Often yes, and more often than business owners expect. Here is how to work out whether the Privacy Act covers you, and why you probably want a policy even if it does not.
As a rule, the Privacy Act 1988 (Cth) applies to businesses with an annual turnover of more than $3 million. Under that figure, a business is generally a “small business operator” and outside the Act.
That is where most articles stop, and it is where most owners get it wrong. The exemption has carve-outs, and several of them catch ordinary small businesses:
General information about Australian law, the same for every reader. It is not advice about your situation, and we are not a law practice. If you are unsure which of these apply to you, your accountant or a lawyer can tell you.
As a rule the Privacy Act 1988 (Cth) applies to businesses with an annual turnover of more than $3 million. Below that a business is generally a small business operator and outside the Act, but the exemption has carve-outs that catch ordinary small businesses, so turnover alone does not settle it.
Businesses with annual turnover above $3 million are covered by the Privacy Act. The threshold is turnover, not profit, so a good year can move a business inside the Act without anything else about it changing.
A business that provides a health service and holds health information, whatever its turnover; an AUSTRAC reporting entity, since 1 July 2026 that includes real estate agencies, accountants, lawyers, conveyancers and dealers in precious metals, though only for the personal information they handle for those anti-money-laundering obligations, not for the whole business; a business that buys or sells personal information; a contracted service provider under a Commonwealth contract; a business related to a larger covered business; and any small business that has opted in.
No. Health service is broader than it sounds, it reaches allied health, childcare, and businesses that screen people for injury or medical conditions. If you provide one and hold health information, the Act applies whatever your turnover.
Three reasons. Customers look, and a website taking names, emails and payments with nothing explaining what happens to them is a question mark at the moment someone is deciding whether to buy. Platforms require it, app stores, advertising platforms, payment providers and many business customers ask for a privacy policy URL before they will deal with you. And your turnover can cross the threshold without you noticing.
No, not for that part of what you do. Since 1 July 2026, providing a designated service listed in section 6 of the AML/CTF Act with a geographical link to Australia makes you a reporting entity, and the Privacy Act then treats a reporting entity as an organisation whatever its turnover, for the personal information it handles for those services.
So a two-person conveyancing practice well under $3 million in turnover is inside the Privacy Act for its client identity records. The exemption is not a blanket one, and this is the exception that has caught the most businesses this year.
If the Privacy Act applies to you and you use software to make or materially assist decisions that could significantly affect people, then from 10 December 2026 your policy has to describe it, which means you need a policy for it to go in. APP 1.7 is a three-limb test, so ordinary software that decides nothing consequential, like a spam filter, is outside it.
If the Act does not apply to you, there is still no exemption from the Australian Consumer Law. A policy that describes automated decisions you do not make, or stays silent about ones you do, is a representation about your business either way.