Institutional exemption · Australia
The Australian Privacy Act does not apply to most businesses below 3 million dollars in annual turnover — about 95 percent of trading businesses as of June 2021 — and the removal agreed in principle in 2023 has not been legislated
When the Privacy Act 1988 was extended to the private sector in 2000, the extension came with a carve-out. Section 6D defines a small business operator by annual turnover, and a business at or below 3 million Australian dollars is not an APP entity. The threshold is still 3 mill…
- Resolution status
- not confirmed
- Checked
- 2026-08-19
- Evidence type
- SecondaryPress reports and institutional documents
- Outlet
- not recorded
- Authoring mode
- Derived from press reports
- Views
- 13
What is happening?
When the Privacy Act 1988 was extended to the private sector in 2000, the extension came with a carve-out. Section 6D defines a small business operator by annual turnover, and a business at or below 3 million Australian dollars is not an APP entity. The threshold is still 3 million dollars in 2026, and no source opened here records it being indexed or adjusted at any point since it was set.
The carve-out is not a narrow one. As of June 2021, 2,288,441 businesses had annual turnover at or below the threshold, and businesses above the line were fewer than 5 percent of trading businesses in the country. The exemption is also not limited to one duty. A business below the line is outside the Australian Privacy Principles as a whole — no obligation to publish a privacy policy, no binding rules on collection, use and disclosure, no security obligation, no right of access or correction for the individual, and no duty to notify anyone under the notifiable data breaches scheme.
Section 6D carries exceptions that pull some businesses back under the Act regardless of turnover, including health service providers other than for employee records, businesses that disclose or collect personal information for a benefit, contracted service providers under Commonwealth contracts, and credit reporting bodies. How many entities remain exempt after those exceptions are applied is not published, so the 2.29 million figure is the population below the turnover line rather than a count of exempt entities.
Removal has been recommended three times. The Australian Law Reform Commission recommended abolishing the exemption in Report 108 in 2008. The Australian Competition and Consumer Commission urged reconsideration of the small business, employee records and political party exemptions in the final report of its digital platforms inquiry in 2019-07, though that report was not opened in this round. The Attorney-General's Department returned to it in the Privacy Act Review Report of 2023-02-16, where proposal 6.1 recommended removal subject to four preconditions — an impact analysis for small business, a support package developed in consultation with the sector, a decision on risk-proportionate compliance such as sector codes, and small business readiness to comply.
The Australian Government responded on 2023-09-28, classifying 116 proposals as 38 agreed, 68 agreed in principle and 10 noted. Proposal 6.1 fell in the agreed in principle group, which is acceptance conditional on further consultation rather than a commitment to a date. Reform was then split. The first tranche, the Privacy and Other Legislation Amendment Act 2024, received royal assent on 2024-12-10 and carried a statutory cause of action for serious invasions of privacy commencing 2025-06-10, a children online privacy code, disclosure duties for automated decision making, a doxxing offence and expanded enforcement powers for the Office of the Australian Information Commissioner. The small business exemption was not in it. As of 2026-06 no second tranche bill had been introduced, no commencement dates existed for the heaviest proposals, and both the small business exemption and the employee records exemption remained in force.
Whose problem is this?
| Role | Who |
|---|---|
| Affected | Individuals whose personal information is held by a business below the turnover threshold. They have no statutory right of access or correction against that business, and no entitlement to be told if the information is lost. No national count of these individuals exists — see the size block |
| Raised by | The Australian Law Reform Commission in 2008 · the Australian Competition and Consumer Commission in 2019 · the Attorney-General's Department in the 2023 review · the Office of the Australian Information Commissioner, whose jurisdiction stops at the same line |
| Decides | The Parliament, which alone can amend section 6D · the Attorney-General's Department, which drafts the second tranche · the Australian Government, which decides whether and when to introduce a bill |
| Bears the cost | Individuals, who carry the risk with no notification right and no complaint path · businesses below the line, which would carry the compliance cost if the exemption is removed · the regulator, which cannot look inside the exempt sector even to measure it |
The body that recommended removal in 2023 is the same body that must now draft the bill, and the body that agreed in principle is the same one that decides when the bill is introduced. Nothing outside those bodies starts the clock, and the individuals on the other side of the line are not parties to any of it.
