Privacy Act guide · general information, not legal advice

Does the Privacy Act apply to your small business?

A business with annual turnover of $3,000,000 or less is usually outside the Privacy Act 1988. Usually is not always. This guide sets out the turnover test, the cases that take a business outside the exemption, and the AML/CTF rule that now brings many small practices in.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227 (compilation date 4 June 2026)

s 6D(1) the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

The short answer

The Privacy Act binds "organisations", and a small business operator is not an organisation.1 s 6C(1) So a business with annual turnover of $3,000,000 or less is generally outside the Act. For accounting practices, real estate agencies, conveyancers and legal practices, three things often change that:

  • AML/CTF. If you are a reporting entity, the Act applies to your AML/CTF activities whatever your turnover.2
  • Tax file numbers. If you hold tax file number information, the tax file number rules bind you, and the Notifiable Data Breaches scheme covers that information.3
  • The statutory tort. A business of any size can be sued for a serious invasion of privacy. The tort has no turnover threshold.4

The turnover test

A business is a small business if its annual turnover for the previous financial year is $3,000,000 or less.5 s 6D(1) If the business was not carried on at any time in the previous financial year, the test uses the current year.5 s 6D(2)

Annual turnover is the total earned in the year in the course of the business from sales of goods and services, commissions, repair and service income, rent, leasing and hiring income, government bounties and subsidies, interest, royalties and dividends, and other operating income.6 s 6DA(1) It is not profit.

A small business operator is an individual, body corporate, partnership, unincorporated association or trust that carries on one or more small businesses and no business that is not small.5 s 6D(3) Two rules catch businesses that expect to be exempt:

  • Once over, always over. You are not a small business operator if a business you carry on has had annual turnover of more than $3,000,000 for any financial year that ended after you started it (or after the section commenced, if later).7 s 6D(4)(a) A later fall in turnover does not restore the exemption.
  • Related companies. A body corporate is not a small business operator if it is related to a body corporate that carries on a business that is not small.8 s 6D(9)

The cases in s 6D(4)

Even under the threshold, you are not a small business operator if any of these applies:7

Privacy Act 1988 s 6D(4): who is not a small business operator
Paragraph You are covered if you Notes
(a) have had a business with annual turnover over $3,000,000 in a financial year See "once over, always over" above
(b) provide a health service to another individual and hold any health information, other than in an employee record Both parts must be true
(c) disclose personal information about another individual to anyone else for a benefit, service or advantage Not if you disclose with the individual's consent, or as required or authorised by or under legislation (s 6D(7))
(d) provide a benefit, service or advantage to collect personal information about another individual from anyone else Not if you collect with consent, or as required or authorised by or under legislation (s 6D(8))
(e) are a contracted service provider for a Commonwealth contract, whether or not you are a party to it Commonwealth contracts only
(f) are a credit reporting body

Paragraphs (b) to (d) do not count things done otherwise than in the course of a business you carry on. For an individual, the thing must also be done only for personal, family or household affairs.9 s 6D(5) s 6D(6)

What does not count on its own

Some things are often said to end the exemption but are not in s 6D(4):7

  • Holding sensitive information. Holding identity documents, biometric information or other sensitive information is not one of the listed cases. The health case needs both a health service and health information.
  • Working for a bigger client. Supplying services to a business that is covered by the Act is not a listed case. Only a contracted service provider for a Commonwealth contract is.
  • Your profession. No listed case turns on being an accountant, agent, conveyancer or lawyer.

Other ways the Act reaches a small business

Section 6E treats some small business operators as organisations, for some or all of what they do:10

  • a reporting entity, or authorised agent of one, under the AML/CTF Act, for its AML/CTF activities (Privacy Act s 6E(1A)), covered below;
  • a protected action ballot agent under the Fair Work Act 2009, for the ballot;
  • an association of employees registered or recognised under the Fair Work (Registered Organisations) Act 2009;
  • a business accredited under the consumer data right, for personal information that is not CDR data;
  • a small business operator, act or practice prescribed by regulations.

The OAIC also lists operating a residential tenancy database, and handling tax file numbers, among the reasons a small business may have privacy obligations.11 OAIC

Separately, anyone who holds a record containing tax file number information is a file number recipient and must not breach the tax file number rules.3 s 11(1) s 18 The Notifiable Data Breaches scheme applies to that information.3 s 26WE(1) Accounting practices that lodge returns for clients will usually hold it.

A small business can also choose to be treated as an organisation. The choice is made in writing to the Commissioner and entered on a public register.12 s 6EA

If you are an AML/CTF reporting entity

From 1 July 2026 the AML/CTF Act applied to listed services provided by real estate agencies, conveyancers, legal practices and accountants. Whether you are captured depends on the service, not your job title: see Is my business a reporting entity?

