
"Australia's Privacy Act reform: what passed, what's drafted, and where the small-business exemption stands in 2026"
Australia's Privacy Act reform: what passed, what's drafted, and where the small-business exemption stands in 2026
The Privacy Act 1988 was written before the smartphone. Two reform tranches later, the pieces are finally moving — one lot already in force, another sitting in an exposure draft that closed submissions in September 2026. Here's what's actually law, what's only a proposal, and what happened to the small-business exemption everyone assumed was doomed.
Status note: legislative positions below were checked on 5 October 2026. Nothing in the second tranche is law yet.
Tranche 1: passed, and largely live
The Privacy and Other Legislation Amendment Act 2024 passed in November 2024 and its headline measures have commenced. The most useful one for individuals is the statutory tort for serious invasions of privacy, in force since 10 June 2025. For the first time, Australians can sue a person or organisation directly in court for a serious invasion of privacy — an intrusion upon seclusion or misuse of their information — where they had a reasonable expectation of privacy. Crucially, the tort is broader than the Privacy Act itself: it reaches individuals and entities the Act's coverage rules don't touch. Remedies include damages, injunctions and ordered apologies, and proceedings must generally start within one year of becoming aware of the invasion or three years after it occurred. (OAIC — statutory tort, Dentons)
Tranche 1 also brought enhanced OAIC enforcement powers (new civil penalty provisions commenced 11 December 2024), mandatory disclosure of automated decision-making in privacy policies, and a Children's Online Privacy Code — the OAIC's exposure draft of which went out for consultation on 31 March 2026, with submissions due in June. (Helios Salinger tracker)
Tranche 2: exposure draft, not law
On 31 August 2026, Attorney-General Michelle Rowland released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 plus a consultation paper; submissions closed on 18 September 2026. This is the ambitious half of the 2023 Privacy Act Review's 116 proposals. (Attorney-General's Department consultation, A&O Shearman)
What the draft Bill would do:
- Replace the collection and use rules with a "fair and reasonable" test, assessed against seven legislated factors, with fresh consent requirements for sensitive information and for "trading" personal information.
- Cut breach notification to 72 hours for eligible data breaches, and impose positive duties to maintain breach response systems and mitigate harm.
- Add a right of erasure — but only for "large digital platforms" meeting a revenue or user threshold (A$500 million group revenue or 2.5 million average monthly Australian users).
- Introduce a controller/processor framework so responsibility sits clearly somewhere instead of everywhere.
Status: exposure draft. It has been consulted on; it has not been introduced into Parliament, let alone passed. Anything you read treating these rules as operative is ahead of the law.
The small-business exemption survives — for now
The $3 million turnover exemption has kept most small businesses outside the Privacy Act since 2002. Tranche 2's draft does not remove it, and it leaves the employee records exemption alone too. There is also no direct right of action beyond the tranche-1 tort. Whether that survives political pressure — after breach years like 2025's record 1,205 notifications, much of it from small health and education providers — is an open question for the parliamentary stage. (A&O Shearman summary)
What this means if you're an individual
The change you can use today is the tort: if a person or company seriously invades your privacy, you have a court route that didn't exist before mid-2025. If you're a business, assume the "fair and reasonable" test and 72-hour notification arrive in some form, and that smaller entities stay exempt at first but not necessarily forever. We track the enforcement side — the OAIC's new teeth in action — in our piece on data breach notifications and OAIC enforcement, and the practical hardening angle in why degoogled phones matter in 2026. If you're reducing the data trail you expose in the first place, a FIDO2 hardware key takes password-based breach exposure mostly off the table.
This article is general information, not legal advice.