Your Privacy Act Exemption Is Shrinking. Here’s What’s Actually Changing.
Australia’s Privacy Act is being rewritten in stages. Some changes are already law, more land by December 2026, and the small business exemption many owners rely on is being worn away from the side, even though it hasn’t officially been removed yet. Here’s what it actually means, in plain terms.
What’s Already Changed
A round of reforms passed at the end of 2024, and the first part is already in effect. Since June 2025, people can sue a business directly through the courts over a serious privacy breach, rather than only being able to complain to the regulator. Penalties have also gone up sharply: smaller breaches can now attract fines around $330,000, and serious ones can reach $50 million, or 30% of a company’s turnover, whichever is higher.
The security rules have been tightened too. Businesses are now expected to have real technical and organisational protections in place, not just a vague promise to “take reasonable steps.” In practice, that means things like multi-factor authentication, endpoint protection, and a proper data breach response plan are moving from “good practice” to something closer to a legal expectation.
What’s Coming by December 2026
-
10 December 2026
If your business uses software or AI that plays a real role in decisions about people, things like automated credit checks, résumé screening, or pricing, you’ll need to say so in your privacy policy.
-
10 December 2026
A new Children’s Online Privacy Code is due, setting stricter standards for any service that’s likely to be used by people under 18.
“We’re a Small Business, We’re Exempt.” Not for Long.
Businesses under $3 million in annual turnover have long been able to sit outside the Privacy Act almost entirely. That exemption still technically exists, but it’s being hollowed out from other directions. Unrelated anti-money-laundering law changes that took effect on 1 July 2026 already pulled more than 100,000 small businesses, including real estate agents, lawyers, accountants, and conveyancers, into scope regardless of their size.
A second round of reforms is expected to remove the small business exemption altogether, along with adding a right for people to have their personal information deleted on request. No bill has been introduced for that yet, so there’s no confirmed date, but the direction of travel is clear: the exemption is shrinking, not staying put.
- Don’t assume you’re exempt. If you’re in real estate, legal, accounting, or finance, recent changes may already apply to you regardless of turnover.
- Know what personal information you hold, and where it’s stored, across email, cloud storage, and any customer systems.
- Check your privacy policy is current, and can be updated ahead of the December 2026 disclosure requirements if you use AI or automated tools.
- Get the security basics genuinely in place: multi-factor authentication, endpoint protection, and a plan for what happens if data is exposed.
Why This Is Worth Acting On Now
Even setting the fines aside, the bigger cost of getting this wrong is usually trust: a data breach that becomes public is hard for a small business to recover from. The rules are only moving in one direction, toward more obligation, not less, so the businesses that get the basics sorted now will have far less to scramble for when the next round of reform arrives.
Not sure where your business stands?
Technicalities can help you check what personal information you’re holding, tighten up your security basics, and get ahead of what’s coming.
Get in Touch