Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

Privacy reforms to impact over 100,000 small businesses

March 12, 2026, Anna Johnston

A little-known side effect of changes to anti-money laundering laws is that more than 100,000 small businesses in Australia will, for the first time, be required to comply with the Privacy Act, starting 1 July 2026.

While most small businesses in Australia – defined as having a turnover of less than $3M pa – have been exempt from the Privacy Act since 2001, there are some exceptions to that rule.  One such exception is for health service providers: no matter how small, and whether for-profit or non-profit, private sector health service providers in Australia must comply with obligations under the Privacy Act 1988, including to handle personal information in accordance with the Australian Privacy Principles (APPs).

A second exception relates to ‘reporting entities’ under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act).  In order to address the risks of money-laundering, Parliament determined that certain industries must gather additional data about their clients and customers, in order to fulfil their ‘know your customer’ obligations.  Since the customers of those industries are therefore obligated to hand over their valuable personal information including evidence of identity documents, there is a parallel obligation on the regulated entities to ensure that they collect, store, use, disclose and dispose of that personal information in a way which respects their customers’ privacy.

So what’s changing on 1 July?

The list of industries regulated under the AML-CTF Act is expanding.  From 1 July 2026, the AML-CTF Act will cover not only the financial sector, but also lawyers, conveyancers, accountants, real estate professionals, and dealers in high value goods such as jewellers, amongst others.

Businesses in those industries which previously enjoyed the ‘small business’ exemption from the Privacy Act will lose the benefit of that exemption on 1 July.  The OAIC estimates that this change will impact more than 100,000 small businesses. 

(Larger businesses should already be complying with the Privacy Act, but guidance from the OAIC about the interplay between AML-CTF rules and the APPs will still be useful.)

What do businesses need to do now?

Businesses need to prepare.  Significant uplift may be required to check data flows and develop a compliant Privacy Policy, collection notices, data retention procedure, and more. Over-collection and over-retention of data in particular can cause significant privacy risks.

Businesses also face a tooled-up privacy regulator, and a recently beefed-up civil penalty regime. With the OAIC currently conducting a compliance sweep of Privacy Policies to check their compliance with APP 1.4, now is the time to act, to get your house in order.

Businesses should prepare by:

  • Drafting a Privacy Policy to meet the requirements of APP 1.4
  • Drafting collection notices to meet the requirements of APP 5
  • Assessing data flows for compliance with APPs 2-13
  • Ensuring data retention procedures are appropriate
  • Training staff in their privacy obligations, and
  • Reviewing overall privacy maturity such as data breach preparedness.

Helios Salinger know-how can assist.  See our:

  • Small Business Privacy Pack for template policy documents and plain language, pragmatic guidance
  • Privacy Act compliance training for easy online training for all staff, and
  • Privacy Self-Assessment Toolkit to assess your maturity, or audit your business practices in more depth.

Or please get in touch with the Helios Salinger team for assistance with any privacy compliance needs, or our sister business Source for specialist advice on AML-CTF compliance.

Photograph © Juan Manuel Núñez Méndez on Unsplash

Filed Under: Blog

If you enjoyed this blog, subscribe to our newsletter to receive more privacy insights and news every month.

Privacy Compliance Kits

Recent Posts

  • Tick and flick: what ’I agree’ really means to Australians in 2026
  • Inching towards individuation: OAIC decision on pixels broadens scope of the Privacy Act
  • How dark patterns can land you in hot water: new case offers lessons for all
  • How to sniff out the landmines that can ruin your AI project
  • Privacy reforms to impact over 100,000 small businesses
  • The view from the summit: trust and hope, caution and concern, and plenty of hard work
  • Is identifiability in the eye of the beholder?  EU case tests limits of pseudonymisation
  • Mind the gap: when legal permission is not enough to ensure compliance
  • Why “Don’t worry it’s de-identified” should (still) be a red flag when considering privacy risk
  • How to get ahead of the new ADM rules before they rule you

Archive

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015

Search

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.