Australia's privacy framework has changed, but one major claim needs correcting: the Privacy Act's small-business exemption has not simply disappeared. Here is what is actually in force in 2026.
The Small-Business Exemption Is Still Part of the Story
The Privacy Act 1988 generally covers organisations with an annual turnover greater than $3 million, as well as some smaller organisations that fall within specified exceptions. The government's Privacy Act Review proposed removing the small-business exemption, but the 2024 reforms did not simply abolish it for every small business.
For consumers, that means "every Australian retailer must now comply with the full Privacy Act regardless of size" is not an accurate 2026 statement.
What the 2024 Reforms Actually Did
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and progressed a number of reforms from the government's Privacy Act Review response. The amendments include stronger protections around children's privacy, overseas data flows, security and retention, and a new statutory tort for serious invasions of privacy.
Different provisions commenced at different times, so a 2026 article should not describe the entire reform package as one single commencement date.
There Is Now a Statutory Tort for Serious Invasions of Privacy
The amended Privacy Act contains a statutory tort for serious invasions of privacy. The cause of action covers serious invasions involving intrusion upon seclusion or misuse of information, subject to the elements, defences, exemptions and limitations set out in the legislation.
This is different from saying every breach of an Australian Privacy Principle automatically gives a consumer a damages action. The statutory tort is a separate cause of action with its own legal tests.
What About a Broad "Direct Right of Action" for Every Privacy Breach?
The government's earlier Privacy Act Review response agreed in principle to a direct right of action framework, but the enacted 2024 reforms should not be described as creating a simple universal court claim for every APP breach by every business.
For individual consumers, the practical route can still involve making a privacy complaint to the organisation and, where appropriate, the OAIC. The new statutory tort is a distinct litigation route.
What Consumers Can Still Request
Depending on coverage and the circumstances, consumers can exercise existing Privacy Act rights such as access and correction. The 2024 reforms also strengthen certain areas of governance and security, including obligations around destruction or de-identification when personal information is no longer needed.
What This Means Practically
- Do not assume the $3 million small-business threshold has disappeared.
- Check whether the organisation is covered by the Privacy Act.
- Distinguish the statutory tort from a general "direct right" for every APP breach.
- Track which reform provisions apply to the relevant date.
- Keep your complaint, evidence and the organisation's response.
Sources
- Attorney-General's Department — Government Response to the Privacy Act Review Report. ag.gov.au
- Federal Register of Legislation — Privacy and Other Legislation Amendment Act 2024. legislation.gov.au
- Federal Register of Legislation — Privacy Act 1988, current compilation. legislation.gov.au
- OAIC — Privacy Act review and proposed reforms. oaic.gov.au