Australia’s Privacy Laws Are Changing Again - What Small Businesses Need To Know

Alex Solo
byAlex Solo10 min read

Australia’s privacy laws are going through another major round of reform, and small businesses should be paying attention.

The latest proposed changes respond to growing concerns around how personal information is collected, used and shared, particularly as technologies such as AI become more common. If introduced, they could bring significant changes around consent, customer data, AI-generated information, direct marketing and data breaches.

Not every small business will be affected in the same way, and many may still fall within the Privacy Act’s small business exemption. However, these reforms could still matter now or in the future, particularly as your business grows or the way you handle personal information changes.

Understanding where the law is heading can help you work out what your current obligations are and what you may need to prepare for next.

What Is Changing Under The Proposed Privacy Reforms?

On 31 August 2026, the Australian Government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 as part of the next stage of its broader Privacy Act reforms.

The changes are still only proposed, so they are not law just yet. However, they give businesses an indication of where Australia’s privacy laws may be heading.

The reforms are designed to strengthen privacy protections and place greater responsibility on how personal information is handled as the digital economy continues to evolve. The broader consultation also looks at emerging technologies, including AI and wearable surveillance technologies such as smart glasses.

For businesses, some of the most important proposals relate to how personal information is collected and used, what counts as valid consent, how customer information can be used or shared for marketing, information generated or inferred through AI, and how businesses respond to data breaches.

There are a number of reforms in the draft, but for small businesses, there is another important question to answer first: does the Privacy Act actually apply to your business?

When Will The New Privacy Rules Start?

Not yet.

The proposed changes are still at the exposure draft stage, which means they could change before anything becomes law. Consultation opened on 31 August 2026 and closes on 18 September 2026, with feedback set to inform the Government’s final reforms.

So, businesses do not need to start complying with these proposed rules just yet.

However, if your business is already covered by the Privacy Act, your existing obligations still apply.

There are also privacy changes already on the way separately. From 10 December 2026, certain businesses covered by the Privacy Act will need to include information in their Privacy Policies where they use personal information in automated decision-making that could significantly affect an individual’s rights or interests.

This makes it important to distinguish between reforms that have already been passed and the new proposals that are still being considered.

Does The Privacy Act Apply To All Small Businesses?

Not every small business in Australia is currently covered by the Privacy Act.

Generally, businesses with annual turnover of $3 million or less fall within the small business exemption. However, there are exceptions, which means some businesses can be covered regardless of their turnover.

For example, certain health service providers and businesses that trade in personal information may already have Privacy Act obligations.

There are also some newer examples. From 1 July 2026, certain businesses with obligations under the Anti-Money Laundering and Counter-Terrorism Financing regime, including some real estate professionals, lawyers, conveyancers and accountants, must comply with the Privacy Act when handling personal information in connection with those obligations, even if they fall below the usual $3 million threshold.

So, being a “small business” does not automatically mean you are exempt.

If the Privacy Act applies to your business, you may already need to meet requirements around how you collect, store, use and disclose personal information. This can include having an appropriate Privacy Policy that accurately reflects how your business handles personal information.

What Could Change For Small Businesses That Are Covered?

If your small business is already covered by the Privacy Act, this is where the proposed reforms become particularly important.

The changes go beyond simply updating a Privacy Policy. They could affect how you collect customer data, the consent you rely on, how information is used for marketing, what happens when you use AI and how prepared you need to be if something goes wrong.

The reforms would also broaden and clarify what can count as personal information. The definition would move from information “about” an individual to information that “relates to” an identified or reasonably identifiable individual. Certain information, including precise geolocation tracking data and genomic information, would also receive stronger protection as sensitive information.

This could mean businesses need to think beyond obvious details such as a customer’s name, phone number or email address when working out what personal information they actually hold.

Your Use Of Customer Data May Need To Be Fair And Reasonable

One of the biggest proposed changes is a new requirement for the collection, use and disclosure of personal information to be fair and reasonable.

This would put more responsibility on businesses to think about what they are actually doing with customer information, rather than simply whether they have mentioned it somewhere in their legal documents.

For example, a customer might provide their email address so you can send an order confirmation or invoice. If you later want to use that information for something completely different or unexpected, you may need to think more carefully about whether that use is reasonable.

Factors such as what the customer would reasonably expect, why the information is needed and the potential impact on the individual could all become more important. Importantly, consent would not necessarily make an otherwise unfair or unreasonable use acceptable.

For businesses, this could mean taking a closer look at the reason behind collecting customer information in the first place - not simply collecting it because you can.

Consent is another area the reforms are looking to tighten.

Under the proposal, consent would need to be voluntary, informed, current, specific and unambiguous. This could make broad, bundled or unclear consent harder to rely on.

In practice, a customer should have a genuine understanding of what they are agreeing to.

It is also important to remember that having a Privacy Policy is not the same thing as obtaining consent.

Your Privacy Policy explains how your business handles personal information. It does not necessarily mean a customer has actively agreed to every use of their data simply because that use appears somewhere in the policy.

For businesses relying heavily on online forms, sign-ups or digital customer journeys, this could be a good reason to look at how and when consent is actually being obtained.

Marketing With Customer Data Could Become More Important

Customer information is often used for marketing, but the way that information moves between businesses and marketing tools can make things more complicated.

