Compliance & privacy · Regulatory deadline

The privacy law exemption you've relied on is ending on 10 December 2026

For over two decades, businesses turning over less than $3 million haven't had to comply with the Privacy Act. That exemption is being removed. About 2.5 million Australian businesses are about to be covered by privacy law for the first time — many without knowing it's coming.

If your business turns over less than $3 million a year, there's a good chance you've never had to think about the Privacy Act. Not because your business doesn't handle personal information — most do — but because a small business exemption has quietly kept roughly 2.5 million Australian businesses outside the scope of federal privacy law for over 20 years.

That exemption ends on 10 December 2026 — a little over 14 weeks from now. On that date, the businesses currently protected by it become subject to all 13 Australian Privacy Principles, the same rules that have applied to larger companies, banks and government agencies for decades. Most owners affected by this don't yet know it's happening.

Glowing network connections over a night-time city skyline, representing a nationwide regulatory change
A change of this scale — roughly 2.5 million businesses newly in scope — doesn't stay quiet for long. The safer position is to be ready before it lands, not after.

What actually changes on 10 December

The reform itself isn't new. The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and is widely described as the most substantial change to Australian privacy law since the Privacy Act was introduced in 1988. Most of its provisions are already in force — a statutory tort for serious invasions of privacy has applied since June 2025, letting individuals sue directly through the courts for damages, including for emotional harm. Read the IAPP's analysis of the reforms.

What lands on 10 December 2026 specifically is the removal of the small business exemption itself. Two things change on that exact date:

  • Full Privacy Act coverage. Businesses under the $3 million turnover threshold — previously exempt — must comply with all 13 Australian Privacy Principles, covering how personal information is collected, used, stored, secured, disclosed and disposed of.
  • Automated decision-making (ADM) transparency. Separately, businesses that use personal information in automated or AI-assisted decisions with the potential to affect a person's rights or interests must disclose that in plain language in their privacy policy — the kinds of personal information used, and the kinds of decisions made using it.

Both obligations commence the same day. A business that has never published a compliant privacy policy, never run a data breach response plan and never had to think about "reasonable steps" to protect information needs both in place before then — not as a project to get to eventually. See a summary of what's now in force.

Why you've never had to think about this before

The small business exemption was written into the original Privacy Act to keep compliance costs off businesses that regulators assumed handled comparatively little personal information. That assumption has aged badly. A five-person allied health clinic holds health records. A trades business holds customer addresses, job histories and payment details. A bookkeeper holds financial information for dozens of clients. None of that stopped being sensitive just because the business was small.

The OAIC — the regulator responsible for the Privacy Act — has been on the record for some time that no comparable jurisdiction exempts small business from privacy law this way, and that the exemption has been a genuine obstacle to Australia being recognised as having "adequate" privacy protection under frameworks like the EU's GDPR. Removing it isn't a minor technical tidy-up; it's closing a gap regulators have flagged as a real problem for years. Read the OAIC's own position on the exemption.

The businesses this hits hardest are the ones that have never had a reason to build privacy practices at all — because for over 20 years, the law simply didn't ask them to.

What the 13 Australian Privacy Principles actually require

Here's what all 13 actually require, in plain language — direct from the OAIC's own text of the Act, not a paraphrase:

1. Open and transparent management
Have a clear, accurate, publicly available privacy policy, and someone in the business accountable for it. Not a template nobody's read — it has to reflect what you actually do.
2. Anonymity and pseudonymity
Where it's practicable, give people the option to deal with you without identifying themselves — unless the law requires ID or it's genuinely impractical for the transaction.
3. Collection of solicited personal information
Only collect personal information that's actually necessary for what you do, and only by lawful, fair means. "Might be useful one day" isn't a reason to collect it.
4. Dealing with unsolicited personal information
If information lands in your hands that you didn't ask for, destroy or de-identify it — unless you would have been allowed to collect it anyway.
5. Notification of collection
Tell people, at or before you collect their information, what you're collecting, why, and what happens to it. This is usually the first thing a business without a real privacy policy gets wrong.
6. Use or disclosure of personal information
Only use or share information for the purpose it was collected for, unless the person agreed or a specific exception applies. This is the principle the new AI decision-disclosure rule sits under.
7. Direct marketing
Don't use personal information for direct marketing without consent or a reasonable expectation of it, and always give people a working opt-out.
8. Cross-border disclosure
Before sending personal information overseas — including to an offshore cloud host or AI provider — take reasonable steps to ensure it's handled to the same standard there.
9. Government related identifiers
Don't adopt a government identifier — a Medicare number, driver's licence number, ABN in some contexts — and reuse it as your own customer ID.
10. Quality of personal information
Take reasonable steps to keep the personal information you hold accurate, complete and up to date.
11. Security of personal information
Protect personal information from misuse, loss and unauthorised access, and destroy or de-identify it once you no longer need it. The 2026 reform specifically tightened what "reasonable steps" has to cover here.
12. Access to personal information
Give people access to their own personal information on request, within a reasonable time and without an unreasonable fee.
13. Correction of personal information
Correct personal information on request if it's wrong, and tell any third party you've shared it with if the correction matters to them.

Source: Read the Australian Privacy Principles — OAIC. The explanations above are our plain-language summary, not the legal text itself.

