1. The default rule and what it means
  2. The carve-outs: when the exemption does not apply
    1. Health service providers
    2. Trading in personal information
    3. Contracted service providers for Commonwealth contracts
    4. AML/CTF reporting entities — including new tranche 2 businesses from 1 July 2026
    5. Residential tenancy database operators
    6. Credit reporting bodies
    7. Employee associations
    8. Protected action ballot agents
    9. Related bodies corporate
    10. Opting in voluntarily
  3. Which small businesses the Act covers
  4. What compliance looks like if you are covered
  5. How Artificer Legal can help
  6. Check the carve-outs first

Your business just crossed a revenue milestone, or you are about to sign a government contract, or a client has asked whether you have a privacy policy. Somewhere in that moment you realise you are not certain whether the Privacy Act 1988 (Cth) actually applies to you. For most small businesses the answer is no — but the exceptions are wide enough that a surprising number of operators are caught without knowing it, and the law is being extended to new industries from mid-2026.

The default rule and what it means

The Privacy Act 1988 (Cth) creates a category called a "small business operator." Under s 6D of the Act, a business with an annual turnover of $3 million or less in the previous financial year is a small business operator — and small business operators are not, as a default, bound by the Act or the Australian Privacy Principles (APPs) that sit within it.

Annual turnover for this purpose includes income from most operating sources: proceeds from goods and services sales, commission income, rent and leasing income, interest, royalties, dividends, and government bounties and subsidies. It does not include capital gains, asset disposals, or proceeds of capital sales. If your business has not completed a full financial year, you project your turnover based on the income earned so far.

So the first question is straightforward: did your business earn more than $3 million last financial year? If yes, you are covered by the Act and the APPs apply to you regardless of anything else in this article. If no, read on — because the exemption comes with a long list of carve-outs.

The carve-outs: when the exemption does not apply

Even if your turnover is under $3 million, your business is brought back within the Act if it falls into one or more of the following categories. These are not administrative suggestions — they are statutory obligations under s 6D.

Health service providers

Any business that provides a health service and holds health information about individuals is covered, regardless of turnover. This includes private hospitals, day surgeries, general practitioners, specialists, pharmacists, allied health professionals (physiotherapists, psychologists, dietitians), and telehealth providers. If your business touches patient or client health data, the exemption is unavailable to you.

Trading in personal information

A business that discloses personal information about individuals for a benefit, service, or advantage — or that provides a benefit, service, or advantage in exchange for personal information collected by someone else — is covered. Buying or selling a mailing list is the most common example. Sharing customer data with a third party in exchange for a service discount could also qualify. If personal information is the currency of a transaction rather than incidental to it, the exemption likely does not apply.

Contracted service providers for Commonwealth contracts

If your business provides services directly under a contract with a Commonwealth agency, the Privacy Act applies to the personal information you handle in performing that contract. This applies to the contractor itself; subcontractors should check whether their arrangement with the head contractor brings them in as well.

AML/CTF reporting entities — including new tranche 2 businesses from 1 July 2026

Businesses that are reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) are covered by the Privacy Act in relation to their AML/CTF activities.

Critically, the scope of AML/CTF reporting entities is expanding. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) brings a new class of businesses — commonly called "tranche 2" entities — into the AML/CTF regime from 1 July 2026. Tranche 2 entities include real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones. Once these businesses become reporting entities under the AML/CTF Act, the Privacy Act will apply to them in respect of that regulated activity, regardless of their annual turnover.

If your business is in one of those industries and you are not yet considering what this means for your privacy obligations, now is the time to start.

Residential tenancy database operators

Businesses that collect, maintain, use, or disclose personal information for the purpose of a residential tenancy database as defined under the Privacy Regulation 2013 (Cth) are covered.

Credit reporting bodies

Businesses that carry on a credit reporting business — maintaining files on individuals' consumer credit histories — are covered.

Employee associations

An employee association registered or recognised under the Fair Work (Registered Organisations) Act 2009 (Cth) is covered by the Privacy Act.

Protected action ballot agents

Businesses that conduct protected action ballots under the Fair Work Act 2009 (Cth) are covered in relation to those activities.

If your business is related to another business that is itself bound by the Privacy Act — for example, a subsidiary of a company with annual turnover exceeding $3 million — then your business is also covered.

