If you run an Australian business, you have probably had an email in the last few months telling you that the Privacy Act's small business exemption disappears on 10 December 2026, that 2.5 million businesses are about to be regulated, and that you should book a compliance audit immediately.

The date is real. Almost everything else in that sentence is not.

We have read a lot of these warnings, mostly published by IT providers, and the pattern is consistent: two entirely separate reforms, one legislated and one still a draft, get merged into a single deadline. The result is businesses buying compliance projects for an obligation that does not exist yet, while ignoring one that has been enforceable since last year.

The short version

  • Law, commencing 10 December 2026: automated decision-making transparency in your privacy policy.
  • Law, already in force since 10 June 2025: a statutory tort letting individuals sue you directly, exemption or not.
  • Not law: removal of the small business exemption. Still an exposure draft.

The claim doing the rounds

The standard version reads something like: "From 10 December 2026, the $3 million small business exemption is removed and approximately 2.5 million Australian businesses must comply with all 13 Australian Privacy Principles."

Removing the exemption is a genuine policy commitment, and it was one of the Attorney-General's Department's agreed responses to the Privacy Act Review. But agreeing to do something is not the same as having done it. The exemption sits in the Privacy Act 1988, and removing it requires amending legislation that, as at September 2026, has not passed.

What exists instead is an exposure draft, the Privacy Amendment (Personal Data Protection) Bill 2026, carrying roughly forty proposals, including a single "fair and reasonable" test for collection, use and disclosure. It was released for public consultation, and that consultation was still open this month. An exposure draft is a proposal the government is asking for comment on. It is not a commencement date.

What is actually law on 10 December 2026

The genuine deadline comes from the Privacy and Other Legislation Amendment Act 2024, which passed in late 2024. Most of it commenced immediately or shortly after. One significant piece was deliberately deferred by 24 months to give organisations time to prepare, and that is the part landing on 10 December 2026: transparency about automated decision-making.

From that date, if you are an APP entity and you use personal information in a computer program to make, or substantially support, a decision that could reasonably be expected to significantly affect an individual's rights or interests, your privacy policy must disclose:

Note the shape of this obligation. It is a disclosure requirement, not a prohibition and not a consent requirement. You are not being told you cannot use automated decision-making. You are being told you have to admit that you do.

Does automated decision-making capture you?

This is where most businesses guess wrong in both directions. "Automated decision-making" sounds like it means a machine learning model, so businesses without a data science team assume it cannot apply. In practice the trigger is much broader, and it is usually satisfied by software you bought rather than software you built.

Three conditions have to line up: personal information is involved, a computer program makes or substantially supports the decision, and the decision could significantly affect someone's rights or interests. Things that routinely qualify:

SystemDecision it drivesLikely in scope?
Recruitment platform with candidate rankingWho progresses to interviewYes, affects employment
Credit or account-application scoringWhether to extend termsYes, affects financial access
Insurance or quoting enginePrice or eligibilityYes
Tenancy or applicant screening toolWho is offered a propertyYes
Fraud or risk engine that blocks accountsAccess to a serviceYes
Marketing segmentationWhich email someone receivesUsually not, low impact
Spam filtering, load balancingNo decision about a personNo

The awkward cases are the ones where a human is nominally in the loop. "Substantially support" is doing real work in that definition. If a system produces a score and a person approves the outcome without meaningfully reviewing the inputs, that is still substantial support. A rubber stamp is not a human decision.

The practical exercise is unglamorous: list every system that touches personal information, and for each one ask what decision it produces and whether that decision changes someone's access to a job, money, housing, a service, or their reputation. Most businesses find between zero and three. Plenty of businesses genuinely find zero, and for them the December date means nothing at all, which is worth knowing before paying for a project.

The change that already happened

Here is the part that gets almost no attention from the same newsletters warning about December, and it is the one we would worry about first.

On 10 June 2025, a statutory tort for serious invasions of privacy came into force. For the first time in Australian law, an individual can sue directly over a serious invasion of privacy.

The significant detail is who it applies to. The tort is not limited to APP entities. It is not switched off by the small business exemption. A business under the $3 million threshold, a contractor, an individual employee: all can be sued directly. To succeed a claimant must establish that they had a reasonable expectation of privacy, that the invasion was serious, and that their privacy interest outweighs any countervailing public interest. They do not need to prove financial loss.

Every business currently relying on the small business exemption is already exposed to direct legal action. That has been true since June 2025.

So the honest framing is close to the opposite of the marketing one. The exemption has not protected you from being sued for over a year. Whether it eventually disappears from the Privacy Act is a question about regulator oversight and the 13 Australian Privacy Principles: a real question, but a second-order one next to the liability that already exists.

