Privacy Act guide · general information, not legal advice

Privacy Act compliance checklist 2026: 12 items

Twelve items for a small practice, in the order to do them: what the law requires now, what starts on 10 December 2026, and what is only proposed. Each item names the provision it comes from.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the Privacy and Other Legislation Amendment Act 2024 (C2024A00128) and the OAIC pages cited below

s 26WH the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

First: does the Act apply to you?

The Australian Privacy Principles (APPs) bind an "APP entity". A business with annual turnover of $3,000,000 or less in the previous financial year is generally a small business and outside the Act.1 s 6D(1) It is inside the Act anyway if one of the cases in s 6D(4) applies, for example it has had turnover over $3,000,000 in any year since it began, or it provides a health service and holds health information.1 s 6D(4)

If you are an AML/CTF reporting entity, the Act applies to your AML/CTF activities as if you were an organisation, whatever your turnover.2 s 6E(1A) Items 9 and 10 are for you.

Not sure? Read Does the Privacy Act apply to your small business? before you start.

The 12 items

Privacy Act checklist, in priority order
# Item Status Source
1 Privacy policy with every APP 1.4 matter In force APP 1.3, 1.4
2 Practices, procedures and a complaints path In force APP 1.2
3 Collection notices where you collect In force APP 5.1
4 Collect only what is reasonably necessary In force APP 3.2
5 Secure it, then destroy or de-identify it In force APP 11.1, 11.2
6 A data breach plan that meets the 30-day rule In force s 26WH
7 Overseas recipients and service providers In force APP 8.1
8 Know the statutory tort In force since 10 June 2025 Schedule 2
9 AML/CTF privacy policy and collection notices Reporting entities s 6E(1A); OAIC guidance
10 Keep KYC particulars, not ID copies Reporting entities OAIC guidance
11 Automated-decision disclosure From 10 December 2026 APP 1.7 to 1.9
12 Watch the proposals, do not act on them Proposed, not law AGD exposure draft

In force now

1. Privacy policy. You must have a clearly expressed and up-to-date privacy policy.3 APP 1.3 It must say what kinds of personal information you collect and hold, how, and why; how people can access and correct it; how they can complain and how you deal with complaints; and whether you are likely to disclose it overseas and, if practicable, to which countries.3 APP 1.4 A missing or incomplete policy is a low-tier contravention: up to 200 penalty units ($72,800), or $364,000 for a body corporate, and it can be dealt with by infringement notice.4 s 13K(1) The OAIC announced a sweep of about 60 entities' privacy policies, to begin in early 2026, including in the rental and property sector.5 OAIC

2. Practices and complaints. Take reasonable steps to put in place practices, procedures and systems that ensure you comply with the APPs and let you deal with inquiries and complaints.3 APP 1.2

3. Collection notices. At or before the time you collect personal information, or as soon as practicable after, take reasonable steps to tell the person the APP 5.2 matters, such as who you are, why you are collecting, any law that requires it, who you usually disclose it to, and that your privacy policy explains access, correction and complaints.3 APP 5.1 Check web forms, onboarding forms and job applications.

4. Collect less. An organisation must not collect personal information (other than sensitive information) unless it is reasonably necessary for one or more of its functions or activities.3 APP 3.2 The OAIC's regulatory action priorities for 2025–26 include "excessive collection and retention of personal information".6 OAIC

5. Secure, then destroy. Take reasonable steps to protect the information from misuse, interference and loss, and from unauthorised access, modification or disclosure.3 APP 11.1 When you no longer need it for a permitted purpose, and no Australian law or court or tribunal order requires you to keep it, take reasonable steps to destroy or de-identify it.3 APP 11.2

6. Data breach plan. If you have reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days after you become aware.7 s 26WH(2) If you have reasonable grounds to believe there has been one, you must give the Commissioner a statement as soon as practicable, then notify the individuals concerned as soon as practicable (or, if that is not practicable, publish the statement and publicise it).7 s 26WK s 26WL See the data breach response plan.

7. Overseas and outsourced. Before you disclose personal information to someone outside Australia, take reasonable steps to ensure they do not breach the APPs.3 APP 8.1 List your cloud and outsourced providers and where they hold data.

8. The statutory tort. Since 10 June 2025 an individual can sue for a serious invasion of privacy. Among other elements, the invasion must have been intentional or reckless, and the public interest in privacy must outweigh any countervailing public interest.8 Sch 2 cl 7(1) It has no turnover threshold. See the statutory tort.

