If you run a small business in Australia, you may have heard that the Privacy Act does not apply to businesses below a certain size. That is partly true, but the turnover threshold is only the starting point.
Under the Privacy Act 1988 (Cth), many businesses with annual turnover of $3 million or less can rely on the small business exemption. However, some smaller businesses are still covered because of the services they provide, the way they handle personal information, their contractual arrangements or other specific activities.
So, when considering the Privacy Act small business rules, the more useful question is not simply, “Is my turnover below $3 million?” It is, “Does an exception or another basis for Privacy Act coverage apply to my business?”
What Is the Privacy Act Small Business Exemption?
The Privacy Act generally distinguishes smaller businesses from larger organisations through an annual turnover threshold.
For Privacy Act purposes, a small business is generally one with annual turnover of $3 million or less. Annual turnover refers to income from all sources. It is not the same as profit, and it does not simply mean the amount left after business expenses are deducted.
This matters because a business with relatively small profits could still have turnover above the Privacy Act threshold.
The Office of the Australian Information Commissioner, or OAIC, also makes clear that the turnover test is not the only factor businesses should consider. A business below the threshold may still be covered if one of the Privacy Act exceptions applies. The OAIC small business guidance provides a checklist businesses can use when assessing their position.
Being under $3 million annual turnover does not automatically mean a business is exempt from the Privacy Act.
Businesses should therefore look at both their size and what they actually do before assuming the exemption applies.

When Does the Privacy Act Apply to a Small Business?
Several circumstances can bring a small business within the Privacy Act even when its turnover is $3 million or less.
Understanding these exceptions is particularly important because some businesses handle sensitive or valuable personal information despite operating on a relatively small scale.
Your Business Has Annual Turnover Above $3 Million
Businesses with annual turnover above $3 million are generally within the Privacy Act's coverage, subject to the Act's definitions and other applicable provisions.For businesses around the threshold, turnover should be assessed carefully rather than estimated from profit, taxable income or a single month's revenue.
Your Business Provides a Health Service
A small business may still be covered by the Privacy Act regardless of its turnover if it provides a health service and handles health information. The health service definition is broader than hospitals and traditional medical practices.
-
It can include private hospitals, pharmacists, psychologists, physiotherapists, occupational therapists, allied health professionals, and other businesses providing services related to physical or mental health.
-
For example, a physiotherapy clinic with an annual turnover of $800,000 should not assume the small business exemption applies simply because its turnover is below $3 million.
-
Depending on where the business operates and what information it handles, state or territory privacy laws may also apply.
In practice, businesses should consider the type of service they provide and the information they collect, not just their annual turnover, when determining whether the Privacy Act applies.
Your Business Trades in Personal Information
Some businesses are covered by the Privacy Act because they trade in personal information. This can apply where a business collects or discloses personal information for a benefit, service or advantage in circumstances covered by the Act.
-
Not every transfer counts: A normal transfer of customer information does not automatically mean a business is trading in personal information.
-
Consider the purpose: Businesses should consider why the information is collected or disclosed, what benefit is received, and whether the activity falls within the relevant Privacy Act rules.
-
Customer lists: Businesses that buy or sell customer lists should carefully assess whether their activities are covered.
-
Commercial arrangements: Exchanging personal information as part of certain commercial arrangements may also require closer consideration.
Businesses involved in these activities should assess how they collect, use and disclose personal information to determine whether the Privacy Act applies.
You Provide Services Under a Commonwealth Contract
A small business may also have Privacy Act obligations if it provides services under a Commonwealth contract.
The exact position depends on the contractual arrangement and the activities involved, so businesses working for Australian Government agencies should review their contract and applicable privacy requirements rather than relying solely on their turnover.
Another Privacy Act Exception Applies
Other categories of small business can also be brought within the Privacy Act.
Examples can include:
-
credit reporting bodies;
-
operators of residential tenancy databases;
-
certain businesses related to larger organisations covered by the Act;
-
Consumer Data Right accredited businesses;
-
reporting entities under the AML/CTF Act, for relevant AML/CTF activities
-
businesses prescribed by regulation.

