The privacy law that applies even if the Privacy Act does not
Small businesses under $3 million turnover have long been exempt from the Privacy Act. Since June 2025 that exemption no longer protects them from being sued directly by an individual.
The gap that closed
For most of the Privacy Act's life, a business turning over less than $3 million a year has sat outside it. No Australian Privacy Principles, no notifiable data breach obligations, no OAIC jurisdiction. A great many Australian medical practices, allied health clinics, real estate agencies, recruiters, clubs and professional firms have operated on that basis for years.
On 10 June 2025 a statutory tort for serious invasions of privacy commenced. It creates a cause of action an individual can bring themselves, in court, against another person or organisation. Critically, it is not limited to entities covered by the Privacy Act. A small business that has never had a privacy obligation in its life can be a defendant.
That is the change worth understanding. Not a new regulator, not a new compliance regime — a new way for an individual to take you to court directly.
What the tort requires
Broadly, the action covers two kinds of invasion: intruding upon someone's seclusion, and misusing information about them. To succeed, an individual generally needs to establish that:
- the invasion was intentional or reckless — negligence alone is not the target of this action;
- a person in their position would have had a reasonable expectation of privacy in the circumstances;
- the invasion was serious; and
- the public interest in privacy outweighs any countervailing public interest.
The intentional-or-reckless requirement is doing real work here, and it is why this is not a licence to sue over every misdirected email. An ordinary mistake is unlikely to qualify. But "reckless" is a lower bar than "deliberate", and an organisation that was told about a risk and did nothing is in a materially worse position than one that was not.
Why this changes the calculation
If you have previously reasoned that privacy is not your problem because you are under the threshold, that reasoning no longer holds. The relevant questions have changed:
- The threshold is irrelevant to this action. Turnover determines whether the Privacy Act applies. It does not determine whether an individual can sue you.
- The complainant is an individual, not a regulator. There is no conciliation process to work through first and no regulatory discretion to rely on.
- Documented warnings become evidence. Recklessness is about state of mind. An unactioned risk assessment, an ignored penetration test, or an email from your IT provider recommending a control you declined all speak to what you knew.
That last point deserves emphasis, because it inverts something. Advice you received and did not act on is now potentially more damaging than advice you never sought. This is not an argument for staying ignorant — it is an argument for closing the items on the list.
Where exposure actually sits
In the environments we assess, the situations most likely to look like a serious invasion of privacy are mundane and long-standing:
- Files everyone can see. A shared drive or SharePoint site where HR records, medical information or client files are open to the whole organisation because permissions were set once in 2019.
- Former staff with live access. Accounts that were never disabled, personal devices never wiped, shared mailboxes still delegated.
- Data retained long past its purpose. Candidate records from recruitment rounds years ago, former client files nobody has authority to delete, backups nobody has scoped.
- Monitoring nobody disclosed. Productivity tooling, mailbox access, location tracking on work devices — the surveillance category is precisely where "intrusion upon seclusion" lives, and workplace surveillance is under active law reform attention.
- Third-party access nobody reviews. Contractors, bookkeepers, marketing agencies and IT providers with standing access to systems holding personal information.
What to do about it
- Find out what personal information you hold and who can reach it. Not a data-mapping project — a permissions review of the systems holding your most sensitive records. For most organisations that is Microsoft 365 and one line-of-business application.
- Fix over-broad access first. Restricting HR and client folders to the people who need them is a morning's work and removes the most plausible scenario.
- Close the offboarding gap. A documented, tested leaver process that disables accounts the same day, revokes sessions and removes device access.
- Decide what you delete and when. Data you no longer hold cannot be exposed. Retention is the only control that reduces the size of the problem rather than defending it.
- Disclose your monitoring. If you monitor staff activity, devices or location, make sure people know, in writing, and that it is proportionate to a purpose you can articulate.
- Work through the recommendations you have already been given. Whatever is sitting unactioned in your last assessment report is the most likely evidence against you. Either do it or record why you decided not to.
What is still coming
The tort is part of the first tranche of Privacy Act reforms, alongside stronger OAIC enforcement powers, new penalty tiers and the automated decision-making transparency obligation commencing in December 2026.
Removing the small business exemption altogether is a proposed second-tranche reform. The government has supported it in principle, but no legislation has confirmed a general removal or a start date, and the timing remains genuinely uncertain. We would not plan a budget around it — but if you are under the threshold today, the direction of travel is not toward being left alone.
A useful test: pick the folder holding your most sensitive personal information — HR files, client health records, whatever it is for you — and ask how many people in the organisation can currently open it. If the answer is "everyone" or "I would have to check", start there.
This is general information about a change in the law, not legal advice. The elements of the tort and how they apply to your circumstances are questions for a lawyer. What we can help with is the part underneath — knowing what you hold, and who can reach it.
Find out who can open what
Every assessment includes a permissions review across Microsoft 365 and your file platforms: over-shared locations, standing third-party access, and accounts that should have been disabled.