TL;DR: Australia privacy law in September 2026
- Is the small business exemption gone? No. Businesses with an annual turnover of AU$3 million or less are generally still exempt from the Privacy Act, unless an exception applies: for example health service providers, businesses that trade in personal information, credit reporting bodies or contracted service providers to the Commonwealth (OAIC).
- Is removal scheduled? The Privacy Act Review proposed removing the exemption. No law doing so has been passed, and no date has been set.
- What is already in force: a statutory tort for serious invasions of privacy, since 10 June 2025. It is not limited to organisations covered by the Privacy Act (OAIC).
- What starts on 10 December 2026: organisations covered by the Act that use personal information in substantially automated decisions that could significantly affect individuals must describe those decisions in their privacy policy (OAIC).
The small business exemption: what it is today
The Privacy Act 1988 exempts most businesses with an annual turnover of AU$3 million or less from the Australian Privacy Principles (APPs). That exemption is still in force.
It does not cover every small business. According to the OAIC, a small business is covered by the Act regardless of turnover if, among other cases, it:
- provides a health service and holds health information;
- trades in personal information, for example by buying or selling it;
- is a contracted service provider under a Commonwealth contract;
- is a credit reporting body or operates a residential tenancy database;
- is a reporting entity under the anti-money laundering and counter-terrorism financing legislation;
- is accredited under the Consumer Data Right.
If you are unsure which side of the line you are on, the OAIC page on small businesses is the reference; check it against your actual activities rather than your turnover alone.
What the Privacy Act Review proposed, and what became law
The Attorney-General’s Privacy Act Review proposed a broad set of changes, including removing the small business exemption and tightening the rules on consent. The Government then passed a first set of reforms in the Privacy and Other Legislation Amendment Act 2024. Removing the small business exemption was not part of it.
What that 2024 Act did include, according to the OAIC:
- a statutory tort for serious invasions of privacy, giving individuals a route to the courts;
- a transparency obligation for automated decisions in privacy policies;
- new enforcement tools for the OAIC, including new tiers of civil penalties and infringement notices;
- a mandate to develop a Children’s Online Privacy Code.
Anything else you read about “the 2026 reforms”, such as the removal of the exemption or new statutory consent standards, is at proposal stage until a bill passes. Planning around a proposal is reasonable; presenting it as an obligation with a date is not.
The statutory tort: the change that reaches small businesses now
The tort commenced on 10 June 2025. It lets an individual sue for a serious invasion of privacy, either by intrusion upon seclusion or by misuse of information about them, where they had a reasonable expectation of privacy. The OAIC notes that it is broader than the Privacy Act: it can apply to individuals and organisations that are not APP entities, which includes exempt small businesses.
In practice, for a small business website this is a reason to handle personal information carefully even while exempt: collect only what you need, protect it, and do not disclose it in ways people would not expect.
Automated decisions: the 10 December 2026 obligation
From 10 December 2026, APP entities that arrange for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual’s rights or interests must include information about this in their privacy policy: the kinds of personal information used and the kinds of decisions made. The OAIC has consulted on guidance for this obligation.
This obligation applies to organisations covered by the Act. An exempt small business is not bound by it, although a covered organisation of any size is.
Consent: what the OAIC already expects
Consent is one of the bases for handling personal information under the APPs. The OAIC’s APP guidelines already set out the elements of valid consent: the individual is adequately informed, gives consent voluntarily, the consent is current and specific, and the individual has the capacity to understand and communicate it (APP guidelines, chapter B). The Review proposed writing a stricter standard into the Act; that proposal has not been legislated.
Separately, the Spam Act 2003 applies to commercial emails and SMS whatever the size of the business: you need consent (express or, in limited cases, inferred), accurate identification of the business that authorised the message, and an unsubscribe option that is easy to use (ACMA). For many small websites, the Spam Act is the privacy-related law that already applies to their newsletter.
Privacy policy requirements for covered organisations
APP 1 requires organisations covered by the Act to have a clearly expressed and up-to-date privacy policy. It must cover, among other things:
- the kinds of personal information collected and held, and how it is collected;
- the purposes of collection, use and disclosure;
- how an individual can access and correct their information;
- how to complain about a breach of the APPs and how complaints are handled;
- whether information is likely to be disclosed overseas and, if practicable, the countries involved.
From 10 December 2026, covered organisations using substantially automated decisions add the information described above.
Practical steps for a small business website
- Check whether you are exempt. Turnover is only the first test. Go through the OAIC’s list of exceptions against what your business actually does.
- If you are covered, publish an APP-compliant privacy policy, map where personal information goes (including overseas providers), and prepare for the automated-decision disclosure if it applies to you.
- If you are exempt, consider publishing a privacy policy anyway: customers, payment providers and platforms often expect one, and the statutory tort applies to you.
- Review your email marketing against the Spam Act, which applies regardless of size.
- Keep an eye on the reforms. If a bill removing the exemption is introduced, it will set its own commencement date and transition period.
Sources (checked on 19 September 2026)
- OAIC, Small business
- OAIC, Statutory tort for serious invasions of privacy
- OAIC, Consultation on guidance for transparency in automated decision making
- OAIC, Passing of bill a significant step for Australia’s privacy law (29 November 2024)
- Federal Register of Legislation, Privacy and Other Legislation Amendment Act 2024
- OAIC, Higher penalties to help protect Australians’ privacy (penalty regime in force since 13 December 2022)
- OAIC, APP guidelines, chapter B: key concepts
- ACMA, Avoid sending spam
This article explains the law in general terms; it is not legal advice for your situation.
How WebLegal can help
If your business is covered by the Privacy Act, or you choose to publish a privacy policy anyway, you can start with a free scan of your website to see which trackers and third-party tools it uses. The WebLegal form then produces a privacy policy based on your answers, from €19.90 (Essential pack: privacy policy + cookie policy). A generated policy reflects what you declare on the day you generate it; it does not update itself when the law or your tools change.