The practical position can be summarised as follows:
|
Business situation |
Likely Privacy Act position |
|
Turnover above $3 million |
Generally covered |
|
$3 million or less with no applicable exception |
Usually able to rely on the small business exemption |
|
Private health service provider |
Privacy Act can apply regardless of turnover |
|
Trades in personal information in circumstances covered by the Act |
Privacy Act can apply |
|
Commonwealth contracted service provider |
Privacy obligations may apply |
|
Certain regulated activities |
Privacy Act coverage may apply |
|
Business voluntarily opts in |
Privacy Act applies |
This table is a starting point only. Businesses should assess their own activities before deciding whether they are exempt.
Does the Privacy Act Apply to Sole Traders?
Being a sole trader does not automatically place a business outside the Privacy Act.
The OAIC's Australian Privacy Principles Guidelines recognise that a small business operator can include an individual, including a sole trader, as well as a body corporate, partnership, unincorporated association or trust.
A sole trader with turnover below $3 million and no applicable exception may therefore be able to rely on the small business exemption.
However, the business structure itself is not decisive. A sole trader who provides a health service, trades in personal information or carries out another activity that brings the business within the Privacy Act may still have privacy obligations.
The relevant question is what the business does, not simply whether it operates as a company or sole trader.
Do the Australian Privacy Principles Apply to Small Businesses?
Where a small business is covered by the Privacy Act, the Australian Privacy Principles, commonly called the APPs, become central to how personal information is handled.
The Privacy Act contains 13 APPs covering areas such as transparency, collection of personal information, use and disclosure, data quality, security, access and correction.
This article does not need to repeat each principle individually. ACT's What Are the Australian Privacy Principles (APPs)? A Simple Guide provides a broader explanation of how the APP framework operates.
For a small business, the first step should therefore be determining whether it is covered. Once that position is clear, it becomes much easier to identify which privacy practices, policies and controls require attention.
How Do the 2026 AML/CTF Changes Affect Small Businesses?
The 2026 expansion of Australia's anti-money laundering and counter-terrorism financing framework creates an important exception for some businesses that might otherwise qualify for the small business exemption.

From 1 July 2026, tranche 2 businesses that become reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 can also have Privacy Act obligations for their AML/CTF activities.
The expanded sectors include certain:
-
real estate professionals;
-
dealers in precious metals and stones;
-
lawyers;
-
conveyancers;
-
accountants;
-
trust and company service providers.
The OAIC's privacy guidance for reporting entities under the AML/CTF Act explains how these Privacy Act responsibilities operate.
A particularly important point is that coverage can be activity-specific.
For example, a small accounting firm may have Privacy Act obligations when handling personal information for activities regulated under the AML/CTF regime while remaining outside Privacy Act coverage for unrelated business activities, unless another basis for coverage also applies.
This is why a simple turnover test is increasingly insufficient for some small businesses.
Has the Small Business Privacy Exemption Been Removed?
No. As at October 2026, businesses should not treat the small business exemption as though it has been removed across the board.
Australia's privacy reform program has considered removal of the exemption. The Australian Government's Government response to the Privacy Act Review Report agreed in principle with a proposal to remove it, but only after several conditions are addressed.
These include:
-
undertaking an impact analysis;
-
determining what support small businesses would need;
-
developing proportionate ways for businesses to meet their obligations;
-
ensuring small businesses are in a position to comply.
The Government response therefore did not immediately abolish the exemption.
Privacy reform has continued since then. In 2026, further Exposure Draft legislation was released for consultation, but the Attorney-General's Department states that the Bill remains subject to further government consideration.
This distinction matters because current law and proposed reform are not the same thing.
Small businesses should comply with obligations that apply now and monitor reform developments without treating every proposal as an existing legal requirement.
Can a Small Business Voluntarily Opt In to the Privacy Act?
Yes. A small business that would otherwise fall outside the Privacy Act can choose to become subject to it.
Section 6EA of the Privacy Act allows eligible small businesses and not-for-profit organisations to opt in voluntarily. Once they opt in, they become subject to the Australian Privacy Principles and relevant APP codes.
The OAIC explains the process for opting in to the Privacy Act.
Businesses applying to opt in need an APP privacy policy. Opting in is therefore not simply a statement that the business values privacy. It creates formal Privacy Act responsibilities.
A business may choose this route because clients or commercial partners expect stronger privacy governance, because it expects to grow beyond the exemption threshold, or because it wants to demonstrate a more formal commitment to personal information handling.
Before opting in, however, the business should understand what compliance will require in practice.
