02 8987 4501  ·  0406 340 856
Google Reviews
Privacy & Compliance

The small business exemption from the Privacy Act is being phased out.

Published 2 August 2026

Right now, most businesses turning over less than $3 million a year sit outside the Privacy Act's obligations. That's changing. Roughly 2.5 million Australian small businesses are set to become newly regulated, with full implementation targeted for December 2026.

Why IT Service Centre
Since 2004Two decades supporting Sydney businesses
2-hour responseDuring business hours, sooner for urgent issues
One partnerSupport, security, networks and cloud, together

What's actually changing

The Privacy Act 1988 currently exempts most businesses with an annual turnover under $3 million from its core obligations. That exemption was written at a time when a small business genuinely handled a limited amount of personal information. The federal government has agreed in principle to remove it entirely, following a recommendation from the Attorney-General's review of the Act, with the phase-in targeted for December 2026.

In practical terms, this brings an estimated 2.5 million Australian small businesses, most of which have never had to think about formal privacy compliance, under the same regime that currently applies to larger organisations. That includes needing a publicly available privacy policy that complies with the Australian Privacy Principles, a documented process for handling data breaches, and the ability to demonstrate that reasonable steps are being taken to protect the personal information a business holds.

Why the exemption is being scrapped

The assumption behind the original threshold no longer holds up well. A small clinic books appointments and stores health records. A local accounting firm holds tax file numbers and bank details. A boutique law firm manages sensitive case files. A community group running a booking system might process far more personal, and in some cases sensitive, information than its size suggests. None of that has much to do with revenue.

Separately, the Notifiable Data Breaches scheme, which already applies regardless of size once serious harm is likely, has been recording its highest breach numbers since it began in 2018. Regulators have been fairly explicit that they expect organisations to have a breach response plan in place before an incident happens, not worked out afterwards under pressure.

What this means for a business like yours

If your practice currently sits under the $3 million threshold, this is worth getting ahead of rather than leaving until the deadline gets close. The core requirements aren't exotic: a written privacy policy that's actually accurate about what you collect and why, a clear process for what happens if something goes wrong, and the everyday technical controls that make both of those meaningful, things like multi-factor authentication, sensible access permissions, device encryption and tested backups.

Most of what's needed overlaps heavily with good IT practice generally, so businesses that already take security seriously have a head start. For everyone else, December 2026 is far enough away to prepare properly, and far too close to leave until the last quarter. We're not lawyers, and the specifics of what your practice needs to comply legally is worth a conversation with one; what we can do is make sure the technical side, access, security and backup, is actually ready to support it.

Wondering where you'd stand?

Let's look at the technical side together.

Access controls, encryption, backup and breach response, the practical groundwork that supports whatever your compliance obligations turn out to be.

Start a conversation