Privacy Act Reforms for Australian Small Business: What Is Law Now vs Proposed
The Australian privacy legislative landscape is undergoing its most comprehensive modernization in over two decades. Following the Attorney-General's Department Privacy Act Review and extensive public consultations, regulatory attention has focused heavily on the future of small business data handling. For years, Australian companies with an annual turnover of $3 million or less operated under the assumption that they were broadly exempt from the 13 Australian Privacy Principles (APPs).
However, significant misconceptions exist regarding which changes have formally passed into law and which remain proposals under review. According to the Office of the Australian Information Commissioner (OAIC) (retrieved 26 September 2026), while the landmark Privacy and Other Legislation Amendment Act 2024 introduced substantial new enforcement mechanisms, the complete abolition of the small business exemption remains a proposed reform subject to ongoing government consultation.
This article provides general informational guidance on Australian privacy compliance and does not constitute formal legal advice.
Key Takeaways
- What Is Law Now: The small business turnover exemption under Section 6D of the Privacy Act 1988 (Cth) (retrieved 26 September 2026) remains in force, but includes critical exceptions where small businesses are already bound by the APPs.
- The 2024 Enacted Amendments: The Privacy and Other Legislation Amendment Act 2024 (assented December 2024) introduced a statutory tort for serious invasions of privacy, tiered civil penalties, and expanded OAIC investigation powers.
- The Proposed Exemption Removal: The proposal to remove or narrow the $3 million annual turnover exemption (Proposal 4 of the Privacy Act Review) is currently a proposed reform; it has not been enacted as statutory law as at September 2026.
- Immediate Exposure Points: Small businesses providing health services, trading in personal data, or fulfilling Commonwealth contracts are already fully subject to the Privacy Act and Notifiable Data Breaches (NDB) scheme.
- Diagnostic Tools: Australian business owners can test their statutory obligations using our Privacy Act Exemption Checker and estimate potential breach liabilities with our Data Breach Cost Estimator.
What Is Law Now: The Current Small Business Exemption
The cornerstone of small business privacy regulation in Australia sits in Section 6D of the Privacy Act 1988 (Cth). Under Section 6D(1), an organisation is classified as a "small business operator" for a financial year if its annual turnover for that year—and every preceding financial year since the threshold was established—is $3 million or less.
If an entity qualifies as a small business operator, it is generally exempt from compliance with the 13 Australian Privacy Principles and the mandatory Notifiable Data Breaches (NDB) scheme under Part IIIC of the Act.
+---------------------------------------------------------------------------------+
| Annual Turnover <= $3M? |
| ├── YES: Does an exception in Section 6D(4) apply? |
| │ ├── YES: FULL PRIVACY ACT COMPLIANCE REQUIRED (APPs + NDB) |
| │ └── NO: Exempt under Section 6D(1) [Current Law] |
| └── NO: FULL PRIVACY ACT COMPLIANCE REQUIRED (Over $3M Threshold) |
+---------------------------------------------------------------------------------+
Critical Exceptions: When Small Businesses Are Bound Today
Many Australian business owners mistakenly believe that generating under $3 million in annual revenue grants an absolute exemption. In reality, Section 6D(4) outlines several specific scenarios where a small business is legally treated as an APP entity, regardless of revenue:
- Health Service Providers (s 6D(4)(b)): Any business that provides a health service and holds health information is fully bound by the Privacy Act. This encompasses medical practices, allied health clinics, psychologists, physiotherapists, dental clinics, aged care providers, gymnasiums conducting medical health screens, and digital health software providers storing patient vitals.
- Businesses Trading in Personal Information (s 6D(4)(c)): If an organisation sells, barters, or discloses personal information to anyone else for a benefit, service, or financial advantage, or collects personal information from someone else for a benefit, it loses the exemption immediately. This frequently catches marketing agencies, data brokers, lead-generation networks, and reciprocal business directories.
- Contracted Service Providers for Commonwealth Contracts (s 6D(4)(e)): Small businesses that provide goods or services under a direct contract with the Australian Government—or subcontractors delivering services on behalf of a prime Commonwealth contractor—are bound to comply with the APPs for all data handled under that contract.
- Credit Reporting and Anti-Money Laundering Entities: Small businesses operating as credit providers, reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), or operators of residential tenancy databases are fully covered.
- Employee Records Exemption Caveat: Section 7B(3) of the Privacy Act exempts acts or practices directly related to a current or former employment relationship. However, this exemption applies strictly to employee records, not job applicant resumes, contractor documentation, or customer personal information.
If your small business operates within any of these categories, you are already legally obligated to implement reasonable security safeguards under APP 11. Learn how to architect compliant cloud baselines with our Azure Governance & Security Services.
