If you run a small business in Australia, there's a good chance you've never had to think much about the Privacy Act. For decades, businesses with an annual turnover under $3 million were exempt from most of its requirements. That's about to change — and the change affects an enormous number of businesses that have never had to comply with privacy law before.
The small business exemption that has protected millions of Australian businesses from Privacy Act obligations is being removed, with the change targeted for December 2026. Once it takes effect, almost every business that collects personal information — names, emails, phone numbers, payment details, booking information — will be expected to comply with the Australian Privacy Principles (APPs), regardless of size.
If your website has a contact form, takes bookings, processes payments, runs an email newsletter, or stores any customer information at all — this almost certainly applies to you, even if you're a one-person operation.
Under APP 1.3 and 1.4, businesses must have a privacy policy that clearly explains what personal information is collected, why, and how it's used — and it needs to actually reflect what the business does, not just be a generic template. The OAIC has already begun actively checking for this.
Pre-ticked checkboxes for marketing emails — extremely common on Australian small business websites — will no longer cut it. Consent needs to be active and informed, not assumed.
If any part of your business uses automated systems to make decisions about customers (this is becoming more common with AI tools), new requirements mean you'll need to disclose this in your privacy policy.
The OAIC has already started actively reviewing privacy policies as part of a compliance sweep — checking specifically for the clear, up-to-date policy requirements under APP 1.3 and 1.4. This isn't a distant, theoretical issue. Regulatory attention is already increasing, well ahead of the December 2026 deadline.
Penalties for serious or repeated breaches have also increased significantly under recent reforms — into the tens of millions of dollars for the most serious cases. While the vast majority of small businesses won't face penalties anywhere near that scale, the direction is clear: privacy compliance is moving from "nice to have" to "expected baseline."
There's a practical side-effect many business owners don't expect: cyber insurance providers are increasingly asking businesses to demonstrate basic privacy and security hygiene before offering — or renewing — coverage. A missing or inadequate privacy policy can become an insurance problem, not just a legal one.
None of this needs to be overwhelming. For most small businesses, the gap between "non-compliant" and "compliant" is a handful of specific, fixable items — not a complete business overhaul. The hardest part is usually knowing exactly what those items are for your specific website.
AegorIQ's Website Risk Report checks your privacy policy, consent forms, and compliance setup against the Australian Privacy Principles — in plain English, with a clear action list.
See Our Reports →This article provides general information only and is not legal advice. For advice specific to your business, consult a qualified Australian legal practitioner.