Veracly
Multi-jurisdiction

The Privacy Act small business exemption — and the date everyone gets wrong

A widely repeated claim says the small business exemption dies on 10 December 2026. That date is real, but it belongs to another provision. Here is what section 6D actually does, who it does not protect, and why we know the mistake well.

By Veracly Compliance Team6 min read

General information, current at the date above. This describes what the cited sources say; it is not legal advice and no lawyer has reviewed it. Australian privacy and discrimination law turns heavily on your specific circumstances — what you collect, from whom, and which carve-outs apply — so treat this as orientation and verify your own position before acting on it.

Australia does something no European privacy regime does: it exempts most small businesses from its privacy law entirely. Not a lighter-touch tier, not reduced record-keeping — out of scope. If you run an Australian SMB, this is probably the single most consequential fact about your privacy obligations, and it is routinely misreported.

What section 6D actually says

The Australian Privacy Principles bind APP entities. Section 6D of the Privacy Act 1988 (Cth) removes a “small business operator” from that definition. The headline test is annual turnover for the previous financial year:AUD 3,000,000 or less and you are outside the Act.

The test only runs one way, and this is the part almost every summary drops. Under section 6D(4)(a) a business is not a small business operator if it has had an annual turnover above AUD 3,000,000 in any financial year since it started trading. A business that turned over four million two years ago and two million last year is not exempt. You cannot drop back under the threshold in a lean year and become exempt again.

The statutory wording in section 6D(1) is “$3,000,000 or less”, so the boundary is inclusive — a business at exactly three million is still exempt. An exempt operator owes no APP duties. No privacy policy obligation under APP 1, no collection notice under APP 5, no access-and-correction machinery.

Compare the GDPR, which has no turnover threshold at all. Articles 13 and 14 bind a sole trader in the same terms as a bank. Australian and European privacy law start from genuinely different premises, which is why advice written for one travels badly to the other.

The 10 December 2026 confusion

You will find a lot of material asserting that the exemption disappears on 10 December 2026. The date is real. The claim attached to it is not.

10 December 2026 is the commencement of new Australian Privacy Principles 1.7 to 1.9, introduced by the Privacy and Other Legislation Amendment Act 2024. Those provisions require an APP entity’s privacy policy to disclose where automated decision-making is used in ways that significantly affect an individual. The delayed start is 24 months from Royal Assent, which is where the date comes from.

The 2024 Act did not repeal the small business exemption. That reform was deferred to a further tranche. As at 20 August 2026, no Bill implementing it has been introduced and no commencement date exists.

The date carries one other thing, which adds to the confusion: 10 December 2026 is also the deadline by which the OAIC must register the Children’s Online Privacy Code.

Two things follow. Section 6D stands until a repeal is actually enacted. And both of those obligations bind APP entities — so an exempt small business is not brought into scope by either.

We made this mistake, which is how we know it well

Our own Australian rule set once carried a gate that switched itself off on 10 December 2026, on exactly the mistaken belief described above. It would have failed in a particularly unpleasant way: on that date the exemption would have stopped being applied, and every exempt Australian customer would have been told they were in breach of a duty they do not have — with no test failing to signal it.

We removed the date. The exemption now stands with no expiry, and a scheduled review forces a human to check the legislative position rather than letting code guess at it. A gate that expires silently on an assumption is worse than one that asks.

We mention this because the error is easy to make and hard to notice, and because a compliance vendor that quietly corrects its own mistakes is not being much use to anyone.

