Privacy Ready
Business Applicability Check · Privacy Act coverage

Am I Covered by the Australian Privacy Act?

Which entities are covered now, what changes on 1 July 2026, and how to check your own business in five questions.

From 1 July 2026, the Privacy Act 1988 (Cth) applies to almost all Australian businesses regardless of size. The $3 million small business exemption is removed by the Privacy and Other Legislation Amendment Act 2024. Health service providers, financial services organisations, credit providers, and government agencies are already covered regardless of turnover. A separate ADM disclosure obligation applies from 10 December 2026 to covered entities using automated decision-making tools.

Last updated: 1 July 2026

Who's covered by the Privacy Act

Category Covered? Example
Health, financial services, credit or government entities Included Sole-trader physio, credit union, local council — covered regardless of turnover
Businesses with turnover over $3 million Included Already covered under the current turnover threshold
Any business, any turnover, from 1 July 2026 From 1 Jul 2026 Sole-trader tradesperson, boutique retailer, small consultancy
Covered entities using automated decision-making Extra disclosure ADM disclosure section required in privacy policy from 10 Dec 2026
Personal, family or household activity — not a business Excluded A personal contact list kept outside any business activity

How this is interpreted in practice

The $3 million turnover test is being removed, not adjusted. Businesses that correctly sat outside the Privacy Act under the old threshold don't get a grace period or a higher replacement number — from 1 July 2026 the exemption is gone entirely, and turnover stops being relevant unless another reform changes it again.

"Carrying on a business" is the concept businesses most often misjudge. The Act's coverage isn't limited to companies — it extends to individuals carrying on a business, which includes sole traders, partnerships, and trusts. A sole-trader plumber or consultant with a client contact list is regulated from 1 July 2026 in exactly the same way as a company.

A second common gap: businesses correctly identify that they're covered by the Privacy Act generally, but miss that a separate ADM disclosure obligation attaches on top of that from 10 December 2026 if they use AI or automated tools to make or assist decisions about customers, applicants, or staff.

Coverage determination hierarchy

Tier Coverage trigger Effective date
Always regulated Health, financial services, credit provider, or government agency Already in effect
Turnover-based Annual turnover over $3 million Already in effect
Universal coverage Any entity carrying on a business, any turnover From 1 July 2026
Not yet covered Turnover under $3 million, non-regulated industry Until 30 June 2026 only
Free diagnostic tool

Business applicability check

Answer five questions about your business. Get an instant verdict on whether the 1 July 2026 threshold change affects you, plus the specific obligations that apply — at a permanent URL you can bookmark or share.

Question 1 of 5

What type of entity is your business?

Different structures have different Privacy Act obligations — some are covered automatically regardless of size.

Question 2 of 5

What's your approximate annual turnover?

Use your most recent completed financial year. The $3 million threshold was the key dividing line before 1 July 2026 — though industry and data types can override it.

Question 3 of 5

What's your primary industry?

Health and financial services are covered regardless of size. Others may have industry-specific obligations layered on top.

Question 4 of 5

What personal information does your business handle?

Select all that apply. Sensitive information types — health records, biometrics, government identifiers — carry additional obligations and can affect whether you're covered at all.

Select at least one to continue.

Question 5 of 5

Do you use AI or automated tools that make decisions affecting individuals?

This includes AI-assisted loan approvals, automated job screening, personalised pricing, AI chatbots handling complaints, or any system where software makes or assists a decision about a specific person. A new disclosure requirement applies to covered entities from 10 December 2026.

When you need a business applicability check

  • You're a sole trader, partnership, or small company with turnover under $3 million
  • You're preparing for the 1 July 2026 removal of the small business exemption
  • You're not sure whether being in health, finance, or a government-adjacent industry already covers you
  • A client or vendor has asked you to confirm your Privacy Act status
  • You use AI or automated tools and need to know if the ADM disclosure deadline applies too
  • You're deciding whether you need a privacy policy, collection notices, or a breach response plan

Frequently asked questions

Does the Australian Privacy Act apply to small businesses from 1 July 2026?

Yes. From 1 July 2026, the $3 million small business exemption is removed by the Privacy and Other Legislation Amendment Act 2024. Almost all Australian businesses that collect personal information are covered under the Privacy Act 1988 (Cth), regardless of annual turnover. Health service providers, financial services businesses, and government agencies were already covered before that date.

Which Australian businesses are automatically covered regardless of size?

Health service providers, financial services organisations, credit providers, and government agencies are covered under the Privacy Act 1988 (Cth) regardless of annual turnover or number of employees. Businesses with annual turnover above $3 million have always been covered. From 1 July 2026, the turnover threshold is removed entirely.

What is the ADM disclosure deadline?

From 10 December 2026, covered entities using automated decision-making (ADM) systems must add a disclosure section to their privacy policy under APP 1.3. The disclosure must list each system, what decisions it affects, and how individuals can seek human review.

What does being covered by the Privacy Act require?

Covered entities must comply with all 13 Australian Privacy Principles (APPs). Core obligations include: a publicly accessible privacy policy (APP 1), collection notices at every data collection point (APP 5), a notifiable data breach procedure (Part IIIC), security measures (APP 11), and processes for access and correction requests (APPs 12–13). Penalties for serious breaches reach $50 million.

Does the Privacy Act apply to sole traders in Australia?

Yes, from 1 July 2026. The Privacy Act 1988 (Cth) applies to individuals carrying on a business — including sole traders who collect personal information from customers. The removal of the $3 million exemption means a sole-trader plumber, accountant, or consultant with a client contact list is regulated from that date.

Run the free business applicability check to find out exactly which Australian Privacy Principles apply to your business before 1 July 2026.

Get my coverage verdict →