Do You Need a Privacy Policy? Privacy Act Rules for Small Business
Most Australian small businesses aren't legally required to have a privacy policy, because the Privacy Act 1988 exempts businesses with annual turnover of $3 million or less, but the exemption has enough holes that plenty of small operators are covered without realising it, and from 1 July 2026 the holes got bigger. Even if you're genuinely exempt, Google, Meta, your website builder and your customers will expect a policy anyway. Here's how to work out where you stand, what the policy has to say, and what to do if data leaks.
The $3 million small business exemption
The Privacy Act and its 13 Australian Privacy Principles (APPs) bind "APP entities". A small business operator, whether sole trader, company, partnership or trust, isn't one if its annual turnover is $3 million or less, unless an exception below applies. Turnover means all income for the year (sales, fees, commissions), not profit, excluding capital items like asset sales.
Exempt means no mandatory privacy policy, no notifiable data breach obligations and no OAIC jurisdiction over you. Privacy law isn't irrelevant, though: the Spam Act covers marketing messages regardless of size, and the statutory tort for serious invasions of privacy, in force since 10 June 2025, lets an individual sue anyone, exempt or not.
Exceptions: small businesses that are covered anyway
The exemption is a default, not a guarantee. Under $3 million, you're still covered by the Privacy Act if any of these describe you (as at September 2026):
| Exception | What it catches |
|---|---|
| Health service providers | Providing a service for physical, emotional, psychological or mental health and holding health information about clients |
| Trading in personal information | Disclosing personal information for a benefit, service or advantage, or paying to collect it, without consent or legal authority |
| AML/CTF reporting entities | Reporting entities (and their agents) under the AML/CTF Act, including the tranche 2 sectors from 1 July 2026 |
| Commonwealth contractors | Providing services under a Commonwealth contract |
| Related to a covered business | Related to a larger body corporate that's subject to the Act |
| Credit reporting and tenancy databases | Credit reporting bodies and operators of residential tenancy databases |
| Opted in | Voluntarily opted in under section 6EA |
Health service providers: broader than you think
"Health service" isn't limited to doctors and dentists: the OAIC's examples include allied health, complementary therapists, pharmacists, gyms and weight loss clinics, private schools and childcare centres. If you record clients' injuries, medications, allergies or mental health, you're very likely covered from your first client, and health information is "sensitive information" with stricter handling rules. Victoria and NSW add their own health records laws for private providers regardless of size.
Trading in personal information
You trade in personal information when you disclose it for a benefit, service or advantage, or pay to collect it, without the individual's consent. Selling a customer list, buying lead lists or swapping your client database for referrals all fit. Passing details to your courier or payment processor to fulfil an order generally isn't trading.
AML/CTF reporting entities: the 1 July 2026 change
Tranche 2 of the anti-money laundering reforms made real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones "reporting entities" from 1 July 2026. Reporting entities lose the small business exemption for personal information handled in connection with their AML/CTF obligations, bringing tens of thousands of small businesses under the Act for the first time. If you're in one of those sectors, treat the whole business as covered.
Where the reform is at (as at September 2026)
The 2023 Privacy Act Review recommended removing the exemption altogether and the government agreed in principle, subject to consultation. It hasn't happened. The first tranche of reforms, passed in December 2024, left the exemption alone while adding the statutory tort, a three-tier penalty structure and automated decision-making disclosure from December 2026.
The second tranche has now reached exposure draft stage. On 31 August 2026 the Attorney-General's Department released the draft Privacy Amendment (Personal Data Protection) Bill 2026 and a consultation paper, with submissions closing 18 September 2026. The draft carries 41 proposals, among them a "fair and reasonable" test for handling personal information, a broader definition that covers information "relating to" a person (including geolocation and AI-generated data), consent that must be voluntary, informed, current, specific and unambiguous, and a fixed 72-hour deadline for notifying the OAIC of an eligible breach. Critically for small business, the draft does not repeal the small business exemption; on the government's own response, removing it would come only after an impact analysis, consultation and a transition period.
So: intact but narrowing, and any policy you write now should assume you'll be covered within a few years.