Where does this problem end?
| Axis | This is the problem | This is not the problem |
|---|---|---|
| What | The existence of the section 6D turnover exemption and the fact that the recommended removal has not been legislated | Whether the compliance burden on small business justifies keeping the exemption is a value question this document does not decide |
| The effect of the exemption on the whole of the Australian Privacy Principles, not the breach notification duty alone | Whether privacy regulation is good or bad for the economy is not decided here either | |
| Who | Businesses inside federal jurisdiction that fall below the turnover line, and the individuals whose information they hold | Entities that section 6D returns to coverage regardless of turnover are already inside the Act and outside this frame |
| Where | The federal Privacy Act 1988 | State and territory privacy statutes governing public sector agencies are a separate scheme on a different axis |
| When | 2000 through 2026-08-19 | The design debate that preceded the 2000 extension was not examined |
| Scale | 2,288,441 businesses below the line as of June 2021 | The merits of any enforcement proceeding now before the courts, and of any individual breach at an entity the Act already covers, are outside this frame |
| Comparison | Australian law only | Comparison with the European or other foreign regimes is context here and not a standard this document applies |
The boundary of this problem is the boundary of the statute itself, and every question inside it is about who the law reaches rather than what the law demands.
What is the state now, and what should it be?
Now
| Indicator | Value | As of |
|---|---|---|
| Small business exemption in force | yes, section 6D of the Privacy Act 1988 | 2026-06, the most recent opened source |
| Turnover threshold | 3 million Australian dollars in annual turnover | 2026-06, the most recent opened source |
| When the threshold was set | 2000, with the extension of the Act to the private sector | 2000 |
| Businesses at or below the threshold | 2,288,441 | June 2021 |
| Share of trading businesses above the threshold | under 5 percent | June 2021 |
| Entities still exempt after the section 6D exceptions | not published | 2026-08-19 |
| Official reviews recommending removal or reconsideration | three — 2008, 2019, 2023 | 2023-02-16 |
| Government response to proposal 6.1 | agreed in principle, one of 68 in that category out of 116 proposals | 2023-09-28 |
| First tranche of reform | Privacy and Other Legislation Amendment Act 2024, royal assent 2024-12-10, exemption not included | 2024-12-10 |
| Second tranche bill before the Parliament | none introduced | 2026-06 |
| Commencement date for removal of the exemption | none named | 2026-06 |
| Breach notifications from entities the Act covers | 1,205 in calendar 2025, the highest since the scheme began in 2018, up 8 percent on 1,112 in 2024 | 2026-07-06 |
| Breach notifications from entities below the threshold | none, the scheme does not reach them | 2026-08-19 |
What it should be. Unlike many problems in this collection, the end state here was named by the institution itself rather than by an outside advocate. The Attorney-General's Department proposed removal of the exemption in proposal 6.1 of the 2023 review, subject to the four preconditions above, and the Australian Government agreed in principle to that proposal on 2023-09-28. What no opened source supplies is a date, a body responsible for certifying that each of the four preconditions has been met, or a published test for what meeting them would look like.
No opened source names a date by which the exemption is meant to end.
How big is it?
The population layer for this document records not-derivable, and the reason is structural rather than clerical. The quantity this problem is about is the number of individuals whose personal information sits outside the Act, and that number has never been produced.
What exists is a count of entities, not of people. As of June 2021 there were 2,288,441 businesses with annual turnover at or below 3 million Australian dollars, and businesses above that line made up fewer than 5 percent of trading businesses. Both figures are reported from Australian Bureau of Statistics data by sources opened here rather than read from the statistical table itself.
Two subtractions are missing between that count and the answer. The first is the section 6D exceptions, which return an unpublished number of below-threshold entities to coverage, so the exempt denominator is smaller than 2,288,441 by an unknown amount. The second is the step from businesses to individuals, and no opened source attempts it.
The count that would answer this question does not exist because nobody is required to produce it.
The one privacy series that does exist has the same boundary as the law. The notifiable data breaches scheme recorded 1,205 notifications in calendar 2025, the highest annual figure since the scheme began in 2018 and 8 percent above the 1,112 of 2024. Every one of those came from an entity the Act covers. For the sector below the threshold the corresponding figure is not zero, it is absent, because no duty to notify exists and therefore no collection exists.
