stones, metals and products
  • Professional service providers — lawyers, conveyancers, accountants, and trust and company service providers

Because reporting entities are an exception to the small business exemption, those businesses are now subject to the Privacy Act in connection with that work, regardless of turnover. The OAIC has published specific guidance for reporting entities setting out what that means.

If you run a two-person conveyancing practice, a suburban real estate agency, or a small accounting firm, the exemption you've relied on your whole working life no longer covers a meaningful part of what you do. Nobody sent you a letter.

The Scope Nuance Most Coverage Will Miss

Here's the part worth reading carefully, because it cuts both ways.

The obligation attaches to personal information handled for the purposes of, or in connection with, your AML/CTF obligations — customer identification, verification records, the documents you collect to satisfy know-your-customer requirements. It is not a blanket declaration that everything your business touches is now regulated.

That sounds like relief, and technically it is. In practice it's a trap, because it means running two regimes inside one filing system: the identity documents you collected for AML purposes are governed, and the ones you collected because you always have aren't, and they're sitting in the same folder in the same shared drive under the same filename convention.

Almost nobody can operate that distinction reliably. The pragmatic answer for most firms of this size is to apply one standard across the whole business rather than trying to maintain a boundary you can't see. That's not a legal requirement — it's an admission about how filing actually works.

The Tort That Ignores The Exemption Entirely

Now the part that applies to every reader, exempt or not.

On 10 June 2025, a statutory tort for serious invasions of privacy commenced under the Privacy and Other Legislation Amendment Act 2024. It gives individuals a direct cause of action — they sue you, rather than complaining to a regulator who decides whether to act.

Two features matter enormously here:

  • There is no small business exemption. No turnover threshold protects a defendant.
  • There is no employee records exemption either — the carve-out that keeps employee records outside the Privacy Act for covered businesses doesn't apply to this action.

So the mental model that a lot of small business owners carry — "the Privacy Act isn't my problem, I'm under $3 million" — was already out of date a year before the AML changes landed. The APPs may not apply to you. Being sued personally by someone whose privacy you seriously invaded is available to them regardless.

The OAIC's page on the statutory tort sets out the elements. The threshold is deliberately high — it requires seriousness, and it's not a remedy for every mishandled email — but the exposure is real and it is not filtered by size.

So Is The General Exemption Going?

Honestly: probably, eventually, and nobody can tell you when.

Removing the $3 million exemption entirely has been recommended by the OAIC, subject to an appropriate transition period so small businesses have time to understand and prepare for the obligations. It sits in the reform program as an agreed-in-principle direction rather than as law. There is no legislation and no commencement date.

You will find articles asserting otherwise, usually written to create urgency. Treat a specific date for the general repeal with suspicion unless it points to an actual bill.

The useful conclusion isn't to prepare for a phantom deadline. It's that two real things have already happened — one group lost the exemption in July, and everyone became directly suable last year — and both of them are addressed by the same short list of housekeeping. Do the housekeeping because it's now load-bearing, not because of a date that hasn't been set.

What To Fix First

In order of return, and none of this is software you buy.

1. Establish whether you're actually covered. Run the OAIC checklist. Check the health service definition properly — it's broader than people assume. Check whether you're in a group with a larger related entity. If you're in real estate, law, conveyancing, accounting, or dealing in precious metals, assume you're in scope for at least part of your work and move on to step two.

2. Write a privacy policy and collection notices that describe what you actually do. Not a template describing a business you don't run. The policy explains how you handle personal information; the collection notice tells someone, at the point you collect it, why you're taking it and what happens to it. Newly covered entities need both.

3. Collect less. The obligation is to limit collection to what's reasonably necessary. This is the cheapest control available and the one most consistently ignored — most businesses collect more identification than they need because a form asked for it once and nobody has revisited the form since.

4. Destroy identity documents when you no longer need them. This is the one that will bite the newly covered hardest. Copies of driver's licences and passports collected for verification tend to live forever in a shared drive, because deleting things feels riskier than keeping them. Under the Privacy Act it's the reverse: holding personal information you no longer need is the exposure. Our guide to data retention policy works through how to reconcile that against the ATO and Fair Work rules that require you to keep other records for years.

5. Write a data breach response plan before you need one. Under the notifiable data breach scheme, a covered entity that suspects an eligible breach has to assess it quickly and notify affected individuals and the OAIC where the harm threshold is met. The plan doesn't need to be elaborate — who decides, who's called, what gets logged, what gets said — but improvising it during an incident is how businesses miss the timeframe.

6. Know where your data goes overseas. Sending personal information to an overseas recipient carries obligations about that recipient's handling of it. For most small firms this isn't an exotic scenario — it's the CRM, the cloud storage, the email platform and the AI tool someone signed up for last month. You can't manage this without knowing what's in your stack.

Underneath all six sits access control: who in your business can reach personal information, and whether that access is removed when someone leaves. Our IT onboarding and offboarding checklist covers the mechanics, and the Essential Eight checklist covers the technical baseline that makes a breach less likely in the first place.

One More Date Already On The Calendar

If you're now an APP entity, there's a second commencement worth diarising.

From 10 December 2026, an APP entity that uses personal information in automated decision-making — where a computer program makes decisions that could reasonably be expected to significantly affect someone's rights or interests — must say so in its privacy policy, including what kinds of personal information are used and what kinds of decisions are made that way. The OAIC has indicated guidance ahead of commencement.

For a small professional firm this may well not apply. But "we don't use automated decision-making" is worth confirming rather than assuming, because the definition reaches further than people expect once scoring, screening and triage tools are in the picture — and those arrive inside products you already pay for, without anyone deciding to adopt them.

What This Actually Costs

Very little in software, and more than you'd like in attention.

There's no product that makes you compliant. What the work needs is a couple of hours to establish scope, a policy and a notice written honestly, a hard look at what you collect and how long you keep it, a one-page incident plan, and a list of where your data goes. Most small firms can do it in a week of elapsed time and a day of actual effort.

The expensive version is the one where nobody does any of it, a laptop with eight years of scanned passports on it goes missing, and the first time anyone reads the notifiable data breach scheme is the week it matters.

Getting Help

The uncomfortable feature of this change is that the businesses most affected — small agencies and professional practices — are precisely the ones without an in-house person whose job includes reading commencement dates. There was no notification, and the exemption most of them relied on stopped applying to part of their work in the middle of a normal week.

Our Small Business IT Support service works through what you actually hold, where it goes, who can reach it, and what needs deleting — the practical layer under the policy, which is where compliance either holds up or quietly doesn't.

This is general information about how these rules work, not legal advice about your business. Where the scope question is genuinely close — and for the newly covered it often is — that's a conversation with a lawyer, not a blog post.