Why you probably want a policy anyway
Even a fully exempt business usually needs a privacy policy, for reasons unrelated to the OAIC:
- Ad and analytics platforms require one. Google Analytics' terms require a privacy policy disclosing your use of cookies and identifiers, with extra disclosures for remarketing; Google can block remarketing campaigns and suspend accounts for repeated breaches, and Meta's business tools have similar terms. Running Google Ads or the Meta pixel? Write the policy first.
- Platforms check. Website builders, e-commerce platforms, payment gateways, booking systems and the app stores commonly require a privacy policy URL. When you're building a small business website, the privacy page belongs on the launch checklist next to your website terms and conditions.
- It's the cheapest privacy audit you'll do. Most small businesses writing their first policy discover they're holding data they don't need.
Want formal coverage? Section 6EA lets you opt in: the OAIC application is free, requires an existing privacy policy, and puts your business name and ABN on a public register, after which the APPs bind you.
What a privacy policy must cover
APP 1.4 sets the compulsory contents for covered businesses and is the sensible outline for everyone else. Keep it plain, current and linked from your website footer.
| Required item | What to write |
|---|---|
| Kinds of personal information you collect and hold | Names, contact and payment details, order history, appointment notes, health information, analytics data |
| How you collect and hold it | Website forms, phone, email, in person, cookies; where it's stored (CRM, accounting software, cloud drive) and how it's secured |
| Purposes of collection, use and disclosure | Delivering the service, invoicing, marketing (and how to opt out), legal obligations; who you share it with (couriers, payment processors, your accountant) |
| Access and correction | How someone asks to see or fix their information, and how long you take |
| Complaints | Who to contact, how you'll respond, and that they can escalate to the OAIC |
| Overseas disclosure | Whether data is likely to go overseas and to which countries if practicable (most cloud and analytics tools store data offshore) |
Two additions. From 10 December 2026, covered businesses must also disclose computer programs that make, or substantially contribute to, decisions significantly affecting people's rights or interests (AI screening of job applicants, say) and the personal information they use. And if you do direct marketing, say how to opt out; the email marketing guide covers the Spam Act side.
A privacy policy isn't a collection notice. APP 5 requires you to tell people, at or before collection, why you're collecting their information and what happens to it: a sentence or two beside the web form or on the intake paperwork, pointing to the full policy.
Data breach basics
If the Privacy Act covers you, the Notifiable Data Breaches (NDB) scheme applies. An eligible data breach has three elements: unauthorised access to, disclosure of, or loss of personal information; a likelihood of serious harm to someone; and no remedial action that prevents it.
- Contain it. Revoke access, reset passwords, recall the email, take the system offline.
- Assess it. Decide whether serious harm is likely, weighing how sensitive the information is and who has it; the OAIC treats 30 days as the maximum and expects faster.
- Notify if required. For an eligible breach, notify the OAIC and the affected individuals as soon as practicable, describing the breach, the information involved and what people should do.
- Review. Fix the cause and update your plan.
Exempt businesses aren't bound by the scheme, but follow the same steps; the tranche 2 exposure draft would replace "as soon as practicable" with a fixed 72-hour deadline for notifying the OAIC (the 30-day assessment window survives unchanged), so build for speed. Cyber cover often funds the response; see business insurance explained.
Penalties if you're covered
The 2024 amendments replaced a single penalty with three tiers. With the Commonwealth penalty unit at $364 from 1 July 2026, the maximums are (as at September 2026):
| Tier | Conduct | Company maximum | Individual maximum |
|---|---|---|---|
| High (serious interference) | Serious or repeated interferences with privacy | Greater of $50 million, 3x the benefit, or 30% of adjusted turnover | $2.5 million |
| Mid (interference) | Interferences that aren't serious | 10,000 penalty units ($3.64 million) | 2,000 penalty units ($728,000) |
| Low (specific breaches) | No compliant privacy policy, no marketing opt-out, incomplete breach statements and similar | 1,000 penalty units ($364,000) | 200 penalty units ($72,800) |
The low tier can also be enforced by infringement notice without going to court: 60 penalty units ($21,840) for a company, 12 ($4,368) for an individual. A missing or incomplete privacy policy is exactly what it was designed for. Penalties scale to the business and the harm, but a fine plus a public OAIC determination is a bad week.
