A board member asked me a version of this question last month. “Are we actually covered by the Privacy Act, or are we one of the small ones that’s exempt?”
I gave her an honest answer, which was also an unsatisfying one. Right now, almost certainly not. But that answer comes with an expiry date I can’t give her, because the Government has already said, formally, that it wants to change it.
That’s the real story with Australia’s privacy laws for small business right now. Not a settled rule. A rule that’s mid-change, with the timing still unclear.
At the moment, many Australian small businesses enjoy a significant exemption from the federal Privacy Act 1988. Generally, if your business has annual turnover of $3 million or less, the Privacy Act does not apply to you. There are important exceptions to that rule, which I’ll come back to shortly.
But for the local builder, consultant, community organisation, tourism operator, retailer or other small business collecting fairly ordinary customer information through their website and business systems, the $3 million threshold has historically meant that many of the requirements imposed on larger organisations simply don’t apply.
That may not remain the case forever.
My assessment is that it’s more likely than not that the current small-business exemption will eventually be removed, substantially narrowed or replaced with a more proportionate set of obligations for smaller organisations.
That doesn’t mean small businesses need to panic. It does mean this is worth watching, and it raises a useful question.
If your business isn’t currently required to take privacy particularly seriously, should you really wait until legislation forces you to?
Does the Privacy Act currently apply to your small business?
Australia’s main federal privacy legislation is the Privacy Act 1988. Among other things, it governs how organisations covered by the Act collect, use, disclose, store and protect personal information.
The Office of the Australian Information Commissioner, or OAIC, explains the current position quite clearly: most small businesses are not covered by the Privacy Act, but some are. For Privacy Act purposes, a small business is generally one with annual turnover of $3 million or less. You can read the OAIC’s current guidance for small businesses.
That exemption is significant. An organisation covered by the Act will generally need to comply with the 13 Australian Privacy Principles, commonly called the APPs. Those principles deal with matters including collecting personal information, telling people what’s being collected, using and disclosing it, keeping it accurate, securing it, giving people access to information held about them, correcting it, direct marketing, and overseas disclosure. You can read the Australian Privacy Principles on the OAIC website.
But the $3 million threshold isn’t an absolute “small businesses don’t have privacy obligations” rule. There are already exceptions. Certain smaller organisations are covered because of what they do rather than how much money they make. Health service providers are one example. Businesses that trade in personal information can also fall within the Act, along with certain other prescribed activities and circumstances.
So if you’re under $3 million turnover, don’t automatically assume the Privacy Act cannot apply to you.
That’s the law today. The more interesting question is what happens tomorrow.
Why are people talking about removing the $3 million exemption?
The Commonwealth Attorney-General’s Department completed a major review of the Privacy Act in 2023. It wasn’t a minor review. The resulting Privacy Act Review Report examined whether a law originally introduced in 1988 remained suitable for an economy in which enormous amounts of personal information now move through websites, apps, CRMs, advertising platforms, cloud systems, AI tools and third-party software.
One of its conclusions was particularly important. The review said existing exemptions from the Privacy Act required “recalibration” to deal with contemporary privacy risks and community expectations. That included the small-business exemption. You can read the Australian Government’s full Privacy Act Review Report here.
This isn’t difficult to understand when you look at how businesses operate today. Turnover isn’t necessarily a good measure of privacy risk. Imagine two businesses. One has $5 million in annual turnover but collects very little personal information. The other is a technology startup turning over $800,000 but has information about hundreds of thousands of Australians sitting in a database. Under a simple revenue threshold, the first business may be covered by the Privacy Act while the second may not be.
The OAIC raised essentially this problem during the review process, describing an ICT provider involved in a data breach that was below the $3 million threshold and therefore outside parts of the regulator’s reach.
Technology has changed the equation. A very small organisation can now collect and process an enormous amount of information. And AI accelerates that further.
AI makes the $3 million threshold increasingly awkward
Artificial intelligence isn’t the sole reason privacy reform is happening, but it makes the policy problem much more obvious.
Ten or twenty years ago, collecting, analysing and combining enormous datasets generally required substantial technical infrastructure. Today, a very small business can connect a website form to a CRM, feed customer interactions through automation platforms, enrich records using external sources, analyse conversations with AI and retain enormous quantities of information in cloud platforms.
You don’t need a building full of servers. You need a credit card and a few software subscriptions.
That creates extraordinary opportunities for small organisations. It also creates privacy risks that aren’t necessarily related to the size of the organisation. The Government’s Privacy Act Review specifically recognised that digital technologies mean privacy risks can arise from a much broader range of information and activities than when Australia’s privacy framework was originally designed. That makes a rule based primarily on annual turnover harder to defend indefinitely.
So has the Government actually decided to remove the exemption?
Not through legislation. But it’s gone further than “this is being discussed.”
