June 2026

Does the Privacy Act Apply to My Small Business? (Probably — Here's What It Means)

For years, small businesses under $3 million turnover treated the Privacy Act as someone else's problem. That comfort is disappearing: penalties have been raised dramatically, reforms are progressively tightening obligations, and the small-business exemption itself has been slated for removal. Here's where you actually stand.

Who's covered today

  • Businesses with annual turnover over $3 million — covered, full stop.
  • Health service providers (including allied health, gyms with health data, childcare) — covered at ANY size.
  • Businesses that trade in personal information, credit reporting bodies, and some others — covered regardless of turnover.
  • Everyone else: the exemption still technically shields you, but reform proposals agreed in principle by government remove it — and your enterprise customers and insurers already expect Privacy Act-grade handling anyway.

What the law actually asks of you

The 13 Australian Privacy Principles (APPs) boil down to common sense, done deliberately:

  • Collect only the personal information you genuinely need, and tell people why (a privacy policy).
  • Keep it accurate, use it only for the purpose collected, and let people access or correct their own data.
  • APP 11 — the security principle: take "reasonable steps" to protect personal information from misuse, loss and unauthorised access — and destroy it when no longer needed.
  • Be careful sending data overseas (APP 8) — you remain accountable for what your offshore providers do with it.

The Notifiable Data Breaches scheme

If personal information you hold is breached and serious harm to individuals is likely, you must notify the affected people and the OAIC "as soon as practicable", with up to 30 days to assess whether the threshold is met. "We didn't know we were breached" is not a defence — which is why detection and logging matter as much as prevention.

What's at stake

Maximum penalties for serious or repeated privacy interference now reach the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover — enterprise-scale numbers designed to make boards pay attention. For an SMB, the realistic risks are the OAIC investigation, the customer exodus and the cost of a mishandled breach, any of which can hurt more than a fine.

"Reasonable steps", translated into a to-do list

  • Know what personal information you hold and where it lives (you can't protect what you haven't mapped).
  • Delete what you no longer need — old CVs, stale customer records, seven-year-old ID scans are pure liability.
  • Protect access: MFA, least-privilege accounts, and offboarding that actually removes ex-staff access.
  • Encrypt devices and backups; monitor endpoints so a breach is detected in hours, not months.
  • Have a current privacy policy that reflects what you really do — including your ad and analytics tracking.
  • Keep a data-breach response plan next to your incident response plan (see our first-24-hours guide).

The strategic view

Privacy compliance and the Essential Eight overlap almost completely at the technical layer: the same MFA, monitoring, backup and access controls satisfy both. Treat them as one uplift program and you get APP 11 "reasonable steps", NDB readiness, insurability and tender eligibility from a single investment — which is exactly how we structure our Compliance+ package.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check