A separate criminal series suggests the sector is exposed. Reports to the national cyber security centre totalled 84,700 in the 2024-25 financial year, about one every six minutes, and the average loss per small business incident was 56,600 Australian dollars, up 14 percent on the prior year. That series counts reports of crime rather than compliance with the Privacy Act, it is drawn here from a secondary summary rather than the annual report itself, and it cannot be converted into the missing number.
Under what conditions does it arise?
1. The exemption is the default, and defaults do not need a decision. Removing it requires a bill, a passage through both houses and a commencement date. Keeping it requires nothing at all. Every year in which no bill is introduced is a year in which the exemption survives without anyone having voted to keep it.
Keeping the exemption requires no decision by anyone, while removing it requires an Act of the Parliament.
2. The 2023 recommendation converted a yes or no into four conditions with no owner. Proposal 6.1 did not recommend removal on a date. It recommended removal after an impact analysis, after a support package developed with the sector, after a decision on risk-proportionate compliance, and after small business is in a position to comply. No opened source names the body that certifies any of the four, or the evidence that would settle them.
3. Reform was split, and this item went to the side without a bill. The first tranche carried the proposals whose design was settled and became law on 2024-12-10. The proposals that change who the Act applies to went to a second tranche that, as of 2026-06, exists as a commitment rather than as a bill before the Parliament.
4. The measurement boundary is drawn in the same place as the legal boundary. The statistics that would show what the exemption costs are collected only from entities the exemption does not cover. A sector that is exempt from reporting is also a sector that generates no reported numbers, and a problem with no numbers is difficult to place against any competing demand on legislative time.
What has been tried?
| Attempt | By whom | What was done | When |
|---|---|---|---|
| Recommendation to abolish the exemption | Australian Law Reform Commission, Report 108, chapter 39 | Recommended removal of the small business exemption as part of a full review of Australian privacy law | 2008 |
| Recommendation to reconsider the exemptions | Australian Competition and Consumer Commission, digital platforms inquiry final report | Identified the small business, employee records and registered political party exemptions as requiring reconsideration. The final report itself was not opened in this round and the wording is taken from secondary summaries | 2019-07 |
| Proposal 6.1 | Attorney-General's Department, Privacy Act Review Report | Recommended removal subject to four preconditions — impact analysis, a support package developed with the sector, a decision on risk-proportionate compliance such as codes, and small business readiness | 2023-02-16 |
| Formal government response | Australian Government | Classified 116 proposals as 38 agreed, 68 agreed in principle and 10 noted. Proposal 6.1 was placed in the agreed in principle category | 2023-09-28 |
| First tranche legislated | The Parliament | Privacy and Other Legislation Amendment Act 2024 received royal assent, carrying a statutory cause of action for serious invasions of privacy from 2025-06-10, a children online privacy code, automated decision disclosure, a doxxing offence and expanded regulator powers. The small business exemption was not addressed | 2024-12-10 |
| Second tranche | Australian Government | No bill introduced. No commencement dates for the most significant proposals. The small business and employee records exemptions remain in force | as of 2026-06 |
Three separate reviews reached the same conclusion across fifteen years, and the instrument that would give effect to it has been drafted zero times.
What was found?
| Finding | Observed value | Evidence grade |
|---|---|---|
| The small business exemption is in force | yes, section 6D | high — described as current by three opened sources dated 2023, 2024 and 2026 |
| Turnover threshold | 3 million Australian dollars | high — two opened sources give the same figure |
| The threshold has not moved since it was set in 2000 | unchanged | medium — inferred from the 2008 review chapter for the origin and 2023 to 2026 sources for the current value. The text of section 6D was not read here |
| Businesses at or below the threshold | 2,288,441 as of June 2021 | medium — an Australian Bureau of Statistics figure reported by an opened secondary source; the statistical table was not opened |
| Share of trading businesses above the threshold | under 5 percent | medium — same basis, two opened sources agree |
| Entities exempt after the section 6D exceptions | not published | high — the absence is consistent across every opened source |
| Scope of the exemption | the whole of the Australian Privacy Principles, not the notification duty alone | high — two opened sources describe it the same way |
| The four preconditions attached to proposal 6.1 | impact analysis, support package, risk-proportionate compliance, readiness | medium — from a legal summary of the review report; the review report itself timed out and was not opened |
| Government response classification | 38 agreed, 68 agreed in principle including 6.1, 10 noted, on 2023-09-28 | high — an opened firm note published two weeks after the response |
| First tranche excluded the exemption | yes, royal assent 2024-12-10 | high — two opened sources |
| Second tranche bill introduced, at the date of the most recent opened source | no, at 2026-06 | medium — one opened source, and no later source was found |
| Breach notifications, calendar 2025 | 1,205, up 8 percent on 1,112 | high — regulator media release opened directly |
| Cybercrime reports and average small business loss | 84,700 reports and 56,600 Australian dollars in the 2024-25 financial year | low — a secondary summary of the annual cyber threat report; the report itself was not opened, and the series measures crime reports rather than privacy compliance |
Why is it still unsolved?
