The $3M exemption is being unwoundSix chapters · sourced

The Privacy Act, for small businesses this time

A plain-English guide to the Privacy Act 1988 (Cth) reforms removing the small business exemption. Covers who is now in scope, the Australian Privacy Principles, the Notifiable Data Breaches scheme, penalties, and a six-month readiness pathway.

Drawn from the Office of the Australian Information Commissioner, the Attorney-General's Department and the Privacy Act Review Report.

~2.5 million businesses

Previously exempt, now in scope

Thirteen Australian Privacy Principles

Substance, discipline, documentation

Up to $50M civil penalty

For serious or repeated breaches

Editorially reviewed
Last reviewed18 May 2026
Sources verified18 May 2026
01

Why the exemption existed

For 25 years, most Australian SMBs sat outside the Privacy Act.

The small business operator exemption is being unwound.

Since 2000, businesses with annual turnover under $3 million have generally been exempt from the Privacy Act 1988 (Cth). This exemption is unusual internationally. The Privacy Act Review Report (2023) recommended its removal, and the Australian Government accepted that recommendation in principle, signalling that the exemption will be unwound with appropriate transition arrangements.

01

Source legislation

Privacy Act 1988 (Cth), section 6D defines a 'small business operator' and the exemption framework. Section 6E lists existing carve-ins (health service providers, credit reporting, contracted Commonwealth service providers, and others).

Source · Privacy Act 1988 (Cth)
02

Privacy Act Review Report

The Attorney-General's Department published the Privacy Act Review Report in February 2023, recommending removal of the small business exemption with appropriate support and transition.

Source · Privacy Act Review Report
03

Government response

The Government Response to the Privacy Act Review Report agreed to remove the exemption in principle, subject to consultation on transition and support measures for small business.

Source · Government Response
04

Current OAIC small business guidance

OAIC publishes interim guidance for small businesses that already handle health information, sell or purchase personal information, or contract to Australian Government agencies, all of whom are already covered today.

Source · OAIC small business guidance
02

Who is now in scope

Approximately 2.5 million Australian small businesses.

Every business handling personal information will eventually be covered.

Once the exemption is removed, any Australian business that collects, holds or discloses personal information will be subject to the Australian Privacy Principles, regardless of turnover. The OAIC will become the regulator for businesses that previously sat outside the framework entirely.

01

Personal information, broadly defined

Any information about an identified individual, or about an individual who is reasonably identifiable. Includes names, contact details, customer records, employment information, video and audio recordings in many cases.

02

Existing carve-ins remain

Health service providers, businesses that sell or purchase personal information, and contractors to Australian Government agencies have always been covered, regardless of turnover. Carve-ins continue under section 6E.

03

Sector-specific obligations still layer on top

Health, financial services, telecommunications, and education sectors continue to have additional privacy obligations under sector-specific law and codes.

04

Employee records partial exemption under review

The current employee records exemption was also reviewed. The Government Response signalled it will be narrowed, particularly for employee health and data breach notifications.

Source · Privacy Act Review Report
03

The Australian Privacy Principles

Thirteen principles. The substance is reasonable, the discipline is documentary.

Most well-run businesses already meet the spirit of the APPs.

The Australian Privacy Principles (APPs) are the operative obligations under the Privacy Act. They cover the full lifecycle of personal information: openness, collection, use, disclosure, storage, security, access, correction, and cross-border disclosure. For most Australian businesses, the obligation is to document what they already do, then close the gaps.

01

APP 1 : Open and transparent management

Have a clearly expressed and up-to-date privacy policy. Make it freely available.

02

APP 3 : Collection of solicited personal information

Only collect personal information reasonably necessary for one or more of the entity's functions or activities.

03

APP 5 : Notification at collection

Notify individuals at or before collection of who is collecting it, why, who it may be shared with, and how to contact the entity.

04

APP 6 : Use and disclosure

Use personal information only for the purpose for which it was collected, unless a specific exception applies.

05

APP 8 : Cross-border disclosure

Take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Entity remains accountable for the overseas recipient's acts.

06

APP 11 : Security of personal information

Take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. This is the operational cybersecurity obligation.

