- The $3 million test
- Covered regardless of turnover
- A privacy policy backed by real practices (APP 1)
- Collect only what you need, and say why (APPs 3 and 5)
- Keep the information secure (APP 11)
- Check before sending data overseas (APP 8)
- Notify a data breach that causes serious harm (Part IIIC)
- The cost of getting it wrong
- A compliance checklist
- Where a lawyer helps
- The threshold that catches businesses by surprise
For more than two decades, most Australian businesses with an annual turnover of $3 million or less have been able to ignore the Privacy Act 1988 (Cth) (the Act). The small business exemption in s 6D means they are not treated as "organisations" for privacy purposes, so they have not needed a privacy policy, have not had to follow the Australian Privacy Principles (the APPs), and have not been caught by the notifiable data breach scheme.
That position is closing. A change already in force from 1 July 2026 brings a large new group of small businesses into the Act, and the federal government has agreed in-principle to remove the small business exemption altogether. If you run a business turning over less than $3 million, you need to know whether you are already covered, what the duties look like if you are, and what non-compliance now costs.
The $3 million test
Under s 6D of the Act, a business is a "small business" if its annual turnover for the previous financial year was $3,000,000 or less. A business that has not yet traded for a full financial year is tested against its projected turnover for the current year instead.
Annual turnover is not simply revenue from sales. Under s 6DA, it includes all income earned in the course of the business: sales of goods and services, commission, rent, leasing and hiring income, interest, royalties, dividends and government subsidies. The OAIC's small business guidance confirms that assets held, capital gains and the proceeds of capital sales are not counted.
Two further points in the test catch people out:
- Related entities count: A body corporate is not a small business operator if it is related to a larger company that is caught by the Act (s 6D(9)). A subsidiary of a large group does not get the exemption just because the subsidiary itself turns over little.
- The test is historic: If your turnover exceeded $3 million in any financial year since the provision commenced, you are not a small business operator now, regardless of current income.
Covered regardless of turnover
The exemption never covered everyone. Under s 6D(4), a business is outside the exemption, whatever its turnover, if it:
- Provides health services: holds health information, which includes private schools, childcare centres, allied health providers and pharmacists;
- Trades in personal information: discloses personal information to someone else for a benefit, service or advantage, or collects it in return for such a benefit, without the individual's consent and without legal authorisation. Selling a customer list to a marketing company is the classic example;
- Provides services under a Commonwealth contract: operates as a contracted service provider;
- Operates a residential tenancy database;
- Is a credit reporting body: otherwise handles credit information or tax file numbers.
A small business can also voluntarily opt in to the Act under s 6EA by notifying the Commissioner. Once covered, any of these businesses must comply with the full set of APPs and with Part IIIC on data breach notification.
Two changes widening the net in 2026
Reporting entities under the AML/CTF regime
From 1 July 2026, the anti-money laundering regime expanded beyond the financial sector, and the Privacy Act came with it. Businesses that now provide certain "designated services" are reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), and s 6E(1A) of the Privacy Act treats them as organisations for those activities, even if they would otherwise qualify for the small business exemption.
The affected sectors, set out in HWL Ebsworth's analysis of the reforms, are:
- real estate professionals, including real estate agents, buyer's agents and property developers;
- lawyers;
- conveyancers;
- accountants, and trust and company service providers;
- dealers in precious metals, stones and products.
The OAIC estimates that more than 100,000 small businesses are affected. The APPs apply to the personal information these businesses collect for customer identification and due diligence, which means identity documents, verification records and ongoing monitoring data are all now within the Act.
The proposed removal of the exemption
In its September 2023 response to the Privacy Act Review, the federal government agreed in-principle to remove the small business exemption. That did not happen in the first tranche of reform, the Privacy and Other Legislation Amendment Act 2024 (Cth), which commenced on 10 June 2025 and left the exemption in place. The removal remains a live proposal for the second tranche, with no commencement date confirmed. If it proceeds, the roughly 2.3 million small businesses currently outside the Act would all need privacy policies and APP compliance. The government has said a transition period and support measures would accompany the change.
Automated decision-making disclosure
Separately, from 10 December 2026, new APPs 1.7 to 1.9 require privacy policies to state whether the business uses automated decision-making that can significantly affect individuals, and to explain how those decisions work. As Allens has noted, this applies to every APP entity, including small businesses that are already caught.
A privacy policy backed by real practices (APP 1)
APP 1 is the foundation. Under cl 1.2 of Schedule 1 to the Act, an APP entity must take reasonable steps to implement practices, procedures and systems that ensure compliance with the APPs and that let it deal with inquiries and complaints. Under cl 1.3, it must have a clearly expressed and up-to-date APP privacy policy, and cl 1.4 sets out what the policy must contain:
- the kinds of personal information collected and held;
- how the information is collected and held;
- the purposes for which it is collected, held, used and disclosed;
- how an individual can access and seek correction of their information;
- how an individual can complain about a breach, and how the business will deal with the complaint;
- whether the business is likely to disclose information to overseas recipients.
A policy that exists only as a PDF on a website is not enough. The OAIC is currently running a privacy policy compliance sweep, checking whether organisations' policies accurately describe how personal information is actually handled, so the gap between the document and the practice is now an active enforcement focus.
