Privacy Act Reforms Now Apply to More Australian Small Businesses: What It Means in Practice
Who is caught by the new rules
From 1 July 2026, tranche two of Australia’s anti-money laundering and counter-terrorism financing reforms brought designated services under the Privacy Act. This includes real estate agents, lawyers, accountants, conveyancers, trust and company service providers, and dealers in precious metals and stones.
Even businesses with turnover below the usual $3 million threshold must now follow privacy obligations when handling personal information connected to these services. The Office of the Australian Information Commissioner estimates more than 100,000 small businesses are newly affected.
What you must actually do
The core requirement is to handle personal information fairly and securely. This means telling clients what data you collect and why, only using it for the stated purpose, and keeping it safe from unauthorised access or loss.
You also need to respond to requests from individuals who want to access or correct their information. Serious privacy breaches that are likely to cause harm must be notified to the OAIC and affected individuals as soon as practicable.
Practical steps for SMBs this month
Start with a quick audit of the personal information your business holds. List what data you collect, where it is stored, who has access, and how long you keep it. Update your privacy policy and client notices so they clearly explain your practices.
Review your security measures. Simple steps such as stronger passwords, multi-factor authentication, regular backups, and staff training on spotting phishing emails go a long way. If you use cloud tools, confirm the provider’s security settings match your new obligations.
Document everything. Good records show regulators and clients that you take privacy seriously and make future audits far easier.
Common pitfalls to avoid
Many small businesses assume the old turnover exemption still applies across the board. It does not for AML-related data handling. Treating privacy as a one-off project rather than an ongoing process is another frequent mistake. Staff need regular reminders, especially when new tools or processes are introduced.
Finally, do not ignore the possibility of civil claims. Individuals can now bring actions for serious invasions of privacy regardless of whether your business meets the old Privacy Act threshold.
Staying on top of these changes protects client trust and avoids costly complaints or penalties. For Sunshine Coast, Brisbane and Sydney businesses that want straightforward guidance on mapping their data flows and tightening security, a short conversation can clarify the next steps.