None of this is exotic. It's the same baseline that larger businesses have operated under for years. The difference is that a business with no prior obligation under the Act typically has none of it written down — no privacy policy that actually reflects what the business does, no record of what's collected and why, no breach response plan, and no one internally responsible for any of it.

The new rule about AI making decisions about people

The ADM transparency obligation lands on the same date and deserves its own attention, because it sits directly on top of how many businesses are already using AI without necessarily realising it counts.

If a business uses personal information in an automated or AI-assisted process that could affect a person's rights or interests — screening a job application, prioritising a customer complaint, generating a quote, flagging a loan or credit risk, ranking leads by likelihood to convert — the business will need to say so, in plain language, in its privacy policy: what kind of personal information goes in, and what kind of decision comes out. See the OAIC's consultation on ADM transparency guidance.

We've written before about the privacy risk in what staff paste into public AI tools and about the questions worth answering before AI becomes part of a business process. The ADM disclosure rule is the same territory from a different angle — it's not about whether the information leaves the business, it's about whether the business is required to tell people when AI played a role in a decision about them.

The regulator is already active — before the deadline lands

This isn't a distant, hypothetical enforcement risk. The OAIC ran its first-ever privacy compliance sweep in January 2026 — months before the small business exemption is even removed — and now holds new infringement notice powers of up to $66,000 per contravention, which it can issue without needing to go to court first for lower-level breaches. See a board-level checklist of the enforcement changes.

~2.5M
additional Australian businesses newly covered from 10 Dec 2026
$66,000
maximum OAIC infringement notice, per contravention
Jun 2025
statutory tort commenced — individuals can now sue directly for serious privacy breaches

There's also a quieter overlap worth knowing about. The AML/CTF Tranche 2 reforms that commenced 1 July 2026 already dragged more than 100,000 small businesses — real estate agents, lawyers, conveyancers, accountants and precious-metal dealers — under Privacy Act obligations for the first time, regardless of whether the broader small-business exemption had been formally removed yet. See AUSTRAC's Tranche 2 announcement. If your business sits in one of those sectors, part of this may already apply to you right now, not from December.

The penalties have real teeth now

Two enforcement paths now exist side by side. The OAIC can issue infringement notices directly for lower-level breaches, and pursue larger civil penalties through the courts for serious or repeated interferences with privacy. Separately, the statutory tort means an individual doesn't need to wait for the regulator to act at all — they can sue a business directly for a serious invasion of privacy and seek damages, including for emotional harm, without proving financial loss.

For a business that has never had to think about any of this, that's a meaningful shift in exposure — not because the rules are unreasonable, but because there's currently nothing in place to meet them.

Where this overlaps with how staff already use AI

If you've read our Before You Use AI series, this will sound familiar. Only around 30% of Australian organisations have any formal policy governing staff use of generative AI tools, and separate research suggests close to half of employees are already using AI in ways that would breach a policy if one existed — pasting customer information into a public chatbot, uploading documents for summarisation, using personal accounts for business work. See the research on Australia's AI governance gap.

That's the exact behaviour the OAIC has already used as a real-world example of how an AI shortcut becomes a notifiable data breach — an employee uploading a customer's financial hardship application, including health and family information, to a public AI tool to prepare a summary. A business with no Privacy Act obligations today would still want to fix that. A business that's about to be covered by all 13 APPs from 10 December can't afford to leave it unaddressed.

What to actually do before 10 December

None of this requires a large compliance program. For most small businesses, it comes down to a handful of concrete steps, done properly rather than quickly:

  • Find out what you actually collect. A short audit of what personal information the business holds, where, and why — most owners are surprised by the answer.
  • Check whether AI is already part of a decision. If any process uses AI to help screen, rank, price or respond to a person, that's the trigger for the ADM disclosure requirement.
  • Get a privacy policy that reflects reality, not a template copied from somewhere else — ideally reviewed by a privacy-qualified lawyer before it's published, since this is the one document that carries genuine legal weight.
  • Put a written AI usage policy in front of staff — what's approved, what must never be entered into a public tool, and what to do if something goes wrong. See Your Staff Are Probably Already Using AI for a practical starting structure.
  • Know what happens if something goes wrong. A short, written incident response process — who gets told, how fast, and who decides whether it needs to go further — is the difference between a contained mistake and an escalating one.

Fourteen weeks sounds like a long runway until you consider that most of the businesses affected haven't started, don't know the date exists, and are the same businesses that have never had to build any of this before. The businesses that get ahead of 10 December won't be the ones scrambling in November — they'll be the ones who treated it as a normal project with a normal deadline, starting now.

This article provides general business information and is not legal or privacy advice. Whether and how these obligations apply to your business depends on your specific circumstances — get advice from a privacy-qualified lawyer before publishing a privacy policy or relying on any exemption.

Matt Wilson
Matt Wilson
Founder, momentuum

28 years building and running businesses across IT, digital and services — including 3 exits, and Microsoft Certified: AI Transformation Leader. Now helping other Australian business owners get their operations, automation and systems into shape. More about Matt →

Not sure whether your business is actually ready for 10 December?

Book a free 20-minute call — we'll help you work out what your business currently collects, whether AI is already part of a decision that needs disclosing, and what a sensible readiness plan looks like before the deadline lands.

Start with what matters.

Tell us what feels slower, harder or less reliable than it should. We'll help you work out whether there's a worthwhile improvement — and the simplest way to make it happen.

No AI pitch. No giant workshop. No obligation.