Quick Answer:
Australia’s Privacy Act is being reformed in stages, and separating what is already law from what is only proposed matters. A statutory tort for serious invasions of privacy has applied since June 2025, and from 10 December 2026 businesses must disclose in their privacy policy where they use automated decision-making that significantly affects people. Separately, from 1 July 2026 new professions such as lawyers, accountants and real estate agents come under anti-money-laundering law, which also brings them under the Privacy Act. Broader changes, including winding back the small-business exemption, have been agreed in principle but are not yet law. Penalties for serious breaches now reach up to $50 million.
In this article
- Privacy Act Reform: The Short Version
- The Changes Already in Force
- The December 2026 Rule: Automated Decisions in Your Privacy Policy
- New Professions Pulled In: The AML Change
- The Small-Business Exemption: Proposed, Not Yet Law
- What Australian Businesses Should Do Now
- Common Misconceptions
- Where Sentrient Fits
- Frequently Asked Questions
Privacy Act reform is one of the most talked-about and most misunderstood compliance topics in Australia right now.
Headlines suggest every small business is suddenly caught, or that a single big change lands in 2026.
The reality is more staged, and the useful thing is to know exactly what is already law, what starts in 2026, and what is still only a proposal.
This guide separates the three parts of the Privacy Act reform, so you can plan against what is real rather than the noise.
The Privacy Act reform is general information here, not legal advice, and given how much is still moving, this is an area where a quick check with a lawyer is worth it.
Sentrient is an Australian-built GRC platform for compliance, risk and HR. See our workplace compliance system and compliance courses, built for Australian and New Zealand workplaces.
Privacy Act Reform: The Short Version
The Privacy Act changes are arriving in tranches rather than all at once. Here is the state of play.
| Change | Status | When |
|---|---|---|
| Statutory tort for serious invasions of privacy | In force | Since 10 June 2025 |
| Higher penalties (up to $50m for serious breaches) | In force | Now |
| Automated-decision disclosure in privacy policies | Becomes law | 10 December 2026 |
| Children’s Online Privacy Code | Being finalised | By 10 December 2026 |
| New professions under AML, and so under the Privacy Act | Starts | 1 July 2026 |
| Winding back the small-business exemption | Proposed only | Not yet law |
The Changes Already in Force
Two parts of the Privacy Act reform are already live and are the ones most businesses have not registered.
First, a statutory tort for serious invasions of privacy has applied since 10 June 2025, giving individuals a direct route to sue for serious privacy harms such as misuse of information or intrusion into their private affairs.
Second, penalties for serious or repeated breaches now reach up to $50 million, or three times the benefit gained, or 30% of adjusted turnover, whichever is greater.
In short, the cost of getting privacy wrong rose well before the 2026 dates, and a person harmed no longer has to wait for the regulator to act. The reforms passed in late 2024 are already reshaping the risk.
The pressure is not abstract either. In the second half of 2024, malicious or criminal attacks were the leading cause of data breaches reported to the OAIC, at 69%. Privacy risk is climbing at the same time as the penalties for getting it wrong.
The December 2026 Rule: Automated Decisions in Your Privacy Policy
The concrete 2026 obligation is a privacy-policy change. From 10 December 2026, businesses covered by the Privacy Act must include information in their privacy policy about automated decision-making, where a computer program uses personal information to make a decision that could significantly affect a person’s rights or interests.
In plain terms, if AI or an automated system helps decide something that matters to a customer or an employee, such as a price, a loan, a job or a service refusal, you will need to say so.
This is the privacy side of the same shift covered in our guide to AI governance for Australian businesses, and it is the reason AI and privacy compliance are now one conversation.
New Professions Pulled In: The AML Change
A separate reform catches businesses that thought privacy law did not apply to them. From 1 July 2026, new professions come under anti-money-laundering law: lawyers, accountants, conveyancers, real estate agents, and dealers in precious metals and stones, for certain services. Enrolment with AUSTRAC opens from 31 March 2026.
The privacy consequence is easy to miss. A business that becomes an anti-money-laundering reporting entity generally loses the small-business exemption from the Privacy Act, because it is now a regulated entity handling personal information under law.
So for these professions, 1 July 2026 is effectively when full Privacy Act obligations begin, even though the privacy exemption itself was not the target of the change.
The Small-Business Exemption: Proposed, Not Yet Law
This is where the headlines outrun the law. There is a long-standing exemption that frees most businesses with under $3 million turnover from the Privacy Act.
The Privacy Act Review recommended removing it, and the Government agreed in principle, which is why you see predictions that millions of small businesses will soon be covered.
But agreed in principle is not the same as enacted. As things stand, the broad removal of the small-business exemption is a proposal, not current law, and would come in a later tranche.