If a small business operator is a reporting entity because of something done in the course of its small business, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations and Rules as if it were an organisation.2 s 6E(1A)

The OAIC's guidance says:11 OAIC

  • this includes collecting and storing personal information for customer due diligence, monitoring and reporting, record keeping, and personnel due diligence where the employee records exemption does not apply;
  • small businesses are not covered for their non-AML/CTF activities, unless they are covered for another reason;
  • you must have a privacy policy and collection notices that explain how you handle personal information for AML/CTF. You need not include information in a collection notice where that would be inconsistent with your tipping off obligations;
  • the AML/CTF Act does not require you to keep copies of identity documents. Take reasonable steps to destroy or de-identify copies once no longer needed, and keep the details you need instead, such as the document type and the outcome of verification.

The OAIC publishes a template collection notice for reporting entities. More in AML tranche 2 and the Privacy Act.

The statutory tort reaches everyone

Since 10 June 2025 an individual can sue another person for a serious invasion of privacy, by intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless.4 Sch 2 cl 7(1) It has no turnover threshold. The OAIC says it is "broader in application than the Privacy Act".13 See the statutory tort.

Proposed changes are not law

The small business exemption is still law. On 31 August 2026 the Attorney-General's Department released an exposure draft Bill for consultation. The draft keeps the exemption and re-words the trading cases in s 6D(4)(c) and (d).14 AGD It is a consultation document only; no Bill to change the exemption has been introduced to Parliament. Plan on the law as it stands.

Six questions for your business

  1. Was annual turnover over $3,000,000 in any financial year since you started, or is a related company's business not small?
  2. Do you provide a health service and hold health information outside employee records?
  3. Do you disclose or collect personal information for a benefit, service or advantage, without consent and without legislation requiring or authorising it?
  4. Are you a contracted service provider for a Commonwealth contract, or a credit reporting body?
  5. Are you an AML/CTF reporting entity?
  6. Do you hold tax file numbers?

A yes to any of questions 1 to 4 means the whole Act very likely applies. A yes to question 5 or 6 means parts of the Act apply to those activities or that information. If you are unsure, ask a lawyer.

Where to go next

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC and Attorney-General's Department pages are guidance, not law. They open in a new window, and linking to them does not mean either body endorses this page.

  1. Privacy Act 1988 s 6C(1), definition of "organisation", compilation No. 104 (C2026C00227). legislation.gov.au/C2004A03712/latest/text

  2. Privacy Act 1988 s 6E(1A).

  3. Privacy Act 1988 ss 11(1), 17, 18 and 26WE(1)(d).

  4. Privacy Act 1988, Schedule 2, clause 7(1); compilation endnote 3 ("sch 2: 10 June 2025").

  5. Privacy Act 1988 s 6D(1) to (3).

  6. Privacy Act 1988 s 6DA(1).

  7. Privacy Act 1988 s 6D(4).

  8. Privacy Act 1988 s 6D(9).

  9. Privacy Act 1988 s 6D(5) and (6).

  10. Privacy Act 1988 s 6E(1), (1A), (1B), (1C), (1D) and (2).

  11. OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026. Guidance, not law. oaic.gov.au

  12. Privacy Act 1988 s 6EA.

  13. OAIC, "Statutory tort for serious invasions of privacy". Guidance, not law. oaic.gov.au

  14. Attorney-General's Department, "Privacy reform: consultation on exposure draft legislation", and the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, Schedule 2, items 2 to 6. An exposure draft is not law. consultations.ag.gov.au

Questions

What is the turnover test?

A business is a small business if its annual turnover for the previous financial year is $3,000,000 or less (s 6D(1)). A new business uses the current year instead (s 6D(2)). Annual turnover is defined in s 6DA: sales proceeds, commissions, repair and service income, rent, leasing and hiring income, government bounties and subsidies, interest, royalties and dividends, and other operating income earned in the course of the business.

What removes the exemption?

The cases in s 6D(4): turnover over $3,000,000 in any financial year since you began; providing a health service and holding health information (other than in an employee record); disclosing or collecting personal information for a benefit, service or advantage (with exceptions for consent and legislation, s 6D(7) and (8)); being a contracted service provider for a Commonwealth contract; or being a credit reporting body. A body corporate related to a business that is not small is also covered (s 6D(9)). Separately, a small business operator that is an AML/CTF reporting entity is treated as an organisation for its AML/CTF activities (Privacy Act s 6E(1A)).

Can I be sued even if the Act does not apply to my business?

Yes. The statutory tort for serious invasions of privacy in Schedule 2 gives an individual a cause of action against another person. It has no turnover threshold. The OAIC describes it as broader in application than the Privacy Act.