What Should a Small Business Do if the Privacy Act Applies?

If the Privacy Act applies, the business should move from determining coverage to understanding how personal information is actually handled in day-to-day operations.
A practical starting point is to work through the following steps.
-
Confirm why the Privacy Act applies.
Identify whether coverage arises because of turnover, a specific exception, a regulated activity or voluntary opt-in. -
Identify the personal information you handle.
Map what information is collected, where it comes from, how it is stored, why it is used and who receives it. -
Review your privacy policy and privacy practices.
Policies should accurately reflect what the business does in practice rather than simply using generic privacy wording. -
Identify who handles personal information.
Consider employees, contractors, service providers and other parties who may have access to customer, employee or other personal information. -
Review security and information-handling arrangements.
Consider access controls, retention, deletion, correction requests and procedures for responding to privacy incidents. -
Build staff awareness.
Employees who collect, use or disclose personal information should understand the organisation's privacy responsibilities and internal procedures.
Businesses that want to build more structured knowledge across privacy obligations and emerging AI-related governance issues can consider ACT's Privacy & AI Governance (Privacy Act) training.
Training can support a wider privacy governance framework, but it should not replace legal advice or a business-specific assessment where the organisation's position is uncertain.
What if Your Small Business Is Exempt?
Being exempt from the Commonwealth Privacy Act does not necessarily mean that a business has no privacy or information-handling responsibilities. Other laws, contracts and sector-specific requirements may still apply.
-
State or territory laws: These may apply to businesses in certain sectors, particularly those handling health information.
-
Contractual requirements: Contracts with clients, government bodies or larger organisations may include specific privacy and data-handling obligations.
-
Good privacy practice: Even when the Privacy Act does not apply, the OAIC encourages small businesses to take reasonable steps to protect personal information.
-
Future growth: A business may later exceed the turnover threshold, enter a regulated sector, obtain a Commonwealth contract or begin activities covered by an exception.
-
Early preparation: Establishing sensible privacy processes early can make it easier to manage new obligations as the business grows.
Taking privacy seriously from the beginning can help small businesses reduce risks and adapt more easily when their legal responsibilities change.
Check Privacy Act Coverage Before Assuming Your Business Is Exempt
For Australian small businesses, the $3 million threshold is useful, but it should never be treated as the entire Privacy Act test.
Health services, personal-information trading, Commonwealth contracts, AML/CTF activities and other exceptions can bring smaller organisations within the Privacy Act even when their turnover is below the threshold.
The safest starting point is to identify why the business may be covered, check the relevant exemptions and exceptions, and separate current requirements from privacy reforms that are still proposed.
That approach gives small businesses a clearer picture of what they actually need to do, without assuming obligations that do not yet apply.
Frequently Asked Questions About the Privacy Act and Small Business
Does the Privacy Act apply to small businesses in Australia?
Many Australian businesses with annual turnover of $3 million or less can rely on the small business exemption. However, the Privacy Act can still apply if an exception is triggered, such as providing a health service, trading in personal information, undertaking certain regulated activities or providing services under a Commonwealth contract.
Are businesses under $3 million exempt from the Privacy Act?
Not automatically. The $3 million threshold is an important part of the test, but it is not the only factor. Some businesses below that threshold are covered because of what they do or the information they handle.
Do small businesses need a privacy policy in Australia?
If a small business is an APP entity covered by the Privacy Act, APP 1 includes requirements relating to having a clearly expressed and up-to-date privacy policy.
A business that is genuinely exempt should not automatically be treated as having the same Privacy Act obligation. However, other legislation, contractual requirements or voluntary opt-in arrangements may still make a privacy policy necessary or useful.
Has the small business exemption been removed in 2026?
No blanket removal is currently in force. The Australian Government has agreed in principle to eventual removal of the exemption, subject to further work and support for small businesses. Current businesses should distinguish that reform direction from the Privacy Act rules that apply today.
Does the Privacy Act apply to sole traders?
It can. A sole trader can fall within the Privacy Act's concept of an organisation or small business operator. Whether the Act applies depends on matters such as turnover and whether an exception to the small business exemption applies.
Can a small business choose to comply with the Privacy Act?
Yes. An eligible small business that would otherwise be exempt can voluntarily opt in under section 6EA of the Privacy Act. Once it does so, it becomes subject to the APPs and relevant APP codes.
