The short answer

Turning over $3 million or less keeps many businesses outside the Privacy Act, but not all of them. You are covered anyway if you provide a health service, trade in personal information, work as a contracted service provider to the Australian Government, or are a reporting entity under the anti-money laundering laws, which now includes accountants who provide designated services.

Three obligations ignore turnover altogether: the rules protecting tax file numbers, the Victorian Health Records Act, and the statutory tort for serious invasions of privacy.

Most businesses of 5 to 30 staff turn over less than $3 million, and many owners have been told, reasonably, that the Privacy Act does not apply to them. For a lot of them that is right. For more than you might expect, it is not, and the records that change the answer are sitting in payroll and client files right now.

Where the exemption stops

The Privacy Act's Australian Privacy Principles apply to businesses with annual turnover over $3 million. Below that, the OAIC lists businesses that are covered regardless of turnover. The ones most likely to catch a business like yours:

  • Health service providers. Any business that provides a health service and holds health information, however small.
  • Trading in personal information. Collecting or disclosing personal information for a benefit, service or advantage, such as buying or selling contact lists.
  • Contracted service providers to the Australian Government. If you deliver services under a Commonwealth contract, the Act follows the contract.
  • Reporting entities under the anti-money laundering laws. This one is new for many practices. The regime expanded on 1 July 2026 to accountants who provide designated services, and reporting entities are on the OAIC's list.
  • Related businesses. A small business related to a larger body corporate that is covered, plus any business that has chosen to opt in.

The OAIC list has several more categories, from credit reporting bodies to residential tenancy databases. If any line on it describes you, the whole Act applies, including the notifiable data breach scheme.

Three obligations that ignore turnover

Even a business the Act does not cover carries these.

Tax file numbers. Every employer that collects a TFN declaration holds tax file numbers. The Tax Practitioners Board notes that businesses receiving TFNs must protect them, and that a data breach involving TFNs is covered by the notifiable data breach scheme whatever your turnover. That makes your payroll records a privacy obligation even if nothing else is.

Health information in Victoria. The Health Records Act 2001 applies to any organisation that handles health information in Victoria, and the Victorian Department of Health is explicit that there is no small business exemption. It lists employers among the organisations it covers, so staff health information, such as medical certificates and workers compensation records, counts.

The privacy tort. Since 10 June 2025, individuals can sue for a serious invasion of privacy, meaning intrusion into their private life or misuse of information about them, where it was intentional or reckless. There is no turnover threshold. The exemptions cover journalism, government bodies, law enforcement and intelligence agencies, not private businesses.

What to do about it

  1. Check the OAIC list carefully. Especially if you are an accounting practice providing designated services, a health-adjacent business, or a Commonwealth supplier. If you are covered, you need a proper privacy policy and a breach response plan.
  2. Find where tax file numbers and health information live. Payroll software is usually fine. The risk is the copies: TFN declarations in an inbox, medical certificates in a shared folder, scans on a desktop.
  3. Restrict who can reach them. Payroll and HR records should sit somewhere only the people who need them can open, protected by multi-factor authentication.
  4. Plan for a breach before you have one. A breach involving tax file numbers starts the 30-day assessment clock even if the rest of the Act does not apply to you.

What is not changing, yet

The Government released a draft Privacy Act bill on 31 August 2026. It proposes notifying the OAIC within 72 hours of a breach for businesses the Act covers, but it leaves the small business exemption in place. It is a draft, not law, so the position above is the position today.

For every obligation by turnover and industry, including the Victorian ones most businesses miss, see our guide to which compliance obligations apply to your business.

Where we fit

We are not lawyers, and your adviser should confirm which categories apply to you. Our part is the technical side: finding where sensitive records sit, locking down who can reach them, and keeping the evidence that you did. That work is part of AgileSECURE. If you would rather talk it through, start with a conversation.

Frequently asked questions

Does the Privacy Act apply to a business turning over less than $3 million?
Often not, but check the exceptions. The OAIC lists small businesses that are covered regardless of turnover, including health service providers, businesses that trade in personal information, contracted service providers to the Australian Government, and reporting entities under the anti-money laundering laws.
We are an accounting practice under $3 million. Are we covered now?
Possibly. The anti-money laundering regime expanded to accountants who provide designated services on 1 July 2026, and reporting entities under those laws are on the OAIC's list of small businesses the Privacy Act covers. Confirm your position with your adviser.
Which privacy rules apply to every business?
Three stand out: the rules protecting tax file numbers, which cover every business that receives them including employers; the Victorian Health Records Act, which applies to any organisation handling health information in Victoria; and the statutory tort for serious invasions of privacy, which has no small business exemption.
Is the small business exemption being removed?
Not in the draft Privacy Act bill released on 31 August 2026, which leaves it in place. That draft is not law yet, so this is the position today.
What should a small business do first?
Check the OAIC categories carefully, then find where tax file numbers and any health information sit in your systems and who can reach them. Those are the records that bring obligations even when the main Act does not apply.