Privacy checklist for small business
- Work out whether you're covered: turnover over $3 million, health service, trading in data, AML/CTF sector, Commonwealth contracts, related to a covered company.
- List every place personal information lives (web forms, CRM, accounting software, email, paper files, staff phones), then delete what you don't need and stop collecting it.
- Write a policy covering the six APP 1.4 items, link it in your website footer, date it, and add a short collection notice to every form and intake document.
- Check your Google Analytics, Google Ads and Meta setups and disclose cookies and remarketing.
- Lock down the basics: multi-factor authentication, unique passwords, encrypted devices, access limited to staff who need it.
- Write a one-page breach response plan, and diarise a review for December 2026 (automated decision-making) and again when the tranche 2 bill passes.
Key takeaways
- Turnover of $3 million or less means you're exempt from the Privacy Act unless an exception applies; health services, trading in personal information, AML/CTF reporting entities and Commonwealth contracts catch many small businesses.
- As at September 2026 the exemption stands and the tranche 2 exposure draft of 31 August 2026 doesn't repeal it, but since 1 July 2026 real estate, legal, conveyancing, accounting and precious metals businesses have lost it for AML/CTF-related information.
- You almost certainly need a policy anyway: Google, Meta, website and payment platforms require one and customers expect it.
- A compliant policy covers the six APP 1.4 items, plus automated decision-making from 10 December 2026; a collection notice at the point of collection is a separate requirement.
- If covered, assess suspected breaches within 30 days at most and notify when serious harm is likely; a missing privacy policy sits in the low penalty tier ($364,000 maximum for a company).
Where to get help
- OAIC (oaic.gov.au): small business guidance, privacy policy checklist, opt-in register, Notifiable Data Breaches form and the Guide to Health Privacy.
- Attorney-General's Department (ag.gov.au): the Privacy Act Review and tranche 2 consultation documents.
- Your state health or privacy regulator if you provide health services in Victoria, NSW or the ACT.
- business.gov.au: privacy and data protection basics.
- A privacy lawyer to review your policy if you handle health, financial or children's information, and your accountant to confirm your turnover against the $3 million line.
Frequently asked questions
Do I need a privacy policy for my small business website in Australia?
Legally, only if the Privacy Act covers you: your annual turnover is over $3 million, or you fall into an exception such as providing a health service, trading in personal information, or having AML/CTF obligations. In practice almost every small business website needs one anyway, because Google Analytics, Google Ads, Meta and most website builders and payment platforms require a privacy policy in their terms, and customers expect to see one before handing over their details.
Does the $3 million small business exemption still exist in 2026?
Yes. As at September 2026 the exemption is still law, and the government's second tranche of reforms — the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, released on 31 August 2026 with submissions closing 18 September 2026 — does not repeal it. It has narrowed, though: since 1 July 2026, real estate agents, lawyers, conveyancers, accountants and dealers in precious metals and stones lose the exemption for personal information they handle in connection with their anti-money laundering obligations.
What must an Australian privacy policy include?
Under Australian Privacy Principle 1.4 it must state the kinds of personal information you collect and hold, how you collect and hold it, why you collect, use and disclose it, how someone can access and correct their information, how they can complain and how you'll deal with the complaint, and whether you're likely to send information overseas and to which countries. From December 2026 it also has to disclose any automated decision-making that significantly affects people.
What do I do if my small business has a data breach?
Contain it first, then assess whether it's likely to cause serious harm to anyone; the OAIC treats 30 days as the maximum for that assessment. If the Privacy Act covers you and the breach is likely to result in serious harm that you can't remediate, you must notify the OAIC and the affected people as soon as practicable. Exempt businesses aren't bound by the scheme, but telling affected customers promptly is still the right call.
Can a small business choose to be covered by the Privacy Act?
Yes. Section 6EA lets an exempt small business opt in through a free application to the OAIC, which then lists your business name and ABN on a public opt-in register. You need a privacy policy in place to apply, you're bound by the Australian Privacy Principles from that point, and you can opt out later by notifying the OAIC in writing.
General information only. This guide doesn't take your personal or business circumstances into account and isn't financial, legal or tax advice. Rates and thresholds change — check the official sources linked in this guide and get qualified advice where your circumstances require it.