Skip to main content
COMPLIANCE

Do sole traders need a privacy policy in Australia?

19 August 2026 · 4 min read

← Back to the blog

Short answer: most sole traders are still covered by the Privacy Act's small-business exemption (annual turnover under $3 million) today, but the exemption already has exceptions that catch some trade businesses, and it narrows further for specific business types from 1 July 2026 — so "I'm too small" is worth double-checking rather than assuming.

Who's already excluded from the exemption, regardless of size

  • Health service providers — including anyone holding health-related records, which can catch businesses that don't think of themselves as health providers.
  • Businesses that trade in personal information — buying or selling contact lists or data as part of the business.
  • Businesses that collect or hold tax file numbers.

What changes from 1 July 2026

Businesses that become "reporting entities" under AML/CTF tranche-two reforms — a group that includes many accountants, lawyers, real estate agents, and some trust or company service providers — lose the small-business exemption from that date, regardless of turnover. If that doesn't describe your trade, this specific change doesn't catch you, but it's a sign the exemption is narrowing rather than staying fixed.

Should you have a privacy policy anyway, even if exempt?

Practically, yes, for reasons beyond strict legal obligation. If you're storing customer names, addresses, phone numbers, and job photos in ServiceM8 or a spreadsheet, having a plain-English one-pager on what you do with that information is the kind of thing that costs an afternoon and heads off an awkward conversation later — with a client, a platform you're selling through, or an insurer asking about your data practices.

It's also simply good practice regardless of the legal threshold — the businesses that treat customer data carelessly before they're legally required to are usually the same ones scrambling when the requirement does eventually catch them.

A straight answer on whether the reforms apply to your specific business, and what minimum-viable compliance actually looks like.

SEE THE COMPLIANCE PACK →

QUICK ANSWERS

RELATED

Compliance22 July 20266 min read

Australia's Privacy Act changes: what small businesses actually need to do before 10 December 2026

"We're too small for privacy law" stops being reliably true this year. Here's what changes and what doesn't.

Read
Compliance19 Aug 20264 min read

The Notifiable Data Breach scheme: the 30-day rule small businesses miss

It doesn't have to be a hack. An email sent to the wrong address can trigger the same 30-day clock.

Read

WANT THIS APPLIED TO YOUR BUSINESS?

15 minutes is enough to know if there's a real gap worth closing.

BOOK YOUR FREE AI AUDIT CALL
Book Free AI Audit Call