Privacy Act changes: what applies to small businesses now, what starts in December, and what's proposed

Most small businesses are still exempt, but not all, and some laws apply to everyone. What's in force, what starts 10 December and what the draft bill proposes.

A desktop monitor displaying a workspace with notes, beside a keyboard and headphones.
Illustrative photograph: Niclas Illg / Unsplash

Australia’s privacy law is changing in stages, and it’s easy to lose track of which parts apply to a small business. The short answer: for most small businesses, the core obligations still don’t apply. But some businesses are covered regardless of size, two recent laws apply to everyone, and a new draft bill would change the rules for businesses that share customer data.

The small business exemption still stands

A small business, for privacy purposes, is one with annual turnover of $3 million or less. Most are not bound by the Australian Privacy Principles (APPs) in the Privacy Act.

Some small businesses are covered anyway. The Office of the Australian Information Commissioner (OAIC) lists examples including:

  • health service providers
  • businesses that trade in personal information without consent
  • Commonwealth government contractors
  • residential tenancy databases
  • businesses with reporting obligations under anti-money laundering law, for those activities.

If you’re in one of those groups, everything below about “covered” businesses applies to you.

Already law for everyone

Two changes from the 2024 reform package apply regardless of turnover:

  • A statutory tort for serious invasions of privacy started on 10 June 2025. People can now sue for serious invasions of their privacy. It applies to individuals and organisations that aren’t necessarily covered by the APPs, and there’s no small business exemption.
  • Criminal offences for doxxing started on 11 December 2024. Using a carriage service to release someone’s personal data in a menacing or harassing way carries a maximum of six years’ imprisonment.

For any business, that means staff shouldn’t publish or misuse customers’ or other people’s personal details, whatever your turnover.

Already law for covered businesses

Since 11 December 2024, the OAIC can issue infringement notices for specific breaches, without going to court. They include failing to have a privacy policy with the required content, failing to give people a simple way to opt out of direct marketing, and not dealing properly with correction requests. Each notice carries a fine per contravention. The amount depends on whether the business is an individual, a company or a listed company, and courts can impose larger civil penalties.

The regulator has signalled it will use these powers. In January 2026 it began a sweep of privacy policies across about 60 organisations in six sectors: rental and property, chemists, licensed venues, car rental, car dealerships, and pawnbrokers and second-hand dealers.

Starting 10 December 2026: automated decisions

From 10 December, covered businesses that use computer programs to make decisions about people must say so in their privacy policy. The obligation applies where a decision could reasonably be expected to significantly affect someone’s rights or interests. Think credit, tenancy or access to a significant service, not an automated email reminder.

The privacy policy will need to describe:

  • the kinds of personal information used by those programs
  • the kinds of decisions made solely by the programs
  • the kinds of decisions where a program does something substantially and directly related to making the decision.

This obligation can also attract infringement notices. The OAIC consulted on guidance between 18 May and 15 June 2026. We could not find final guidance as of 25 September.

A separate Children’s Online Privacy Code must be registered by December 2026. Once registered, it will apply to covered businesses providing social media and other online services likely to be accessed by children.

Proposed: the tranche 2 draft bill

On 31 August 2026, the Attorney-General’s Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, with a consultation paper setting out about 40 proposals. Consultation closed on 18 September. This is a draft for comment. It is not law, it has no start dates yet, and we found no sign it has been introduced to Parliament.

The proposals most relevant to small businesses:

  • The exemption stays, but “trading” gets wider. Under current law, a small business that trades in personal information without consent already loses the exemption. The draft keeps that rule but broadens what counts as trading: disclosing personal information for money or other consideration, or for direct marketing purposes, with some carve-outs. That could bring more small businesses under the Act.
  • Trading would need consent. The paper says consent would not be needed for a business’s own direct marketing, but would be needed to trade personal information.
  • Direct marketing would be defined more broadly. It would cover people targeted individually or as part of an audience, segment or cohort, including online behavioural advertising. The simple opt-out obligation would remain.
  • A “fair and reasonable” test would replace the current rules on collecting, using and disclosing personal information.
  • A right to erasure would be limited to large digital platforms.

The consultation paper says disclosure “for the purposes of direct marketing” should be read broadly, and may include disclosures through cookies or pixels in programmatic advertising. If your business uses advertising pixels or tracking tools, shares customer lists with partners, or passes customer data to others for marketing, watch the final bill closely.

What to do now

  1. Check whether you’re covered despite the $3 million threshold. Health service providers are one common example.
  2. If you’re covered, review your privacy policy now. Missing or incomplete policies can already attract infringement notices.
  3. If you’re covered and use software to make significant decisions about people, add the required information to your privacy policy before 10 December.
  4. Whatever your size, set clear rules for staff about publishing or sharing people’s personal details.
  5. If you share customer data or use advertising pixels, note the draft trading rules and follow the bill’s progress.

This is general information, not legal advice.

Sources 9 sources
  1. Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024
  2. OAIC: Small business
  3. OAIC: Statutory tort for serious invasions of privacy
  4. OAIC: Privacy compliance sweep to put privacy policies under the spotlight
  5. OAIC: Consultation on guidance for transparency in automated decision-making
  6. OAIC: Children's Online Privacy Code
  7. Attorney-General's Department: Privacy reform consultation (tranche 2)
  8. Attorney-General's Department: Consultation paper
  9. Attorney-General's Department: Exposure draft – Privacy Amendment (Personal Data Protection) Bill 2026

How this story was made. Researched from the primary sources listed above (open Sources to see them), drafted with AI assistance and checked against those sources before publication. Details can change after publication; check the original source before acting. Spotted an error? Tell us and we will check it.

General information only, not legal, tax or financial advice.

Editorial standards · Corrections · Ownership

Help us improve Digital Advisors

Allow Google Analytics to measure visits and use of our guides and resources? You can decline and still use everything, or change your choice below.

Read our privacy notice