Privacy law gets overcomplicated very quickly, especially for small businesses. One article says every business is covered, another says businesses under $3 million are exempt, and a third says the exemption is about to disappear.
The current position is more specific than that. Most Australian small businesses with annual turnover of $3 million or less are still not covered by the Privacy Act 1988, but there are important exceptions. Some small businesses are covered because of what they do, the information they handle, or another law that brings particular activities within the Privacy Act.
This article focuses on the technology and cybersecurity side. It is not legal advice, and Q10 does not determine whether a business is legally required to comply with the Privacy Act. If you are unsure about your legal obligations, the OAIC small business guidance and your legal adviser are the right starting points.
Does the Privacy Act apply to every small business?
No. The OAIC currently says most small businesses are not covered by the Privacy Act. For this purpose, a small business is generally one with annual turnover of $3 million or less.
However, turnover is not the whole test. A smaller business can still be covered if, for example, it provides a health service, trades in personal information, operates a residential tenancy database, is related to an organisation already covered by the Act, provides services under certain Commonwealth contracts, has opted in, or is covered through another specific activity.
AML/CTF is now an important exception for many professional services firms
From 1 July 2026, the expanded AML/CTF regime applies to certain designated services commonly provided by lawyers, conveyancers, accountants, trust and company service providers, real estate professionals and dealers in precious metals and stones.
The OAIC has made it clear that small businesses that become reporting entities can have Privacy Act obligations for their activities under the AML/CTF Act, even where they would otherwise fall within the small business exemption. That does not automatically mean every activity in the business is covered in the same way, so the legal scope still needs to be worked out properly.
For the technology side, though, the direction is pretty clear: if the business is collecting identity documents and other personal information for AML/CTF purposes, it needs to know where that information is stored, who can access it, how it is protected, how long it must be retained and what happens if something goes wrong.

Photo by Towfiqu barbhuiya via Unsplash.
What does the Privacy Act expect on information security?
For organisations covered by the Privacy Act, Australian Privacy Principle 11 requires reasonable steps to protect personal information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
Importantly, APP 11 now expressly says that reasonable steps include both technical and organisational measures. In other words, a privacy policy on its own is not the security control, and neither is buying one cybersecurity product.
What should the technology side actually cover?
Know where personal information is stored
You cannot protect information properly if nobody knows where it lives. That includes Microsoft 365, practice-management systems, accounting platforms, shared drives, laptops, email, cloud storage, line-of-business applications and copies sitting in old folders that nobody has looked at for years.
The goal is not to build a giant spreadsheet for the sake of it. The useful question is whether the business can identify the systems holding important personal information and who is responsible for them.
Limit access to the people who actually need it
Access tends to grow over time. Team members change roles, people leave, temporary permissions become permanent and shared accounts make it hard to tell who did what.
Named user accounts, sensible permissions, prompt offboarding and regular access reviews are basic controls, but they do a lot of useful work. Privileged administrator access should be more tightly controlled again.
Protect identities, devices and email
Most businesses now hold personal information across cloud services and mobile devices rather than on one server in a locked office. That makes identity and device security a major part of privacy protection.
Multi-factor authentication, secure device configuration, patching, endpoint protection, email security and appropriate controls around remote access all reduce the chance that a stolen password or compromised laptop turns into access to a much larger set of records.

Photo by Dan Nelson via Unsplash.
Back up information that the business genuinely needs
Privacy is not only about stopping somebody from reading information. Loss matters too. If a system is encrypted by ransomware, a team member deletes important records, or a cloud account is compromised, the business needs a realistic way to recover.
That means understanding what is actually backed up, keeping appropriate independent copies, monitoring backup jobs and testing recovery rather than simply assuming the backup exists.
Do not keep everything forever
APP 11 also deals with information that is no longer needed. Where an organisation is covered by the Privacy Act, it may need to take reasonable steps to destroy or de-identify personal information once there is no permitted reason to keep it, unless another law or order requires retention.
This is where the technology needs to match the business rules. Email archives, backups, document systems and old user accounts can quietly retain information long after people think it has been removed. Retention requirements can also come from other laws, so deletion should be deliberate rather than automatic.
Keep enough visibility to investigate a problem
If suspicious activity occurs, the business should be able to work out what happened. Appropriate logging, security monitoring and audit trails help answer practical questions such as which account signed in, whether data was accessed, what changed and when the activity started.
Have a breach response process before you need it
Businesses covered by the Privacy Act can also have obligations under the Notifiable Data Breaches scheme. Not every security incident is automatically a notifiable data breach, but the business needs a process for containing an incident, understanding what information was involved and getting the right legal or privacy advice quickly.
The technical response should support that process with evidence. That can include sign-in records, device information, email logs, security alerts, affected systems, timestamps and details of the containment work already completed.
Being under $3 million does not make the information worthless
A business that is genuinely outside the Privacy Act still has good reasons to protect personal information properly. The OAIC itself recommends that exempt small businesses protect the information they hold as a matter of good practice.
There are also customer requirements, contracts, cyber insurance, professional obligations and simple business risk to think about. A leaked identity document or compromised mailbox is still a serious problem even when the legal framework applying to it is different.
What Q10 can help with
Q10 focuses on the technology controls behind information protection: identity and access, Microsoft 365, managed devices, email security, backups, monitoring, secure configuration, logging and evidence that the agreed controls are actually in place.
We do not decide whether your business is legally covered by the Privacy Act, write the legal privacy program, determine whether an incident meets the notification threshold or take ownership of your broader compliance obligations. Those questions belong with the business and its legal or privacy advisers.
Where the legal requirement is already understood, we can help translate it into the systems and controls that need to exist in practice. That is particularly useful where the business needs clearer evidence around access, security, backups, retention or incident readiness.
The bottom line
The small business exemption has not simply disappeared. Most businesses with annual turnover of $3 million or less remain outside the Privacy Act unless an exception applies, but those exceptions matter and they now include important AML/CTF scenarios for professional services and other newly regulated sectors.
Once the legal scope is clear, the IT side is much more concrete: know where the information is, limit access, secure identities and devices, maintain recoverable backups, monitor the environment, manage retention and be ready to investigate an incident.
If you need help getting the technical side into better shape, Q10 can review the current cybersecurity setup and work through the priorities in sensible stages.
