There is a run of changes to the Privacy Act arriving through 2026, and between them they raise 2 questions every business owner should be able to answer. Are you newly caught by the Act. And if you were already covered, what do you now have to do that you did not before. Plenty of owners sit in one of those 2 groups without realising it, which is the reason this is worth 10 minutes of your attention now rather than a scramble later.
Start with the first question, because the answer surprises people. A change to anti money laundering law, of all things, is about to make tens of thousands of businesses subject to the Privacy Act for the first time. From 1 July 2026, a new wave of the AML rules, the reforms often called Tranche 2, brings a fresh group into the net: accountants, business brokers, real estate agents, conveyancers, property developers, and trust and company service providers. The moment a business is caught for AML, it loses the small business exemption that kept it out of the Privacy Act, for the part of its work that triggers those rules. The OAIC estimates more than 100,000 small businesses will be pulled in this way, most of them having assumed privacy law was someone else’s problem.
Why this catches more businesses than people expect
For years the rule of thumb was comfortable. Turnover under $3m, so the Privacy Act does not apply. For a long time that held for most small businesses. In 2026 it stops being a safe assumption, and on more than one front.
You are likely already in the Act, or about to be, if any of these is true:
- You are over the $3m turnover line, so you are covered already.
- You handle sensitive personal information, or you sit in one of the categories that never had the exemption, such as health information, trading in personal information, or credit reporting.
- You are caught by the AML changes from 1 July 2026, through the services your business provides.
- You are not caught yet, but the small business exemption is on the Government’s list to wind back, so the direction of travel is clear.
- You are growing, or you expect to sell one day, which means you may punch through the threshold, or become part of a larger business that already has.
If you landed on any of those, the changes below are yours to deal with.
Already covered? The second change is aimed straight at you
Here is the part that gets missed when all the attention goes on the question of who is newly caught. One of the 2026 changes has nothing to do with whether you are in the Privacy Act. It applies to every business already under it, and for a lot of established businesses that is the change that actually matters.
From 10 December 2026, any business subject to the Act has to set out in its privacy policy where it uses a computer program to make decisions that significantly affect people. That includes AI. A tool that screens job applicants, a system that approves or declines a customer, automated scoring of any kind, each has to be described: what the decision is, what personal information feeds it, and in general terms how it works. If you were already over the $3m line, or covered for any other reason, this is a fresh obligation landing on you no matter what happens with the AML change.
It also arrives in a privacy regime with more teeth than it used to have. The same wave of reforms gave the regulator stronger enforcement powers and opened up new ways for individuals to pursue a business that mishandles their personal information, which lifts the cost of a privacy policy that is out of date or silent on how you really use data.
Put it together and the squeeze comes from both sides. A business that was exempt can walk into AML reporting in July, which pulls it under the Act, which means the December AI rule applies to it too. A business that was already covered skips the first step and goes straight to the second. Either way, 2026 is the year the privacy policy you have not opened in years stops being good enough.
The regulator has already started looking
This is not a rule that sits on the books waiting for a complaint. The OAIC is running a compliance sweep of privacy policies right now, checking that they say what the law requires. A privacy policy that is silent on automated decisions, or that does not exist because the business assumed it was exempt, is exactly what a sweep is built to find.
The most expensive time to fix this is when you are selling
Here is the part that turns a compliance job into a commercial one.
We see it on the sell side all the time. An owner has built something valuable over years, a real customer base, data collected and stored across a handful of systems, some of it flowing to tools that sit offshore. None of it was a problem while they ran the business their own way. Then a buyer gets serious, and the buyer’s lawyers start asking how the data was collected, what the business is allowed to do with it, and where it is held. When the answers are not written down anywhere, that does not usually collapse the deal outright. What it does is wear down the buyer’s confidence, and a less confident buyer protects themselves through the deal terms: tighter warranties about the data, more money held back at completion, more of the price made conditional on nothing surfacing later.
The same logic runs in reverse, and in your favour. Built at the source, while you are setting up your systems and collecting information as you go, getting the privacy policy and collection statements right is a small, contained job. Retrofitted under a buyer’s timetable, or after a regulator has come knocking, it is neither small nor contained. This is the quiet case for getting compliant now even if you are convinced you are still exempt. The cheapest version of this work is the one you do before you need it.
What getting it right actually looks like
The work itself is more contained than the law makes it sound, and it tends to come down to a few things.
Knowing what you collect and where it goes. A proper privacy policy is built on an honest map of the personal information moving through the business, including whether any of it goes offshore and to where, because that changes what the policy has to say. Most owners have never drawn that map, and drawing it is where the real value sits.
A privacy policy and a collection statement that match what you actually do. Not a template lifted from another business, which is the thing the regulator’s sweep is most likely to catch, but documents that reflect your systems, including any automated or AI driven decisions you make about people.
A way to keep it current. Privacy is not set and forget. Every time you add a new system, a new tool, or send data somewhere new, the picture shifts, and the obligations shift with it. The businesses that handle this well treat it as something they check when things change, not a document they wrote once and never opened again.
Exactly which of these apply, and how far you need to go, depends on your business, the information you hold, and whether the AML changes catch you. That is the conversation worth having before December, not after.
What to do about it
The cheapest moment to act is now, while this is a setup job rather than a salvage job. There is no deadline pressure yet, no buyer in the room, and no regulator at the door, which is precisely what makes it easy.
If you run a business: the first step is working out whether these changes catch you, and most owners cannot tell from the outside. Book a free 15-minute call with our legal team. We will tell you straight whether you are likely caught now, whether you are heading that way, and what getting compliant would actually involve. From there we can take it as far as you need, or leave you with a clear picture and nothing to buy.
If you advise businesses: your clients are about to start asking about this, and the accountants, agents and conveyancers among them are the ones the AML change catches first, which means your own firm is very likely caught too. It is worth flagging to clients now, while fixing it is simple. Book a call and we will work through it with them, and with you.
If you broker business sales: privacy is becoming a due diligence issue, so a selling client with gaps here can see their deal slow down or even possibly their price reduced. Flagging it early protects the deal and your relationship, and the AML change may catch your own brokerage too. Point your clients our way, or book a call and we will work through it with them.















