If your business turns over less than $3 million a year, there's a good chance you've never had to think about the Privacy Act. Not because your business doesn't handle personal information — most do — but because a small business exemption has quietly kept roughly 2.5 million Australian businesses outside the scope of federal privacy law for over 20 years.
That exemption ends on 10 December 2026 — a little over 14 weeks from now. On that date, the businesses currently protected by it become subject to all 13 Australian Privacy Principles, the same rules that have applied to larger companies, banks and government agencies for decades. Most owners affected by this don't yet know it's happening.
What actually changes on 10 December
The reform itself isn't new. The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and is widely described as the most substantial change to Australian privacy law since the Privacy Act was introduced in 1988. Most of its provisions are already in force — a statutory tort for serious invasions of privacy has applied since June 2025, letting individuals sue directly through the courts for damages, including for emotional harm. Read the IAPP's analysis of the reforms.
What lands on 10 December 2026 specifically is the removal of the small business exemption itself. Two things change on that exact date:
- Full Privacy Act coverage. Businesses under the $3 million turnover threshold — previously exempt — must comply with all 13 Australian Privacy Principles, covering how personal information is collected, used, stored, secured, disclosed and disposed of.
- Automated decision-making (ADM) transparency. Separately, businesses that use personal information in automated or AI-assisted decisions with the potential to affect a person's rights or interests must disclose that in plain language in their privacy policy — the kinds of personal information used, and the kinds of decisions made using it.
Both obligations commence the same day. A business that has never published a compliant privacy policy, never run a data breach response plan and never had to think about "reasonable steps" to protect information needs both in place before then — not as a project to get to eventually. See a summary of what's now in force.
Why you've never had to think about this before
The small business exemption was written into the original Privacy Act to keep compliance costs off businesses that regulators assumed handled comparatively little personal information. That assumption has aged badly. A five-person allied health clinic holds health records. A trades business holds customer addresses, job histories and payment details. A bookkeeper holds financial information for dozens of clients. None of that stopped being sensitive just because the business was small.
The OAIC — the regulator responsible for the Privacy Act — has been on the record for some time that no comparable jurisdiction exempts small business from privacy law this way, and that the exemption has been a genuine obstacle to Australia being recognised as having "adequate" privacy protection under frameworks like the EU's GDPR. Removing it isn't a minor technical tidy-up; it's closing a gap regulators have flagged as a real problem for years. Read the OAIC's own position on the exemption.
The businesses this hits hardest are the ones that have never had a reason to build privacy practices at all — because for over 20 years, the law simply didn't ask them to.
What the 13 Australian Privacy Principles actually require
Here's what all 13 actually require, in plain language — direct from the OAIC's own text of the Act, not a paraphrase:
Source: Read the Australian Privacy Principles — OAIC. The explanations above are our plain-language summary, not the legal text itself.
None of this is exotic. It's the same baseline that larger businesses have operated under for years. The difference is that a business with no prior obligation under the Act typically has none of it written down — no privacy policy that actually reflects what the business does, no record of what's collected and why, no breach response plan, and no one internally responsible for any of it.
The new rule about AI making decisions about people
The ADM transparency obligation lands on the same date and deserves its own attention, because it sits directly on top of how many businesses are already using AI without necessarily realising it counts.
If a business uses personal information in an automated or AI-assisted process that could affect a person's rights or interests — screening a job application, prioritising a customer complaint, generating a quote, flagging a loan or credit risk, ranking leads by likelihood to convert — the business will need to say so, in plain language, in its privacy policy: what kind of personal information goes in, and what kind of decision comes out. See the OAIC's consultation on ADM transparency guidance.
We've written before about the privacy risk in what staff paste into public AI tools and about the questions worth answering before AI becomes part of a business process. The ADM disclosure rule is the same territory from a different angle — it's not about whether the information leaves the business, it's about whether the business is required to tell people when AI played a role in a decision about them.
The regulator is already active — before the deadline lands
This isn't a distant, hypothetical enforcement risk. The OAIC ran its first-ever privacy compliance sweep in January 2026 — months before the small business exemption is even removed — and now holds new infringement notice powers of up to $66,000 per contravention, which it can issue without needing to go to court first for lower-level breaches. See a board-level checklist of the enforcement changes.
There's also a quieter overlap worth knowing about. The AML/CTF Tranche 2 reforms that commenced 1 July 2026 already dragged more than 100,000 small businesses — real estate agents, lawyers, conveyancers, accountants and precious-metal dealers — under Privacy Act obligations for the first time, regardless of whether the broader small-business exemption had been formally removed yet. See AUSTRAC's Tranche 2 announcement. If your business sits in one of those sectors, part of this may already apply to you right now, not from December.
The penalties have real teeth now
Two enforcement paths now exist side by side. The OAIC can issue infringement notices directly for lower-level breaches, and pursue larger civil penalties through the courts for serious or repeated interferences with privacy. Separately, the statutory tort means an individual doesn't need to wait for the regulator to act at all — they can sue a business directly for a serious invasion of privacy and seek damages, including for emotional harm, without proving financial loss.
For a business that has never had to think about any of this, that's a meaningful shift in exposure — not because the rules are unreasonable, but because there's currently nothing in place to meet them.
Where this overlaps with how staff already use AI
If you've read our Before You Use AI series, this will sound familiar. Only around 30% of Australian organisations have any formal policy governing staff use of generative AI tools, and separate research suggests close to half of employees are already using AI in ways that would breach a policy if one existed — pasting customer information into a public chatbot, uploading documents for summarisation, using personal accounts for business work. See the research on Australia's AI governance gap.
That's the exact behaviour the OAIC has already used as a real-world example of how an AI shortcut becomes a notifiable data breach — an employee uploading a customer's financial hardship application, including health and family information, to a public AI tool to prepare a summary. A business with no Privacy Act obligations today would still want to fix that. A business that's about to be covered by all 13 APPs from 10 December can't afford to leave it unaddressed.
What to actually do before 10 December
None of this requires a large compliance program. For most small businesses, it comes down to a handful of concrete steps, done properly rather than quickly:
- Find out what you actually collect. A short audit of what personal information the business holds, where, and why — most owners are surprised by the answer.
- Check whether AI is already part of a decision. If any process uses AI to help screen, rank, price or respond to a person, that's the trigger for the ADM disclosure requirement.
- Get a privacy policy that reflects reality, not a template copied from somewhere else — ideally reviewed by a privacy-qualified lawyer before it's published, since this is the one document that carries genuine legal weight.
- Put a written AI usage policy in front of staff — what's approved, what must never be entered into a public tool, and what to do if something goes wrong. See Your Staff Are Probably Already Using AI for a practical starting structure.
- Know what happens if something goes wrong. A short, written incident response process — who gets told, how fast, and who decides whether it needs to go further — is the difference between a contained mistake and an escalating one.
Fourteen weeks sounds like a long runway until you consider that most of the businesses affected haven't started, don't know the date exists, and are the same businesses that have never had to build any of this before. The businesses that get ahead of 10 December won't be the ones scrambling in November — they'll be the ones who treated it as a normal project with a normal deadline, starting now.
This article provides general business information and is not legal or privacy advice. Whether and how these obligations apply to your business depends on your specific circumstances — get advice from a privacy-qualified lawyer before publishing a privacy policy or relying on any exemption.
Not sure whether your business is actually ready for 10 December?
Book a free 20-minute call — we'll help you work out what your business currently collects, whether AI is already part of a decision that needs disclosing, and what a sensible readiness plan looks like before the deadline lands.
