Privacy Act 2026
Privacy Act Changes 2026: The Complete Australian Business Guide
Every 2026 change to Australia's Privacy Act 1988, on one page: the statutory privacy tort already in force, the 10 December 2026 automated-decision disclosure deadline, the Children's Online Privacy Code, AML Tranche 2's privacy ripple, and the penalties — plain English, source-checked, for Australian businesses.
If you run a business in Australia, the Privacy Act 1988 is changing around you in 2026 — and the changes are landing on different dates, so it is easy to miss the one that affects you. This guide puts every confirmed change on a single page, in plain English, with each date and figure checked against the OAIC, the Attorney-General's Department, AUSTRAC and the Federal Register of Legislation.
One thing to clear up first: this is about Australia's Privacy Act 1988, not the US Privacy Act of 1974. Different country, different law. Everything below applies to Australian businesses and the Australian Privacy Principles (APPs).
The 2026 timeline at a glance
These are the dates that are actually in force or legislated. The one item that is not settled — a future removal of the small-business exemption — is flagged clearly so you do not act on it as if it were law.
| Date | What changes | Status |
|---|---|---|
| 10 June 2025 | Statutory tort for serious invasions of privacy — individuals can sue directly | In force |
| 1 July 2026 | AML/CTF Tranche 2 obligations begin; reporting entities fall under the Privacy Act for that information regardless of turnover | Legislated |
| 10 December 2026 | Automated decision-making (ADM) transparency becomes mandatory in privacy policies | Legislated |
| 10 December 2026 | Children's Online Privacy Code must be finalised/registered by the OAIC | Legislated deadline |
| No confirmed date | Proposed removal of the $3M small-business exemption | Proposed only — not law |
(Sources: OAIC statutory tort; OAIC ADM consultation; OAIC Children's Online Privacy Code; AUSTRAC reforms.)
Does this apply to you?
The honest answer is "it depends on what you do, not just how big you are." A business under $3 million in turnover is not automatically safe, for three reasons that are already true today:
- The statutory tort reaches everyone. Since 10 June 2025, an individual can sue
for a serious invasion of privacy through the courts — and this tort can reach businesses that the Privacy Act itself does not. Turnover is irrelevant to it.
- Several categories are covered regardless of size — for example businesses
that provide a health service and hold health information, or that trade in personal information, or that are contracted service providers under a Commonwealth contract.
- AML/CTF Tranche 2 is the big one for small firms. From 1 July 2026, real
estate agents, conveyancers, lawyers, accountants, trust and company service providers, and dealers in precious metals and stones become reporting entities — and the moment you are a reporting entity, the Privacy Act applies to the personal information you collect for AML/CTF purposes regardless of your turnover.
The fastest way to see where you stand is the free checker. It asks six questions and tells you which obligations apply and when.
The statutory privacy tort — already live
Since 10 June 2025, individuals (not corporations) can sue for an intentional or reckless serious invasion of privacy — either through intrusion upon seclusion or misuse of information — where they had a reasonable expectation of privacy and that interest outweighs any competing public interest. The OAIC does not run this; the courts do. Remedies include damages, an injunction or an order to apologise. Proven economic loss is not capped; non-economic-loss damages are capped (indexed). Full detail in Can you be sued for invading someone's privacy? (Source: OAIC.)
Automated decision-making disclosure — by 10 December 2026
From 10 December 2026, if a computer program makes — or does something substantially and directly related to making — a decision that could reasonably be expected to significantly affect a person's rights or interests, your privacy policy must disclose the kinds of personal information used and the kinds of decisions made. This is a new APP 1 obligation. Think credit or eligibility decisions, pricing, tenant or job screening, and risk scoring. The OAIC opened its draft ADM guidance consultation on 18 May 2026 (submissions closed 15 June 2026). See the ADM privacy-policy guide and are you making "automated decisions"? (Source: OAIC.)
Children's Online Privacy Code — register by 10 December 2026
The OAIC must finalise and register a Children's Online Privacy Code by 10 December 2026 (two years from the 11 December 2024 Royal Assent). It will apply to APP entities providing a social media service, a relevant electronic service or a designated internet service likely to be accessed by children. An exposure draft was released on 31 March 2026; commencement may fall later than registration. If you run an app or website that kids might use, read does the Children's Online Privacy Code apply to you? (Source: OAIC.)
AML Tranche 2: the change that drags small firms in
This is the most concrete "this happens regardless" event for around 100,000 small businesses. From 1 July 2026, the AML/CTF regime extends to new professions. Once you are a reporting entity, you must comply with the Privacy Act for the personal information you handle for AML/CTF — IDs, beneficial-ownership details, KYC documents — independent of the proposed broader exemption removal and independent of your turnover. If you are in real estate, law, accounting, conveyancing, a TCSP or a precious-metals dealer, start with AML Tranche 2 just dragged your agency into the Privacy Act. (Source: AUSTRAC.)
The $3M exemption removal — proposed, not law
You will see commentary claiming the small-business exemption "is gone." It is not. As of June 2026, the removal of the $3 million small-business exemption is proposed in a future tranche — no Bill has been introduced, and there is no confirmed commencement date. Today that exemption still covers roughly 95% of Australian businesses (about 2.3 million entities). Treat the removal as a "monitor" item, not a deadline. The detail (and why it still may not save you) is in the $3 million exemption explained. (Source: IAPP.)
What non-compliance can cost
Penalties run across three tiers, and they should never be lumped together. The high tier (serious interference) reaches the greater of $50M, three times the benefit, or 30% of adjusted turnover. The mid tier (non-"serious" interference) is up to $3.3M. The low tier (administrative breaches, such as a non-compliant privacy policy under APP 1) is up to $330,000 for incorporated entities, and the OAIC can issue infringement notices up to $66,000 for a non-compliant policy. The full breakdown is in Privacy Act penalties 2026. (Sources: Clyde & Co; MinterEllison.)
Where to start
- Run the free checker to confirm which obligations apply to your business and when.
- Grab the free readiness checklist so you have the deadlines and the gaps in one place.
- Fix the in-force items first — the statutory tort and the 30-day data-breach
assessment clock apply now; ADM disclosure is the 10 December 2026 headline.
- If you are heading into AML Tranche 2, treat privacy and AML as one project — you
will be collecting more personal information than ever from 1 July 2026.
Read every spoke below for the detail on your situation. Each one links back here and cites its primary sources.
General information only, not legal or compliance advice. Dates, penalties and thresholds are drawn from OAIC, the Attorney-General's Department, AUSTRAC and the Federal Register of Legislation (current to June 2026) and can change — confirm your specific obligations at oaic.gov.au or with a qualified adviser before acting. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →