Privacy Ready
← Learn

Does the Privacy Act Apply to My Australian Small Business?

The short answer

From 1 July 2026, the small business exemption under the Privacy Act 1988 (Cth) is removed, bringing an estimated 100,000+ additional Australian businesses under the Act for the first time. Previously, any business with annual turnover under $3 million was exempt. After that date, if you collect, use, or disclose personal information — regardless of size — your business has obligations under all 13 Australian Privacy Principles (APPs).

Governing law Privacy Act 1988 (Cth)
Key change Small business exemption removed
Effective date 1 July 2026
Businesses affected ~100,000+ newly regulated
Regulator Office of the Australian Information Commissioner (OAIC)
Maximum penalty Up to $50M, or 3× benefit obtained, or 30% of adjusted annual turnover
Per-contravention Up to $66,000 (minor breaches)

What was the small business exemption?

The small business exemption has existed since the Privacy Act was amended in 2000. It allowed any business with annual turnover of $3 million or less to opt out of most of the Act's requirements. For more than two decades, the majority of Australian businesses — sole traders, family businesses, local retailers, tradespeople — operated entirely outside the Privacy Act's reach.

The exemption was removed by the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent in December 2024. The removal takes effect on 1 July 2026.

Who is newly covered from 1 July 2026?

If your business previously relied on the small business exemption — annual turnover of $3 million or less — it becomes subject to the Privacy Act from 1 July 2026. This includes:

  • Sole traders who collect customer personal information
  • Partnerships and companies with turnover under $3M
  • Small franchisees (franchisors were often already covered)
  • Clubs, associations, and not-for-profits previously exempt

Some businesses were already covered regardless of turnover:

  • Healthcare providers (GPs, dentists, allied health, pharmacies)
  • Businesses that trade in personal information
  • Businesses holding Commonwealth contracts or Commonwealth records
  • Credit providers and credit reporting bodies

What does being covered by the Privacy Act mean in practice?

Being regulated means complying with all 13 Australian Privacy Principles. The core practical obligations are:

  1. Have a privacy policy (APP 1) — publicly available, written in plain language, explaining what you collect and how you handle it
  2. Only collect information you need (APP 3) — no collecting "just in case"
  3. Tell people why you're collecting (APP 5) — at or before the point of collection
  4. Keep information secure (APP 11) — reasonable steps against misuse, loss, or unauthorised access
  5. Give access on request (APP 12) — within 30 days
  6. Correct information on request (APP 13)
  7. Be careful about overseas transfers (APP 8) — specific rules apply when personal information passes through offshore services

The OAIC commenced an enforcement sweep in January 2026, targeting approximately 60 entities across 6 sectors. Enforcement is active, not theoretical.

Are there businesses that remain exempt after 1 July 2026?

Yes. Some specific carve-outs remain:

  • Registered political parties — still exempt under the Act
  • Purely personal or household activities — individuals acting in a personal (not business) capacity
  • Media organisations — exempt where acting in a journalistic capacity with a published code of ethics

State and territory governments operate under their own privacy legislation. If your business only interacts with state agencies, the Commonwealth Act may not be your primary framework — though it applies where you handle Commonwealth records or contracts.

What do you need to do before 1 July 2026?

Start by confirming whether and how you're covered — use the free Privacy Act business applicability check to get a plain-English verdict in five questions.

  1. Audit what personal information you hold — customer names, emails, phone numbers, payment details, health information, employee records
  2. Map where it flows — what systems store it, who can access it, which third-party tools receive it
  3. Write or update your privacy policy — must be publicly available and meet APP 1 requirements
  4. Review your collection notices — every form, booking page, or sign-up needs to tell people what you're collecting and why (APP 5)
  5. Assess your data security — is customer data encrypted? Who has access?
  6. Understand your breach obligations — once covered, the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act applies

Frequently asked questions

My turnover is under $3 million — am I still exempt after 1 July 2026?

No. The $3 million turnover threshold is removed from 1 July 2026 by the Privacy and Other Legislation Amendment Act 2024. After that date, turnover is no longer a factor. If you collect personal information in the course of running a business, your business is regulated regardless of size.

I'm a sole trader. Does the Privacy Act apply to me?

Yes, if you collect personal information through your business activities. The Act applies to "organisations," which includes individuals carrying on a business. A sole trader plumber with a customer contact list, or a freelancer who invoices clients, is carrying on a business and will be regulated from 1 July 2026.

What if I only collect names and email addresses?

Names and email addresses are personal information under s 6 of the Privacy Act — they identify or are reasonably identifiable to specific individuals. You will need to comply with collection, notification, and security obligations even for a simple contact list or mailing list.

Do I need everything ready exactly on 1 July 2026?

Your obligations apply from that date, so your privacy policy, collection notices, and basic security measures should be in place by then. The OAIC is unlikely to take immediate enforcement action against businesses making a genuine, demonstrable effort to comply — but being completely unprepared is a different matter.

What happens if I do nothing?

The OAIC can investigate, issue determinations, and seek civil penalties. For serious or repeated interference with privacy, penalties can reach $50 million, or 3 times the benefit obtained, or 30% of adjusted annual turnover — whichever is highest. Per-contravention penalties for less serious breaches reach $66,000. The OAIC's January 2026 enforcement sweep confirms this is active regulation.

Use the free Privacy Act Business Applicability Check to find out whether your business is covered from 1 July 2026 and which obligations apply — takes about 5 minutes.

Check if I'm covered →