In its formal response to the Privacy Act Review, released on 28 September 2023, the Government agreed in principle to removing the small-business exemption, one of 68 proposals it agreed to in principle out of 116 in total. Not “agreed to consider it.” Agreed in principle, subject to consulting on how it’s actually implemented, what modified obligations would be appropriate for smaller organisations, and what support they’d need to get there. You can read the Government’s full response here.
That’s a meaningfully stronger signal than a review recommending something. It’s a position the Government has already taken, with the mechanism and timing still to be worked out.
The first tranche of reforms followed in late 2024, when Parliament passed the Privacy and Other Legislation Amendment Act 2024, implementing 23 of the review’s recommendations. It didn’t touch the small-business exemption. That wasn’t a rejection. It’s been pushed into the next, harder round of reform, alongside the other proposals the Government agreed to in principle rather than outright.
The Council of Small Business Organisations Australia, or COSBOA, was pleased the exemption survived that first round. Its argument is straightforward: extending the full Privacy Act to every small business could impose real compliance costs on operators without a legal, cybersecurity or compliance team behind them.
That’s a legitimate concern. A regional business employing five people doesn’t have a privacy department. The owner might simultaneously be the managing director, salesperson, HR manager, IT support person, accounts department and the person taking the bins out on Thursday night. The same is true for a lot of charities and community organisations, and imposing the same compliance infrastructure on a volunteer-led group as on a bank doesn’t necessarily produce a better outcome.
More recently, COSBOA has signalled it’s open to an alternative compliance pathway if the exemption does go, rather than insisting on all-or-nothing. That matters. It suggests the eventual outcome doesn’t have to be binary between “completely exempt” and “identical to a bank’s compliance regime.” There’s a lot of territory in between: simpler obligations, transition periods, requirements that scale with actual risk rather than turnover.
How likely is the exemption to actually disappear?
There’s no official Government probability forecast, so what follows is my assessment based on the policy direction, not a statement of fact.
My current estimate is roughly a 70 to 80% probability that the $3 million small-business exemption is eventually materially narrowed, removed or replaced during the next significant phases of Australian privacy reform. I’m deliberately not saying there’s an 80% probability that Parliament simply deletes the $3 million threshold. That’s only one possible outcome. What matters is whether Australia’s current broad exemption survives substantially unchanged, and I think that’s increasingly unlikely over the longer term, particularly given the Government has already agreed in principle to removing it.
Before the end of 2027, I’d put the chance of ordinary Australian small businesses actually becoming subject to materially broader Privacy Act obligations at somewhere around 30 to 40%. That’s far from impossible, but substantial reforms take time. There has to be further policy development, stakeholder consultation, legislative drafting, parliamentary consideration, implementation guidance and potentially a transition period.
Extend the horizon to 2028 through 2030, and I think the probability climbs substantially, to somewhere around 60 to 75%. It could take different forms: abolition of the exemption, a reduced or altered turnover threshold, broader categories of businesses being brought within the Act, risk-based obligations, simplified APP requirements for small businesses, or separate baseline obligations applying regardless of turnover. My confidence is much greater in the direction of travel than in the precise mechanism.
Australia’s already done this once in an adjacent space. When the anti-money laundering regime expanded to cover more real estate agents, lawyers, accountants and property developers from 1 July 2026, roughly 80,000 additional businesses had to enrol with AUSTRAC, plenty of them well under the Privacy Act’s $3 million threshold. Size didn’t exempt them from that regime. It’s the same underlying argument privacy reform is having: risk, not revenue, is what should determine who’s covered.
I’d be genuinely surprised if Australia reached the early 2030s with the existing small-business exemption completely untouched. Technology, AI, cybersecurity threats and the sheer quantity of personal information businesses collect make the current distinction increasingly difficult to sustain. That doesn’t mean regulation will be unreasonable. It means “we’re small, therefore privacy law isn’t really our problem” is becoming a poor long-term strategy.
Why hasn’t Government just changed it already?
Because there’s a real trade-off. The public has a legitimate expectation that organisations handling personal information do it responsibly. Government also has to weigh whether a new requirement will meaningfully improve privacy outcomes against whether the compliance cost is proportionate to the problem it’s solving.
A large corporation can employ a chief information security officer, in-house lawyers and dedicated compliance staff. A six-person not-for-profit can’t. Neither can the local plumber, the tourism operator, or the neighbourhood house running partly on volunteers.
Any workable reform has to account for that. It’s why I don’t expect a sudden, wholesale removal of the exemption.
It isn’t a strong argument for doing nothing indefinitely either.
Consumers are changing too
Legislation isn’t the only reason to think about this. Customer expectations are shifting too.
In the OAIC’s 2023 Australian Community Attitudes to Privacy Survey, 77% of Australians said small businesses should be required to protect personal information the same way government agencies and large businesses do. Most people don’t distinguish between a $2.9 million regional business and a $50 million one when they’re handing over their name, phone number and enquiry. They just expect it to be handled properly.
