There is a run of changes to the Privacy Act arriving through 2026, and between them they pull a lot more businesses under the Act than were caught even a year ago. If you are buying a business, that is worth knowing on 2 fronts. It is a real question to dig into during due diligence. And it is something to stay on top of once the business is yours.
Why this is suddenly a buyer’s question
The reason more targets are now caught comes from an unexpected direction. From 1 July 2026, a wave of anti money laundering reforms, often called Tranche 2, makes a new group of businesses reporting entities: accountants, business brokers, real estate agents, conveyancers, property developers, and trust and company service providers. The moment a business is caught for AML, it loses the small business exemption that kept it out of the Privacy Act for that part of its work. The OAIC estimates more than 100,000 small businesses are pulled in this way, most of them having assumed privacy law was someone else’s problem.
For a buyer, privacy shows up in 1 of 2 ways:
- The business you are buying is already caught, through its turnover, the kind of information it holds, or the AML changes.
- You are caught, and you are bringing the target into your group, so it picks up the obligations that already apply to you, even if it was exempt on its own.
And even if the target is not caught today, the exemption is on the Government’s list to wind back, and a growing business may push through the threshold anyway. The direction of travel is one way.
What the changes actually are
2 of them matter here. The AML capture from 1 July, above, is the one that decides who is newly in. The second is aimed at businesses already under the Act. From 10 December 2026, any covered business has to disclose in its privacy policy where it uses a computer program, including AI, to make decisions that significantly affect people. So if the target screens applicants, approves or declines customers, or scores people automatically, that disclosure obligation comes with it. The regime also has more enforcement teeth than it used to, which means inherited non-compliance is a real cost, not a theoretical one.
What this means for due diligence
Privacy belongs on the due diligence list next to the financials, as a real question about what you are taking on. The questions go to how the data was collected, what you can lawfully do with it after settlement, and what you would inherit if something has not been handled. A list built without the right consents, for instance, can be one you cannot use the way you had planned. We have a list of questions that can be asked during due diligence, and we can work through them with you.
When you buy the business, you generally take on its privacy history as well, including how the data was collected and anything that was never dealt with. If something has gone wrong, it can surface after settlement and become your problem.
The due diligence itself is worth handling with care. When the seller hands over the customer database for you to review, that is a disclosure of personal information under the Act. It should reach you de-identified, or with the right consents in place, rather than as a full copy emailed across. A seller who is casual about that is often telling you something about how the rest of the data has been handled.
How far you take it depends on the deal and what the business actually does, which is where it helps to have a set of eyes that has seen it before. The answers feed straight into the price, and into whether you need warranties, indemnities or a holdback to cover the risk.
And it does not stop at settlement
Once the business is yours, the obligations are yours too. If the target was caught and not compliant, you are the one carrying that from day 1, with a December deadline already on the calendar for the AI disclosure rule. Knowing this before you sign lets you build the fix into the plan, and the cost of it into the deal, rather than discovering it the first time a customer or the regulator asks.
We see buyers check the financials to the cent and fall in love with a customer list, then inherit a privacy gap nobody thought to ask about. The ones who ask early either get comfortable or get protection written into the contract. The ones who ask late find out after settlement, when the leverage has gone.
What to do about it
The cheapest moment to get this right is before you sign, while it can still shape the price and the warranties, and before the obligations become yours to run.
If you are buying a business: put privacy on the due diligence list as a real question about what you are taking on. We can run that review with you and build the right protections into the contract. Book a free 15-minute call and we will show you where the risk usually hides.















