Australia's Privacy Act 1988: What Small Businesses Must Do Before the December 2026 Deadline

Reviewed by IT Cares · Updated August 2026

Digital shield and padlock over a stylized map of Australia, representing Privacy Act 1988 compliance for small business
Australia's private-sector privacy exemption for small business is scheduled to disappear on 10 December 2026.
🌏
This guide is general information for Australian small businesses, not legal advice. IT Cares supports businesses remotely from Canada and does not operate an office in Australia — for formal legal compliance sign-off, confirm details with an Australian privacy lawyer or the OAIC directly.

Australia's Federal Court has already handed down its first-ever civil penalty under the Privacy Act 1988 — $5.8 million against a pathology provider in October 2025 — and from 10 December 2026, roughly 2.5 million small businesses that have never had to think about privacy law will suddenly be inside its scope. For over two decades, the Privacy Act's private-sector rules mostly skipped past small operators: if your annual turnover sat under AUD $3 million and you weren't in a handful of specifically regulated sectors, you were exempt from the bulk of the Act's obligations. That exemption is now on its way out, and the reform package around it — new penalties, a new personal right to sue, a criminal offence for doxxing, and a forthcoming children's privacy code — has already started applying well before the exemption itself disappears.

This guide walks through what the Privacy Act 1988 actually requires, who is covered today versus who becomes covered in December 2026, what changed in the 2024 reform package and why some of it already affects exempt businesses, what real penalties have looked like in practice, and a practical sequence for getting ready before the transition deadline arrives.

A note before we start

This article is general information to help Australian small business owners understand the landscape and ask better questions of a privacy lawyer or the OAIC — it is not legal advice, and the December 2026 date discussed throughout reflects the timeline anticipated at the time of writing for the second tranche of reforms, which had not yet been finalized in legislation. Confirm current commencement dates directly with the OAIC (oaic.gov.au) before treating any date in this guide as certain.

The Privacy Act 1988, in Plain Language

The Privacy Act 1988 (Cth) is Australia's principal law governing how organisations handle personal information, enforced by the Office of the Australian Information Commissioner (OAIC). Rather than a long list of prescriptive rules, its core sits in 13 Australian Privacy Principles (APPs) — a principles-based framework covering the full lifecycle of personal information, from collection through use, disclosure, storage, security, and eventual access or correction by the individual it concerns.

The Act applies to "APP entities" — Australian government agencies and private-sector organisations above a certain size or in certain regulated categories. That last clause is the whole story for small business: unlike most comparable privacy regimes overseas, Australia has historically carved most small operators out of coverage entirely, rather than just softening specific requirements for them.

Who's Covered Today — and Who's About to Be

Under the current small business exemption, an organisation with annual turnover of AUD $3 million or less is generally exempt from the Privacy Act's private-sector obligations — unless it falls into one of several carve-outs that apply regardless of size: health service providers, businesses that trade in personal information for a benefit, credit reporting bodies and credit providers, contracted service providers for Commonwealth contracts, and organisations that hold tax file number information, among others. A small bookkeeping firm, a boutique retailer, or a local trades business under the turnover threshold and outside those carve-outs has, until now, largely sat outside the Act's reach.

That changes with the second tranche of Privacy Act reforms. The blanket small-business exemption is expected to be formally removed with a commencement date of 10 December 2026 — the same date set for the OAIC's forthcoming Children's Online Privacy Code to be registered. Industry estimates put the number of newly-covered businesses at roughly 2.5 million, concentrated in sectors like real estate, healthcare and allied services, retail, trades, hospitality, and professional services — businesses that have, in many cases, never had a privacy policy or a documented data handling process because they've never legally needed one.

Category Today (pre-Dec 2026) After exemption removal
Under $3M turnover, no carve-out Generally exempt from most APPs Subject to all 13 APPs
Health service providers (any size) Already covered regardless of turnover No change — already covered
Businesses trading in personal information Already covered regardless of turnover No change — already covered
Statutory tort for serious privacy invasions Applies now (since 10 June 2025) — independent of exemption Continues to apply
Notifiable Data Breaches scheme Only applies if otherwise covered Newly applies to formerly-exempt businesses

Not sure how the December 2026 change affects your setup?

IT Cares provides remote cybersecurity consulting to businesses navigating exactly this kind of cross-border compliance question.

The 2024 Reforms: What Changed and When

The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024 as the first tranche ("tranche 1") of a broader reform package. Several of its changes are already in force, well ahead of the small-business exemption removal:

1

Statutory tort for serious invasions of privacy — commenced 10 June 2025

For the first time, individuals in Australia have a personal legal right to sue over a serious invasion of privacy — either intrusion upon their seclusion or misuse of information relating to them. Crucially, this tort operates independently of the Privacy Act and the APPs, meaning it can reach defendants who are not otherwise regulated by the Act at all, including small businesses currently covered by the turnover exemption.

