Most owners assume privacy law skips small business. In 2026 that assumption is getting expensive.
Resources / Does the New Privacy Act Apply to My Small Business?
Possibly, and in more ways than the old "under three million dollars turnover" rule suggests. The small-business exemption still exists in 2026, but two things now reach past it: a new statutory tort that lets a person sue your business for a serious invasion of privacy whether or not you are exempt,1 and a rule that from 10 December 2026 requires any business using AI or automated systems to make decisions about people to say so in its privacy policy.2 Here is who is actually covered, and what a sensible owner does about it.
the statutory tort for serious invasions of privacy commenced
deadline to disclose AI and automated decision-making in your privacy policy
turnover above which the small-business exemption never applied anyway
Often, but far less reliably than owners think. The exemption only covers businesses with an annual turnover of three million dollars or less, and even then it has large exceptions. You are not exempt if you provide a health service and hold health information, and that sweeps in gyms, allied health, childcare, natural therapists and many clinics. You are also outside the exemption if you buy or sell personal information, if you are a contractor providing services under a Commonwealth contract, or if you handle credit information. Plenty of "small" businesses were never exempt in the first place and simply did not realise it.
The Privacy and Other Legislation Amendment Act 2024 commenced on 10 December 2024 and rolls out in stages.3 Three parts matter to a small business: a new statutory tort for serious invasions of privacy that started on 10 June 2025; an automated decision-making transparency rule that starts on 10 December 2026; and stronger enforcement powers and penalty tiers for the regulator. It is the first serious update to the Act in a generation, and more is flagged for a later tranche.
This is the change most likely to surprise a small business. The statutory tort lets an individual take you to court directly over a serious invasion of their privacy, and it applies regardless of whether your business is otherwise exempt from the Act.1 In plain terms: mishandling a customer's personal information, or an employee snooping where they should not, can now be actioned by the person affected, not just the regulator. The exemption you were relying on does not shield you from this.
From 10 December 2026, businesses covered by the Act that use personal information in automated decision-making with the potential to affect a person's rights or interests must set out, in their privacy policy, the kinds of information used and the kinds of decisions made that way.2 If you use an AI tool to screen job applicants, score customers, or approve or decline anything, that is the rule talking to you. Even if you are exempt today, this is the clear direction of travel.
The government has signalled that the exemption is under review and is a candidate for removal in a future round of reform. Nothing has removed it yet, so do not let a competitor's blog panic you into thinking it is already gone. The honest position for 2026 is this: the exemption is borrowed time, not a permanent shield, and the parts of the law that already reach past it are the ones worth acting on now.
We handle the practical side of this, the access controls, the backups and the security baseline, as part of managed IT, and we can point you to the right advice on the policy itself. This article is general information, not legal advice.
The Essential Eight for small business: the controls that stop a breach becoming a claim.
Free email security checker: test the basics that protect customer data.
All resources: tools, guides and case studies.
Not necessarily. The exemption has exceptions: if you hold health information, buy or sell personal information, handle credit data, or contract to the Commonwealth, you are covered regardless of turnover.
Yes. The statutory tort for serious invasions of privacy applies regardless of the small-business exemption, so an affected individual can pursue your business directly.
Using personal information in an automated or AI system to make, or substantially help make, a decision that could affect a person's rights or interests, such as screening applicants or approving customers.
If you are covered by the Act you must have one, and it is good practice regardless. From December 2026 it is also where automated decision-making has to be disclosed.
It has not been removed. It is under review and flagged as a candidate for a future round of reform, so treat it as temporary rather than permanent.
General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. For guidance on your situation, get in touch.
Tell us what customer or staff data you hold and what tools you use. We will map where you stand and lock down the security basics that keep a slip from becoming a claim. One business day, no obligation.
Prefer to talk? Call (02) 9053 8789.