Australia's Federal Court has already handed down its first-ever civil penalty under the Privacy Act 1988 — $5.8 million against a pathology provider in October 2025 — and from 10 December 2026, roughly 2.5 million small businesses that have never had to think about privacy law will suddenly be inside its scope. For over two decades, the Privacy Act's private-sector rules mostly skipped past small operators: if your annual turnover sat under AUD $3 million and you weren't in a handful of specifically regulated sectors, you were exempt from the bulk of the Act's obligations. That exemption is now on its way out, and the reform package around it — new penalties, a new personal right to sue, a criminal offence for doxxing, and a forthcoming children's privacy code — has already started applying well before the exemption itself disappears.
This guide walks through what the Privacy Act 1988 actually requires, who is covered today versus who becomes covered in December 2026, what changed in the 2024 reform package and why some of it already affects exempt businesses, what real penalties have looked like in practice, and a practical sequence for getting ready before the transition deadline arrives.
A note before we start
This article is general information to help Australian small business owners understand the landscape and ask better questions of a privacy lawyer or the OAIC — it is not legal advice, and the December 2026 date discussed throughout reflects the timeline anticipated at the time of writing for the second tranche of reforms, which had not yet been finalized in legislation. Confirm current commencement dates directly with the OAIC (oaic.gov.au) before treating any date in this guide as certain.
The Privacy Act 1988, in Plain Language
The Privacy Act 1988 (Cth) is Australia's principal law governing how organisations handle personal information, enforced by the Office of the Australian Information Commissioner (OAIC). Rather than a long list of prescriptive rules, its core sits in 13 Australian Privacy Principles (APPs) — a principles-based framework covering the full lifecycle of personal information, from collection through use, disclosure, storage, security, and eventual access or correction by the individual it concerns.
The Act applies to "APP entities" — Australian government agencies and private-sector organisations above a certain size or in certain regulated categories. That last clause is the whole story for small business: unlike most comparable privacy regimes overseas, Australia has historically carved most small operators out of coverage entirely, rather than just softening specific requirements for them.
Who's Covered Today — and Who's About to Be
Under the current small business exemption, an organisation with annual turnover of AUD $3 million or less is generally exempt from the Privacy Act's private-sector obligations — unless it falls into one of several carve-outs that apply regardless of size: health service providers, businesses that trade in personal information for a benefit, credit reporting bodies and credit providers, contracted service providers for Commonwealth contracts, and organisations that hold tax file number information, among others. A small bookkeeping firm, a boutique retailer, or a local trades business under the turnover threshold and outside those carve-outs has, until now, largely sat outside the Act's reach.
That changes with the second tranche of Privacy Act reforms. The blanket small-business exemption is expected to be formally removed with a commencement date of 10 December 2026 — the same date set for the OAIC's forthcoming Children's Online Privacy Code to be registered. Industry estimates put the number of newly-covered businesses at roughly 2.5 million, concentrated in sectors like real estate, healthcare and allied services, retail, trades, hospitality, and professional services — businesses that have, in many cases, never had a privacy policy or a documented data handling process because they've never legally needed one.
| Category | Today (pre-Dec 2026) | After exemption removal |
|---|---|---|
| Under $3M turnover, no carve-out | Generally exempt from most APPs | Subject to all 13 APPs |
| Health service providers (any size) | Already covered regardless of turnover | No change — already covered |
| Businesses trading in personal information | Already covered regardless of turnover | No change — already covered |
| Statutory tort for serious privacy invasions | Applies now (since 10 June 2025) — independent of exemption | Continues to apply |
| Notifiable Data Breaches scheme | Only applies if otherwise covered | Newly applies to formerly-exempt businesses |
Not sure how the December 2026 change affects your setup?
IT Cares provides remote cybersecurity consulting to businesses navigating exactly this kind of cross-border compliance question.
The 2024 Reforms: What Changed and When
The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024 as the first tranche ("tranche 1") of a broader reform package. Several of its changes are already in force, well ahead of the small-business exemption removal:
Statutory tort for serious invasions of privacy — commenced 10 June 2025
For the first time, individuals in Australia have a personal legal right to sue over a serious invasion of privacy — either intrusion upon their seclusion or misuse of information relating to them. Crucially, this tort operates independently of the Privacy Act and the APPs, meaning it can reach defendants who are not otherwise regulated by the Act at all, including small businesses currently covered by the turnover exemption.
Doxxing criminalised — passed 29 November 2024
Publishing another person's private information in a menacing or harassing way is now a specific criminal offence under Commonwealth law, addressing a gap that previously left doxxing victims with limited recourse.
Stronger OAIC enforcement powers
The OAIC gained broader authority to compel information from organisations under investigation, require specific corrective actions, and issue binding directions — moving it closer to a modern regulator with real day-to-day enforcement teeth rather than relying solely on court action.
