Does the Privacy Act apply to my business? (Australia, 2026)
Reference page · Privacy

Does the Privacy Act apply to my business?

The short answer is "it depends on turnover and on what you hold", and the long answer is below. If you use AI tools with client, patient or customer information, the answer matters more than it did two years ago.

Updated 28 August 2026Sources linked in textGeneral information, not legal advice

The one-minute version

  • The Privacy Act 1988 applies to most organisations with annual turnover over $3 million.
  • Some businesses are covered regardless of turnover. The big one for small to medium business is any health service provider: clinics, allied health, remedial therapy, psychology, anyone who holds health information as part of providing a service.
  • Businesses that trade in personal information, contract to the Commonwealth Government, or fall into a handful of other categories are also covered at any size. The OAIC keeps the list on its small business page.
  • Removing the small business exemption altogether has been proposed by the Australian Government. As at the date above it has not been legislated. Do not plan on the exemption lasting; do not assume it has gone.
  • From 10 December 2026, covered businesses whose systems make or substantially shape decisions about people must say so in their privacy policy. That is enacted law, not a proposal.
Why this matters more with AI

The moment a client's name and details go into an AI tool, you have used their personal information and, with most providers, sent it overseas. If the Act applies to you, that use has to sit inside your privacy policy and your obligations. If the Act does not apply to you, your clients still expect you to know where their information went. Either way, the answer starts with knowing which side of the line you are on.

Work out which side of the line you are on

Your situationCovered?What to check
Turnover over $3 million a yearYesTurnover is for the business as a whole, including related bodies. The OAIC explains the test.
You provide a health service and hold health informationYes, at any sizeThis includes allied health, remedial and massage therapy, fitness professionals who record health details, and NDIS providers. Check the OAIC's definition of "health service".
You contract to the Australian GovernmentYes, for that workContracted service providers are covered for the activities under the contract.
You buy, sell or trade personal informationYes, at any sizeIncludes selling lists or being paid to collect details for someone else.
You are a reporting entity under the anti money laundering laws (accountants, real estate agents, conveyancers, some others, from 1 July 2026)PartlyThe OAIC confirms these businesses must comply with the Privacy Act, but only for their activities under the AML/CTF laws. Tranche 2 entities became reporting entities on 1 July 2026. The scope is narrow and often overstated; confirm your own position before relying on it either way.
Under $3 million, none of the aboveGenerally notYou are outside the Act today. You can opt in. Your clients, insurers and larger customers may still expect Act-level handling, and the exemption is under review.

If you are covered, what AI changes

Nothing in the Act mentions ChatGPT. What it regulates is personal information: how you collect it, what you tell people, where it goes, and how you keep it safe. AI tools sit inside that. Three things follow.

  1. Your privacy policy has to describe what you actually do. If staff use AI tools with client information, a policy that does not mention AI is out of date. The OAIC's guidance on commercially available AI products is the regulator's own position, and it is short enough to read in one sitting.
  2. Overseas disclosure counts. Most AI providers process information outside Australia. Under the Act you remain responsible for it once it leaves. That is the rule that catches free-plan use by staff.
  3. From 10 December 2026, automated decisions must be disclosed. If a computer program makes a decision, or does something substantially and directly related to making a decision, that could significantly affect a person, your privacy policy must say what kinds of information it uses and what kinds of decisions it makes. The obligation was inserted into Australian Privacy Principle 1 by the Privacy and Other Legislation Amendment Act 2024. Screening tenants, pricing quotes, triaging enquiries and shortlisting applicants are the everyday small to medium business examples.

If you are not covered

You are not off the hook, you are outside one law. Australian Consumer Law still applies to what you tell customers. Your professional body may have its own rules. Your larger clients increasingly send questionnaires. And the practical risk, a staff member pasting the wrong file into a free tool, is identical whether the Act applies or not. The sensible position for a small to medium business outside the Act is to behave as if it were inside it on the two things that cost nothing: know where client information goes, and write down what tools are allowed to touch it.

The one thing to do next

Take the two-minute Exposure Check. It asks ten yes-or-no questions about where AI already touches client information in your business, and its result page routes you to the reference page that fixes each gap. If you answered "health service" above, do it today rather than this month.

Where to check for yourself

What changed on this page
28 Aug 2026: first published. Next scheduled check: when the OAIC releases guidance on the automated decision provisions, or 10 December 2026, whichever comes first.
The monthly change note

When a rule changes, you will hear about it here first.

One short email a month. What changed, what it means for your business, and the page that answers it. If nothing changed, a two-line note says so. That is all the list is ever used for.

Unsubscribe with one click. Your address is never shared.