A small conveyancing firm that was fully exempt from the Privacy Act on 30 June woke up on 1 July with new obligations attached to its client files, and almost certainly hasn’t been told. On 1 July 2026 the Act reached tens of thousands of firms like it. The change did not arrive as a privacy reform at all. It came in through the anti-money-laundering laws, and it works by switching off the exemption that has kept small businesses out of the Privacy Act for a generation. If you run a law practice, an accounting firm, a conveyancer or a real estate agency, there is a good chance you are now in scope for the first time.

We have been running a series on the standards and rules Australian businesses keep getting asked about, covering ISO 27001, ISO 42001 and the ASD’s 2026 AI guidance. The Privacy Act belongs on that list now, because the ground under it just moved.

What changed on 1 July 2026?

The trigger is the second tranche of Australia’s anti-money-laundering and counter-terrorism-financing reforms, which commenced on 1 July 2026. Those reforms extend AML/CTF obligations to a group the sector calls designated non-financial businesses and professions. In plain terms: real estate agents, lawyers and conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones.

The early coverage mostly skipped the privacy consequence. When one of those firms becomes a reporting entity, a provision of the Privacy Act (section 6E(1A)) deems the Act to apply to it for the personal information it handles in connection with its AML/CTF obligations, regardless of the firm’s size. The small business exemption, which normally frees a business turning over $3 million or less from the Australian Privacy Principles, does not apply to that data.

The data caught is the ordinary furniture of the work: identity documents, source-of-funds records, client due-diligence files that now sit under the Australian Privacy Principles. The OAIC estimates the change affects more than 100,000 small businesses, which makes it the single biggest expansion of Privacy Act coverage in more than two decades.

So the small business exemption is gone?

No, and this is where a lot of the online commentary has it wrong. Plenty of posts are telling small businesses “the $3 million exemption has been removed.” That is not what happened, and acting on the wrong version wastes money in one direction or leaves you exposed in the other.

The general small business exemption is still law as of mid-2026. What the AML/CTF reforms did was carve a hole in it, so the exemption no longer covers AML/CTF-related information handling by the newly regulated firms. If you are one of those firms, the exemption is off for that slice of your data and on for the rest. If you are not, it is unchanged for now.

“For now” is carrying weight in that sentence. In its response to the Privacy Act Review, the Government agreed in principle to remove the small business exemption altogether, conditional on consulting business first and softening the landing. That broader removal is expected in a further tranche of Privacy Act reform that has not yet been introduced to Parliament. The direction of travel is not in doubt. The exemption is being narrowed now and is likely to disappear later, so a business relying on it is relying on something with a use-by date.

What else is changing in the Privacy Act

The 1 July expansion sits on top of a bigger overhaul. The Privacy and Other Legislation Amendment Act 2024 passed in late 2024 and rolls out in stages, and three of its changes matter to an ordinary business.

A statutory tort for serious invasions of privacy, live since 10 June 2025. For the first time, an individual can sue a business directly for a serious invasion of their privacy, either by intruding on their seclusion or by misusing their information. They do not have to prove they lost money, and they do not have to go through the regulator. It widens your exposure, because it hands a right of action to the people whose data you hold rather than leaving enforcement to the OAIC alone.

Automated decision-making transparency, from 10 December 2026. If you use a computer program to make, or to substantially help make, a decision that could significantly affect someone, your privacy policy has to spell out what personal information those programs use, which decisions they make on their own, and which ones they shape for a human to sign off. The rule asks for nothing more. No ban on automated decisions, no mandated human-review process, no fresh consent, whatever the louder headlines claim. Writing the paragraph is easy. Writing it honestly means knowing every place automation already touches a decision about a person: the tool that screens CVs, the rule that scores or prices a client, the intake system that triages and rejects. That is more places than most firms would guess, and it is the one obligation here a lawyer will flag and then hand straight back, because finding it is not a legal question but a technical one about what your software is quietly doing. The clock runs out in December. It connects, too, to ISO 42001 and the wider question of who owns the AI you switched on last year.