Collect only what you need, and say why (APPs 3 and 5)
APP 3 limits collection to personal information that is reasonably necessary for the business's functions or activities, and APP 3.3 requires consent before collecting sensitive information such as health, biometric or racial information. APP 5 requires the business to notify individuals, at or before collection, of who is collecting the information, why, and what will happen to it. For AML/CTF reporting entities there is a carve-out where notification would breach tipping-off restrictions, but the default is transparency at the point of collection.
Keep the information secure (APP 11)
APP 11.1 requires an APP entity to take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. What is "reasonable" scales with the sensitivity of the data and the size of the business, but basic measures such as access controls, encryption, staff training and a retention and destruction schedule are the starting points. Information that is no longer needed should be destroyed or de-identified.
Check before sending data overseas (APP 8)
Before disclosing personal information to a recipient outside Australia, APP 8.1 requires the business to take reasonable steps to ensure the recipient does not breach the APPs. The stakes are high because, under s 16C, the acts of the overseas recipient are treated as the acts of the disclosing business, so the small business remains liable for what happens to the data offshore. Reliance on a substantially similar foreign law, or the individual's informed consent, are the main ways out.
Notify a data breach that causes serious harm (Part IIIC)
Since 2018, the notifiable data breach scheme has applied to every APP entity. An "eligible data breach" under s 26WE is unauthorised access to, unauthorised disclosure of, or loss of, personal information where a reasonable person would conclude it is likely to result in serious harm to an affected individual. Section 26WG lists what to weigh: the kind and sensitivity of the information, the security measures protecting it, who has obtained it and the likelihood the harm materialises.
The process when something goes wrong is:
- If you suspect an eligible data breach, carry out a reasonable and expeditious assessment and complete it within 30 days (s 26WH).
- If the assessment confirms an eligible data breach, prepare a statement describing the breach, the kinds of information involved and the steps individuals should take, and give it to the Commissioner as soon as practicable (s 26WK).
- Notify each affected individual, or if that is not practicable, publish the statement on your website (s 26WL). The Commissioner can also direct notification (s 26WR).
Note that a 72-hour notification window has been floated in reform discussions, but it is not current law. The existing obligation is to notify as soon as practicable after the breach is confirmed.
The cost of getting it wrong
The penalties in the Act were dramatically increased in 2022 and are not theoretical. For a serious interference with privacy under s 13G, the maximum penalty for a body corporate is the greater of $50 million, three times the value of the benefit obtained from the conduct, or 30% of the entity's adjusted turnover during the breach turnover period. For an individual, the maximum is $2.5 million. Even a non-serious interference with privacy under s 13H carries a penalty of up to 2,000 penalty units.
There is also a middle tier. Under s 13K, the Commissioner can issue infringement notices and compliance notices for specific APP failures, including not having an APP privacy policy (APP 1.3), not having the required contents (APP 1.4), and failing to honour opt-out requests in direct marketing. These lower-level tools mean a small business can be penalised for a paperwork failure without needing a full court case.
Enforcement sits with the OAIC. It investigates complaints, conciliates disputes and can make determinations, and it can commence Commissioner-initiated investigations. Civil penalties are recoverable through the Federal Court and the Federal Circuit and Family Court under s 80U. Add the reputational cost of a public determination or penalty, and for a small business the real exposure is often commercial rather than merely financial.
A compliance checklist
If you now sit inside the Act, work through this list:
- Confirm your status: Apply the s 6D test to your last full financial year, and check the exceptions for health services, trading in personal information, Commonwealth contracts and AML/CTF reporting.
- Map your data: Document what personal information you collect, where it comes from, where it is stored, who you share it with, and whether any of it goes overseas.
- Adopt a privacy policy: Draft an APP 1.3-compliant policy that accurately describes your actual practices, and make it publicly available and easy to find.
- Write collection notices: Prepare an APP 5 notice that is given to customers and clients at the point of collection.
- Secure the data: Implement access controls, encryption, staff training and a retention and destruction schedule appropriate to the sensitivity of what you hold.
- Plan for breaches: Assign someone to run a suspected-breach assessment within 30 days, and keep a template statement ready for the Commissioner and affected individuals.
- Review before December: If you use software that makes decisions about people, plan the automated decision-making disclosures your privacy policy will need from 10 December 2026.
Where a lawyer helps
A privacy lawyer's main job here is confirming whether you are covered at all, because the answer determines everything else. A practitioner can apply the s 6D and s 6DA tests to your actual revenue mix, work through the exceptions, and map how the AML/CTF reporting entity provisions apply to your particular services. From there, a lawyer can draft a privacy policy and collection notices that match your real practices, review your data flows and overseas transfers, and put a breach response plan in place that satisfies Part IIIC. If a breach has already happened, early legal advice on whether the harm threshold is met, and on what to say to the Commissioner and affected individuals, materially reduces both penalty risk and reputational damage.
The threshold that catches businesses by surprise
The misstep that costs the most is assuming the exemption applies when it never did. A boutique health clinic, a childcare centre, a business that has ever sold or swapped a customer list, and now every real estate agency, law firm, conveyancing practice and accounting firm, are or may already be inside the Act regardless of turnover. The $3 million figure feels like a safe harbour, but the exceptions in s 6D(4) and the AML/CTF change in s 6E(1A) mean many small businesses have been exposed for years without knowing it. This week, run the s 6D test against your last financial year and check the exception list. If you are covered, the first action is a privacy policy that reflects what you actually do with customer information, because that is the document the OAIC is now checking.