Does the New Privacy Act Apply to My Small Business in 2026?

Most owners assume privacy law skips small business. In 2026 that assumption is getting expensive.

Resources / Does the New Privacy Act Apply to My Small Business?

Possibly, and in more ways than the old "under three million dollars turnover" rule suggests. The small-business exemption still exists in 2026, but two things now reach past it: a new statutory tort that lets a person sue your business for a serious invasion of privacy whether or not you are exempt,1 and a rule that from 10 December 2026 requires any business using AI or automated systems to make decisions about people to say so in its privacy policy.2 Here is who is actually covered, and what a sensible owner does about it.

10 Jun 2025

the statutory tort for serious invasions of privacy commenced

10 Dec 2026

deadline to disclose AI and automated decision-making in your privacy policy

$3M

turnover above which the small-business exemption never applied anyway

Isn't my small business exempt from the Privacy Act?

Often, but far less reliably than owners think. The exemption only covers businesses with an annual turnover of three million dollars or less, and even then it has large exceptions. You are not exempt if you provide a health service and hold health information, and that sweeps in gyms, allied health, childcare, natural therapists and many clinics. You are also outside the exemption if you buy or sell personal information, if you are a contractor providing services under a Commonwealth contract, or if you handle credit information. Plenty of "small" businesses were never exempt in the first place and simply did not realise it.

What actually changed in the 2024 reforms?

The Privacy and Other Legislation Amendment Act 2024 commenced on 10 December 2024 and rolls out in stages.3 Three parts matter to a small business: a new statutory tort for serious invasions of privacy that started on 10 June 2025; an automated decision-making transparency rule that starts on 10 December 2026; and stronger enforcement powers and penalty tiers for the regulator. It is the first serious update to the Act in a generation, and more is flagged for a later tranche.

The part that ignores the exemption: the new statutory tort

This is the change most likely to surprise a small business. The statutory tort lets an individual take you to court directly over a serious invasion of their privacy, and it applies regardless of whether your business is otherwise exempt from the Act.1 In plain terms: mishandling a customer's personal information, or an employee snooping where they should not, can now be actioned by the person affected, not just the regulator. The exemption you were relying on does not shield you from this.

If you use AI or automation, this points straight at you

From 10 December 2026, businesses covered by the Act that use personal information in automated decision-making with the potential to affect a person's rights or interests must set out, in their privacy policy, the kinds of information used and the kinds of decisions made that way.2 If you use an AI tool to screen job applicants, score customers, or approve or decline anything, that is the rule talking to you. Even if you are exempt today, this is the clear direction of travel.

Is the small-business exemption going away?

The government has signalled that the exemption is under review and is a candidate for removal in a future round of reform. Nothing has removed it yet, so do not let a competitor's blog panic you into thinking it is already gone. The honest position for 2026 is this: the exemption is borrowed time, not a permanent shield, and the parts of the law that already reach past it are the ones worth acting on now.

What should a small business do now?

  1. Work out if you are actually exempt. Check turnover, and check the exceptions (health information is the common trap). Many owners are surprised.
  2. Have a real privacy policy. If you collect customer or staff data, a plain, current policy is the baseline, and it is where the AI disclosure will need to live.
  3. Prevent the breach that triggers a tort. Multi-factor authentication, sensible access control and a backup mean a lost laptop or a phished mailbox does not become a serious invasion of privacy.
  4. Map any automated decisions. If AI touches decisions about people, note it now so the December 2026 disclosure is a five-minute update, not a scramble.

We handle the practical side of this, the access controls, the backups and the security baseline, as part of managed IT, and we can point you to the right advice on the policy itself. This article is general information, not legal advice.

References

  1. Office of the Australian Information Commissioner, Statutory tort for serious invasions of privacy, oaic.gov.au.
  2. Office of the Australian Information Commissioner, Transparency in automated decision-making, oaic.gov.au.
  3. Office of the Australian Information Commissioner, Passing of bill a significant step for Australia\u2019s privacy law, oaic.gov.au.

Related resources

The Essential Eight for small business: the controls that stop a breach becoming a claim.
Free email security checker: test the basics that protect customer data.
All resources: tools, guides and case studies.

Frequently asked questions

Is my business automatically exempt if turnover is under $3 million?

Not necessarily. The exemption has exceptions: if you hold health information, buy or sell personal information, handle credit data, or contract to the Commonwealth, you are covered regardless of turnover.

Does the statutory tort apply even if I am exempt?

Yes. The statutory tort for serious invasions of privacy applies regardless of the small-business exemption, so an affected individual can pursue your business directly.

What counts as automated decision-making?

Using personal information in an automated or AI system to make, or substantially help make, a decision that could affect a person's rights or interests, such as screening applicants or approving customers.

Do I need a privacy policy?

If you are covered by the Act you must have one, and it is good practice regardless. From December 2026 it is also where automated decision-making has to be disclosed.

When is the small-business exemption being removed?

It has not been removed. It is under review and flagged as a candidate for a future round of reform, so treat it as temporary rather than permanent.

General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. For guidance on your situation, get in touch.

Not sure if the Privacy Act applies to you?

Tell us what customer or staff data you hold and what tools you use. We will map where you stand and lock down the security basics that keep a slip from becoming a claim. One business day, no obligation.

Prefer to talk? Call (02) 9053 8789.