Skip to main content
COMPLIANCE

Australia's Privacy Act changes: what small businesses actually need to do before 10 December 2026

22 July 2026 · 6 min read

← Back to the blog

Most small businesses have operated for years under the assumption that the Privacy Act doesn't really apply to them — the small-business exemption (annual turnover under $3 million) has covered a lot of ground since 2001. The 2026 reforms narrow that safety margin, and the deadline that matters for anyone touching customer data is 10 December 2026.

What's actually changing

The exemption itself isn't gone outright, but new obligations — around notifiable data breaches, transparency about automated decision-making, and stronger consent standards — increasingly apply regardless of business size when certain triggers are met (health information, data trading, certain contracted government work, and businesses using automated tools to make decisions about people). If any of those apply to you, the size exemption stops being a reliable shield.

Who this actually catches

  • Anyone using AI tools that make or influence decisions about customers (credit, eligibility, pricing, risk scoring).
  • Anyone handling health, biometric, or other sensitive information, regardless of turnover.
  • Businesses that received a third party's customer data as part of a partnership, referral, or acquisition.
  • Any business that's had — or could plausibly have — a data breach involving personal information.

What it doesn't mean

It doesn't mean every small business needs a compliance officer or a six-figure legal review. For most operators the real gap is smaller and more practical: knowing what personal data you actually hold, where it lives, who can access it, and having an honest answer ready if someone asks what happens to their information. That's a few days of work done properly, not a program.

A useful gut check

If you can't currently answer "what personal data do we hold, where does it live, and who can see it" in under two minutes without checking with someone else, that's the gap worth closing first — before the deadline, not after someone asks the question for you.

Fixed-price Privacy Act compliance for AU small business, scoped to what actually applies to you.

SEE THE COMPLIANCE PACK →

RELATED

Compliance19 Aug 20264 min read

Do sole traders need a privacy policy in Australia?

"I'm under $3 million turnover" is true for almost every sole trader. It's not the whole answer anymore.

Read
Compliance19 Aug 20264 min read

The Notifiable Data Breach scheme: the 30-day rule small businesses miss

It doesn't have to be a hack. An email sent to the wrong address can trigger the same 30-day clock.

Read

WANT THIS APPLIED TO YOUR BUSINESS?

15 minutes is enough to know if there's a real gap worth closing.

BOOK YOUR FREE AI AUDIT CALL
Book Free AI Audit Call