Compliance

Privacy Act Changes 2026: SME Compliance Guide

HB
HMC Bot
8 min read

The Privacy Act Is Changing -- Are You Ready?

The Australian Privacy Act 1988 is undergoing its most significant reforms in decades. Following the Attorney-General's department review and the landmark Optus and Medibank breaches of 2022, the government has committed to a series of reforms that will directly impact how Australian SMEs collect, store, and handle personal information.

For many small business owners, the Privacy Act has historically been something they could mostly ignore, thanks to the small business exemption. That is changing. Here is what you need to know and what you need to do.

Key Reforms at a Glance

1. The Small Business Exemption Under Review

Currently, businesses with annual turnover under $3 million are generally exempt from the Privacy Act (with some exceptions for health service providers, businesses that trade in personal information, and those related to the Commonwealth). The government has committed to reviewing and potentially removing this exemption.

The implications are significant. If the exemption is narrowed or removed, an estimated 2.4 million additional Australian businesses would need to comply with the Australian Privacy Principles (APPs). This means:

  • Having a compliant privacy policy
  • Only collecting personal information that is reasonably necessary
  • Securing personal information against unauthorised access and breaches
  • Responding to access and correction requests from individuals
  • Complying with the Notifiable Data Breaches (NDB) scheme
Our advice: Do not wait for the exemption to be formally removed. If you handle customer data -- names, emails, phone numbers, payment details -- you should be building privacy compliance into your operations now. The cost of doing so proactively is a fraction of the cost of retrofitting after a breach or regulatory action.

2. Significantly Increased Penalties

The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 already increased maximum penalties dramatically. For serious or repeated breaches, penalties can now reach:

  • $50 million, or
  • Three times the value of any benefit obtained from the breach, or
  • 30% of adjusted turnover in the relevant period

Whichever is greatest. While these maximum penalties are aimed at large corporates, the OAIC has also increased enforcement action against smaller organisations. In 2024-25, the OAIC resolved over 3,200 Privacy Act complaints -- a record number -- and has signalled its intent to take a more proactive enforcement approach.

3. Strengthened Notifiable Data Breaches (NDB) Scheme

The NDB scheme, in force since February 2018, requires organisations covered by the Privacy Act to notify the OAIC and affected individuals when a data breach is likely to result in serious harm. Proposed reforms include:

  • Clearer thresholds: Updated guidance on what constitutes "likely to result in serious harm," reducing ambiguity for businesses assessing breaches.
  • Faster notification: Pressure to reduce the assessment period from the current "as soon as practicable" (with a 30-day outer limit) to more prescriptive timeframes.
  • Expanded scope: If the small business exemption is removed, millions more businesses will fall under the NDB scheme.

Having a tested cyber incident response plan is critical for meeting NDB obligations. Without one, most SMEs cannot assess and report a breach within the required timeframes.

4. New Individual Rights

Proposed reforms will strengthen the rights of individuals whose data you hold:

  • Right to erasure: Individuals may gain the right to request deletion of their personal information (similar to GDPR's "right to be forgotten"). Businesses will need processes to locate and delete data across all systems.
  • Right to explanation: Where automated decision-making (including AI) substantially affects an individual, they may have the right to an explanation of how the decision was made.
  • Direct right of action: Individuals may be able to take legal action directly against organisations for privacy breaches, without needing to go through the OAIC first. This could significantly increase litigation risk for businesses of all sizes.
  • Consent reforms: Stronger requirements around obtaining meaningful, informed consent for data collection and use, particularly for sensitive information.

Practical Compliance Steps for SMEs

Regardless of whether the small business exemption is removed in 2026 or later, these steps will protect your business and build customer trust:

Step 1: Conduct a Data Audit

You cannot protect data you do not know you have. Map out:

  • What personal information do you collect? (Names, emails, phone numbers, payment details, health information, etc.)
  • Where is it stored? (CRM, email, spreadsheets, accounting software, paper files, third-party platforms)
  • Who has access to it? (Staff, contractors, IT providers, software vendors)
  • How long do you keep it? (Retention periods should match business need and legal requirements)
  • Is any of it unnecessary? (If you do not need it, do not collect or keep it)

If this feels overwhelming, it helps to have a structured way to think about it. The IDIA framework organises every cybersecurity control into four pillars, and two are particularly relevant to Privacy Act compliance. The Data pillar covers data classification, protection, encryption, and backups -- exactly the disciplines a data audit demands. The Assurance pillar covers compliance governance, policy management, and continuous improvement -- ensuring you can demonstrate to regulators that you have a repeatable, documented approach to handling personal information.

Step 2: Update Your Privacy Policy

Your privacy policy should be clear, current, and accessible. It must cover:

  • What information you collect and why
  • How you use and disclose personal information
  • How individuals can access or correct their information
  • How you secure personal information
  • Your complaints handling process
  • Whether information is disclosed overseas

Step 3: Strengthen Data Security

The Privacy Act requires organisations to take "reasonable steps" to protect personal information. What is "reasonable" depends on your business, but at minimum:

  • Enable MFA on all accounts that hold personal data
  • Encrypt sensitive data at rest and in transit
  • Maintain regular, tested backups
  • Apply security patches promptly
  • Restrict data access to staff who genuinely need it
  • Use strong, unique passwords (ideally managed through a password manager)

The cost of a data breach far exceeds the cost of implementing these baseline controls.

Step 4: Prepare for Data Breach Response

Under the NDB scheme, you need to be able to:

  1. Detect a breach quickly
  2. Assess whether it is likely to result in serious harm
  3. Contain the breach and take remedial action
  4. Notify the OAIC and affected individuals if required

A documented incident response plan is essential. If your business is subject to mandatory ransomware reporting requirements, you have additional obligations under the Cyber Security Act 2024 -- see our guide on mandatory ransomware reporting in Australia.

Step 5: Train Your Staff

Privacy compliance is not just an IT issue. Every staff member who handles personal information needs to understand:

  • What data they can and cannot collect
  • How to handle data securely (clean desk policy, secure disposal, screen locking)
  • How to recognise and report a potential data breach
  • How to respond to customer requests for access, correction, or deletion

Timeline: What to Watch For

Timeframe Expected Development
2024 (completed) Privacy Act Review response published; increased penalties in force
2025 Draft legislation for small business exemption reform; new individual rights framework
2026 Expected passage of major reform package; consultation on implementation timeline
2027 (expected) Small business exemption changes likely to take effect with transition period

Start With a Baseline

Privacy compliance and cyber security go hand in hand. You cannot meet your obligations under the Privacy Act without adequate security controls in place. Platforms like How's My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard -- including the Privacy Act and the Australian Privacy Principles. Start with the free CYBER9 assessment to benchmark your business across nine critical domains in under 10 minutes. The results give you a clear picture of your readiness for both cyber threats and regulatory obligations, with actionable recommendations tailored to your business.

Share

How secure is your business?

Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.

Try CYBER9 Free