2

Doxxing criminalised — passed 29 November 2024

Publishing another person's private information in a menacing or harassing way is now a specific criminal offence under Commonwealth law, addressing a gap that previously left doxxing victims with limited recourse.

3

Stronger OAIC enforcement powers

The OAIC gained broader authority to compel information from organisations under investigation, require specific corrective actions, and issue binding directions — moving it closer to a modern regulator with real day-to-day enforcement teeth rather than relying solely on court action.

4

Children's Online Privacy Code — expected registration 10 December 2026

The OAIC has been mandated to develop a dedicated APP Code for online services likely to be accessed by children, requiring services to consider children's best interests, obtain consent before using their data for targeted advertising, and support deletion requests.

5

Small business exemption removal — expected 10 December 2026

Tranche 2 of the reforms, still under development at time of writing, is expected to remove the blanket $3 million turnover exemption, bringing millions of previously-uncovered small businesses into full APP compliance alongside a "fair and reasonable" test for data handling and expanded individual erasure rights.

The New Privacy Tort — Why It Matters Even If You're "Exempt"

The single most misunderstood point among small business owners we hear from is the assumption that falling under the $3 million turnover exemption means privacy law simply doesn't touch them. The statutory tort breaks that assumption. Because it creates a personal civil right of action rather than a regulatory obligation enforced by the OAIC, it doesn't care whether your business is an "APP entity" or not — a customer, employee, or member of the public who experiences a serious invasion of their privacy at the hands of your business can sue you directly, exemption or no exemption.

In practice, this means the safest posture for a currently-exempt small business is not "wait until December 2026 to think about this" but rather "start behaving like a covered entity now, on a timeline that suits you, rather than being forced into it under deadline pressure later." Basic safeguards — not sharing customer information without a clear reason, securing databases and customer lists, having a real process before publishing anything about an identifiable individual — reduce exposure to the tort regardless of what the Privacy Act's formal exemption boundary says.

IT Cares field note

Businesses that assume "we're too small for privacy law" are working from an outdated picture even before December 2026 arrives. The tort already removes that shield for serious invasions of privacy, and OAIC enforcement powers have already been strengthened — the exemption removal is the last domino, not the first.

Handling customer or patient data and want a second opinion?

Our remote cybersecurity team reviews data handling setups for businesses outside Canada too — no on-site visit required.

Penalties: What Non-Compliance Actually Costs

The penalty regime under the Privacy Act has been substantially strengthened. Since the 2024 reforms, the OAIC now has three tiers of civil penalty available depending on severity:

Tier Applies to Maximum penalty
Mid-tier (individuals) Interferences with privacy below the "serious or repeated" threshold 2,000 penalty units — roughly AUD $660,000
Mid-tier (companies) Interferences with privacy below the "serious or repeated" threshold 10,000 penalty units — roughly AUD $3.3 million
Serious or repeated interference Egregious or repeated privacy breaches Greater of $50 million, 3× the benefit obtained, or 30% of adjusted turnover during the breach period

Failing to notify the OAIC of an eligible data breach "as soon as practicable" — a separate obligation under the Notifiable Data Breaches scheme — carries its own civil penalty exposure, reported at up to roughly AUD $2.1 million in recent guidance. These aren't theoretical numbers: in October 2025, the Federal Court handed down Australia's first-ever civil penalty under the Privacy Act, ordering Australian Clinical Labs (trading as Medlab Pathology) to pay a combined $5.8 million, including $800,000 specifically for failing to notify a data breach as soon as practicable under section 26WK(2). Separately, IBM's Cost of a Data Breach research puts the average total cost of a data breach for an Australian organisation at roughly AUD $4.2 million once detection, containment, notification, and reputational costs are all factored in — a number that dwarfs what most small businesses budget for cybersecurity in an entire year.

The 13 Australian Privacy Principles, Summarized

The 13 APPs are principles-based rather than prescriptive checklists, which makes them flexible but also means small businesses often don't know where to start. Here's a plain-language summary of the ones that matter most day-to-day:

APP What it requires, in practice
APP 1 — Open and transparent management Maintain a clear, publicly available privacy policy describing what you collect and why
APPs 3-5 — Collection Only collect personal information reasonably necessary for your business, by lawful and fair means, and notify individuals at or before collection
APPs 6-7 — Use, disclosure, direct marketing Use data only for the purpose it was collected (or a related purpose the person would expect); give a clear opt-out for marketing
APP 8 — Cross-border disclosure Take reasonable steps to ensure an overseas recipient (e.g. a cloud vendor) also protects the data appropriately
APP 11 — Security Take reasonable steps to protect personal information from misuse, loss, and unauthorised access, and destroy or de-identify it once no longer needed
APPs 12-13 — Access and correction Give individuals access to their own personal information on request, and correct it when it's wrong

The OAIC publishes the full text of all 13 APPs and detailed guidance at oaic.gov.au — worth bookmarking directly rather than relying solely on secondary summaries, since guidance is updated as the reform package rolls out.

