Who must prepare for the proposed removal of the small business exemption?
The applicability test for Prepare for the proposed removal of the small business exemption (OAIC), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has not app holds pi.
What the obligation is
Removing the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
Removing the Privacy Act's small business exemption (s 6D) — which currently exempts most businesses with annual turnover under $3M — was recommended in the Privacy Act Review and agreed in principle by the Government. It was NOT included in the first reform tranche (the Privacy and Other Legislation Amendment Act 2024). As of 2026 it remains proposed for a future ('second tranche') bill with no commencement date set. If enacted, roughly 2 million Australian SMBs would become 'APP entities' — requiring a Privacy Policy, lawful collection notices, NDB readiness, training, and access/correction processes. Businesses can prepare now, but no specific commencement date should be treated as fixed.
The applicability test
Applies when the business has not app holds pi.
How the regulator frames it: Any business currently relying on the small business operator exemption (annual turnover under $3M).
What triggers it: Commencement of a future bill removing the small business exemption (not yet introduced to Parliament).
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (24 of 35: depends on size or structure; 11 of 35: no).
Business structure and size
Structure does not change the answer in the 24 industries it can reach: for every structure the answer is "depends on size or structure".
| Size band | Answer in the 24 industries it can reach, any structure |
|---|---|
| No employees (turnover $100K–$1M) | Yes |
| 1–5 employees (turnover $100K–$1M) | Yes |
| 6–19 employees (turnover $1M–$3M) | Yes |
| 20–99 employees (turnover $3M–$10M) | No |
| 100–499 employees (turnover $10M–$100M) | No |
| 500+ employees (turnover $100M–$1B) | No |
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: applies. Holds personal information but relies on the small business exemption (turnover under $3M)
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires not app holds pi.
- Pty Ltd company in fintech (non-bank) with 500+ employees, turnover $100M–$1B: does not apply. Requires not app holds pi.
What you must do, and when
- When due
- Not yet legislated — proposed for a future privacy reform tranche.
- Frequency
- Ongoing
- Evidence to keep
- Privacy Policy, collection notices, breach response plan, staff training records, data inventory.
- Status
- Upcoming (not yet in force)
- Priority
- High
Penalty for not complying
Maximum penalty: The standard Privacy Act penalty regime (up to $50M / 3× benefit / 30% turnover for serious or repeated interferences) would apply if and when the exemption is removed.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Office of the Australian Information Commissioner.
OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
Privacy Act 1988: Federal privacy Act.
Free tools that help with this obligation:
Questions
- Who must prepare for the proposed removal of the small business exemption?
- Applies when the business has not app holds pi.
- Do sole traders need to prepare for the proposed removal of the small business exemption?
- Depends on size or structure. Looking in the 24 industries it can reach and every size band, the engine's answer for a sole trader is: depends on size or structure.
- Do businesses with 1–5 employees need to prepare for the proposed removal of the small business exemption?
- Yes (1–5 employees, turnover $100K–$1M).
- When is "Prepare for the proposed removal of the small business exemption" due?
- Not yet legislated — proposed for a future privacy reform tranche.
Related
- Prepare for the proposed removal of the small business exemption: full obligation detail
- Who must comply: all obligations
- Who must publish a Privacy Policy that meets APP 1
- Who must comply with Notifiable Data Breach (NDB) scheme
- Does it apply to real estate agents?
- Does it apply to accountants & bookkeepers?
- Does it apply to precious metals & stones dealers?
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.