The Privacy Act, for small businesses this time
A plain-English guide to the Privacy Act 1988 (Cth) reforms removing the small business exemption. Covers who is now in scope, the Australian Privacy Principles, the Notifiable Data Breaches scheme, penalties, and a six-month readiness pathway.
Drawn from the Office of the Australian Information Commissioner, the Attorney-General's Department and the Privacy Act Review Report.
~2.5 million businesses
Previously exempt, now in scope
Thirteen Australian Privacy Principles
Substance, discipline, documentation
Up to $50M civil penalty
For serious or repeated breaches
Why the exemption existed
For 25 years, most Australian SMBs sat outside the Privacy Act.
The small business operator exemption is being unwound.
Since 2000, businesses with annual turnover under $3 million have generally been exempt from the Privacy Act 1988 (Cth). This exemption is unusual internationally. The Privacy Act Review Report (2023) recommended its removal, and the Australian Government accepted that recommendation in principle, signalling that the exemption will be unwound with appropriate transition arrangements.
Source legislation
Privacy Act 1988 (Cth), section 6D defines a 'small business operator' and the exemption framework. Section 6E lists existing carve-ins (health service providers, credit reporting, contracted Commonwealth service providers, and others).
Source · Privacy Act 1988 (Cth)Privacy Act Review Report
The Attorney-General's Department published the Privacy Act Review Report in February 2023, recommending removal of the small business exemption with appropriate support and transition.
Source · Privacy Act Review ReportGovernment response
The Government Response to the Privacy Act Review Report agreed to remove the exemption in principle, subject to consultation on transition and support measures for small business.
Source · Government ResponseCurrent OAIC small business guidance
OAIC publishes interim guidance for small businesses that already handle health information, sell or purchase personal information, or contract to Australian Government agencies, all of whom are already covered today.
Source · OAIC small business guidanceWho is now in scope
Approximately 2.5 million Australian small businesses.
Every business handling personal information will eventually be covered.
Once the exemption is removed, any Australian business that collects, holds or discloses personal information will be subject to the Australian Privacy Principles, regardless of turnover. The OAIC will become the regulator for businesses that previously sat outside the framework entirely.
Personal information, broadly defined
Any information about an identified individual, or about an individual who is reasonably identifiable. Includes names, contact details, customer records, employment information, video and audio recordings in many cases.
Existing carve-ins remain
Health service providers, businesses that sell or purchase personal information, and contractors to Australian Government agencies have always been covered, regardless of turnover. Carve-ins continue under section 6E.
Sector-specific obligations still layer on top
Health, financial services, telecommunications, and education sectors continue to have additional privacy obligations under sector-specific law and codes.
Employee records partial exemption under review
The current employee records exemption was also reviewed. The Government Response signalled it will be narrowed, particularly for employee health and data breach notifications.
Source · Privacy Act Review ReportThe Australian Privacy Principles
Thirteen principles. The substance is reasonable, the discipline is documentary.
Most well-run businesses already meet the spirit of the APPs.
The Australian Privacy Principles (APPs) are the operative obligations under the Privacy Act. They cover the full lifecycle of personal information: openness, collection, use, disclosure, storage, security, access, correction, and cross-border disclosure. For most Australian businesses, the obligation is to document what they already do, then close the gaps.
APP 1 : Open and transparent management
Have a clearly expressed and up-to-date privacy policy. Make it freely available.
APP 3 : Collection of solicited personal information
Only collect personal information reasonably necessary for one or more of the entity's functions or activities.
APP 5 : Notification at collection
Notify individuals at or before collection of who is collecting it, why, who it may be shared with, and how to contact the entity.
APP 6 : Use and disclosure
Use personal information only for the purpose for which it was collected, unless a specific exception applies.
APP 8 : Cross-border disclosure
Take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Entity remains accountable for the overseas recipient's acts.
APP 11 : Security of personal information
Take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. This is the operational cybersecurity obligation.
APP 12 and APP 13 : Access and correction
Provide individuals access to personal information held about them, and correct it on reasonable request.
Full APP guidance
The OAIC publishes detailed guidance against each of the 13 APPs. Most Australian businesses can become compliant by combining published OAIC templates with sound internal documentation.