Building an APP-Compliant Program Before December 2026

1

Map what personal information you actually hold

List every place personal information enters your business — booking forms, POS systems, email inboxes, spreadsheets, CRM tools — and where it's stored. Most small businesses are surprised by how scattered this turns out to be once mapped honestly.

2

Draft (or update) a plain-language privacy policy

Cover what you collect, why, how it's used, whether it's disclosed to third parties (including cloud vendors), and how someone can request access or correction. APP 1 requires this to be freely available, not buried in fine print.

3

Review your security safeguards against APP 11

Password hygiene, access controls limiting who in your business can see customer data, encrypted storage where practical, and a documented process for securely disposing of data you no longer need.

4

Check your vendor and cloud contracts (APP 8)

If customer data flows to an overseas cloud provider, payment processor, or marketing platform, confirm that vendor's own data protection commitments are adequate — this becomes a documented obligation once you're covered.

5

Build a basic data breach response plan

Even before you're formally subject to the Notifiable Data Breaches scheme, having a plan for what happens if data is lost or exposed — who assesses it, who decides on notification, how you'd contact affected people — turns a scramble into a process.

6

Nominate a privacy contact

A named person (even part-time, even the owner) who handles privacy questions and access requests. It doesn't need a formal title yet, but customers and regulators alike expect there to be someone accountable.

Real-World Scenarios

The following are composite, fictional scenarios illustrating common patterns among Australian small businesses preparing for these changes — not specific real companies.

Scenario: a regional real estate agency

A 12-person real estate agency in regional Victoria, with turnover just under the $3 million threshold, had never had a written privacy policy — tenant and buyer information was collected via paper forms and a shared spreadsheet accessible to the whole office. Anticipating the exemption removal, the agency's principal engaged a local consultant to build a proper client database with role-based access, a one-page privacy policy for its website, and a retention schedule for old tenancy applications, at a cost of roughly AUD $4,000 for the initial build-out.

Scenario: a boutique allied health clinic

A physiotherapy clinic with two locations and combined turnover under $3 million discovered, during a routine review, that it was already covered by the Privacy Act regardless of turnover because health service providers fall outside the small business exemption entirely. The clinic had been operating for six years without a compliant privacy policy or breach response process. It engaged a privacy consultant to build both, alongside staff training on handling patient records, for approximately AUD $6,500.

Scenario: a small e-commerce retailer

An online homewares retailer with turnover of $1.8 million relied on an overseas email marketing platform and a separate overseas-hosted customer database. While technically still exempt under the turnover threshold at the time, the retailer's founder became concerned about the new statutory tort after a competitor's customer list was leaked publicly and the affected business faced a wave of customer complaints and reputational damage even without formal OAIC action. The retailer proactively reviewed its vendor contracts and added basic access controls to its customer database ahead of any legal requirement to do so, at minimal cost using existing platform features.

Budget Reality Check

Compliance costs for Australian small businesses preparing for December 2026 scale with how much existing infrastructure needs to be built versus simply documented:

These are directional figures for budgeting conversations, not fixed quotes. Every case study above shares one pattern: businesses that started before the deadline paid a fraction of what a reactive, post-incident compliance scramble typically costs — and none of it approaches the $4.2 million average cost of an actual data breach.

Australian Government Resources

For the notification side of this framework specifically, see our companion guide on the Notifiable Data Breaches scheme.

Want a second set of eyes on your data security setup?

IT Cares provides remote cybersecurity consulting and security reviews for businesses outside Canada as well — entirely remote, no local office required. We can review your technical safeguards against APP 11's "reasonable steps" standard even if the legal sign-off still needs an Australian lawyer.

