Insights & News
Has the Privacy Act small business exemption been removed?
- September 14, 2026
No, the small business exemption has not been removed. As at September 2026 the exemption at section 6D of the Privacy Act 1988, which covers most businesses with annual turnover of $3 million or less, remains fully in force. A good deal of Australian commentary says it disappears on 10 December 2026. That date is real, but it belongs to a different obligation entirely, and the exposure draft released on 31 August 2026 does not remove the exemption either.
Key facts
- The $3 million small business exemption at section 6D of the Privacy Act 1988 has not been repealed and is still in force.
- The 10 December 2026 date being widely quoted is the commencement of automated decision-making transparency obligations, added by Schedule 1 Part 15 of the Privacy and Other Legislation Amendment Act 2024, which commences 24 months after that Act received Royal Assent on 10 December 2024.
- On 31 August 2026 the Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026. Consultation submissions close on 18 September 2026.
- That exposure draft does not remove the small business exemption, and it does not remove the employee records exemption either.
- What did change is narrower and already in force: from 1 July 2026 businesses providing AML/CTF designated services are covered by the Privacy Act for that handling, regardless of turnover. The OAIC estimates this affects more than 100,000 small businesses.
- The statutory tort for serious invasions of privacy has applied since 10 June 2025 and applies regardless of whether the Privacy Act covers you.
Where the 10 December 2026 date comes from
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. Most of it commenced the following day. Two parts were delayed: the statutory tort, which commenced on 10 June 2025, and a set of automated decision-making provisions, which sit in Schedule 1 Part 15 and commence the day after the end of a 24 month period beginning on the day of Royal Assent. That works out to 10 December 2026.
Those provisions insert new subclauses into Australian Privacy Principle 1. From that date, an entity covered by the Privacy Act has to disclose in its privacy policy where it uses automated processes to make decisions that significantly affect an individual's rights or interests.
So the date is genuine legislation with a fixed commencement, which is presumably why it has travelled so well. It has simply been attached to the wrong reform. Automated decision-making transparency and removal of the small business exemption are separate things in separate tranches, and only one of them is law.
What the 31 August exposure draft does and does not do
The second tranche did arrive, and more recently than most commentary reflects. On 31 August 2026 the Attorney-General's Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 for public consultation, with submissions closing on 18 September 2026. It contains roughly 40 proposals.
The central one is a fair and reasonable test. Australian Privacy Principles 3, 4 and 6 would be replaced by a single rule under which an organisation may collect, use or disclose personal information only where doing so is lawful and is fair and reasonable in the circumstances. That is a significant shift, because at present consent does a lot of work. Under the draft, an organisation that obtained textbook consent could still be in breach if the handling was not objectively fair and reasonable. The draft also shortens the window for notifying the Commissioner of an eligible data breach to 72 hours, and creates a right to erasure that applies to large digital platforms rather than to everyone.
What the draft does not contain is the removal of the small business exemption. Practitioner analyses of the draft are consistent on this point, and they note the same omission for the employee records exemption, mandatory privacy impact assessments and a direct right of action for individuals. The Privacy Act Review recommended removing the small business exemption and the Government agreed in principle. The Bill in front of the country right now does not do it.
An exposure draft is also not a Bill before Parliament. It is a draft released for comment, and it can change before introduction. The Government has indicated it intends to introduce the Bill this year, so this position may move, but it will move through a visible legislative process rather than overnight.
What did change for small businesses in 2026
One real change has already happened and it caught a large number of Australian small businesses. It came from anti-money laundering law rather than privacy law, which is why so many of the affected businesses did not see it coming.
From 1 July 2026, tranche 2 of the AML/CTF reforms brought new categories of business into the regime as reporting entities: real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones. Being a reporting entity under the AML/CTF Act is one of the existing exceptions to the small business exemption, so the moment those businesses became reporting entities, the Privacy Act began applying to the personal information they handle for AML/CTF purposes. Turnover is irrelevant to this. The OAIC estimates it affects more than 100,000 small businesses.
Two points about the scope are worth being precise on. First, the coverage attaches to the AML/CTF related handling rather than to everything the business does, so a small accounting practice is covered for its customer due diligence records without the whole firm becoming an APP entity for every other purpose. Second, the trigger is providing a designated service, not belonging to a profession, so the question is what work you do rather than what is on your letterhead.
The OAIC has published guidance for these businesses, and one part of it deserves attention because it runs against a common habit. Reporting entities are told not to retain full copies of identification documents where they are not required, and to destroy or de-identify personal information once it is no longer needed. Identity document copies collected before 31 March 2026 may be retained for the standard AML record-keeping period of seven years, after which continued retention has to be justified. If your business has been quietly accumulating drivers licence scans in a mailbox, that is now a regulated pile of data rather than an administrative habit.
Who is covered regardless of turnover
The exemption has always had exceptions. A business under $3 million turnover is covered by the Privacy Act if it:
- Is a health service provider that holds health information.
