small business privacy australia 2026

Privacy law is changing for small businesses

Most small businesses in Australia assume privacy law doesn’t apply to them, and for a long time that’s largely been true. Businesses with annual turnover under $3 million have generally been exempt from the Privacy Act 1988, which covers the vast majority of sole traders and small operators. That exemption isn’t disappearing overnight, but the landscape is shifting and there are some changes happening right now that are worth understanding.

What’s changing from 1 July 2026

From 1 July 2026, changes to anti-money laundering laws will bring more than 100,000 small businesses under Privacy Act obligations for the first time. The affected sectors are accounting, legal services, real estate, conveyancing and related professional services. If your business falls into one of those categories, the $3 million turnover exemption won’t protect you from these new requirements – and 1 July is close.

For businesses outside those sectors, the broader exemption remains in place for now. The government has confirmed further reforms are in progress and the exemption won’t last indefinitely.

The law aside, there’s a simpler test

Would the people whose information you hold be comfortable with what you’re doing with it?

Many organisations collect more personal information than they realise – contact forms, booking systems, email lists, client files, payment details. That information sits in various places: your email inbox, a spreadsheet, a CRM, a form plugin on your website. In most cases it was set up quickly and the privacy implications often get overlooked.

A few years ago I was working with an organisation that had contact forms on their website collecting personal information from members of the public. The data had been flowing through the system for years without anyone questioning it. When I looked at how it was actually being transmitted, the personal information was going out by email in plain text – no encryption, no secure portal. The system had just been built without privacy in mind and had been running unexamined ever since.

That’s a common pattern. The intent isn’t usually malicious – it’s just that systems get set up in a hurry and the question of what happens to the personal information in them doesn’t always come up.

A quick audit you can do yourself

  1. What personal information are you actually collecting?
    Go through your contact forms, booking systems, email lists and client files. You may be collecting more than you need, or keeping it longer than necessary.
  2. Where does it go and who can see it?
    Is it sitting in a shared inbox? A spreadsheet on someone’s desktop? A cloud platform you haven’t checked the settings on?
  3. Does your privacy policy reflect what you actually do?
    Most small business websites don’t even have a privacy policy but often if they do it’s been either copied from a template or haven’t been checked or updated in years. If you’re now using AI tools to handle client information, your policy probably needs to cover that.

This review doesn’t require a lawyer. It needs about an hour of honest attention to how your business actually handles people’s information.

If you’d like help reviewing how your digital systems and tools handle personal data, the Cyber Security & Safety service covers exactly this kind of practical review. For more on the broader privacy changes affecting Australian businesses, the Australian Privacy Principles on the OAIC website are a useful reference.