Does the Privacy Act Apply to
My Small Business?
The $3 Million Exemption Explained
If you run a small business in Australia and earn under $3 million a year, you might think the Privacy Act doesn’t apply to you. For most businesses, that’s still true today – but the picture is shifting fast in some industries, and stalling in others. Here’s exactly what’s confirmed law, what’s locked in but not yet active, and what’s still just a proposal.
How to read this guide
The Quick Answer: Where Does Your Business Stand Right Now?
The honest answer depends on two things: what industry you’re in and what your annual turnover is. Neither question is complicated, but the answer matters – because the rules genuinely differ depending on which category you fall into, and not every change you’ve heard about is actually law yet.
Here’s the part that’s certain: if you run a health practice, provide financial services, or – from 1 July 2026 – work in real estate, accounting, law, conveyancing, or high-value goods dealing, the Privacy Act applies to your business right now, whether you earn $500,000 or $5 million a year. In force
Here’s the part that’s genuinely uncertain: if you run a café, retail store, tradie business, or most other types of small business, the $3 million exemption currently still applies to you. Removing that exemption entirely is something the government has agreed to in principle, but as of June 2026 it has not been introduced as a Bill, has no legislated text, and has no confirmed commencement date. Proposed only
Don’t put a date on your calendar for the small business exemption removal – there isn’t one yet. What is certain is the direction of travel: the OAIC has publicly called the exemption “no longer appropriate,” and two separate reforms (AML/CTF Tranche 2, and the December 2026 automated decision-making disclosure rule) are already narrowing who can rely on it. Preparing now is sensible regardless of the exact date the broader exemption is removed.
What the $3 Million Exemption Actually Means
The Privacy Act 1988 (Cth) is Australia’s main law governing how personal information is collected, stored, used, and disclosed. It sets out 13 Australian Privacy Principles – known as the APPs – that businesses must follow if they’re covered by the Act.
Since 2000, there’s been a carve-out for small businesses. Under Section 6C(1) of the Privacy Act, a business with annual turnover of $3 million or less is generally exempt from being treated as an “organisation” for the purposes of the Act, meaning the APPs don’t apply. In force This is the small business exemption, and it has not changed since it was introduced.
What counts as “annual turnover”?
This is one of the most commonly misunderstood parts of the exemption. Turnover is not profit. It’s not what’s left after expenses. Annual turnover for Privacy Act purposes generally means all income from all sources in the previous financial year, including:
- Revenue from sales or services
- Income from investments or rental
- Grants, subsidies, or government payments received as income
- Revenue from related entities if you’re part of a corporate group
It does not include capital gains, proceeds from asset sales, or assets you hold. The turnover calculation follows the definition used in the Privacy Act and related legislation, and businesses with complex group structures, multiple entities, or related-party arrangements should get specific professional advice rather than relying on a general guide like this one.
Many business owners think “turnover” means profit, or take-home pay. It doesn’t. A café with $1.2M in annual revenue and $200K in profit still has $1.2M turnover for Privacy Act purposes – currently exempt if no other trigger applies. A café with $3.2M in revenue does not qualify for the exemption, even if it runs at a loss.
Who Is Already Regulated – Regardless of Turnover
The $3 million exemption has never applied to everyone. The Privacy Act has always regulated certain types of businesses regardless of their size, and one major new category was added on a confirmed date in 2026. If your business falls into any of these categories, you are regulated right now – even as a sole trader or micro-business.
Always regulated (since the small business exemption began) In force
- Health service providers – GPs, dentists, physiotherapists, pharmacists, naturopaths, chiropractors, psychologists, nurses, and any business that provides a health service and holds health information about patients or clients.
- Financial services businesses – any business holding an Australian Financial Services Licence (AFSL) or Australian Credit Licence (ACL), including financial planners, mortgage brokers, credit providers, and insurance businesses.
- Businesses that trade in personal information – if buying, selling, or trading personal information about individuals is part of your business model, the exemption doesn’t apply.
- Commonwealth government contractors – businesses with a contract to provide services to the Australian Government that requires handling personal information.