Institutional exemption — the rule that would close it has been recommended three times and written zero times, and the state that persists in the meantime is the one nobody has to defend.
The first part of the answer is the direction of the default. A gap in a statute has to be closed by an act of the legislature, and a carve-out inside a statute has to be removed by one. Both require the same effort, but only one of them looks like inaction when nothing happens. Fifteen years of no legislation on this item reads in the public record as a pending matter rather than as a decision, and no vote has ever been taken that could be pointed at.
The second part is that the 2023 recommendation attached four preconditions and no owner. A recommendation to remove an exemption on a date can be reported as late. A recommendation to remove it after four things are true can only be reported as pending, and it stays pending for exactly as long as nobody is responsible for saying whether the four things are true. No opened source names such a body, or a published test, or a review point at which the question is asked again.
A condition with no owner cannot be reported as met, and a reform with no bill cannot be reported as late.
The third part is that the reform was split and this item went to the tranche without a bill. Splitting a package by difficulty is an ordinary way to get the settled parts into law quickly, and the first tranche did become law. The cost of the split falls entirely on the second group, which now consists of the proposals that change who the Act applies to and which has no draft text, no introduction date and no commencement date.
The fourth part is the one that keeps the pattern stable. The evidence that would make this problem visible is collected from entities that are not exempt. Breach notifications rise year after year and every one of those notifications comes from the covered 5 percent, while the sector below the line produces no series at all. The result is that the exemption is invisible in exactly the statistics that measure the harm it is supposed to be weighed against.
What observation would mean it is solved?
Candidates — (a) a bill removing the section 6D turnover exemption is enacted with a stated commencement date (b) the regulator begins publishing breach notifications and complaints from entities below the former threshold (c) an individual can obtain access to, or correction of, personal information held by a business below the threshold, and can complain to the regulator if refused.
(a) alone is weaker than it looks. An amending Act can arrive with a transition period long enough, a replacement threshold high enough, or a code-based compliance path light enough that the practical position of the individual does not change. The four preconditions in proposal 6.1 are also the design space in which such softening would be legitimate, so the enacted form matters more than the enactment.
(b) alone can move for the wrong reason. If coverage expands, notification counts rise mechanically because the reporting population grew, not because practice changed. A rise would confirm that the sector was never empty, which is worth knowing, but it would not measure whether personal information is better handled. The series would need several years and a stable population before it says anything about behaviour.
(c) is the one that is actually about the person, and it is also the one nobody currently measures. The right of access and the complaint path are what the exemption removes, so the observation that matters is whether those two work when exercised against a small business, not whether they exist on paper. The three have to be read together, with (c) treated as the test of whether (a) did anything.
What is it connected to?
Fills with researchthe employee records exemption and the registered political party exemption, which sit in the same set of carve-outs and were named alongside this one in 2019; the fair and reasonable test proposed for the second tranche; state and territory privacy statutes covering public sector agencies, which govern a different set of bodies on a different basis; small business cyber security support programs, which address exposure without altering legal obligation; and the treatment of turnover thresholds in other Australian regulatory statutes. Relation type and evidence grade were not confirmed in this round.
What these sources do not say
- How many individuals are affected. No opened source estimates the number of people whose personal information is held by businesses below the threshold. This is closer to an uncollected quantity than an unfindable one — the exemption itself removes the duty that would generate the records, so no agency is positioned to count it.