07

APP 12 and APP 13 : Access and correction

Provide individuals access to personal information held about them, and correct it on reasonable request.

08

Full APP guidance

The OAIC publishes detailed guidance against each of the 13 APPs. Most Australian businesses can become compliant by combining published OAIC templates with sound internal documentation.

Source · OAIC Australian Privacy Principles
04

Notifiable data breaches

The 30-day assessment rule extends to small business.

Notification can include both the OAIC and affected individuals.

The Notifiable Data Breaches scheme has been mandatory for entities covered by the Privacy Act since 2018. As the small business exemption is removed, the NDB scheme will apply to small businesses for the first time. Most Australian SMBs have never previously been required to notify a data breach to the regulator.

01

Eligible data breach test

Three elements: there is unauthorised access, disclosure or loss of personal information; the entity has been unable to prevent the likely risk of serious harm; and notification is required.

02

Assessment within 30 days

Where a suspected eligible data breach occurs, entities must take reasonable and expeditious steps to assess whether it is in fact an eligible data breach. The OAIC expects assessment within 30 days where reasonably practicable.

Source · OAIC NDB scheme
03

Notification to OAIC and individuals

Once an eligible data breach is identified, the entity must notify the OAIC and affected individuals as soon as practicable. The OAIC notification follows a prescribed form.

04

Sits alongside other reporting obligations

If the breach involves a ransomware payment, the Cyber Security Act 2024 (Cth) Part 3 reporting obligation may also apply for businesses over $3 million turnover. Two separate clocks.

05

Penalties and enforcement

OAIC enforcement powers have been materially strengthened.

$66,000 infringement notices. Up to $50M for serious breaches.

Penalties under the Privacy Act 1988 (Cth) were significantly increased by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022. The OAIC has additional infringement notice powers and the courts can impose substantial civil penalties for serious or repeated interferences with privacy.

01

Civil penalties for serious or repeated interferences

Up to the greater of $50 million, three times the value of the benefit obtained from the misuse of information, or 30 per cent of adjusted turnover during the breach period. Most relevant to large breaches but applicable in principle to any covered entity.

Source · Privacy Act 1988 (Cth)
02

Infringement notices

The OAIC can issue infringement notices for less serious breaches of certain provisions. Infringement notices for body corporates currently sit at $66,000 per contravention.

03

Enforceable undertakings

The OAIC can accept enforceable undertakings from entities. Public undertakings are common after settled investigations.

04

Determinations and conciliation

Most complaints to the OAIC are dealt with by conciliation rather than determination. Determinations can include compensation to affected individuals.

06

Practical readiness pathway

A six-month pathway for previously exempt businesses.

Mostly documentation, partly operational, manageable by any business.

Most Australian small businesses can reach a defensible Privacy Act position inside six months. The pathway below is intentionally proportionate. It does not assume a large compliance team. It assumes a leadership team that takes the obligation seriously and is willing to document what the business already does.

01

Month 1 : Personal information inventory

List every category of personal information collected, where it is stored, who it is shared with, and which staff have access. The OAIC publishes templates for this.

02

Month 2 : Privacy policy and collection notices

Publish a plain-English privacy policy on the website. Update collection notices on forms, websites and onboarding documents to meet APP 5.

03

Month 3 : Security baseline

Bring the APP 11 'reasonable steps' obligation into line with the controls insurers and customers already expect: MFA, EDR, tested backups, patching, access controls, training.

04

Month 4 : Cross-border disclosure

Map every overseas data processor (Microsoft 365, Google Workspace, ChatGPT, payment processors, cloud backups). Confirm APP 8 obligations are met or that an exception applies.

05

Month 5 : Data breach response

Draft and rehearse a data breach response plan. Include the 30-day OAIC assessment clock and the parallel Cyber Security Act 2024 reporting obligation if applicable.

06

Month 6 : Access and correction process

Document a clear process for individuals to request access to their personal information and correction. Train front-line staff to recognise and route requests appropriately.

What changes in your tech stack

The Australian Privacy Principles, translated into Microsoft 365 controls.