Children's Online Privacy Code — expected registration 10 December 2026
The OAIC has been mandated to develop a dedicated APP Code for online services likely to be accessed by children, requiring services to consider children's best interests, obtain consent before using their data for targeted advertising, and support deletion requests.
Small business exemption removal — expected 10 December 2026
Tranche 2 of the reforms, still under development at time of writing, is expected to remove the blanket $3 million turnover exemption, bringing millions of previously-uncovered small businesses into full APP compliance alongside a "fair and reasonable" test for data handling and expanded individual erasure rights.
The New Privacy Tort — Why It Matters Even If You're "Exempt"
The single most misunderstood point among small business owners we hear from is the assumption that falling under the $3 million turnover exemption means privacy law simply doesn't touch them. The statutory tort breaks that assumption. Because it creates a personal civil right of action rather than a regulatory obligation enforced by the OAIC, it doesn't care whether your business is an "APP entity" or not — a customer, employee, or member of the public who experiences a serious invasion of their privacy at the hands of your business can sue you directly, exemption or no exemption.
In practice, this means the safest posture for a currently-exempt small business is not "wait until December 2026 to think about this" but rather "start behaving like a covered entity now, on a timeline that suits you, rather than being forced into it under deadline pressure later." Basic safeguards — not sharing customer information without a clear reason, securing databases and customer lists, having a real process before publishing anything about an identifiable individual — reduce exposure to the tort regardless of what the Privacy Act's formal exemption boundary says.
IT Cares field note
Businesses that assume "we're too small for privacy law" are working from an outdated picture even before December 2026 arrives. The tort already removes that shield for serious invasions of privacy, and OAIC enforcement powers have already been strengthened — the exemption removal is the last domino, not the first.
Handling customer or patient data and want a second opinion?
Our remote cybersecurity team reviews data handling setups for businesses outside Canada too — no on-site visit required.
Penalties: What Non-Compliance Actually Costs
The penalty regime under the Privacy Act has been substantially strengthened. Since the 2024 reforms, the OAIC now has three tiers of civil penalty available depending on severity:
| Tier | Applies to | Maximum penalty |
|---|---|---|
| Mid-tier (individuals) | Interferences with privacy below the "serious or repeated" threshold | 2,000 penalty units — roughly AUD $660,000 |
| Mid-tier (companies) | Interferences with privacy below the "serious or repeated" threshold | 10,000 penalty units — roughly AUD $3.3 million |
| Serious or repeated interference | Egregious or repeated privacy breaches | Greater of $50 million, 3× the benefit obtained, or 30% of adjusted turnover during the breach period |
Failing to notify the OAIC of an eligible data breach "as soon as practicable" — a separate obligation under the Notifiable Data Breaches scheme — carries its own civil penalty exposure, reported at up to roughly AUD $2.1 million in recent guidance. These aren't theoretical numbers: in October 2025, the Federal Court handed down Australia's first-ever civil penalty under the Privacy Act, ordering Australian Clinical Labs (trading as Medlab Pathology) to pay a combined $5.8 million, including $800,000 specifically for failing to notify a data breach as soon as practicable under section 26WK(2). Separately, IBM's Cost of a Data Breach research puts the average total cost of a data breach for an Australian organisation at roughly AUD $4.2 million once detection, containment, notification, and reputational costs are all factored in — a number that dwarfs what most small businesses budget for cybersecurity in an entire year.
The 13 Australian Privacy Principles, Summarized
The 13 APPs are principles-based rather than prescriptive checklists, which makes them flexible but also means small businesses often don't know where to start. Here's a plain-language summary of the ones that matter most day-to-day:
| APP | What it requires, in practice |
|---|---|
| APP 1 — Open and transparent management | Maintain a clear, publicly available privacy policy describing what you collect and why |
| APPs 3-5 — Collection | Only collect personal information reasonably necessary for your business, by lawful and fair means, and notify individuals at or before collection |
| APPs 6-7 — Use, disclosure, direct marketing | Use data only for the purpose it was collected (or a related purpose the person would expect); give a clear opt-out for marketing |
| APP 8 — Cross-border disclosure | Take reasonable steps to ensure an overseas recipient (e.g. a cloud vendor) also protects the data appropriately |
| APP 11 — Security | Take reasonable steps to protect personal information from misuse, loss, and unauthorised access, and destroy or de-identify it once no longer needed |
| APPs 12-13 — Access and correction | Give individuals access to their own personal information on request, and correct it when it's wrong |
The OAIC publishes the full text of all 13 APPs and detailed guidance at oaic.gov.au — worth bookmarking directly rather than relying solely on secondary summaries, since guidance is updated as the reform package rolls out.
Building an APP-Compliant Program Before December 2026
Map what personal information you actually hold
List every place personal information enters your business — booking forms, POS systems, email inboxes, spreadsheets, CRM tools — and where it's stored. Most small businesses are surprised by how scattered this turns out to be once mapped honestly.