Australians have also lived through major data breaches involving some of the country’s largest and most recognisable organisations, and cybersecurity is now a regular feature of mainstream news. People increasingly understand that the information they hand over can sit in a database for years, and they’re more alert to identity theft, tracking and the digital trail ordinary interactions leave behind.
The commercial question therefore isn’t only “am I legally required to do this?” Increasingly it’s “what does a responsible organisation do with information entrusted to it?”
Privacy is becoming part of trust. For an impact-driven organisation particularly, trust is an asset.
Privacy and cybersecurity aren’t quite the same thing
They’re closely related, but it’s useful not to confuse them.
Cybersecurity asks how you stop someone who shouldn’t have this information from accessing it. Privacy goes further. It asks why you’re collecting the information at all, what you’re doing with it, who you’re giving it to, how long you’re keeping it, whether the person understands what’s happening, and whether you should still have it three years from now.
A business can have excellent cybersecurity and poor privacy practices. You might have a beautifully secured database containing 15 years of personal information you have absolutely no reason to retain. Nobody has hacked you. You still have a privacy problem.
This concept of data minimisation is likely to become increasingly important. Often the safest piece of personal information your business can hold is the information you no longer hold, because you didn’t need it anymore.
What should a small business do today?
I don’t think small businesses need to respond to potential reform by building giant compliance systems. But there are a handful of questions every organisation should already be able to answer: what personal information you’re collecting, why, and where it’s actually stored, the website contact form, the CRM, old form submissions nobody’s looked at in years, whatever third-party system it eventually lands in.
Who inside your organisation can access it. How long you keep it. How you’d delete it. What happens if one of those systems is breached.
And the one that matters most: have you clearly told people what you’re doing with their information?
None of that is exotic. It’s good business practice, reform or not.
Does my small business need a Privacy Policy now?
Potentially. Remember the $3 million rule has exceptions, so some small businesses are already covered by the Privacy Act. The OAIC maintains specific guidance on when the Privacy Act applies to small businesses.
But whether the Act technically applies to you isn’t really the most useful question to start with. I’ve written more on that specifically, including what a Privacy Policy actually needs to cover and what it costs to get right, in “Do I Really Need a Privacy Policy on My Website?”
The short version: even where you’re not legally required to comply, having a clear one is increasingly sensible. It tells people what you collect, why, how you use it, who you might disclose it to, and how to contact you about it. It forces you to actually think about your own practices. And it demonstrates that privacy isn’t something you’ve simply ignored because your turnover happens to sit below a legislative threshold.
My advice: don’t wait for the threshold to disappear
I’m not suggesting every small business should pretend it’s legally subject to requirements that don’t apply to it. What I am suggesting is that Australia’s privacy landscape is moving.
The Government has completed a comprehensive Privacy Act Review and formally agreed in principle to removing the small-business exemption. The country’s privacy regulator has raised concerns about privacy risks sitting outside the existing regulatory framework. Small-business representatives are actively engaging with Government about what compliance could look like if the exemption changes. And meanwhile, the technological capacity of even the smallest businesses to collect and process personal information continues to accelerate.
It’s the same logic as fencing a dam before the shire asks about it, not after someone’s had a close call. The requirement might be coming. The sensible time to sort it is before it’s compulsory, not during the scramble after.
So I wouldn’t build a long-term privacy strategy around the sentence “we’re under $3 million, so we don’t need to worry about it.” I’d approach it like this instead: let’s get the basics right now, because it protects our customers, protects our organisation, and puts us in a far better position if the law changes later.
That’s both a compliance strategy and a good-business strategy.
Need a Privacy Policy for your small business?
At Regional Business Toolkit, we manage this for clients through Termageddon, at $180 a year. It covers your Privacy Policy, Website Terms and Cookie Policy together, and updates them automatically when the law or your website changes, rather than relying on someone remembering to check. Given where privacy reform is heading, that automatic-update part matters more than it might have five years ago.
The aim isn’t to bury a small organisation under layers of legalistic paperwork. It’s to make sure the privacy information on your website actually reflects how your organisation handles data today, and keeps up as both your website and the law change.
If you’ve launched a website without a Privacy Policy, inherited an old one that no longer reflects your systems, or simply aren’t sure whether what you currently have is adequate, get in touch and I’ll take a look.
Flick me an email and I’ll take a look →
This article provides general information about Australian privacy developments and is not legal advice. Whether the Privacy Act applies to a particular organisation depends on its individual circumstances and activities. If you need advice about your specific legal obligations, speak to an appropriately qualified legal professional.
Sources and further reading:
OAIC — Small business and the Privacy Act;
OAIC — Australian Privacy Principles;
OAIC — Australian Community Attitudes to Privacy Survey 2023;
Attorney-General’s Department — Privacy Act Review Report;
Attorney-General’s Department — Government response to the Privacy Act Review Report;
COSBOA — Small business secures reprieve on privacy law obligations.