Frequently Asked Questions

Does the Privacy Act 1988 apply to my small business right now?
Only if your annual turnover exceeds AUD $3 million, or you fall into one of the carve-outs that apply regardless of size — health service providers, businesses that trade in personal information, credit reporting bodies and credit providers, and tax file number recipients, among others. If none of those apply and your turnover is under $3 million, you are currently exempt from most of the Privacy Act's obligations. That exemption is scheduled to be removed on 10 December 2026, which will bring an estimated 2.5 million additional small businesses into full scope.
If I'm exempt from the Privacy Act, can I still be sued over a privacy breach?
Yes. The new statutory tort for serious invasions of privacy, which commenced 10 June 2025, operates independently of the Privacy Act and the Australian Privacy Principles. It gives individuals a personal right to sue for a serious invasion of privacy — intrusion upon seclusion or misuse of information — against a wide range of defendants, including small businesses and individuals who are not otherwise regulated by the Privacy Act. Being exempt from the Act's registration and reporting obligations does not put you outside the reach of this new civil action.
What exactly changes for my business on 10 December 2026?
10 December 2026 is the date currently anticipated for the small business exemption to be removed as part of the second tranche of Privacy Act reforms. Once removed, any business currently relying on the under-$3-million-turnover exemption would become subject to all 13 Australian Privacy Principles — meaning a compliant privacy policy, defined collection and disclosure practices, a designated way to handle access and correction requests, and integration into the Notifiable Data Breaches scheme. As of this writing the exemption has not yet been formally repealed by legislation, so businesses should monitor OAIC and Attorney-General's Department announcements for the confirmed commencement date rather than treating December 2026 as guaranteed to the day.
What are the 13 Australian Privacy Principles in simple terms?
The 13 APPs cover the full lifecycle of personal information: how openly and transparently you manage it (APP 1), what you can collect and how (APPs 3-5), how you use and disclose it including for direct marketing (APPs 6-7), rules for sending data overseas (APP 8), restrictions on government identifiers (APP 9), data quality and security (APPs 10-11), and individuals' rights to access and correct their own information (APPs 12-13). In practice, most small businesses spend the bulk of their compliance effort on collection notices, a public privacy policy, reasonable security safeguards, and a workable access-request process.
What penalties can a small business actually face under the Privacy Act?
Since the 2024 reforms, the OAIC has a mid-tier civil penalty option of up to 2,000 penalty units (roughly AUD $660,000) for individuals and 10,000 penalty units (roughly AUD $3.3 million) for companies, for interferences with privacy that don't meet the higher "serious or repeated" threshold. For serious or repeated interferences, maximum penalties rise to the greater of $50 million, three times the benefit obtained from the breach, or 30% of adjusted turnover during the breach period. In October 2025, the Federal Court handed down Australia's first-ever civil penalty under the Privacy Act — a combined $5.8 million against a pathology provider, including $800,000 specifically for failing to notify a data breach as soon as practicable.
Do I need a privacy officer or a formal privacy policy if I'm currently exempt?
It's not legally mandatory while the exemption applies, but it's increasingly a practical necessity. Many larger customers, government tenders, insurers, and platform partners now ask small suppliers to demonstrate privacy practices regardless of legal exemption status, and building the habit now — a short privacy policy, a named contact for privacy questions, basic data handling documentation — makes the transition to full compliance in December 2026 far less disruptive than starting from zero after the exemption disappears.
What's the Children's Online Privacy Code and does it affect my business?
The Children's Online Privacy Code is a new APP Code the OAIC has been mandated to develop, targeting online services — apps, games, websites — that are likely to be accessed by children or are primarily directed at children. It sets additional requirements including considering children's best interests, obtaining consent before using children's information for targeted advertising, and enabling deletion requests. The Code is expected to be registered by 10 December 2026. If your business operates any online service that children are likely to use, even incidentally, it's worth reviewing the Code's requirements as they're finalized rather than waiting until after registration.
What's the single most useful first step for a small business preparing for these changes?
Map what personal information you actually collect, where it's stored, who can access it, and how long you keep it — before drafting any policy or process. Most small businesses that scramble in the final months before a compliance deadline do so because they never inventoried their own data in the first place. A clear data map turns every subsequent step (privacy policy, breach response plan, access-request process) from a guessing exercise into a documentation exercise.

Need Help Reviewing Your Data Security Before December 2026?

IT Cares reviews technical safeguards remotely for businesses worldwide — a practical second opinion on your APP 11 "reasonable steps" security posture.

Comments (3)

RH
Rachel H., Brisbane
August 2, 2026

Didn't realise the tort already applies regardless of the turnover exemption. We're under $3M and had assumed we had until December 2026 to worry about any of this. Getting our privacy policy sorted this month instead of waiting.

DT
David T., Perth
July 29, 2026

The Medlab penalty figure really puts it in perspective. We're a small allied health practice and had no idea health providers were already covered regardless of size — fixing that gap now rather than finding out the hard way.

SN
Sarah N., Adelaide
July 25, 2026

Good clear breakdown of the 13 APPs — most explainers I found just link to the OAIC page without actually summarising it. Sent this to our office manager as a starting checklist.

Leave a Comment