There is a difference between using information you already hold to market your own products and disclosing someone’s personal information to another organisation for marketing purposes.

Under the draft, businesses would generally need consent to trade personal information, subject to certain exceptions. The proposed definition of trading is broader than simply selling a customer database - it can also include disclosing personal information for money, other considerations or direct marketing purposes.

This may be particularly relevant if your business relies on customer databases, third-party advertising platforms or other businesses to carry out marketing.

It does not mean every time you use a marketing platform you are automatically doing something wrong. However, it does mean businesses may need a clearer understanding of what customer information is being shared, who receives it and what they are allowed to do with it.

AI Does Not Sit Outside Privacy Law

AI might feel like a new area of technology, but using it does not mean existing privacy responsibilities disappear.

The proposed reforms would make this connection even clearer by expressly confirming that information generated or derived from other information can amount to a collection of personal information.

For example, your customer might never directly tell you that they are likely to cancel their subscription. However, an AI system analysing their behaviour might reach that conclusion.

The fact that the AI generated that information does not necessarily put it outside privacy law.

Businesses using AI should therefore think about what customer or client information is being uploaded, what the tool does with that information and what new information may be generated from it.

Having an AI Acceptable Use Policy can also help set boundaries around what employees can put into AI tools and how those tools should be used within the business.

Businesses May Need To Take A Closer Look At The Data They Keep

It is easy for customer information to build up over time.

It might sit across old email inboxes, cloud storage, a CRM, accounting software, marketing platforms and different third-party tools - including systems your business no longer regularly uses.

Businesses covered by the Privacy Act already have obligations around securing personal information and destroying or de-identifying information they no longer need. The proposed reforms would strengthen this area further, including by requiring businesses to be able to identify relevant personal information and regularly evaluate whether their security and destruction practices are actually working.

This means privacy compliance is not only about what you collect. It is also about what happens to that information afterwards.

For small businesses, a useful starting point can simply be understanding what information you have, where it is stored, who can access it and why you are still keeping it.

Businesses May Need To Act Faster After A Data Breach

A data breach can already create serious problems for a small business. Under the proposed reforms, businesses covered by the Privacy Act could also have a tighter timeframe to work within.

The draft proposes a 72-hour deadline for notifying the OAIC once a business becomes aware that there are reasonable grounds to believe an eligible data breach has occurred.

Importantly, this does not mean every suspected cybersecurity incident automatically needs to be reported within 72 hours. The existing process for assessing whether an eligible data breach has occurred would still matter.

However, once the reporting obligation is triggered, businesses would have a clear deadline to work within.

This makes having a plan before a breach happens particularly important. You do not want the first few hours after an incident to be spent working out who is responsible, where the affected information is stored or who needs to be contacted.

A Data Breach Response Plan can set out what your business should do if personal information is lost, accessed without authorisation or disclosed incorrectly.

Could The Small Business Exemption Eventually Disappear?

Potentially - but this is not happening under the current proposed reforms.

The Government has previously agreed in principle to remove the Privacy Act’s small business exemption. However, that came with some important conditions, including further assessment of how the change would affect small businesses, what support businesses would need and how their obligations could be made proportionate to the risk involved.

The current 2026 exposure draft does not generally remove the exemption.

So, if your business is exempt today, these new proposals do not suddenly mean you need to comply with every Australian Privacy Principle.

However, it is still worth paying attention.

The Government’s earlier position shows that the small business exemption remains part of the broader privacy reform conversation. Your business can also become subject to the Privacy Act as it grows or changes the activities it carries out.

The OAIC encourages growing businesses to take a privacy by design approach, where privacy is considered from the beginning rather than added later once obligations apply. It also points to the commercial and customer-trust benefits that can come with good privacy practices.

This does not mean every exempt business needs the same privacy compliance program as a large organisation. However, putting sensible privacy practices in place now can make it easier to adapt later.

What Should Small Businesses Do Now?

You do not need to completely overhaul your business because an exposure draft has been released.

A good first step is understanding where your business currently stands.

Start by working out whether the Privacy Act applies to you. If it does, look at how personal information actually moves through your business - what you collect, why you collect it, where it goes, who you share it with and how long you keep it.

Your legal documents should match what happens in practice. For example, your Privacy Policy should reflect the way your business genuinely collects and handles information, rather than relying on generic wording that does not match your systems or processes.

It is also worth understanding the third-party providers that handle personal information on your behalf. The proposed reforms would introduce a clearer controller and processor framework, making the roles of businesses and service providers that process data for them more explicit.

Where another provider processes personal information for your business, a Data Processing Agreement can help set out how that information will be handled, secured and used.

If your business is currently exempt from the Privacy Act, you may not be legally required to meet all of these obligations. However, good privacy practices can still help protect customer information, build trust and make it easier to adapt if your business becomes covered later.

You do not need to change everything overnight, but this is a good time to understand how your business currently handles personal information and where your privacy obligations may be heading.

Need Help With Privacy Compliance?

Privacy obligations can depend on the size of your business, the industry you operate in and what you do with personal information.

If you are unsure whether the Privacy Act applies to your business, or whether your current privacy documents and processes are appropriate, Sprintlaw’s legal experts can help you understand your obligations and put the right protections in place.

If you would like help understanding your privacy obligations, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.