Start with the thing most articles get wrong
If you have been reading about Australian privacy law lately, you have probably seen the claim that the small business exemption has been removed. It has not. As of the current version of the Privacy Act 1988 (Cth) — Compilation No. 104, dated 4 June 2026 — section 6D still exempts most businesses with an annual turnover of A$3 million or less from the Act's obligations. That is the law today, not a transitional arrangement and not something that quietly lapsed.
That matters, because a lot of owners have spent worry on the wrong problem: a deadline that does not exist, while the thing that genuinely puts them in scope — an exception in the same section — goes unnoticed. The exemption is also narrower than the turnover number suggests, and there are now ways to be on the wrong end of a privacy problem that have nothing to do with whether the regulator can reach you.
Who this applies to
Australia's main privacy law is the Privacy Act 1988 (Cth), built around thirteen Australian Privacy Principles, usually shortened to the APPs. They are the operative rules: how you may collect personal information, what you must tell people, how you can use and disclose it, how you secure it, and what rights people have to see and correct it. The regulator is the Office of the Australian Information Commissioner, or OAIC, and an organisation bound by the APPs is called an APP entity.
Above A$3 million in annual turnover, you are an APP entity and the rest of this post is your baseline. Under it, you are probably exempt — but check the exceptions first, because several catch ordinary small businesses.
You are covered regardless of turnover if you are a health service provider that holds health information. That is broader than it sounds: a physiotherapy practice, a small dental clinic, a solo psychologist, a gym collecting injury histories on its intake form. You are covered if you trade in personal information — that is, you buy or sell it — so selling a customer list on exit, or taking money to pass contact data to a partner, puts you in scope. You are covered if you are a credit reporting body, or a contracted service provider under a Commonwealth contract, which sweeps in small consultancies that would never think of themselves as regulated. And you are covered if you opt in voluntarily, which some businesses do because enterprise customers ask for it.
Read that list against what your business actually does. The gym owner who added a health questionnaire two years ago is the one most likely to be surprised.
What you actually have to do
If you are an APP entity, these take most of the time. If you are exempt, treat them as the standard customers already assume you meet.
Be open about how you handle personal information. The APPs require a clearly expressed, up-to-date privacy policy, available free of charge, describing what you collect, why, who you disclose it to, whether it goes overseas, and how someone can complain. The failure mode is rarely a missing policy — almost everyone has one — but a template describing a business you are not running. If yours does not mention the analytics tool, the email platform, or the offshore support contractor you actually use, it is not doing its job.
Collect only what you need, and tell people at the time. Personal information should be collected because it is reasonably necessary for what you do, and people must be told at or around the point of collection who you are, why you are collecting it, and who you will pass it to. Sensitive information, including health information, generally requires consent. In practice this means auditing your forms: the checkout field asking for date of birth when you have no reason to know it is a liability, not a feature.
Use information for the purpose you collected it for. If you took an email address to fulfil an order, using it for a marketing campaign is a different purpose, and the rules on secondary use and direct marketing both apply. People must be able to opt out easily, and you have to honour it. This is where most complaints about small organisations start.
Secure what you hold, and get rid of what you do not need. You must take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access — and to destroy or de-identify it once you no longer need it. The second half is the one people skip. Old customer databases, exported spreadsheets, and a decade of form submissions in an inbox are all risk you are choosing to keep.
Know what happens when data goes overseas. If you disclose personal information to an overseas recipient — and most cloud tools involve exactly that — you generally have to take reasonable steps to ensure they handle it consistently with the APPs, and you often stay accountable for what they do. Write down which tools store data where.
Have a breach plan before you need one. Under the Notifiable Data Breaches scheme, an APP entity that suspects an eligible data breach must assess it within 30 days, and where the breach is likely to result in serious harm, must notify the OAIC and the affected individuals as soon as practicable. Thirty days sounds generous until the clock starts on a Friday and nobody knows who is responsible.
Be able to answer access and correction requests. People can ask what personal information you hold about them and ask you to fix it. You need a route for the request to arrive, a way to find the data across your systems, and a habit of responding within a reasonable time. If you cannot search your own records, you cannot answer.
What changed
The Privacy and Other Legislation Amendment Act 2024 passed in December 2024 and is the most significant change in years. Four parts matter here.
First, it created a statutory tort for serious invasions of privacy, which commenced in June 2025. This is the one to understand, because an individual can sue you directly, independently of the OAIC — and the small business exemption does not shield you from being sued. Being outside the Act is not the same as being outside legal risk.
Second, it introduced new criminal offences for doxxing, the malicious publication of someone's personal details. Third, it directed the OAIC to develop a Children's Online Privacy Code. That code is still in development — it is not in force, whatever you may read.
Fourth, it expanded enforcement powers and added new civil penalty tiers. Be careful with any dollar figure you see online: Commonwealth penalties are set in penalty units, and the value of a unit rose from A$330 to A$364 on 1 July 2026, so totals published before that date are stale. The numbers move, and they move upward.
Further tranches of reform have been flagged, including proposals that could narrow or remove the small business exemption. None of it is enacted. Treat it as a reason to build habits that survive a change in the law, not a deadline to panic about.
Common mistakes
The most expensive mistake is assuming turnover settles the question. Owners check the A$3 million figure, conclude they are exempt, and never read the exceptions — which is how a clinic or gym ends up regulated without knowing it.
The second is treating a privacy policy as a document rather than a description. A policy that does not match your real tools and data flows is worse than a short honest one, because it puts in writing a promise you are not keeping.
The third is confusing exemption with immunity. The statutory tort, Australian Consumer Law, promises made in your own contracts, and the plain commercial damage of a breach all reach businesses the Privacy Act does not.
The fourth is collecting sensitive information casually — health details on an intake form, or identity documents kept "just in case". The fifth is having no owner: privacy belongs to someone specific, or it belongs to nobody at 5pm on a Friday.
Where Dxtra fits
Dxtra generates a privacy program from a questionnaire about your business: a privacy policy, a cookie notice, consent records, processing records, a public Transparency Center, and a process for handling data subject access requests. It covers 500+ obligations across 140-plus countries and starts at $10 a month. It will not tell you whether your gym counts as a health service provider — that is a judgement call for an adviser — but it handles the documentation layer.
Where to start
Do three things this month. Write down every system that holds customer data and where it lives, spreadsheets included. Check your business against the exception list above and get a straight answer on whether you are an APP entity. Then name the person who owns a breach if one happens, and give them half an hour to write down what they would do.
After that, look at what your website tells the public, because that is the part customers and regulators can see without asking. Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band with findings mapped to named sources, so you can see what is missing before you decide what to fix.
This article is general information, not legal advice. Rules change; confirm anything that matters with the Office of the Australian Information Commissioner (oaic.gov.au) or a qualified adviser before you rely on it.