The chapters above set out the obligation. This block sets out what the obligation actually looks like in the tenant. The controls below are the ones we implement during a Privacy Act readiness engagement, mapped to the APP they satisfy.

APP 1

Privacy policy and openness

Obligation: Plain-English privacy policy, freely available, current.

How we implement this

Hosted on the public website with a last-reviewed badge. Reviewed quarterly as part of the governance cadence. Same document referenced from sales contracts, customer onboarding and the staff handbook.

APP 3 & 5

Collection and notification

Obligation: Only collect what is necessary. Notify the individual at the point of collection.

How we implement this

Microsoft Forms and SharePoint form templates updated with collection notices. Web forms use a consistent privacy statement block. CRM onboarding fields tagged with the lawful basis they were collected against.

APP 6

Use and disclosure

Obligation: Use personal information only for the purpose collected, unless an exception applies.

How we implement this

Microsoft Purview sensitivity labels applied to documents containing personal information. Auto-labelling rules for HR, finance and customer records. DLP policies blocking external sharing of labelled content unless explicitly approved.

APP 8

Cross-border disclosure

Obligation: Reasonable steps to ensure overseas recipients handle personal information consistently with the APPs.

How we implement this

Tenant data residency confirmed against Microsoft data location. Copilot and Teams transcription routing reviewed quarterly. Vendor inventory in SharePoint with each entry tagged by data residency, including ChatGPT, Google Workspace, payment processors and SaaS analytics.

APP 11

Security of personal information (the operational one)

Obligation: Reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

How we implement this

MFA enforced on all users via Conditional Access. EDR on all endpoints via Defender for Business or Defender for Endpoint. Backup of M365 data to an independent vendor. Patching cadence aligned to Essential Eight Maturity Level One. Privileged Identity Management on Global Admin and Exchange Admin roles.

APP 11 (mobile)

BYOD and personal devices

Obligation: Personal information on personal devices is still your responsibility.

How we implement this

Intune Mobile Application Management for personal devices accessing email and Teams. Wipe-on-leaver enforced through the offboarding runbook. App protection policies prevent copy-paste of corporate content into personal apps.

None of the controls above are new tooling. Most Australian businesses on a Microsoft 365 Business Premium or E3 plan already hold the licences. The work is configuration, documentation and proof. Same applies on Google Workspace Business Plus or Enterprise tiers, with equivalent controls in the Google Admin console.

The Australian view

OAIC notifiable data breach data tells the Australian story.

The Verizon DBIR is the global benchmark. The Office of the Australian Information Commissioner publishes the canonical Australian view: who is notifying, why, and how often. The figures below are drawn from OAIC's published Notifiable Data Breaches statistics, which are the single most reliable source for breach trends in the Australian market.

1,205

notifiable data breaches received by OAIC in calendar year 2025.

The highest annual total since the NDB scheme commenced in 2018, up 8 per cent on 2024.

716

caused by malicious or criminal activity the majority of all 2025 notifications.

Cyber hacking remains the primary cause of breaches reported to the OAIC.

225

health service provider breaches the most commonly affected sector.

19 per cent of the annual total. Financial services followed on 157 notifications.

82%

of Australians are concerned about data breaches.

The top perceived privacy risk in the 2026 Australian Community Attitudes to Privacy Survey, up from 74 per cent in 2023.

Source: Office of the Australian Information Commissioner, calendar year 2025 Notifiable Data Breaches statistics, published 6 July 2026, and the 2026 Australian Community Attitudes to Privacy Survey. Figures as published by OAIC. Refresh expected when OAIC publishes the next reporting period.

Common questions

Questions previously-exempt Australian businesses ask first.

The Government Response to the Privacy Act Review Report accepted removal of the exemption in principle, subject to consultation on transition arrangements. Final commencement timing depends on the consultation outcome and amending legislation. Businesses should plan to be ready well before any commencement date.

If your business has not been Privacy Act covered before

The six-month pathway is mostly documentation, partly operational.

Most Australian businesses can reach a defensible Privacy Act position inside six months. If your business has not been covered before, we can help you build the inventory, the policy, the breach response plan and the APP 11 security baseline, in a proportionate way that does not assume a compliance department.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.