Source · OAIC Australian Privacy PrinciplesNotifiable data breaches
The 30-day assessment rule extends to small business.
Notification can include both the OAIC and affected individuals.
The Notifiable Data Breaches scheme has been mandatory for entities covered by the Privacy Act since 2018. As the small business exemption is removed, the NDB scheme will apply to small businesses for the first time. Most Australian SMBs have never previously been required to notify a data breach to the regulator.
Eligible data breach test
Three elements: there is unauthorised access, disclosure or loss of personal information; the entity has been unable to prevent the likely risk of serious harm; and notification is required.
Assessment within 30 days
Where a suspected eligible data breach occurs, entities must take reasonable and expeditious steps to assess whether it is in fact an eligible data breach. The OAIC expects assessment within 30 days where reasonably practicable.
Source · OAIC NDB schemeNotification to OAIC and individuals
Once an eligible data breach is identified, the entity must notify the OAIC and affected individuals as soon as practicable. The OAIC notification follows a prescribed form.
Sits alongside other reporting obligations
If the breach involves a ransomware payment, the Cyber Security Act 2024 (Cth) Part 3 reporting obligation may also apply for businesses over $3 million turnover. Two separate clocks.
Penalties and enforcement
OAIC enforcement powers have been materially strengthened.
$66,000 infringement notices. Up to $50M for serious breaches.
Penalties under the Privacy Act 1988 (Cth) were significantly increased by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022. The OAIC has additional infringement notice powers and the courts can impose substantial civil penalties for serious or repeated interferences with privacy.
Civil penalties for serious or repeated interferences
Up to the greater of $50 million, three times the value of the benefit obtained from the misuse of information, or 30 per cent of adjusted turnover during the breach period. Most relevant to large breaches but applicable in principle to any covered entity.
Source · Privacy Act 1988 (Cth)Infringement notices
The OAIC can issue infringement notices for less serious breaches of certain provisions. Infringement notices for body corporates currently sit at $66,000 per contravention.
Enforceable undertakings
The OAIC can accept enforceable undertakings from entities. Public undertakings are common after settled investigations.
Determinations and conciliation
Most complaints to the OAIC are dealt with by conciliation rather than determination. Determinations can include compensation to affected individuals.
Practical readiness pathway
A six-month pathway for previously exempt businesses.
Mostly documentation, partly operational, manageable by any business.
Most Australian small businesses can reach a defensible Privacy Act position inside six months. The pathway below is intentionally proportionate. It does not assume a large compliance team. It assumes a leadership team that takes the obligation seriously and is willing to document what the business already does.
Month 1 : Personal information inventory
List every category of personal information collected, where it is stored, who it is shared with, and which staff have access. The OAIC publishes templates for this.
Month 2 : Privacy policy and collection notices
Publish a plain-English privacy policy on the website. Update collection notices on forms, websites and onboarding documents to meet APP 5.
Month 3 : Security baseline
Bring the APP 11 'reasonable steps' obligation into line with the controls insurers and customers already expect: MFA, EDR, tested backups, patching, access controls, training.
Month 4 : Cross-border disclosure
Map every overseas data processor (Microsoft 365, Google Workspace, ChatGPT, payment processors, cloud backups). Confirm APP 8 obligations are met or that an exception applies.
Month 5 : Data breach response
Draft and rehearse a data breach response plan. Include the 30-day OAIC assessment clock and the parallel Cyber Security Act 2024 reporting obligation if applicable.
Month 6 : Access and correction process
Document a clear process for individuals to request access to their personal information and correction. Train front-line staff to recognise and route requests appropriately.
Sources referenced
- 01
Privacy Act 1988 (Cth) : current text
Federal Register of Legislationwww.legislation.gov.au - 02
Privacy Act Review Report
Attorney-General's DepartmentFeb 2023www.ag.gov.au - 03
Government Response to the Privacy Act Review Report
Attorney-General's Departmentwww.ag.gov.au - 04
Small business and the Privacy Act
Office of the Australian Information Commissionerwww.oaic.gov.au - 05
Australian Privacy Principles
OAICwww.oaic.gov.au - 06
Notifiable Data Breaches scheme
OAICwww.oaic.gov.au
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
What changes in your tech stack
The Australian Privacy Principles, translated into Microsoft 365 controls.
