Home Insights Compliance
Compliance

Australia's Privacy Act reforms: what SMBs need to do

Adam Dodds
Adam Dodds
3 August 2026 · 7 min read
Australia's Privacy Act reforms: what SMBs need to do

Australia’s privacy laws are being rewritten in stages, and the changes have quietly started to reach businesses that were never covered before. If you run a small or medium business, you do not need to become a privacy lawyer. You do need to know which parts apply to you, and what to have in place. Here is the plain-English version.

What has actually changed so far

The first round of reforms passed at the end of 2024 in the Privacy and Other Legislation Amendment Act 2024. It was not the full overhaul that was promised, but several pieces are now live:

  • People can sue over a serious invasion of privacy. Since 10 June 2025 there has been a statutory tort for serious invasions of privacy. In practice that means an individual can take legal action directly, whether the invasion was intruding on their seclusion or misusing their information. Importantly, this one is not limited to businesses covered by the Privacy Act.
  • Doxxing is now a criminal offence. Maliciously publishing someone’s personal details online carries criminal penalties.
  • The regulator has sharper teeth. The Office of the Australian Information Commissioner (OAIC) gained new mid-tier and lower-tier civil penalties, plus the ability to issue infringement notices. Previously the main penalty was reserved for serious or repeated breaches, with fines running as high as $50 million. Now smaller and more administrative failures, like not having a compliant privacy policy, can be actioned without building a blockbuster case first.
  • Automated decisions have to be disclosed. From 10 December 2026, if you use a computer program to make (or substantially help make) decisions that could significantly affect someone’s rights or interests, your privacy policy has to say so and explain what personal information is used. This is deliberately broad. It captures artificial intelligence tools, but also rule-based systems and automated assessment tools that have been around for years.
  • A Children’s Online Privacy Code is coming. The OAIC must register the code by 10 December 2026. If your business runs a service that children are likely to use, that one is worth watching.

The small business exemption: still there, but shrinking

For years, most Australian businesses turning over $3 million or less have sat outside the Privacy Act entirely. That exemption still exists. The government has agreed in principle to remove it, but that sits in the second tranche of reforms, which had not been introduced to Parliament as of mid-2026. There is no confirmed start date, so nobody should be panicking about a deadline that has not been set.

What has changed is that the exemption now has a very large hole in it.

If you are an accountant, lawyer, conveyancer or real estate agent, read this bit

From 1 July 2026, the anti-money laundering reforms (known as tranche 2) brought a long list of professional services into the regime: lawyers, conveyancers, accountants, trust and company service providers, real estate professionals, and dealers in precious metals and stones. Those businesses need to be enrolled with AUSTRAC.

Here is the part that catches people out. Becoming a reporting entity under the anti-money laundering rules also pulls you into the Privacy Act for that work, no matter how small you are. When you collect, use or disclose personal information for anti-money laundering purposes, you must handle it in line with the Australian Privacy Principles. The OAIC estimates this brings well over 100,000 small businesses into the privacy regime for the first time.

The OAIC published guidance for reporting entities in February 2026, and its tone is worth noting: meeting your anti-money laundering obligations does not give you licence to collect or keep more personal information than you actually need. Verifying a client’s identity is a reason to collect certain documents. It is not a reason to keep scanned passports in a shared folder forever.

Why this matters even if you are still exempt

Plenty of businesses will read the above and conclude the reforms are somebody else’s problem. Three reasons to think again:

  1. The new right to sue does not care about your turnover. A serious invasion of privacy claim can be brought against a business of any size.
  2. Your clients and insurers are asking anyway. Larger customers now push privacy and security obligations down through contracts, and cyber insurers ask pointed questions at renewal. “We are under the threshold” is not an answer either group accepts.
  3. The exemption is on borrowed time. It has been recommended for removal repeatedly. Getting your house in order while it is optional is far cheaper than doing it against a legislated deadline.

What to do now: a practical checklist

None of this requires a big project. Most of it is good practice you would want regardless.

  • Find out what you actually hold. Write down what personal information you collect, where it lives (email, file shares, your practice management system, that spreadsheet on someone’s desktop), who can reach it, and who you share it with. Almost every business is surprised by this exercise.
  • Stop collecting what you do not need, and delete what you no longer need. Data you do not hold cannot be breached, subpoenaed or leaked. Set a retention rule and actually apply it.
  • Refresh your privacy policy. It needs to be current, clear and easy to find. If you use any automated or artificial intelligence tool to make decisions about people, plan the wording for that now so it is ready before 10 December 2026.
  • Secure it properly. The Privacy Act requires reasonable steps to protect personal information, and in 2026 “reasonable” means multi-factor authentication, restricted access on a need-to-know basis, managed and encrypted devices, and current patching. Aligning to the Essential Eight, the eight strategies the Australian Signals Directorate recommends every business start with, gives you a recognised way to demonstrate you have done this rather than just asserting it. If you want the difference between a framework and a certificate explained, we cover it in SMB1001 vs Essential Eight.
  • Know what you would do on a bad day. If you are covered by the Act and have a data breach likely to cause serious harm, you have 30 days to assess it and then must notify the OAIC and the affected individuals. Thirty days sounds generous until you are in the middle of one. Our guide to building a data breach response plan walks through what to prepare in advance.
  • Look at your suppliers. You remain responsible for personal information you hand to a third party. Know who your providers are, what they hold, and where it is stored.
  • Give it an owner and tell your team. Someone in the business needs to be accountable for privacy, and your staff need to know the basics: do not email client documents to personal addresses, do not keep local copies, report anything odd immediately.

Where the technology fits

Most of the practical work here is technical: controlling who can open what, applying retention and deletion rules, and being able to answer “what happened” quickly if something goes wrong. If your business runs on Microsoft 365, a good deal of that capability is already in the licences you pay for and simply switched off.

This is the sort of work we do under IT compliance and IT security: mapping where the data sits, closing the obvious gaps, and producing evidence you can show a client, an auditor or an insurer. For businesses that want a certificate at the end of it, SMB1001 is an Australian standard with five tiers from Bronze through to Diamond, so you can start at a level that matches your size and step up over time.

The bottom line

The Privacy Act reforms are not one big deadline. They are a series of changes, some already in force, some landing in December 2026, and more still being drafted. For most small businesses the sensible response is not to wait for the second tranche. Know what personal information you hold, hold less of it, protect what remains, and have a plan for the day something goes wrong. If you are one of the professional services firms swept in by the anti-money laundering changes on 1 July 2026, that work is no longer optional.

If you would like a hand working out which of this applies to your business, we are happy to walk through it in plain English. Take a look at our compliance services or get in touch for a chat.

Adam Dodds
Adam Dodds

Adam leads the Itopia team in Brisbane, helping professional-services firms get secure, productive and confident with their technology, in plain English.

Keep reading

Related insights

Compliance
8 min read

Claude vs Copilot: which AI is safe for client data?

Read more →
Compliance
4 min read

Getting SMB1001 certified in 2026: a step-by-step guide

Read more →
Compliance
4 min read

SMB1001 vs Essential Eight: which does your business need?

Read more →

Want IT advice tailored to your business?

Talk to a local Brisbane technician, no jargon, no obligation.

Get a Quote Call 07 3063 2211