Draft (or update) a plain-language privacy policy
Cover what you collect, why, how it's used, whether it's disclosed to third parties (including cloud vendors), and how someone can request access or correction. APP 1 requires this to be freely available, not buried in fine print.
Review your security safeguards against APP 11
Password hygiene, access controls limiting who in your business can see customer data, encrypted storage where practical, and a documented process for securely disposing of data you no longer need.
Check your vendor and cloud contracts (APP 8)
If customer data flows to an overseas cloud provider, payment processor, or marketing platform, confirm that vendor's own data protection commitments are adequate — this becomes a documented obligation once you're covered.
Build a basic data breach response plan
Even before you're formally subject to the Notifiable Data Breaches scheme, having a plan for what happens if data is lost or exposed — who assesses it, who decides on notification, how you'd contact affected people — turns a scramble into a process.
Nominate a privacy contact
A named person (even part-time, even the owner) who handles privacy questions and access requests. It doesn't need a formal title yet, but customers and regulators alike expect there to be someone accountable.
Real-World Scenarios
The following are composite, fictional scenarios illustrating common patterns among Australian small businesses preparing for these changes — not specific real companies.
Scenario: a regional real estate agency
A 12-person real estate agency in regional Victoria, with turnover just under the $3 million threshold, had never had a written privacy policy — tenant and buyer information was collected via paper forms and a shared spreadsheet accessible to the whole office. Anticipating the exemption removal, the agency's principal engaged a local consultant to build a proper client database with role-based access, a one-page privacy policy for its website, and a retention schedule for old tenancy applications, at a cost of roughly AUD $4,000 for the initial build-out.
Scenario: a boutique allied health clinic
A physiotherapy clinic with two locations and combined turnover under $3 million discovered, during a routine review, that it was already covered by the Privacy Act regardless of turnover because health service providers fall outside the small business exemption entirely. The clinic had been operating for six years without a compliant privacy policy or breach response process. It engaged a privacy consultant to build both, alongside staff training on handling patient records, for approximately AUD $6,500.
Scenario: a small e-commerce retailer
An online homewares retailer with turnover of $1.8 million relied on an overseas email marketing platform and a separate overseas-hosted customer database. While technically still exempt under the turnover threshold at the time, the retailer's founder became concerned about the new statutory tort after a competitor's customer list was leaked publicly and the affected business faced a wave of customer complaints and reputational damage even without formal OAIC action. The retailer proactively reviewed its vendor contracts and added basic access controls to its customer database ahead of any legal requirement to do so, at minimal cost using existing platform features.
Budget Reality Check
Compliance costs for Australian small businesses preparing for December 2026 scale with how much existing infrastructure needs to be built versus simply documented:
- Micro business (under 5 staff, simple data flows): Often achievable in the AUD $1,500-$4,000 range for a privacy policy, basic security review, and breach response plan using templates plus limited professional review.
- Small business (5-30 staff, customer database or online sales): Typically lands in the AUD $4,000-$12,000 range, including a data mapping exercise, vendor contract review, and staff training.
- Larger small business (30+ staff, sensitive data like health or financial records): Can scale into the AUD $12,000-$30,000+ range, particularly where legacy systems need rework rather than just documentation.
These are directional figures for budgeting conversations, not fixed quotes. Every case study above shares one pattern: businesses that started before the deadline paid a fraction of what a reactive, post-incident compliance scramble typically costs — and none of it approaches the $4.2 million average cost of an actual data breach.
Australian Government Resources
- Office of the Australian Information Commissioner (OAIC, oaic.gov.au): Australia's privacy regulator — guidance on the APPs, the Notifiable Data Breaches scheme, and reform updates.
- Attorney-General's Department (ag.gov.au): Policy background on the Privacy Act reform package and legislative timeline.
- Australian Cyber Security Centre (ACSC, cyber.gov.au): Practical security guidance, including the Essential Eight framework, relevant to meeting APP 11's security expectations.
For the notification side of this framework specifically, see our companion guide on the Notifiable Data Breaches scheme.
Want a second set of eyes on your data security setup?
IT Cares provides remote cybersecurity consulting and security reviews for businesses outside Canada as well — entirely remote, no local office required. We can review your technical safeguards against APP 11's "reasonable steps" standard even if the legal sign-off still needs an Australian lawyer.
Frequently Asked Questions
Need Help Reviewing Your Data Security Before December 2026?
IT Cares reviews technical safeguards remotely for businesses worldwide — a practical second opinion on your APP 11 "reasonable steps" security posture.

Comments (3)
Didn't realise the tort already applies regardless of the turnover exemption. We're under $3M and had assumed we had until December 2026 to worry about any of this. Getting our privacy policy sorted this month instead of waiting.
The Medlab penalty figure really puts it in perspective. We're a small allied health practice and had no idea health providers were already covered regardless of size — fixing that gap now rather than finding out the hard way.
Good clear breakdown of the 13 APPs — most explainers I found just link to the OAIC page without actually summarising it. Sent this to our office manager as a starting checklist.
Leave a Comment