- How many entities are exempt after the section 6D exceptions. The 2,288,441 figure reflects the turnover test alone. No opened source subtracts health service providers, credit reporting bodies, Commonwealth contractors or businesses that trade in personal information, so the size of the exempt population is known only as an upper bound.
- How many breaches occur below the threshold. The notifiable data breaches series does not extend to exempt entities, so the answer is not zero and not unknown-but-estimated. There is no collection.
- Who certifies the four preconditions. No opened source names a body responsible for determining whether the impact analysis, the support package, the compliance model and the readiness of the sector have been achieved, or what evidence would settle any of the four.
- When the second tranche bill will be introduced. No opened source carries draft text or an introduction date, and the most recent of them, dated 2026-06, records that no bill had been introduced. Nothing opened here covers the two months between that date and this check, so the record after 2026-06 is unexamined rather than empty. This is a statement about the record and not a forecast.
- What the 2019 inquiry final report actually said about the exemption. That report exceeded the file size that could be retrieved here, so its treatment of the small business exemption is taken from secondary summaries that agree with each other but were not checked against the original.
- The position of the small business sector in its own words. A peak body page setting out the argument for retaining or delaying the removal was identified but returned an automated access refusal, so no opened source carries that argument as its author stated it. The institutional acknowledgement of the compliance burden that is available here is the wording of proposal 6.1 itself, which conditions removal on support and readiness.
- Any on-the-record reason for placing this item in the second tranche. No opened source carries a statement from the Attorney-General's Department or the Australian Government explaining why the exemption was left out of the first tranche.
See the evidence
| Item | Source | Confirmation |
|---|---|---|
| Origin of the small business exemption with the 2000 extension of the Act to the private sector, and the 2008 recommendation to abolish it | Australian Law Reform Commission, Report 108, For Your Information, chapter 39 on the small business exemption | 2026-08-19 |
| Proposal 6.1 and its four preconditions · turnover threshold of 3 million dollars · 2,288,441 businesses at or below it as of June 2021 · fewer than 5 percent of trading businesses above the line · section 6D exceptions | Keypoint Law, note on the proposed removal of the small business exemption, 2023-05-22 | 2026-08-19 |
| Government response of 2023-09-28 classifying 116 proposals as 38 agreed, 68 agreed in principle and 10 noted, with proposal 6.1 in the agreed in principle group | Allens, note on the federal government response to the review, 2023-10-11 | 2026-08-19 |
| Contents of the first tranche and royal assent on 2024-12-10 — statutory cause of action from 2025-06-10, children online privacy code, automated decision disclosure, doxxing offence, expanded regulator powers — with the small business exemption not included | MinterEllison, note on the Privacy and Other Legislation Amendment Act 2024 | 2026-08-19 |
| Second tranche status as of 2026-06 — no bill introduced, no commencement dates for the most significant proposals, small business and employee records exemptions still in force | Rules Mate, note on the second tranche of Privacy Act reforms, 2026-06-12 | 2026-08-19 |
| Scale of the exemption and its effect on the Australian Privacy Principles as a whole rather than the notification duty alone | International Association of Privacy Professionals, note on small businesses and the Privacy Act amendments, 2024-02 | 2026-08-19 |
| 1,205 notifiable data breach notifications in calendar 2025, the highest since the scheme began in 2018, up 8 percent on 1,112 in 2024, covering entities the Act applies to | Office of the Australian Information Commissioner, media release, 2026-07-06 | 2026-08-19 |
| 84,700 cybercrime reports in the 2024-25 financial year, about one every six minutes, and an average small business loss of 56,600 Australian dollars, up 14 percent | Secondary summary by a managed services provider of the Australian Signals Directorate annual cyber threat report 2024-25, published 2025-10-24 | 2026-08-19 |
| The 2019 digital platforms inquiry final report and its treatment of the small business, employee records and political party exemptions | Australian Competition and Consumer Commission, Digital Platforms Inquiry final report, 2019-07 | URL not confirmed: the file exceeds the 10 MB retrieval limit, so the original was not opened and the wording is taken from secondary summaries |
| The position of a national small business peak body on removal of the exemption | Council of Small Business Organisations Australia, post on small business and privacy law obligations | URL not confirmed: automated retrieval returned HTTP 403 |
| The full text of proposal 6.1 and its four preconditions as published | Attorney-General's Department, Privacy Act Review Report, released 2023-02-16 | URL not confirmed: automated retrieval timed out on two attempts, so the preconditions are taken from a legal summary |