What is still only a draft

To be explicit, because the conflation is the whole problem:

ChangeStatusDate
Statutory tort for serious invasions of privacyIn force10 June 2025
Automated decision-making transparencyLegislated, commencing10 December 2026
Children's Online Privacy CodeBeing developed by the OAICIn progress
Removal of the small business exemptionExposure draft onlyNo commencement date
"Fair and reasonable" test for collection and useExposure draft onlyNo commencement date

Will the exemption eventually go? Probably. It has been criticised for years, Australia is an outlier in having it, and the government has committed to removing it. If and when it does, the sensible expectation is a transition period rather than an overnight switch; the policy intent has always been to give small businesses time.

But "probably, eventually, with a transition period" is a very different planning input from "you have until December." One justifies building good habits. The other justifies an emergency budget.

What to actually do between now and December

Our advice to clients has not changed much, because the things worth doing are worth doing regardless of which reforms land.

1. Do the automated decision-making inventory. It is a half-day exercise for most businesses. List systems holding personal information, identify which produce decisions that significantly affect people, and write down the answer. If the answer is "none", document that you checked; that record is the useful artefact.

2. If you do use ADM, update the privacy policy before December. This is a drafting task, not an engineering project. Describe the kinds of information and the kinds of decisions in plain language.

3. Treat the security basics as the real deadline. Australian organisations notified 1,205 data breaches in 2025, an 8% rise on the prior year and the highest annual figure since mandatory reporting began in 2018. Malicious or criminal attacks drove about two-thirds. Ransomware notifications rose 24%. Compromised credentials were the root cause in roughly a quarter of all breaches.

That last statistic is the one to sit with. A quarter of reported breaches trace back to a credential someone obtained and used. Multi-factor authentication on email, remote access and administrative accounts is not a compliance control; it is the single highest-return security change available to most businesses, and it addresses the most common cause of the incidents actually being reported.

4. Have a breach response plan you have read out loud. If the exemption is removed, the Notifiable Data Breaches scheme extends to newly covered businesses, and the clock on an assessment is short. Knowing who calls whom, who can take a system offline, and where the backups are, before you need it, is worth more than a policy document nobody has opened.

5. Be sceptical of December-shaped urgency. If a provider is quoting you for Privacy Act compliance work, a fair question is: which specific obligation, in which Act, commencing on what date? A good provider will answer without hesitating. If the answer is vague, the deadline is doing the selling.

Not legal advice

This is an engineering firm's reading of publicly available material as at September 2026, written because our clients kept asking. Privacy obligations turn on specifics we cannot see from here, and the second tranche is actively moving. For advice about your circumstances, talk to a privacy lawyer. For the authoritative position, the OAIC is the source of record.

The genuinely useful work (knowing what personal information you hold, where it lives, who can reach it, and what happens when something goes wrong) pays off under any version of these reforms. It also happens to be the work that stops you being in the breach statistics, which is a better outcome than being compliant while being breached.

Frequently asked questions

Does the Privacy Act small business exemption end on 10 December 2026?

No. As at September 2026 the removal of the small business exemption is not law. It is part of the second tranche of reforms, which exists as an exposure draft, the Privacy Amendment (Personal Data Protection) Bill 2026, and was still in public consultation this month. What genuinely commences on 10 December 2026 is the automated decision-making transparency obligation under the Privacy and Other Legislation Amendment Act 2024, which is already legislated.

What commences on 10 December 2026 under the Privacy Act?

The automated decision-making (ADM) transparency requirement. From that date, APP entities that use personal information in computer programs to make, or substantially support, decisions that could reasonably be expected to significantly affect a person's rights or interests must say so in their privacy policy, including the kinds of personal information used and the kinds of decisions involved.

My business turns over less than $3 million. Am I covered by the Privacy Act?

Generally not yet, under the small business exemption, but there are long-standing exceptions that already capture many small operators, including health service providers, businesses that trade in personal information, credit reporting bodies, and contractors delivering Commonwealth contracts. Separately, since 10 June 2025 the statutory tort for serious invasions of privacy applies to any person or business, exemption or not.

Can someone sue my business directly for a privacy breach in Australia?

Yes. A statutory tort for serious invasions of privacy came into force on 10 June 2025. It gives individuals a direct right of action, and it is not limited to APP entities: small businesses, contractors and individual employees can be sued. A claimant must show a reasonable expectation of privacy, that the invasion was serious, and that their privacy interest outweighs any countervailing public interest. They do not need to prove financial loss.

What are the maximum penalties for a serious privacy breach?

For serious or repeated interferences with privacy, the maximum civil penalty for a body corporate is the greatest of $50 million, three times the benefit obtained from the conduct, or 30% of adjusted turnover for the relevant period.

What should a business do before December 2026?

Work out whether you use automated decision-making at all, including third-party SaaS that scores, ranks or screens people, and if so, update your privacy policy to describe it. Separately, and regardless of exemption status, get the security basics right: MFA everywhere, patching, backups you have actually restored from, and a written breach response plan. Those reduce real risk today rather than preparing for a law that may not arrive.