A tougher penalty regime and a regulator with more teeth. The OAIC can now issue infringement notices for administrative failures, such as a privacy policy that does not meet the standard, without taking anyone to court. More on the numbers below.

A timeline of Australian Privacy Act reform from 2024 to 2026: the 2024 Amendment Act receiving assent in December 2024, the statutory tort commencing in June 2025, the AML/CTF Tranche 2 expansion of coverage on 1 July 2026, and the automated decision-making transparency rules and Children’s Online Privacy Code arriving on 10 December 2026

Does the Privacy Act apply to your business now?

For years the rule of thumb was simple. Under $3 million turnover, you were probably exempt. That rule of thumb is now unreliable, because scope has shifted from how big you are to what you do. Treat the following as triggers that put you in scope or close to it:

  • You provide a designated service under the AML/CTF regime, which captures a lot of everyday legal, conveyancing, accounting, real estate and trust-and-company work. New since 1 July 2026, it overrides the small business exemption for the data involved.
  • You already turn over more than $3 million a year, in which case you have been covered all along and the ADM and penalty changes still apply to you.
  • You trade in personal information, provide a health service, or are a contractor to the Commonwealth, all of which have long pulled otherwise-small businesses into the Act.
  • You use automated tools in decisions about people, in which case the December transparency rules reach you even if nothing else here does.

If more than one of those describes you, the question is no longer whether the Privacy Act applies but how far behind you are. And even if none of them does yet, the exemption you are leaning on is one that the Government has already said it intends to remove.

What the penalties look like now

The numbers are built to be taken seriously by boards, not just compliance teams. There are three tiers:

  • Serious or repeated interference with privacy carries a maximum of the greater of $50 million, three times the benefit obtained from the conduct, or 30% of adjusted turnover for the relevant period. That headline number is reserved for the worst cases, such as a major data scandal.
  • A mid-tier now covers interferences that are not serious, closing the old all-or-nothing gap where the regulator either threw the book or did nothing.
  • Infringement notices let the OAIC penalise administrative failures, like a non-compliant privacy policy, without litigation. The amounts are far smaller than the headline, and far more likely to land on an ordinary business.

Layered over all of that is the statutory tort. A regulator has finite capacity and picks its cases; an aggrieved individual with a direct right to sue does not work to the same constraints. For most businesses, that shift, from one regulator to many potential litigants, matters more than any single penalty tier.

What to do about it

You do not need a privacy team. You need an owner and a short sequence of decisions, most of which a small business can make without major spend.

  1. Work out if you are in scope. Check whether you provide an AML/CTF designated service, and if you do, confirm your AUSTRAC enrolment and accept that the small business exemption no longer covers that client data. Make the call deliberately rather than assuming you are still exempt.
  2. Map where personal information lives. You cannot protect or disclose what you have not inventoried. List what you collect, why, where it is stored, who it is shared with, and how long you keep it. AML/CTF record-keeping runs to seven years, which raises the stakes on getting storage and security right.
  3. Fix the privacy policy and collection notices. Make the policy compliant now, and by 10 December 2026 add the automated-decision disclosures if any tool makes or shapes decisions about people. Getting those disclosures right forces the inventory in step two.
  4. Get the security fundamentals underneath it solid. The Australian Privacy Principles require you to protect the information you hold, which is the same baseline work that ISO 27001 and the Essential Eight describe, and the same work a notifiable data breach would test in public.
  5. Name someone accountable. A responsibility shared across the whole firm is one nobody actually holds. Give privacy an owner with the authority to make the calls before an incident makes them for you.