- Discloses personal information about another individual for a benefit, service or advantage, or collects it from someone else for that purpose. In plain terms, trades in personal information.
- Is a credit reporting body, or a credit provider handling credit reporting information.
- Is a tax file number recipient.
- Is a contracted service provider for a Commonwealth contract.
- Is accredited under the Consumer Data Right.
- Provides AML/CTF designated services, for that handling, from 1 July 2026.
- Is related to a body corporate that is covered, or has opted in to Privacy Act coverage.
Health service provider is broader than most people assume. It reaches allied health, psychology, physiotherapy, dental, complementary medicine and anyone else providing a service assessing or maintaining a person's health, and it applies from the first patient record rather than at some volume threshold.
What applies to you even while the exemption stands
The exemption exempts you from the Australian Privacy Principles. It does not put you outside the reach of privacy law generally, and two things now cut across it.
The statutory tort for serious invasions of privacy commenced on 10 June 2025 and gives individuals a direct right to sue for intrusion upon seclusion or misuse of information relating to them. It is not an APP compliance regime and it does not care about your turnover. An exempt business can be sued.
The second is commercial rather than legal. Cyber insurance proposal forms ask whether you have a privacy policy, a cookies policy and a data retention and destruction policy, and they ask it as a tick list where a partial answer is visible. Tender processes and larger customers ask the same. The legal question of whether the Act compels you is separate from the practical question of whether you can win work without the documents.
What to do about it
If you provide AML/CTF designated services, you are covered now for that handling and this is not a planning exercise. Work out what personal information you collect for customer due diligence, stop keeping full identity document copies you do not need, and set a retention period for what remains.
If you are covered by the Privacy Act for any reason and you use automated or AI-assisted decisioning that significantly affects people, your privacy policy needs updating before 10 December 2026. Automated client risk scoring, AI-assisted document review and algorithmic tenant screening are all realistic triggers in Australian SMEs.
If you are exempt and expect to stay exempt for now, the sensible posture is neither panic nor complacency. Adopt the four documents because customers and insurers ask for them, know what personal information you hold and where, and destroy what you no longer need. If the exemption is removed in a later tranche, the transition period will be spent doing this work anyway, and doing it early costs less than doing it under a deadline.
We have published free templates for all four documents, with no email address required: a privacy policy, cookies policy, data retention and destruction policy, and bring your own device policy. If you want the detail on how insurers word these questions, the cyber insurance questionnaire guide covers all 45 of them.
Frequently asked questions
Has the small business exemption been removed?
No. Section 6D of the Privacy Act 1988 still exempts most businesses with annual turnover of $3 million or less, and as at September 2026 no legislation has repealed it. Removal was recommended by the Privacy Act Review and agreed to in principle by the Government, but the exposure draft released on 31 August 2026 does not include it.
What happens on 10 December 2026?
Automated decision-making transparency obligations commence. Entities covered by the Privacy Act will have to disclose in their privacy policy where automated processes are used to make decisions that significantly affect an individual. This is Schedule 1 Part 15 of the Privacy and Other Legislation Amendment Act 2024, commencing 24 months after that Act received Royal Assent. It has nothing to do with the small business exemption.
Does the Privacy Act apply to my business if I turn over less than $3 million?
Not usually, but check the exceptions. You are covered regardless of turnover if you hold health information as a health service provider, trade in personal information, handle credit reporting information, receive tax file numbers, hold a Commonwealth contract, are accredited under the Consumer Data Right, or provide AML/CTF designated services. That last one has applied since 1 July 2026 and captures accountants, lawyers, conveyancers and real estate professionals for their AML related data handling.
When will the second tranche become law?
There is no fixed date. The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 was released on 31 August 2026 with submissions closing on 18 September 2026, and the Government has indicated it intends to introduce a Bill this year. An exposure draft can change before introduction, and any date circulating before a Bill passes is commentary rather than law.
If I am exempt, can I still be sued over a privacy breach?
Yes. The statutory tort for serious invasions of privacy commenced on 10 June 2025 and applies regardless of turnover or whether the Australian Privacy Principles bind you. It gives individuals a direct right of action for intrusion upon seclusion or misuse of information relating to them.
This article is general information and not legal advice. If you need to know whether the Privacy Act applies to your particular business, talk to a lawyer. If you want help working out what personal information you hold, where it sits and what to stop keeping, that part is ours. Request a callback or get in touch.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on backup and disaster recovery, cybersecurity, and Microsoft 365, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
Has the Privacy Act small business exemption been removed? -
Microsoft Authenticator Setup for Business -
Windows Hello for Business: Passwordless Sign-In for SMEs -
Microsoft 365 MFA Setup: Security Defaults or Conditional Access -
Microsoft Is Retiring SMS and Voice MFA: What to Do Before February 2027 -
Choosing a Password Manager for Small Business -
Passkeys vs Passwords: What Businesses Need to Know -
Password Policy for Australian Small Business -
How to Share Passwords Securely With Staff -
What Is Veeam, and Why 4iT Uses It for Backup







