On 31 August 2026 the Attorney-General released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 - the long-awaited second round of Privacy Act reform. Submissions closed on 18 September, and the headlines since have ranged from accurate to alarmist. If you run a Perth business with fewer than 50 staff, the most common question we're hearing is simple: does any of this apply to me? Here's what's already law, what's only proposed, and what's worth doing either way.
Already law
Statutory privacy tort (since 10 June 2025), tougher OAIC enforcement, clearer security obligations, automated decision disclosure from 10 December 2026.
Proposed only
"Fair and reasonable" test, 72-hour breach notification to the OAIC, tighter consent and direct marketing rules. No start date yet.
Not in the draft
General removal of the small business exemption, removal of the employee records exemption, a universal right to erasure.
First: Does the Privacy Act Apply to Your Business Today?
The Australian Privacy Principles (APPs) apply to businesses with annual turnover above $3 million. Below that, most businesses are exempt - but the exemption has more holes in it than many owners realise. You are covered regardless of turnover if, for example, you:
- Provide a health service and hold health information - which captures dental clinics, allied health practices, psychologists, and many NDIS providers.
- Trade in personal information - buying or selling customer data or leads.
- Hold a contract with the Australian Government as a service provider.
- Are related to a larger business that isn't exempt, or have chosen to opt in.
- Are a reporting entity under the AML/CTF Act - relevant to law firms, accountants and real estate agencies brought into the AML/CTF regime from 1 July 2026, at least for their AML/CTF-related activities.
If none of those apply and you're under $3 million, the APPs probably don't bind you yet. But keep reading - one of the changes that's already in force applies to everyone.
What's Already Law
The first round of reform, the Privacy and Other Legislation Amendment Act 2024, passed in late 2024. Most of it is in force now.
A statutory tort for serious invasions of privacy (since 10 June 2025)
Individuals can now sue in the courts for a serious invasion of their privacy - either an intrusion into their private space or misuse of information about them. The key points for a business owner:
- It isn't tied to the $3 million threshold. A five-person business can be sued the same as a large one.
- It must be serious, and intentional or reckless. An honest mistake or simple carelessness isn't enough on its own.
- Claims go to court, not the OAIC. The OAIC has no direct role in the tort.
In IT terms, the realistic risk isn't a sophisticated hack - it's a staff member browsing a customer's records out of curiosity, forwarding someone's personal details where they shouldn't go, or sharing camera footage. The controls that reduce that risk are unglamorous: people only having access to what their role needs, audit logs that record who opened what, and prompt removal of access when someone leaves. Our guides to auditing Microsoft 365 permissions and offboarding staff properly cover the practical side.
Clearer security obligations under APP 11
For covered businesses, the law now spells out that taking "reasonable steps" to protect personal information includes both technical measures (MFA, encryption, patching, endpoint protection) and organisational measures (policies, training, access reviews). It was always implied; now it's explicit, which makes it much harder to argue after a breach that basic controls weren't expected of you.
Stronger enforcement
The OAIC now has a wider range of penalty tiers and can issue infringement notices for lower-level breaches, such as a non-compliant privacy policy, without going to court. In practice, enforcement no longer only reaches businesses that suffer a headline-making breach.
Automated decision disclosure (from 10 December 2026)
From 10 December 2026, covered businesses must say in their privacy policy if they use computer programs to make, or substantially help make, decisions that significantly affect individuals using their personal information. If you use software or AI tools to screen job applicants, approve credit or accounts, or prioritise customers, check your privacy policy before December. An AI usage policy is a good place to find out which tools your staff are actually using.
What's Proposed: The 2026 Exposure Draft
The exposure draft contains around 40 proposals. It is not law, it may change after consultation, and no commencement date or transition period has been published. The changes most relevant to a small or medium business are:
- A "fair and reasonable" test. Collecting, using and disclosing personal information would need to be fair and reasonable in the circumstances - judged against factors such as what a reasonable person would expect, transparency, and whether people had a genuine choice. Ticking a box in a privacy policy would no longer be enough on its own.
- 72-hour breach notification. Businesses would have to notify the OAIC within 72 hours of having reasonable grounds to believe an eligible data breach has occurred. Today the rule is to assess within 30 days and notify as soon as practicable - a very different pace. See our guide to the current Notifiable Data Breaches scheme.
