Does the Australian Privacy Act's $3M Small Business Exemption Apply to You?

Australia exempts most small businesses from the Privacy Act if their turnover is under $3 million — but the exceptions are wide and growing. Find out whether the exemption applies to you, what the 1 July 2026 AML reforms change, and where the law is heading.

Last updated: 2026-06-22

Australia is the odd one out. In the UK, Canada, New Zealand, Ireland, and South Africa, privacy law applies to businesses of every size. In Australia, most small businesses are exempt from the Privacy Act 1988 — but the exemption is riddled with exceptions, and from 1 July 2026 a large new group of businesses loses it. This article helps you work out, specifically, whether the exemption applies to you.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Whether the exemption applies can turn on the specific facts of your business. Consult a qualified lawyer or privacy professional for advice on your situation. Information is current as of the date below.

How the Small Business Exemption Works

The Privacy Act regulates "APP entities." The definition of an organisation excludes a "small business operator" — broadly, a business with an annual turnover of $3 million or less for the previous financial year. If that is you, and none of the exceptions below apply, the 13 Australian Privacy Principles do not legally bind you.

A few things people get wrong about the threshold:

  • "Annual turnover" is broad. It means the total income you earned from all sources during the financial year — not just profit, and not limited to a single product line. It excludes things like assets held and the proceeds of selling capital assets, but otherwise it is your gross income.
  • It is assessed on the previous financial year. A new business is treated as a small business operator until its turnover for a financial year exceeds $3 million.
  • It is the whole legal entity, not a division. You can't ring-fence a small part of a larger business to claim the exemption.

For the avoidance of doubt: as of June 2026, the $3 million exemption is still in force, and no law has been passed to remove it. But that does not mean you are automatically exempt, because of the exceptions.

The Exceptions That Override the Exemption

This is where most small businesses discover they are covered after all. Even with turnover under $3 million, you are an APP entity — and must comply with the Privacy Act — if you:

You are covered if you...Example
Provide a health service and hold health informationPhysiotherapists, dentists, gyms, allied health, natural therapists
Trade in personal information (buy or sell it)Selling a marketing list; buying customer data
Are a credit reporting bodyCredit reference agencies
Are a contracted service provider for a Commonwealth contractA small supplier delivering services under a federal government contract
Are an AML/CTF reporting entityFrom 1 July 2026, many lawyers, accountants, real estate agents, conveyancers, and dealers in precious metals/stones (see below)
Operate a residential tenancy databaseTenancy blacklist operators
Are accredited under the Consumer Data RightCDR-accredited data recipients
Are related to a covered body corporate, or have opted inA small subsidiary of a larger covered group

The health-service exception alone catches a surprising number of small operators, because "health information" and "health service" are defined broadly. If you hold health information about your clients, assume you are covered regardless of turnover.

What Changes on 1 July 2026: AML "Tranche 2"

The biggest near-term change comes not from privacy law but from anti-money-laundering law. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extends AML/CTF obligations to a new group of "tranche 2" professions:

  • Lawyers and conveyancers
  • Accountants
  • Trust and company service providers
  • Real estate professionals
  • Dealers in precious metals and precious stones

The key dates:

  • 31 March 2026 — enrolment with AUSTRAC opened for tranche 2 entities.
  • 1 July 2026 — AML/CTF obligations commence. AUSTRAC's regulated population grows from roughly 19,000 businesses to around 100,000.

Here is the privacy connection: becoming an AML/CTF reporting entity removes the small business exemption for the personal information you handle for your AML/CTF obligations. So from 1 July 2026, a sole-practitioner conveyancer or a two-person accounting firm — well under $3 million in turnover — must comply with the Privacy Act when handling customer information for "know your customer" and customer due diligence.

Two important nuances:

  1. It is triggered by "designated services," not your industry label. You are only captured if you provide one or more of the specific designated services listed in the AML/CTF rules. Not every accountant or real estate professional automatically qualifies — it depends on what services you actually provide.
  2. The Privacy Act obligation is targeted, not total. It applies to the personal information you handle for your AML/CTF obligations (KYC and due diligence). Your privacy policy and APP compliance need to cover that handling — you are not necessarily pulled into full Privacy Act coverage for every other part of your business. Some commentary overstates this; the carve-in is specific.

If you are in one of these professions, check the AUSTRAC guidance on designated services to confirm whether you are caught, and treat 1 July 2026 as the date you need a Privacy Act–compliant approach to customer information.

Is the Exemption Going Away Entirely?

Possibly — but not yet, and not on any fixed timetable.

The 2023 Privacy Act Review recommended removing the small business exemption altogether. The Government's 2023 response agreed in principle, but only after consultation with small business and an impact analysis. The first tranche of reforms (the Privacy and Other Legislation Amendment Act 2024) did not remove it.

As of June 2026, a second tranche of reforms that could remove the exemption has not been introduced as a bill, and there is no commencement date. There is also genuine uncertainty about the final shape: the Productivity Commission's 2025 review recommended against some of the proposed expansions. In short: the exemption stands today, removal is signalled but not legislated, and the direction of travel is clearly toward less exemption over time.

How to Tell If You're Covered: A Quick Check

Work through these in order:

  1. Is your annual turnover over $3 million (previous financial year)? If yes — you are covered. Stop here.
  2. Do you provide a health service and hold health information? If yes — covered.
  3. Do you buy or sell personal information? If yes — covered.
  4. Will you be an AML/CTF reporting entity from 1 July 2026 (tranche 2 designated services)? If yes — covered for your AML/CTF data handling.
  5. Do any other exceptions apply (Commonwealth contractor, credit reporting, residential tenancy database, CDR accreditation, related body corporate, opted in)? If yes — covered.
  6. If none apply — you are currently exempt, but keep watching the reform timetable, and consider voluntary compliance (see below).

What to Do If You're Covered — or Soon Will Be

If any branch above caught you, the practical starting points are the same:

Even if you are exempt, many small businesses choose to comply voluntarily. Customers increasingly expect it, larger clients often require it in contracts, and it positions you for the reforms that are coming. If you serve customers overseas, you may also be caught by other laws — the UK GDPR and New Zealand's Privacy Act, for instance, have no small business exemption. See multi-jurisdiction privacy compliance.

References

Last reviewed: June 2026. The small business exemption is under active review and the AML/CTF reforms commence 1 July 2026. Verify your specific status against current OAIC and AUSTRAC guidance and consult qualified legal counsel before relying on (or assuming you are outside) the exemption.


Crossing Borders? One Process for Every Request

If you serve customers in the UK, EU, Canada, or New Zealand, you face access-request obligations with no small business exemption. Our DSAR Compliance Guide gives you one workflow that works across the Australian Privacy Act, GDPR, PIPEDA, and more — so a request from any jurisdiction follows the same reliable process.