What's actually changing
The Privacy Act 1988 currently exempts most businesses with an annual turnover under $3 million from its core obligations. That exemption was written at a time when a small business genuinely handled a limited amount of personal information. The federal government has agreed in principle to remove it entirely, following a recommendation from the Attorney-General's review of the Act, with the phase-in targeted for December 2026.
In practical terms, this brings an estimated 2.5 million Australian small businesses, most of which have never had to think about formal privacy compliance, under the same regime that currently applies to larger organisations. That includes needing a publicly available privacy policy that complies with the Australian Privacy Principles, a documented process for handling data breaches, and the ability to demonstrate that reasonable steps are being taken to protect the personal information a business holds.
Why the exemption is being scrapped
The assumption behind the original threshold no longer holds up well. A small clinic books appointments and stores health records. A local accounting firm holds tax file numbers and bank details. A boutique law firm manages sensitive case files. A community group running a booking system might process far more personal, and in some cases sensitive, information than its size suggests. None of that has much to do with revenue.
Separately, the Notifiable Data Breaches scheme, which already applies regardless of size once serious harm is likely, has been recording its highest breach numbers since it began in 2018. Regulators have been fairly explicit that they expect organisations to have a breach response plan in place before an incident happens, not worked out afterwards under pressure.
What this means for a business like yours
If your practice currently sits under the $3 million threshold, this is worth getting ahead of rather than leaving until the deadline gets close. The core requirements aren't exotic: a written privacy policy that's actually accurate about what you collect and why, a clear process for what happens if something goes wrong, and the everyday technical controls that make both of those meaningful, things like multi-factor authentication, sensible access permissions, device encryption and tested backups.
Most of what's needed overlaps heavily with good IT practice generally, so businesses that already take security seriously have a head start. For everyone else, December 2026 is far enough away to prepare properly, and far too close to leave until the last quarter. We're not lawyers, and the specifics of what your practice needs to comply legally is worth a conversation with one; what we can do is make sure the technical side, access, security and backup, is actually ready to support it.