If you are an AML/CTF reporting entity

9. Privacy policy and collection notices for AML/CTF handling. Tranche-2 obligations applied from 1 July 2026. The OAIC says reporting entities must have a privacy policy and collection notices that explain how they handle personal information for AML/CTF obligations, and that a small business covered only because it is a reporting entity need only cover those activities in its policy. You do not need to provide information in a collection notice where that would be inconsistent with tipping-off obligations.9 OAIC AML/CTF Act s 123 The OAIC publishes a template collection notice for reporting entities.

10. Particulars, not copies. The OAIC says the AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents. It says to take reasonable steps to destroy or de-identify copies once no longer needed, and to keep the details you need: for example the name, date of birth, address, document number and expiry, the type of document, what you did and the outcome of verification.9 OAIC More in AML tranche 2 and the Privacy Act.

Dated: 10 December 2026

11. Automated decisions. From 10 December 2026, if you have arranged for a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and personal information about the individual is used in its operation, your privacy policy must describe:10 POLA Act s 2

  • the kinds of personal information used in the operation of those programs;
  • the kinds of decisions made solely by those programs;
  • the kinds of decisions for which a program does something substantially and directly related to making the decision.

It applies to decisions made after the rule commences on that day, even if the program was set up earlier. List each tool, the decision it affects and the data it uses. See automated-decision disclosure.

Proposed, not law

12. Watch the exposure draft; plan on the law as it stands. On 31 August 2026 the Attorney-General's Department released an exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 for consultation; submissions closed on 18 September 2026. The department says the Bill "remains subject to further consideration by government".11 AGD The draft does not repeal the $3 million small business exemption. As at 25 September 2026, no Bill removing the exemption has been introduced to Parliament.

Work through it

Do items 1 to 10 first, then item 11 before 10 December 2026. Penalties: Privacy Act penalties 2026.

For a sector's AML/CTF obligations, see the AML/CTF kit and the sector pages for accountants, real estate and conveyancers. More in the Privacy Act section. Every source we use: sources.

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. Dollar amounts worked out from penalty units are our arithmetic. OAIC and Attorney-General's Department pages are guidance, not law, and open in a new window.

  1. Privacy Act 1988 ss 6C(1), 6D(1) and 6D(4), compilation No. 104 (C2026C00227). legislation.gov.au/C2004A03712/latest/text

  2. Privacy Act 1988 s 6E(1A).

  3. Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.2 to 1.4, APP 3.2, APP 5.1 and 5.2, APP 8.1, APP 11.1 and 11.2.

  4. Privacy Act 1988 ss 13K(1) and (4) and 80UB; Regulatory Powers (Standard Provisions) Act 2014 s 82(5)(a) (body corporate: 5 times). Penalty unit $364 for conduct on or after 1 July 2026: Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424). Dollar amounts are our arithmetic.

  5. OAIC, "Privacy compliance sweep to put privacy policies under the spotlight", media release, 9 December 2025. Guidance, not law. oaic.gov.au

  6. OAIC, "OAIC releases regulatory action priorities for 2025-26". Guidance, not law. oaic.gov.au

  7. Privacy Act 1988 ss 26WE, 26WH, 26WK and 26WL (Part IIIC, Notifiable Data Breaches).

  8. Privacy Act 1988 Schedule 2, clause 7(1); commenced 10 June 2025 (compilation endnotes).

  9. OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026. Guidance, not law. oaic.gov.au

  10. Privacy and Other Legislation Amendment Act 2024 (C2024A00128), assented to 10 December 2024: Schedule 1, items 87 to 89 (APP 1.7 to 1.9), commencing 10 December 2026 under s 2(1), table item 7. legislation.gov.au/C2024A00128/latest/text

  11. Attorney-General's Department, "Privacy reform: consultation on exposure draft legislation", and the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026. An exposure draft is not law. consultations.ag.gov.au

Questions

What do I do first?

The items already in force: a current privacy policy, collection notices, and a data breach plan that can meet the 30-day assessment rule in s 26WH. If you are an AML/CTF reporting entity, add collection notices for customer due diligence and keep the identity details you need rather than copies of the documents, as the OAIC's guidance for reporting entities recommends.

What is dated?

From 10 December 2026, if a computer program makes, or does something substantially and directly related to making, decisions that could significantly affect individuals, and it uses their personal information, your privacy policy must describe the kinds of information and decisions involved (APP 1.7 and 1.8, inserted by the Privacy and Other Legislation Amendment Act 2024).

What is not law?

Removing the $3 million small business exemption. It is not in the Act, and the exposure draft Bill the Attorney-General's Department released on 31 August 2026 does not repeal it. An exposure draft is a consultation document, not a Bill before Parliament.