Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227 (compilation date 4 June 2026)
s 6D(1) the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law
The short answer
The Privacy Act binds "organisations", and a small business operator is not an organisation.1 s 6C(1) So a business with annual turnover of $3,000,000 or less is generally outside the Act. For accounting practices, real estate agencies, conveyancers and legal practices, three things often change that:
- AML/CTF. If you are a reporting entity, the Act applies to your AML/CTF activities whatever your turnover.2
- Tax file numbers. If you hold tax file number information, the tax file number rules bind you, and the Notifiable Data Breaches scheme covers that information.3
- The statutory tort. A business of any size can be sued for a serious invasion of privacy. The tort has no turnover threshold.4
The turnover test
A business is a small business if its annual turnover for the previous financial year is $3,000,000 or less.5 s 6D(1) If the business was not carried on at any time in the previous financial year, the test uses the current year.5 s 6D(2)
Annual turnover is the total earned in the year in the course of the business from sales of goods and services, commissions, repair and service income, rent, leasing and hiring income, government bounties and subsidies, interest, royalties and dividends, and other operating income.6 s 6DA(1) It is not profit.
A small business operator is an individual, body corporate, partnership, unincorporated association or trust that carries on one or more small businesses and no business that is not small.5 s 6D(3) Two rules catch businesses that expect to be exempt:
- Once over, always over. You are not a small business operator if a business you carry on has had annual turnover of more than $3,000,000 for any financial year that ended after you started it (or after the section commenced, if later).7 s 6D(4)(a) A later fall in turnover does not restore the exemption.
- Related companies. A body corporate is not a small business operator if it is related to a body corporate that carries on a business that is not small.8 s 6D(9)
The cases in s 6D(4)
Even under the threshold, you are not a small business operator if any of these applies:7
| Paragraph | You are covered if you | Notes |
|---|---|---|
| (a) | have had a business with annual turnover over $3,000,000 in a financial year | See "once over, always over" above |
| (b) | provide a health service to another individual and hold any health information, other than in an employee record | Both parts must be true |
| (c) | disclose personal information about another individual to anyone else for a benefit, service or advantage | Not if you disclose with the individual's consent, or as required or authorised by or under legislation (s 6D(7)) |
| (d) | provide a benefit, service or advantage to collect personal information about another individual from anyone else | Not if you collect with consent, or as required or authorised by or under legislation (s 6D(8)) |
| (e) | are a contracted service provider for a Commonwealth contract, whether or not you are a party to it | Commonwealth contracts only |
| (f) | are a credit reporting body |
Paragraphs (b) to (d) do not count things done otherwise than in the course of a business you carry on. For an individual, the thing must also be done only for personal, family or household affairs.9 s 6D(5) s 6D(6)
What does not count on its own
Some things are often said to end the exemption but are not in s 6D(4):7
- Holding sensitive information. Holding identity documents, biometric information or other sensitive information is not one of the listed cases. The health case needs both a health service and health information.
- Working for a bigger client. Supplying services to a business that is covered by the Act is not a listed case. Only a contracted service provider for a Commonwealth contract is.
- Your profession. No listed case turns on being an accountant, agent, conveyancer or lawyer.
Other ways the Act reaches a small business
Section 6E treats some small business operators as organisations, for some or all of what they do:10
- a reporting entity, or authorised agent of one, under the AML/CTF Act, for its AML/CTF activities (Privacy Act s 6E(1A)), covered below;
- a protected action ballot agent under the Fair Work Act 2009, for the ballot;
- an association of employees registered or recognised under the Fair Work (Registered Organisations) Act 2009;
- a business accredited under the consumer data right, for personal information that is not CDR data;
- a small business operator, act or practice prescribed by regulations.
The OAIC also lists operating a residential tenancy database, and handling tax file numbers, among the reasons a small business may have privacy obligations.11 OAIC
Separately, anyone who holds a record containing tax file number information is a file number recipient and must not breach the tax file number rules.3 s 11(1) s 18 The Notifiable Data Breaches scheme applies to that information.3 s 26WE(1) Accounting practices that lodge returns for clients will usually hold it.