Where the exemption stops

Turnover is necessary but not sufficient. The main ways a small business is pulled into the Act anyway — this list is not exhaustive — are:

  • you provide a health service and hold health information (s 6D(4)(b)) — this catches a great many small clinics and allied-health practices;
  • you disclose personal information about another individual for a benefit, service or advantage, or provide a benefit, service or advantage in order to collect it from someone else (ss 6D(4)(c)–(d)) — broadly, trading in personal information. Note the statutory exception: a disclosure made with the individual’s consent, or required or authorised by law, does not knock you out of the exemption (ss 6D(7)–(8));
  • you are a contracted service provider for a Commonwealth contract (s 6D(4)(e));
  • you are a credit reporting body (s 6D(4)(f));
  • you are a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (s 6E(1A)) — since the AML/CTF reforms commencing 1 July 2026 this catches many real-estate agents, accountants, conveyancers and lawyers, for the personal information they handle in connection with those obligations;
  • you hold a Consumer Data Right accreditation, are a registered employee association, or are otherwise prescribed by regulation (s 6E);
  • you are related to a body corporate that carries on a business that is not a small business (s 6D(9)); or
  • you have opted in to coverage under section 6EA.

The health services limb deserves particular attention, because Veracly’s own customer base includes clinics. A dental or physiotherapy practice turning over well under three million is still an APP entity if it holds health records. For that business the privacy policy obligation is real.

Other law does not go away

The exemption is specific to the Privacy Act. It does not touch:

  • The Disability Discrimination Act. Section 24 has no turnover threshold. Accessibility obligations apply to a one-person business.
  • The Spam Act 2003. Consent rules for commercial electronic messages apply regardless of size.
  • Australian Consumer Law. Misleading statements about how you handle data are still misleading conduct — including a privacy policy that describes practices you do not follow.
  • Foreign law. The GDPR and UK GDPR apply on their own terms if you target or monitor individuals there. No Australian threshold affects that.

That last one is the common trap. An exempt Australian business selling to European customers has full GDPR obligations for those customers, including a privacy notice and a lawful basis, while owing nothing under the Privacy Act domestically.

How we handle it in a scan

A missing privacy policy is graded differently depending on which market a site is scored against. Under EU and UK rules it is a serious finding, because those regimes have no equivalent exemption. Under the Australian rule set we suppress it for businesses at or below the section 6D threshold, because reporting a breach of a duty that does not bind you is simply an incorrect finding.

That means we need to know your turnover band to grade the Australian privacy rule honestly. It is the only question of its kind we ask, and this is why.

Common questions

What is the small business exemption?+

Section 6D of the Privacy Act 1988 (Cth) excludes a "small business operator" from the definition of an APP entity. The core test is annual turnover for the previous financial year: section 6D(1) says "$3,000,000 or less", so a business at exactly AUD 3,000,000 is still within the exemption. But the test runs one way only — under s 6D(4)(a), a business that has exceeded the threshold in any financial year since it started trading is not a small business operator, and cannot regain the exemption by having a lean year.

Was the exemption repealed on 10 December 2026?+

No. That claim conflates two different parts of the Privacy and Other Legislation Amendment Act 2024. 10 December 2026 is the commencement date for new Australian Privacy Principles 1.7 to 1.9, which require privacy policies to explain automated decision-making — a 24-month delayed start from Royal Assent. The repeal of the small business exemption was not part of that Act; it was deferred to a further tranche of reform, and as at 20 August 2026 no Bill implementing it has been introduced.

Which small businesses are covered anyway?+

Turnover is not the only test, and the carve-outs are broader than most summaries suggest. A small business operator is still an APP entity if it provides a health service and holds health information, trades in personal information, is a contracted service provider under a Commonwealth contract, is a credit reporting body, is a reporting entity under the AML/CTF Act 2006 — which since the reforms commencing 1 July 2026 catches many real-estate agents, accountants, conveyancers and lawyers — holds a Consumer Data Right accreditation, or is related to a body corporate that is not a small business. Businesses can also opt in under section 6EA. This list is not exhaustive, and if any limb applies the AUD 3,000,000 threshold does not help you.

If I am exempt, do I still need a privacy policy?+

Not as a matter of Australian law. Australian Privacy Principle 1.3 is what requires a privacy policy, and it binds APP entities — which an exempt small business is not. There are still good reasons to publish one: it is expected by customers and partners, some platforms require it, and it is mandatory if you have EU or UK visitors, since the GDPR has no turnover threshold. But it is a commercial or foreign-law reason, not an Australian legal duty.

See where your site stands.

Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.

Run a free scan

Keep reading