The businesses actually losing the exemption in 2026 are the anti-money-laundering professions above, not small business generally. Plan for the direction, but do not act on a rule that does not yet exist.
What Australian Businesses Should Do Now
You do not need to wait for every part of the Privacy Act reform to land before acting. A few steps put you ahead now.
- Map your personal data: Know what personal information you hold, where it lives, and who can access it
- Check for automated decisions: Identify any AI or automated system that affects people, ready for the December 2026 disclosure
- Refresh your privacy policy and breach plan: Make sure both are current and reflect how you actually operate
- Watch your exposure if you are an AML profession: Lawyers, accountants and agents should plan for full Privacy Act obligations from 1 July 2026
- Treat privacy as good practice, not just law: The statutory tort means a harmed individual can act whether or not you are technically exempt
Common Misconceptions
- “Every small business is covered from 2026.” Not yet. The broad exemption removal is proposed, not law. AML professions are the ones caught in 2026.
- “It is all one big change in 2026.” The reform is staged: some parts are already in force, some start in 2026, some are future.
- “We are exempt, so privacy does not apply.” The statutory tort applies regardless, and the exemption is narrower than many assume.
- “AI has nothing to do with privacy.” The December 2026 automated-decision rule sits inside the Privacy Act.
Where Sentrient Fits
Sentrient does not replace legal advice on privacy, and it is not a data-security product. What it does is hold the compliance and evidence layer the reform rewards: your privacy and data policies with individual acknowledgements, the training that goes with them, and audit-ready records you can produce on request. Much of privacy compliance is proving people were told, trained and signed off, which ties directly to how mature governance, risk and compliance works.
Being straight about scope: for the legal questions, get advice. For making your privacy policies, training and records real and provable, that is what Sentrient is built for.
See privacy policies acknowledged, trained and tracked in one place.
Plan for the Direction, Act on the Law
Privacy Act reform is real, staged, and easy to get wrong in both directions: panicking about rules that are only proposed, or missing the ones already in force.
Know what is law today, prepare for the 10 December 2026 automated-decision rule, watch your position if you are an AML profession, and keep your privacy policies and records provable.
That is how you stay ahead of the reform without chasing headlines.
Disclaimer: General information for Australian businesses, not legal advice. Privacy law is reforming in stages and some measures referenced here are proposed rather than enacted. Confirm your specific obligations with the OAIC or a qualified privacy lawyer before acting. Correct as at August 2026.
Frequently Asked Questions
1. What is the Privacy Act reform?
It is a staged overhaul of Australia’s Privacy Act. Some changes are already law, including a statutory tort for serious invasions of privacy (since June 2025) and higher penalties. Others start on 10 December 2026, such as disclosing automated decision-making in privacy policies. Broader changes, like removing the small-business exemption, are proposed but not yet law.
2. What changes on 10 December 2026 under the Privacy Act reform?
From 10 December 2026, businesses covered by the Privacy Act must include information in their privacy policy about automated decision-making that uses personal information and could significantly affect a person’s rights or interests. The Children’s Online Privacy Code is also due to be finalised by that date.
3. Is the small-business exemption being removed in 2026?
Not as a general rule. Removing the small-business exemption has been agreed in principle but is not yet law and would come in a later tranche. The businesses losing the exemption in 2026 are the new anti-money-laundering professions, not small business across the board.
4. Which businesses come under privacy law from 1 July 2026?
From 1 July 2026, new anti-money-laundering professions, including lawyers, accountants, conveyancers, real estate agents and dealers in precious metals and stones, come under AML law for certain services. Becoming an AML reporting entity generally brings a business under the Privacy Act too.
5. What is the statutory tort for serious invasions of privacy?
A change already in force since 10 June 2025 that lets individuals sue directly for serious invasions of privacy, such as misuse of information or intrusion into private affairs. It applies regardless of the small-business exemption, so it raises privacy risk for businesses that assumed they were outside the Act.
6. What are the penalties for breaching the Privacy Act?
For serious or repeated breaches, penalties can reach up to $50 million, or three times the benefit obtained, or 30% of adjusted turnover, whichever is greater. These higher penalties are already in force.
7. What should my business do to prepare?
Map the personal information you hold, identify any automated decisions that affect people, refresh your privacy policy and breach-response plan, and, if you are an AML profession, plan for full Privacy Act obligations from 1 July 2026. For legal specifics, get advice from a qualified privacy lawyer.
Sources
- OAIC, Statutory tort for serious invasions of privacy
- OAIC, Transparency in automated decision-making
- OAIC, Passing of bill a significant step for Australia’s privacy law
- OAIC, Notifiable Data Breaches report (July to December 2024)
- Attorney-General’s Department, Privacy
- AUSTRAC, Newly regulated businesses: get ready for the reforms
