You have probably been told you have until 10 December to comply. You do not.
The claim doing the rounds is that the $3 million small business exemption disappears on that date, and that 2.5 million Australian businesses are about to fall under the Privacy Act for the first time. It is worth being clear about it, because the deadline is being repeated widely enough to sound settled. The exemption has not been repealed. Removing it sits in the second tranche of privacy reform, and as of February 2026 the Attorney General had confirmed only that the government is progressing that tranche. There is no Bill before Parliament and no commencement date. If your turnover is under $3 million, the exemption still applies to you today.
What is actually happening in December
The date is real, it just belongs to a different change. From 10 December 2026, new rules in Australian Privacy Principle 1.7 to 1.9 commence. If you are an organisation covered by the Act and you use automated decision making, including AI tools, in a way that significantly affects someone, your privacy policy has to say so.
That is a genuine obligation with a genuine date on it. It is also much narrower than “the exemption is gone”, and conflating the two is how a three month panic gets manufactured.
So does any of it matter yet
Yes, for two reasons.
The first is that the direction is not really in doubt. The Office of the Australian Information Commissioner has said publicly that it considers the small business exemption no longer appropriate given the privacy risks posed by organisations of every size. Reform is coming. What nobody can honestly tell you is when, which is exactly why a countdown is the wrong way to think about it.
The second is that the exemption was never as broad as people assume. Plenty of small businesses are already covered regardless of turnover, including anyone trading in personal information, private health service providers, and contractors delivering Commonwealth contracts. Allied health practices are the one that surprises people most often. If you hold health information, you are in scope now, not in December.
The part people underestimate
Writing a privacy policy takes an afternoon. Proving you actually protect the information is the harder half, and that half is a systems job rather than a paperwork one.
Australian Privacy Principle 11 asks for reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. Most people read only the last one. In practice it breaks into four jobs.
Keeping people out. A large share of notifiable breaches in this country start with a compromised mailbox. Email is the front door, so that means multi factor authentication on every account, and filtering that catches the phish before somebody clicks it.
Keeping the data recoverable. Loss counts. Ransomware that encrypts eight years of client records is a privacy incident, not just a bad week. Backups need to sit separate from the systems they protect, and to have been restored from at least once.
Noticing when something goes wrong. This is the one that catches people out. The Notifiable Data Breaches scheme gives you 30 days to assess a suspected breach and to notify both the OAIC and the people affected. You cannot start a clock you never noticed had started. Something has to be watching the alerts outside business hours.
Not keeping what you do not need. Old customer spreadsheets on a shared drive. An exported contact list sitting in somebody’s downloads folder. You cannot be breached over data you deleted because you no longer needed it.
If you are already on Microsoft 365 Business Premium, a fair slice of the first job is sitting in your tenant right now. Defender for Office 365 covers email, conditional access controls who gets in and from where, and Intune manages the devices. It is the plan we standardise our managed clients on for this reason, and the usual gap is that it is licensed but never switched on. Backup and after hours alerting sit outside Microsoft’s licensing, which is why they are part of our base package rather than an optional extra.
Four things worth doing this month
- Run a data stocktake. List every system holding personal information: the CRM, accounting software, email, shared drives, booking tools, and that one spreadsheet everybody uses. Note who can reach each one.
- Close the doors you left open. Disable accounts for departed staff, remove file shares nobody uses, and switch on multi factor authentication everywhere that touches customer data.
- Test a restore rather than checking the backup ran. A green tick in a dashboard is not evidence. Pick one file and one mailbox and actually bring them back.
- Write the breach plan before you need it. One page: who gets called, who assesses it, who notifies the OAIC, who talks to customers. Deciding that during an incident never goes well.
None of this is expensive, and none of it is wasted if the exemption stays where it is for another two years. It is the same work that stops you losing a week to ransomware, and the same work that makes the answer easy whenever the law does catch up.
If you want a hand working out where your business actually stands, that is the sort of thing a technology business review is for.