What Changed: The Privacy and Other Legislation Amendment Act 2024
In late 2024, the Australian Parliament passed the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024. This Act represented the "first tranche" of legislative reforms arising from the Attorney-General's Department Privacy Act Review (retrieved 26 September 2026).
The 2024 enacted reforms introduced major structural updates to Australia's privacy framework:
1. Statutory Tort for Serious Invasions of Privacy
The 2024 Act established a new statutory cause of action enabling individuals to take direct legal action in court against entities or persons who commit a serious invasion of privacy—either by intruding upon their seclusion or by misusing their private information.
- Application to Small Business: While standard APPs remain subject to the Section 6D turnover exemption, the statutory tort can apply more broadly where an intentional or reckless intrusion occurs with a reasonable expectation of privacy and causes serious harm.
2. Tiered Civil Penalty Framework
Previously, the Privacy Act operated under an "all-or-nothing" enforcement model: the OAIC could only pursue civil penalties for "serious or repeated interferences with privacy" carrying massive maximum fines (the greater of $50 million, three times the value of the benefit obtained, or 30% of adjusted turnover).
The 2024 Act introduced a pragmatic three-tier penalty regime:
- Tier 1 (Severe Violations): Retains the maximum penalty threshold for egregious corporate data breaches and systemic privacy failures.
- Tier 2 (Mid-Tier Penalties): Addresses serious non-compliance that does not meet the threshold of catastrophic system failures, allowing the OAIC to seek proportionate court-imposed fines.
- Tier 3 (Infringement Notices): Grants the OAIC powers to issue administrative infringement notices with on-the-spot financial penalties for procedural failures (such as failing to publish a compliant privacy policy under APP 1 or failing to notify eligible data breaches).
3. Enhanced OAIC Regulatory Powers
The 2024 legislation empowered the Information Commissioner with expanded investigation, search, and information-gathering tools, including powers to compel documents, conduct public inquiries, and issue binding code-making determinations.
What Is Proposed: The Future of the Small Business Exemption
The most debated aspect of privacy reform in Australia is the complete removal of the small business turnover threshold. In the Privacy Act Review Final Report, Proposal 4 recommended that the small business exemption be removed in its entirety, arguing that in the modern digital economy, small businesses routinely collect, store, and process high-risk personal data (including biometric information, credit card numbers, and health records) that presents significant threat exposure if breached.
In its formal response, the Australian Government agreed in principle to Proposal 4, acknowledging that personal information deserves consistent legal protection regardless of the revenue of the business holding it.
Current Status of the Proposed Exemption Removal
As of September 2026, the complete abolition of the small business exemption has not been passed into law. The Federal Government has committed to:
- Undertaking extensive economic impact analysis to evaluate the regulatory compliance burden on micro and small enterprises.
- Developing tailored, simplified compliance guides and transition periods (potentially 12 to 24 months) before full enforcement takes effect.
- Consulting with small business ombudsmen, industry associations, and regional commercial chambers.
Crucial Takeaway for Business Owners: Do not be misled by marketing materials claiming that small businesses with turnover under $3 million must immediately comply with the general APPs under "2026 enacted reforms." The turnover exemption remains the statutory law of the land today, unless your business falls into one of the established Section 6D(4) exception categories. You can evaluate your exact statutory position using our free Privacy Act Checker Tool.
Regulatory Status Matrix: Enacted Law vs Proposed Reforms
The following table summarizes the legal status of key Australian privacy measures as at September 2026, with verifiable primary source citations:
| Reform Item / Policy Area | Current Legal Status | Effective / Commencement Date | Primary Source Citation |
|---|---|---|---|
| Small Business Turnover Exemption (s 6D) | In Force (Law) | Continuous since 2000 amendments | Privacy Act 1988 (Cth) Section 6D |
| Health Service Provider Exception | In Force (Law) | Continuous since 2000 amendments | Privacy Act 1988 (Cth) Section 6D(4)(b) |
| Trading in Personal Data Exception | In Force (Law) | Continuous since 2000 amendments | Privacy Act 1988 (Cth) Section 6D(4)(c) |
| Statutory Tort for Serious Invasions of Privacy | Passed (Enacted Law) | Commencing mid-2025 (within 6 months of Assent) | Privacy & Other Legislation Amendment Act 2024 |
| Tiered Civil Penalties & Infringement Notices | Passed (Enacted Law) | Royal Assent received 10 Dec 2024 | Privacy & Other Legislation Amendment Act 2024 |
| Enhanced OAIC Investigation Powers | Passed (Enacted Law) | In force post-Royal Assent | OAIC Regulatory Action Framework |
| Abolition / Narrowing of Small Business Exemption | Proposed Reform | Awaiting Phase 2 Bill / Consultation | AGD Privacy Act Review — Proposal 4 Response |
| Direct Right of Action for APP Breaches | Proposed Reform | Subject to future parliamentary tranches | AGD Privacy Act Review — Proposal 26 Response |
| Children's Online Privacy Code | Enacted (In Development) | Due late 2026 / 2027 following OAIC drafting | Privacy & Other Legislation Amendment Act 2024 |
Practical Implications of the Future Small Business Scenario
If Parliament passes subsequent legislation removing or restricting the Section 6D exemption, every commercial enterprise in Australia—from sole traders and suburban retail stores to boutique consultancy practices—will become fully accountable under the 13 Australian Privacy Principles.