Opting in voluntarily

Under s 6EA of the Act, a business can elect to be treated as though it is bound by the Privacy Act even if it would otherwise be exempt. This is a one-way door: once you opt in, you must comply with the APPs. Some businesses do this because their customers, platforms, or industry expectations demand it, or because they are planning for growth and want their systems ready.

Which small businesses the Act covers

The table below summarises the most common scenarios for an Australian small business.

Situation Covered by the Privacy Act?
Retail or hospitality business, turnover under $3M, no government contracts No — default exemption applies
GP practice or allied health clinic, any turnover Yes — health service provider carve-out
Marketing agency that buys or sells contact lists Almost certainly yes — trading in personal information
IT contractor to a federal government department Yes — Commonwealth contract carve-out
Accountant or lawyer with turnover under $3M, from 1 July 2026 Yes — AML/CTF tranche 2 reporting entity
Small property manager operating a tenancy blacklist database Yes — residential tenancy database operator
Subsidiary of a covered group company Yes — related body corporate
Small business that has opted in voluntarily Yes — s 6EA election

The businesses most likely to be caught unaware are those in professional services — particularly accountants, solicitors, conveyancers, and real estate agents — who have historically assumed the small business exemption covered them. From 1 July 2026, that assumption will be wrong for anyone who becomes an AML/CTF reporting entity.

A reform proposal to remove the small business exemption entirely has been discussed and recommended by the Office of the Australian Information Commissioner (OAIC). As at the date of this article, it has not been legislated — the Privacy and Other Legislation Amendment Act 2024 (Cth), which passed Parliament in November 2024, did not include the removal. Further reform is expected but the timing is uncertain. Businesses would be wise to monitor this.

What compliance looks like if you are covered

If your business is covered — whether because of turnover, a carve-out, or a voluntary election — you must comply with the 13 Australian Privacy Principles. In practice, for most small businesses, that means:

  • Privacy policy: A clearly written policy explaining what personal information you collect, why you collect it, how you hold it, and how individuals can access or correct it. The policy must be freely available (usually on your website).
  • Collection: Only collecting personal information that is genuinely necessary for your business functions, with appropriate notice to the individual at the point of collection.
  • Security: Taking reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure.
  • Access and correction: Giving individuals access to their personal information on request, and correcting it if it is inaccurate.
  • Use and disclosure: Only using or disclosing personal information for the purpose for which it was collected, unless an exception applies (such as a legal obligation or with consent).
  • Unsolicited information: Destroying or de-identifying unsolicited personal information that you are not permitted to collect.
  • Complaints handling: Having a process for responding to privacy complaints.

Serious or repeated breaches of the APPs can attract civil penalties. For serious or repeated interferences with privacy, the OAIC can seek penalties of up to $50 million or three times the benefit obtained, whichever is greater, or 30% of adjusted turnover in the relevant period — provisions introduced by the 2024 amendments.

Determining whether your business is covered is only the first step. The harder questions follow: whether a particular activity constitutes "trading in personal information," whether your Commonwealth contracts trigger the carve-out, what a compliant privacy policy for your specific business looks like, and how to build systems that will hold up under scrutiny.

Artificer Legal works with Australian small and medium businesses on precisely these questions. Our practitioners can review your business model, identify which limbs of the Act apply, draft or update a privacy policy that is accurate for your operations (not a generic template), and advise on the steps you need to take before 1 July 2026 if you are in a tranche 2 industry. Where the OAIC's position on a particular activity is ambiguous, we can help you assess the risk and structure your practices accordingly.

Check the carve-outs first

The factor that most often catches small businesses by surprise is not the $3 million threshold — it is the carve-outs. If you handle health information, work under a government contract, deal in personal information as part of your service, or are in an industry about to be swept into the AML/CTF regime, the exemption you assumed applies to you may not. Check each carve-out against your actual business model, not against your general sense of what kind of business you run.

The $3 million threshold matters. But given how many carve-outs exist, the better starting question is: "Is there any specific reason the exemption does not apply to me?" rather than "Is my turnover low enough?" Run through the list above, check the OAIC's guidance for small businesses, and if any carve-out is plausibly relevant, seek advice before assuming you are exempt. The cost of getting this wrong — especially post the 2024 penalty increases — is significant.