No primary source was read in full. The regulator media release on the 2025 breach statistics and the law reform commission chapter on the exemption were opened directly and carry the notification counts and the origin of the carve-out. Everything else rests on professional and trade sources that cite the review report, the government response and the amending Act. Three documents that would have been the primary basis for this dossier were not opened — the review report itself timed out, the 2019 inquiry final report exceeds the retrieval size limit, and the peak body page refused automated access — and the rows above say which claims consequently rest on secondary summaries. Where the opened sources overlap they agree: the 3 million dollar threshold appears identically in two, the exclusion of the exemption from the first tranche appears in two, and the classification of proposal 6.1 as agreed in principle appears in one source published two weeks after the response and is consistent with the second tranche status described three years later. The one figure carried on a single opened source is the 2026-06 statement that no second tranche bill has been introduced, and no later source was located that would confirm or contradict it. This is a Path A output, research-based definition, so observation_refs is empty and provenance_mode: press-derived.
This table holds 11 evidence rows, 8 of which carry a source you can open · 8 distinct sources. How this table is made
People affected
Estimated range Not derivable
The reason and what is missing are listed under “What is missing” below
What is missing 2
Grouped by how it gets filled, not by block number — that axis is the only one that tells a reader what can be done next.
- SectionWhat is it connected to?
the employee records exemption and the registered political party exemption, which sit in the same set of carve-outs and were named alongside this one in 2019; the fair and reasonable test proposed for the second tranche; state and territory privacy statutes covering public sector agencies, which govern a different set of bodies on a different basis; small business cyber security support programs, which address exposure without altering legal obligation; and the treatment of turnover thresholds in other Australian regulatory statutes. Relation type and evidence grade were not confirmed in this round.
Fills with research
- Derived valueThe affected population could not be derived
The quantity this problem is about is the number of individuals whose personal information is held by businesses that sit outside the Privacy Act, and no opened source produces it. What exists is a count of entities: 2,288,441 businesses had annual turnover at or below 3 million Australian dollars as of June 2021, and businesses above that line were fewer than 5 percent of trading businesses. Two steps are missing between that count and a headcount of people. The first is the set of exceptions in section 6D, which returns an unpublished number of below-threshold entities to coverage regardless of turnover, so the exempt denominator is smaller than 2,288,441 by an unknown amount and can only be stated as an upper bound. The second is the step from businesses to the individuals whose records they hold, and no opened source attempts an average, a distribution or a national total. A derivation from the breach statistics is also blocked, because the notifiable data breaches series counts only entities the Act applies to. Its 1,205 notifications in calendar 2025 come entirely from the covered minority, and for the exempt sector the corresponding figure is not zero but absent, since the exemption removes the duty that would create the record. That absence is the structure of the problem rather than a gap in this research round.
A national count of individuals whose personal information is held by businesses below the 3 million dollar turnover threshold; a published count of entities that remain exempt after the section 6D exceptions are applied, which would fix the denominator; any survey or estimate of records held per business in the exempt population; and any collection of breach or complaint data from entities the Act does not reach.
Needs a new measurement
Voting and commenting require you to be signed in. Sign in from the account page
Comments
The comment was empty, so nothing was posted.
The comment exceeded the limit, so nothing was posted. We do not truncate and save.
You just posted a comment. Please try again in a moment.
The target comment could not be found, so nothing was posted.
You must be signed in to comment.
You have already reported this comment. Each person counts once — to withdraw it, use Cancel report under Reports you filed on the notifications page.
This report has already been reviewed. A judged report cannot be filed again or withdrawn.
No reason was chosen, or Other was picked without a note, so the report was not filed.
You cannot report your own comment or your own profile. Use Delete to take down your own comment.
Report received. Once 3 different people report it, the comment is hidden until review finishes — the outcome appears on your notifications page.
Voting and commenting require you to be signed in. Sign in from the account page
No comments yet.