The chapters above set out the obligation. This block sets out what the obligation actually looks like in the tenant. The controls below are the ones we implement during a Privacy Act readiness engagement, mapped to the APP they satisfy.
APP 1
Privacy policy and openness
Obligation: Plain-English privacy policy, freely available, current.
How we implement this
Hosted on the public website with a last-reviewed badge. Reviewed quarterly as part of the governance cadence. Same document referenced from sales contracts, customer onboarding and the staff handbook.
APP 3 & 5
Collection and notification
Obligation: Only collect what is necessary. Notify the individual at the point of collection.
How we implement this
Microsoft Forms and SharePoint form templates updated with collection notices. Web forms use a consistent privacy statement block. CRM onboarding fields tagged with the lawful basis they were collected against.
APP 6
Use and disclosure
Obligation: Use personal information only for the purpose collected, unless an exception applies.
How we implement this
Microsoft Purview sensitivity labels applied to documents containing personal information. Auto-labelling rules for HR, finance and customer records. DLP policies blocking external sharing of labelled content unless explicitly approved.
APP 8
Cross-border disclosure
Obligation: Reasonable steps to ensure overseas recipients handle personal information consistently with the APPs.
How we implement this
Tenant data residency confirmed against Microsoft data location. Copilot and Teams transcription routing reviewed quarterly. Vendor inventory in SharePoint with each entry tagged by data residency, including ChatGPT, Google Workspace, payment processors and SaaS analytics.
APP 11
Security of personal information (the operational one)
Obligation: Reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
How we implement this
MFA enforced on all users via Conditional Access. EDR on all endpoints via Defender for Business or Defender for Endpoint. Backup of M365 data to an independent vendor. Patching cadence aligned to Essential Eight Maturity Level One. Privileged Identity Management on Global Admin and Exchange Admin roles.
APP 11 (mobile)
BYOD and personal devices
Obligation: Personal information on personal devices is still your responsibility.
How we implement this
Intune Mobile Application Management for personal devices accessing email and Teams. Wipe-on-leaver enforced through the offboarding runbook. App protection policies prevent copy-paste of corporate content into personal apps.
None of the controls above are new tooling. Most Australian businesses on a Microsoft 365 Business Premium or E3 plan already hold the licences. The work is configuration, documentation and proof. Same applies on Google Workspace Business Plus or Enterprise tiers, with equivalent controls in the Google Admin console.
OAIC notifiable data breach data tells the Australian story.
The Verizon DBIR is the global benchmark. The Office of the Australian Information Commissioner publishes the canonical Australian view: who is notifying, why, and how often. The figures below are drawn from OAIC's published Notifiable Data Breaches statistics, which are the single most reliable source for breach trends in the Australian market.
1,205
notifiable data breaches received by OAIC in calendar year 2025.
The highest annual total since the NDB scheme commenced in 2018, up 8 per cent on 2024.
716
caused by malicious or criminal activity the majority of all 2025 notifications.
Cyber hacking remains the primary cause of breaches reported to the OAIC.
225
health service provider breaches the most commonly affected sector.
19 per cent of the annual total. Financial services followed on 157 notifications.
82%
of Australians are concerned about data breaches.
The top perceived privacy risk in the 2026 Australian Community Attitudes to Privacy Survey, up from 74 per cent in 2023.
Source: Office of the Australian Information Commissioner, calendar year 2025 Notifiable Data Breaches statistics, published 6 July 2026, and the 2026 Australian Community Attitudes to Privacy Survey. Figures as published by OAIC. Refresh expected when OAIC publishes the next reporting period.
Common questions
Questions previously-exempt Australian businesses ask first.
The Government Response to the Privacy Act Review Report accepted removal of the exemption in principle, subject to consultation on transition arrangements. Final commencement timing depends on the consultation outcome and amending legislation. Businesses should plan to be ready well before any commencement date.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
If your business has not been Privacy Act covered before
The six-month pathway is mostly documentation, partly operational.
Most Australian businesses can reach a defensible Privacy Act position inside six months. If your business has not been covered before, we can help you build the inventory, the policy, the breach response plan and the APP 11 security baseline, in a proportionate way that does not assume a compliance department.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.

Remote Support