- Childcare centres and similar services collecting sensitive information about minors.
If your business has been operating in health or financial services, you likely already have privacy practices in place. The key thing to check now is whether your privacy policy is ready for the 10 December 2026 automated decision-making disclosure requirement – this is confirmed law, not a proposal, if you use tools like AI scheduling, credit scoring software, or automated marketing decisions.
Newly regulated from 1 July 2026 – AML/CTF Tranche 2 In force
The Anti-Money Laundering and Counter-Terrorism Financing Act expanded from 1 July 2026 to cover new industries. When a business becomes a “reporting entity” under that Act, it generally also comes under the Privacy Act for handling personal information collected as part of AML/CTF obligations. This is confirmed, commenced law – not a proposal.
From 1 July 2026, the following businesses are regulated under the Privacy Act for AML/CTF-related data, regardless of annual turnover:
- Real estate agents, buyer’s agents, and property developers
- Accountants and tax agents
- Lawyers, solicitors, and barristers
- Conveyancers
- Dealers in high-value goods (jewellery, cars, art, bullion, precious metals)
If you work in real estate, accounting, law, conveyancing, or high-value goods, the 1 July 2026 commencement date has already passed. If you haven’t updated your privacy practices, this is the most urgent item to fix – the AML/CTF reporting entity enrolment deadline was 29 July 2026. Check your exact obligations directly with AUSTRAC and confirm your Privacy Act position with the OAIC or a privacy lawyer.
Not sure which category you fall into? Our free compliance checker walks you through plain-English questions and shows you exactly where your business stands today – no legal knowledge needed.
Check My Business Free →Industry Lookup: Find Your Compliance Status
Use the table below to find your industry and see whether you’re already regulated, confirmed to be regulated from a fixed date, or only potentially affected by a future proposal. Type your industry name or use the filter buttons to narrow it down.
The Privacy Act Timeline: In Force, Confirmed, and Proposed
The Privacy Act reforms have rolled out in stages since 2024, and it’s easy to lose track of what’s actually law versus what’s still being discussed. Here’s the full picture, grouped by legal status rather than mixed together by date.
What Happens If You Don’t Comply?
These penalties apply to businesses already covered by the Privacy Act today – health providers, financial services businesses, AML/CTF Tranche 2 entities, and any business above the $3 million turnover threshold. They do not currently apply to businesses still within the small business exemption.
The maximum penalties are reserved for serious or repeated cases involving entities already covered by the Act. If you currently rely on the small business exemption and the exemption hasn’t been removed yet, these penalty provisions don’t apply to your business today. They become directly relevant the moment your business becomes covered – whether through an industry trigger like AML/CTF Tranche 2, exceeding the turnover threshold, or (eventually, once legislated) a general exemption removal.
Does Employee Information Count?
This is one of the most common questions Australian business owners ask, and the answer has an important limit that’s easy to miss.
The Privacy Act contains a separate exemption for employee records. Generally, where a current or former employee’s personal information is directly related to the employment relationship – and the handling is by the employing organisation – that handling is exempt from the APPs under what’s known as the employee records exemption.
However, this exemption has real limits worth understanding:
- It generally only applies to private sector employers and to information directly related to the employment relationship – not all information a business happens to hold about an employee.
- It does not cover job applicants who are not yet employees, or contractors who aren’t legally “employees.”
- It is a different exemption from the small business exemption – a business above the $3 million threshold that is otherwise covered by the Act still generally benefits from the separate employee records exemption for genuine employment-relationship data.
- State and territory work health and safety, anti-discrimination, and other employment laws can impose separate privacy-related obligations regardless of the Privacy Act position.
If your business handles sensitive employee data – health information, biometric access systems, performance management data shared with third parties – it’s worth getting specific advice rather than assuming the employee records exemption covers everything.
Five Things to Do This Week – Regardless of Your Status
Whether you’re already regulated, newly regulated from July 2026, or still within the $3 million exemption – there are practical steps every Australian small business owner can take now. They take a few hours, cost nothing, and reduce your risk regardless of how or when the broader reforms eventually land.
Not Sure Where Your Business Stands?