Under this future operating model, small businesses will need to maintain:
+-------------------------------------------------------------------------------+
| 1. Transparent Privacy Policies (APP 1) --> Clear data collection notices
| 2. Purpose-Driven Collection (APP 3 & 5) --> Collecting only essential data
| 3. Stringent Security Safeguards (APP 11) --> Technical cyber defences
| 4. Mandatory Breach Notification (Part IIIC) --> 30-day reporting to OAIC
+-------------------------------------------------------------------------------+
1. Mandatory Data Security Safeguards (APP 11)
Under APP 11, entities must take "reasonable steps" to protect personal information from misuse, interference, loss, and unauthorized access, modification, or disclosure. For modern small businesses storing customer data in cloud repositories, reasonable steps include:
- Mandatory Multi-Factor Authentication (MFA) across all email and administrative accounts.
- Encrypting customer data at rest and in transit across Microsoft 365, Google Workspace, and web applications.
- Establishing least-privilege role boundaries so standard staff cannot export bulk customer databases to unmanaged personal devices.
2. Notifiable Data Breaches (NDB) Scheme Compliance
If customer or employee data is accessed without authorization and is likely to result in "serious harm" to any affected individual, the business must:
- Conduct a prompt assessment within 30 calendar days.
- Notify the Australian Information Commissioner via the official OAIC breach notification portal.
- Issue written breach notifications to all affected individuals outlining the incident and recommended protective steps.
Failing to report an eligible data breach exposes the entity to Tier 2 civil penalties and statutory infringement notices. You can evaluate the potential financial liability of a customer data breach using our Data Breach Cost Estimator.
Action Plan for Australian Small Businesses
Regardless of when Parliament introduces the next tranche of privacy legislation, proactive compliance is far more cost-effective than emergency post-breach remediation. Organisations should take three immediate steps:
- Conduct a Data Asset Audit: Map where personal information resides across your enterprise—including customer CRM records, website contact forms, email archives, accounting platforms, and backup vaults.
- Review Exception Criteria: Verify whether your business provides health services, trades in customer leads, or participates in Commonwealth supply chains. If so, establish immediate APP 11 alignment.
- Deploy Foundational Cyber Defences: Implement basic security hygiene aligned with the ACSC Essential Eight framework—specifically multi-factor authentication, endpoint patching, and immutable backups.
AgenorIT specializes in implementing automated security baselines and data governance guardrails across enterprise cloud environments. Explore our Azure Governance & Security Services to secure your customer data.
Conclusion & Next Steps
Australia's privacy laws are evolving to reflect the realities of the digital economy. While the complete removal of the small business exemption remains a proposed reform undergoing policy consultation, the introduction of statutory torts, tiered civil penalties, and strict enforcement across existing exception categories means small businesses cannot afford complacency.
- Check your current statutory obligations with our Privacy Act Exemption Checker.
- Calculate potential financial and regulatory breach exposure using our Data Breach Cost Estimator.
- Learn how our Melbourne team secures cloud environments in Azure Governance & Security.
- Review technical endpoint hardening standards in our Essential Eight Implementation Guide.
Written by Gurinder Singh
AuthorPrincipal Cloud & Software Architect at AgenorIT. Specialising in Microsoft Azure Landing Zones, Microsoft Entra identity architectures, Microsoft Fabric lakehouses, and high-performance digital products for Australian organisations.
Related Architecture & Engineering Insights
Azure AD B2C to Entra External ID Migration Guide: Architectural Patterns & Cutover Strategy
Step-by-step engineering guide to migrating Azure AD B2C to Microsoft Entra External ID with zero user downtime, JIT password migration, and token mapping.
Azure Landing Zone Cost in Australia: 2026 Implementation & Consumption Guide
Understand Azure Landing Zone implementation costs in Australia. Compare architecture drivers, subscription sizing, IaC accelerators, and Azure cloud spend.
Need Senior Architecture Guidance on Your Platform?
Speak directly with an experienced engineer about cloud infrastructure, data pipelines, or software development.