The safe assumption now

The Privacy Act has stopped being a big-company concern. AML/CTF reform brought a new wave of small firms into scope on 1 July, the automated-decision rules land in December, and the Government has already said the small business exemption is going. A firm still betting on that exemption is betting on something with a stated expiry. The ones that get caught short will be the ones that wait for a breach notification, an OAIC infringement notice or a client’s lawyer to make the question urgent.

The reason this sits undone in a lot of firms is not that anyone disagrees it matters. It is that privacy, data security and the algorithms tucked inside the software you bought answer to no one in particular. The managing partner assumes the office manager has it, the office manager assumes the IT provider does, and the provider assumes it was never their call. It usually wasn’t; keeping the lights on and owning a compliance obligation are different jobs. You did not start a law or accounting practice to become its privacy officer, and you should not have to read three tranches of legislation to work out whether you are exposed. A lawyer can confirm the obligation exists. What a lawyer cannot do is walk your systems and find where the in-scope client data actually lives and where automation is already making calls about people. Our Security Assessments do exactly that, and a Fractional CIO or CISO then owns the job, so it stops being the thing everyone assumes someone else has.

The obligation itself is not complicated. Know what personal information you hold, keep it safe, and describe how you use it accurately. What changed in 2026 is who gets to hold you to it. The regulator can now fine you for the small failures without going to court, and since June an individual can take you there directly. The list of people entitled to make you prove it has never been longer. The firms that come through this cleanly will not be the biggest. They will be the ones that checked in July rather than finding out in December.

Frequently asked questions

Not in general. The exemption that frees most businesses turning over $3 million or less from the Australian Privacy Principles is still on the books as of mid-2026. What changed on 1 July 2026 is narrower and specific. Firms newly regulated under the AML/CTF reforms, such as law practices, accountants, conveyancers and real estate agents, are now covered by the Privacy Act for the personal information they handle for anti-money-laundering purposes, even if they would otherwise be exempt. The broader removal of the exemption has been agreed in principle by the Government but has not yet been legislated.

Very possibly, for the first time. If your firm provides a “designated service” under the AML/CTF regime, which captures a lot of ordinary legal, accounting, conveyancing and real estate work, you became a reporting entity on 1 July 2026 and the small business exemption no longer shields the client data you collect for that work. The OAIC estimates the change affects more than 100,000 small businesses. Whether it catches you turns on the services you provide, not your size, so the safe move is to check rather than assume you are still exempt.

From 10 December 2026, if you use a computer program to make, or to substantially help make, a decision that could significantly affect someone, your privacy policy has to say so. Three things go in the policy: the kinds of personal information the program uses, the kinds of decisions it makes on its own, and the kinds it shapes for a person to sign off. The rule asks for nothing else. There is no ban, no mandated human-review process, and no requirement to collect fresh consent. The hard part is knowing every place automation already touches a decision about a person.

There are three tiers. For serious or repeated interference with privacy, the maximum is the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover for the relevant period. A newer mid-tier covers interferences that are not serious, and the regulator can now issue infringement notices for administrative failures like a non-compliant privacy policy without going to court. Separately, since June 2025 individuals can sue directly for a serious invasion of privacy, which puts exposure in the hands of the people affected rather than only the regulator.

It is a new right, in force since 10 June 2025, that lets an individual take a business to court directly for a serious invasion of their privacy, either by intruding on their seclusion or by misusing their information. They do not have to prove financial loss, distress is enough, and they do not have to go through the OAIC first. Damages for non-economic loss are capped, with the cap indexed each year to the defamation limit. For a business it means data mishandling is no longer only a regulator problem; it is now something an affected person can litigate on their own.

Privacy & compliance review

Not sure whether the Privacy Act now applies to you?

Book a free Discovery Call with InnovateX Solutions. The article covers the rules; the call tells you which of your data sets are in scope, where automation is making calls about people, and the shortest path from there.

Senior-led and Australian-owned. We'll map your client data against the Australian Privacy Principles, show you where automated decisions are hiding before the December deadline, and give you a phased plan you can resource.