A small business can also choose to be treated as an organisation. The choice is made in writing to the Commissioner and entered on a public register.12 s 6EA
If you are an AML/CTF reporting entity
From 1 July 2026 the AML/CTF Act applied to listed services provided by real estate agencies, conveyancers, legal practices and accountants. Whether you are captured depends on the service, not your job title: see Is my business a reporting entity?
If a small business operator is a reporting entity because of something done in the course of its small business, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations and Rules as if it were an organisation.2 s 6E(1A)
The OAIC's guidance says:11 OAIC
- this includes collecting and storing personal information for customer due diligence, monitoring and reporting, record keeping, and personnel due diligence where the employee records exemption does not apply;
- small businesses are not covered for their non-AML/CTF activities, unless they are covered for another reason;
- you must have a privacy policy and collection notices that explain how you handle personal information for AML/CTF. You need not include information in a collection notice where that would be inconsistent with your tipping off obligations;
- the AML/CTF Act does not require you to keep copies of identity documents. Take reasonable steps to destroy or de-identify copies once no longer needed, and keep the details you need instead, such as the document type and the outcome of verification.
The OAIC publishes a template collection notice for reporting entities. More in AML tranche 2 and the Privacy Act.
The statutory tort reaches everyone
Since 10 June 2025 an individual can sue another person for a serious invasion of privacy, by intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless.4 Sch 2 cl 7(1) It has no turnover threshold. The OAIC says it is "broader in application than the Privacy Act".13 See the statutory tort.
Proposed changes are not law
The small business exemption is still law. On 31 August 2026 the Attorney-General's Department released an exposure draft Bill for consultation. The draft keeps the exemption and re-words the trading cases in s 6D(4)(c) and (d).14 AGD It is a consultation document only; no Bill to change the exemption has been introduced to Parliament. Plan on the law as it stands.
Six questions for your business
- Was annual turnover over $3,000,000 in any financial year since you started, or is a related company's business not small?
- Do you provide a health service and hold health information outside employee records?
- Do you disclose or collect personal information for a benefit, service or advantage, without consent and without legislation requiring or authorising it?
- Are you a contracted service provider for a Commonwealth contract, or a credit reporting body?
- Are you an AML/CTF reporting entity?
- Do you hold tax file numbers?
A yes to any of questions 1 to 4 means the whole Act very likely applies. A yes to question 5 or 6 means parts of the Act apply to those activities or that information. If you are unsure, ask a lawyer.
Where to go next
- Reporting entities: AML tranche 2 and the Privacy Act.
- Everything else in 2026: the Privacy Act section.
- Every source we use: sources.
AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC and Attorney-General's Department pages are guidance, not law. They open in a new window, and linking to them does not mean either body endorses this page.
-
Privacy Act 1988 s 6C(1), definition of "organisation", compilation No. 104 (C2026C00227). legislation.gov.au/C2004A03712/latest/text
-
Privacy Act 1988 s 6E(1A).
-
Privacy Act 1988 ss 11(1), 17, 18 and 26WE(1)(d).
-
Privacy Act 1988, Schedule 2, clause 7(1); compilation endnote 3 ("sch 2: 10 June 2025").
-
Privacy Act 1988 s 6D(1) to (3).
-
Privacy Act 1988 s 6DA(1).
-
Privacy Act 1988 s 6D(4).
-
Privacy Act 1988 s 6D(9).
-
Privacy Act 1988 s 6D(5) and (6).
-
Privacy Act 1988 s 6E(1), (1A), (1B), (1C), (1D) and (2).
-
OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026. Guidance, not law. oaic.gov.au
-
Privacy Act 1988 s 6EA.
-
OAIC, "Statutory tort for serious invasions of privacy". Guidance, not law. oaic.gov.au
-
Attorney-General's Department, "Privacy reform: consultation on exposure draft legislation", and the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, Schedule 2, items 2 to 6. An exposure draft is not law. consultations.ag.gov.au