Australian Privacy Act: A Plain-English Guide for Small Businesses
A practical guide to Australia's Privacy Act 1988 for small businesses. Who's covered, the $3M small business exemption and its exceptions, the 13 Australian Privacy Principles, access requests, breach notification, penalties, and the 2024-2026 reforms.
Last updated: 2026-06-23
Australia is the odd one out among English-speaking countries: its Privacy Act 1988 still exempts most small businesses. But that exemption is riddled with exceptions, the penalties have grown sharply, and a wave of reforms running through 2025 and 2026 is pulling more businesses into scope. This guide explains who is covered, what the law requires, and where it is heading.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified lawyer or privacy professional for guidance specific to your business. The information here is based on the Privacy Act 1988 (Cth) and OAIC guidance, as of the date below.
The Privacy Act is regulated by the Office of the Australian Information Commissioner (OAIC) and built around the 13 Australian Privacy Principles (APPs) — the rules for how organisations collect, use, store, disclose, and give people access to their personal information.
Does This Law Apply to Your Business?
The Act applies to APP entities — Australian Government agencies, and organisations (individuals, body corporates, partnerships, trusts, and unincorporated associations). Critically, the definition of "organisation" excludes a small business operator — a business with an annual turnover of $3 million or less in the previous financial year.
This is the small business exemption, and it is the single most important thing for an Australian SMB to understand. But it is far from absolute. Even under $3 million, you are covered if you:
- Provide a health service and hold health information (physiotherapists, dentists, gyms, allied health);
- Trade in personal information (buy or sell it);
- Are a credit reporting body;
- Are a contracted service provider for a Commonwealth contract;
- Are an AML/CTF reporting entity — which from 1 July 2026 captures many lawyers, conveyancers, accountants, real estate professionals, and dealers in precious metals and stones (the AML "tranche 2" reforms);
- Operate a residential tenancy database, are Consumer Data Right accredited, are related to a covered body corporate, or have opted in.
Because the exemption decides whether the rest of this guide binds you, work through it in detail first: Does the $3M small business exemption apply to you?
What Rights Do Individuals Have?
The APPs give individuals several rights over their personal information. The two that generate the most day-to-day work are access and correction.
Access (APP 12). Individuals can request the personal information you hold about them — Australia's version of a data subject access request. Organisations must respond within a "reasonable period" (the OAIC says no more than 30 calendar days). See Australian privacy access requests (APP 12).
Correction (APP 13). Individuals can ask you to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
Direct marketing opt-out (APP 7). Individuals can ask not to receive direct marketing, and you must provide a simple way to opt out.
Anonymity and pseudonymity (APP 2). Where practical, individuals must have the option of dealing with you without identifying themselves.
| Right | Principle | Key detail |
|---|---|---|
| Access | APP 12 | Copy of the personal information you hold; respond within ~30 days |
| Correction | APP 13 | Correct inaccurate, outdated, or misleading information |
| Direct marketing opt-out | APP 7 | Provide a simple way to opt out; honour it |
| Anonymity/pseudonymity | APP 2 | Option to deal with you without identifying themselves, where practical |
| Serious invasion of privacy | Statutory tort | Sue for serious invasions of privacy (in force since 10 June 2025) |
Note that information about current and former employees may fall under the separate employee records exemption, which is narrower than most employers assume.
What Your Business Must Do
If you are a covered APP entity, the practical obligations are:
Maintain a privacy policy and handle information openly (APP 1). A clear, current privacy policy explaining what you collect, why, and who you share it with.
Give collection notices (APP 5). Tell people, at or before collection, what you are collecting and why.
Collect only what you need (APP 3). Stricter rules apply to sensitive information (health, biometric, racial or ethnic origin, religious beliefs, sexual orientation). See personal data vs sensitive data.
Use information only for its purpose (APP 6) and take care with cross-border disclosure (APP 8).
Keep information secure (APP 11). Protect personal information from misuse, loss, and unauthorised access — and destroy or de-identify it when no longer needed.
Respond to access and correction requests (APP 12, APP 13) within about 30 days.
Have a breach-response plan. Under the Notifiable Data Breaches (NDB) scheme, if you have an eligible data breach — unauthorised access, disclosure, or loss that is likely to result in serious harm — you must assess within 30 days and notify the OAIC and affected individuals as soon as practicable. See Australia's Notifiable Data Breaches scheme.
A current data inventory — knowing what personal information you hold and where — is what makes access requests and breach assessments manageable.
Penalties
Penalties rose dramatically in late 2022 and were expanded again by the 2024 reforms:
- Serious interference with privacy: for a body corporate, the greater of AUD $50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach period.
- Mid-tier civil penalty: up to 10,000 penalty units for a body corporate (around $3.3 million) for interferences that don't meet the "serious" threshold.
- Low-tier civil penalty: up to 200 penalty units (around $66,000) for specified administrative breaches, enforced through infringement notices.
The OAIC can now issue infringement and compliance notices directly, making lower-level enforcement faster.
Recent and Upcoming Reforms
The Privacy and Other Legislation Amendment Act 2024 (assented 10 December 2024) delivered the first tranche of reforms from the 2023 Privacy Act Review:
- Statutory tort for serious invasions of privacy — in force 10 June 2025. Individuals can now sue for serious invasions of privacy, actionable without proof of damage.
- Doxxing offences under the Criminal Code — in force since December 2024.
- Stronger OAIC enforcement powers and the new civil penalty tiers above.
- Automated decision-making transparency — commences 10 December 2026. If you use computer programs to make decisions that significantly affect people, your privacy policy must disclose it.
- Children's Online Privacy Code — the OAIC must register a binding code by 10 December 2026; still in development.
A second tranche — which could remove the small business exemption and the employee records exemption, and add a "fair and reasonable" test and broader individual rights — has been agreed in principle but, as of June 2026, no bill has been introduced and no commencement date has been set. We track this on the data governance news page.
References
- Privacy Act 1988 (Cth): Federal Register of Legislation
- The Australian Privacy Principles: OAIC
- Small business and the Privacy Act: OAIC
- Notifiable Data Breaches scheme: OAIC
- Statutory tort for serious invasions of privacy: OAIC
Last reviewed: June 2026. Australia's privacy laws are in an active reform period. Verify all statutory references against the current text of the Act and consult qualified legal counsel before making compliance decisions for your business.
Related Articles
- California Privacy Law (CCPA/CPRA): What Small Businesses Need to Know
- PIPEDA: A Plain-English Guide to Canadian Privacy Law for Small Businesses
- GDPR for Small Businesses: A Plain-English Guide to EU Data Privacy
- US State Privacy Laws & Global Data Protection: A Complete Jurisdiction Guide
- GDPR in Ireland: A Plain-English Guide for Small Businesses