- A real definition of consent. Consent would have to be voluntary, informed, current, specific and unambiguous - pre-ticked boxes and bundled consent wouldn't cut it.
- New sensitive information. Precise geolocation tracking data and genomic information would join health information as sensitive, needing consent to collect. That matters for businesses running vehicle or phone tracking on field staff.
- Direct marketing and trading data. Disclosing personal information for direct marketing would need consent, and unsubscribing would have to be simple. Small businesses that trade in personal information would lose the exemption.
- Ongoing security, not a one-off. APP 11 would require businesses to be able to respond effectively to suspected breaches, mitigate harm, and regularly evaluate whether their security measures actually work.
The right to erasure that attracted so much attention only applies to large digital platforms under the draft - roughly $500 million or more in annual revenue, or 2.5 million or more users. It isn't aimed at Perth SMBs.
So Is the Small Business Exemption Going Away?
Not in this bill. The Government agreed in principle in 2023 to remove the exemption, subject to an impact analysis and support for small business, but the exposure draft doesn't do it. The only change is the narrower one above, for small businesses that trade in personal information.
Our view: plan as though the exemption will eventually go, but don't panic. Everything worth doing to get ready is basic security and data hygiene that pays off anyway - in insurance applications, client security questionnaires, and simply being harder to breach.
What to Do Now: A Practical Checklist
- Confirm whether you're covered. Check turnover, then the exceptions above - especially health services and AML/CTF.
- Find where personal information lives. Mailboxes, SharePoint and OneDrive, your CRM or practice software, spreadsheets, an old file server, and backups. An IT asset register is a natural starting point, and auditing external sharing usually turns up surprises.
- Tighten access and turn on logging. Least-privilege access, MFA on every account, and audit logs retained long enough to answer "who opened this?"
- Get breach-ready at a 72-hour pace. Even though it isn't law yet, a written incident response plan and a practice drill make the difference between a controlled response and a panicked one.
- Delete what you don't need. Information you no longer hold can't be breached. Set a retention policy and apply it to backups as well as live data.
- Review your privacy policy before 10 December 2026 if you're covered and use automated decision-making.
- Check your marketing lists. Know where every contact came from and what they agreed to.
Important: This article is general information about the IT and security side of privacy compliance, current as of September 2026. It isn't legal advice. For questions about your specific obligations, speak to a lawyer, and see the OAIC and the Attorney-General's Department consultation page for official detail.
Frequently Asked Questions
Has the small business exemption been removed from the Privacy Act?
No. Most businesses with annual turnover of $3 million or less are still exempt from the Australian Privacy Principles. The Government agreed in principle in 2023 to remove the exemption, but the exposure draft released on 31 August 2026 does not remove it. It only narrows it for small businesses that trade in personal information.
Does the new privacy tort apply to small businesses?
Yes. The statutory tort for serious invasions of privacy, which commenced on 10 June 2025, is a separate right to sue and isn't tied to the $3 million turnover threshold. The invasion has to be serious and intentional or reckless (carelessness alone isn't enough), and claims go to the courts rather than the OAIC.
Is the 72-hour data breach notification rule in force?
Not yet. It is a proposal in the 2026 exposure draft, which was open for submissions until 18 September 2026 and has no commencement date. Under the current Notifiable Data Breaches scheme, covered businesses must assess a suspected breach within 30 days and notify as soon as practicable once they know an eligible breach has occurred.
My business is under $3 million turnover. Can I ignore all of this?
Not necessarily. Health service providers, businesses that trade in personal information, contractors to the Australian Government and some other small businesses are covered regardless of turnover. The privacy tort applies to everyone. Clients, insurers and tenders also increasingly ask privacy questions whether or not the law requires it.
What's the first practical step for a small business?
Work out where personal information actually lives: mailboxes, SharePoint and OneDrive, your CRM or practice software, spreadsheets, old file shares and backups. You can't restrict access to, secure or delete information you haven't found, and every obligation in both the current law and the proposals starts there.
Want to know where personal information sits in your systems, and who can reach it? That's exactly what a security audit maps out.
IT Security Audit →Not sure how ready your business is?
Call 0433 087 091 for a free, no-obligation review of your access controls, logging and backups.
Book a Free IT Health CheckFor related reading, see our guides to data sovereignty and data residency and cyber insurance for Perth businesses.