Answer a few plain-English questions and get a free status report. No account, no legal jargon, no obligation.
Start Free Compliance Check →What Happens After You Run the Compliance Checker
A free status check is a starting point, not a finish line. Here’s the practical sequence most businesses follow after finding out where they stand.
Frequently Asked Questions
The questions Australian small business owners ask most about the Privacy Act and the $3 million exemption.
For most businesses earning under $3 million annually, the exemption still applies today – but with important exceptions. If you operate in health services, financial services, or as a Commonwealth contractor, you’ve never been exempt. If you’re a real estate agent, accountant, lawyer, conveyancer, or high-value goods dealer, the exemption stopped applying to your AML/CTF-related data on 1 July 2026. For everyone else, the broader removal of the exemption is a government proposal with no legislated text and no confirmed date as of June 2026.
No – this is a common point of confusion, partly because December 2026 is genuinely an important date for two other, separate, confirmed reforms (the automated decision-making disclosure rule and the Children’s Online Privacy Code). The general removal of the $3 million exemption is not tied to that date. It remains a proposal the government has agreed to “in principle” but has not introduced as legislation, and no commencement date has been set as of June 2026. Don’t rely on December 2026 as a deadline for the exemption removal specifically – but do treat it as confirmed for the ADM disclosure rule if your business is already covered by the Act.
Annual turnover for Privacy Act purposes generally means all income from all sources – not profit, not take-home pay. It includes revenue from business activities, investment income, rent, and grants received as income. It does not include assets held, capital gains, or proceeds from selling assets. If you’re part of a corporate group, the turnover test generally considers the group as a whole. Businesses with complex structures should get specific advice rather than relying on this general explanation.
Being a sole trader doesn’t change your Privacy Act obligations – what matters is what information you collect and what industry you’re in. A sole-trader physiotherapist has always been regulated. A sole-trader accountant became regulated for AML/CTF-related data from 1 July 2026. A sole-trader plumber earning under $3M currently relies on the exemption, and whether that changes depends on a proposal that hasn’t been legislated yet. Business structure alone doesn’t determine your status.
Personal information is broadly defined as information or an opinion about an identified individual, or an individual who is reasonably identifiable. This includes customer names, email addresses, phone numbers, addresses, dates of birth, payment details, booking records, photos and videos, employee records (subject to the separate employee records exemption), and identifiers such as cookies or device IDs where they can reasonably be linked back to an identifiable person. Customer support chat logs that include identifying details are also generally personal information.
If you’re currently covered by the exemption and no new law has been passed, you’re not breaking the law today by doing nothing. But there are practical reasons not to wait: if and when the exemption removal is eventually legislated, a large number of businesses may need to act around the same time, which could make professional help harder to access. The OAIC has also been clear that it views the exemption as a gap in consumer protection, and separate reforms (AML/CTF Tranche 2, the ADM disclosure rule) are already narrowing the practical scope of who remains exempt. Preparing some basics now – knowing what data you hold, having a sensible privacy policy regardless of strict legal necessity – is lower-risk and lower-cost than scrambling later.
No. The employee records exemption is narrower than many business owners assume. It generally only covers private sector employers handling information directly related to the employment relationship of current or former employees – it doesn’t extend to job applicants, contractors, or information unrelated to employment. It’s also a separate exemption from the small business exemption, so even a business clearly covered by the Privacy Act can still rely on the employee records exemption for genuine employment data, subject to its limits. State employment, work health and safety, and anti-discrimination laws can impose separate obligations regardless.
Sources Referenced
- Privacy Act 1988 (Cth), Section 6C(1) – small business exemption
- Privacy and Other Legislation Amendment Act 2024 (Cth)
- Attorney-General’s Department, Privacy Act Review Report (2022) and Government Response (2023)
- Office of the Australian Information Commissioner – oaic.gov.au
- AUSTRAC – AML/CTF Tranche 2 reforms – austrac.gov.au
- Federal Court of Australia – Australian Clinical Labs civil penalty proceedings (2025)
Related Guides
These articles work together with this guide to give you the full picture on Privacy Act compliance for Australian small businesses.