
From 1 July 2026, a group of small businesses came under the Privacy Act 1988 for the first time, whatever their turnover. It covers real estate agents, conveyancers, accountants, lawyers, trust and company service providers, and dealers in precious metals and stones. The rule is narrower than it looks. It applies to the information these businesses handle for anti-money-laundering checks, not to everything else they collect. On a website, that line usually falls between the general enquiry form and the page where a client uploads a licence.
A two-person conveyancing practice in Camberwell has run the same website for six years. A contact form, a page about fees, a photo of the front office. Nothing about the site changed on 1 July. What changed is that the practice became a reporting entity under the anti-money-laundering laws. That pulls part of its work into a privacy regime it has never faced.
The Office of the Australian Information Commissioner is the federal privacy regulator. It has estimated that more than 100,000 small businesses are affected. Almost all the guidance written since is aimed at compliance officers. Very little of it answers what the owner asks first: what has to change on the website.

The trigger is the service, not the profession. The anti-money-laundering laws apply to a list of designated services. If your business provides one, you are a reporting entity. The Privacy Act then covers the personal information you handle in connection with those obligations.
That distinction does real work. The regulator’s own example is a law firm advising on a family law matter. The same client asks for help selling a house. Family law advice is not a designated service. Helping sell real estate is. The firm is caught for one part of its work and not the other.
Two other things decide whether you were already covered.
Turnover. The Privacy Act exempts a business turning over $3 million or less. This is the small business exemption. The OAIC checklist asks whether turnover has passed $3 million in any financial year since 2002. One strong year a decade ago is enough to put a business inside the Act for good.
Category. Health service providers, businesses that trade in personal information, Commonwealth contractors and operators of residential tenancy databases are covered at any size. An agency running a tenancy database was already in.
This is not a general removal of the small business exemption. If you run a cafe, a salon or a workshop under $3 million, nothing changed for you on 1 July 2026. One group of businesses lost the exemption, for one part of what they do.

A privacy policy under the Privacy Act is a public document. It describes what a business collects, why, who else sees it, how someone reaches their own record, and how to complain. It has to be clear, current and free to read.
Here is the part that saves work, and it comes from the OAIC directly. If your business is covered only because it is a reporting entity, the policy needs to cover your anti-money-laundering handling. It does not have to describe everything else the business collects.
So the first job is sorting: what does the site collect, and where does each item fall?
| What the website collects | Where it ends up | Caught by the 1 July 2026 change? |
|---|---|---|
| General enquiry, appraisal or fee request | Your inbox, and often the website database as well | No, unless it is part of onboarding for a designated service |
| Client onboarding form | The website, then your practice management system | Yes |
| Identity document uploaded through the site | Wherever the upload tool stores it, sometimes overseas | Yes, and the record-keeping rules changed as well |
| Newsletter sign-up | Your email platform, usually offshore | No |
| Analytics and third-party tracking code | The company that supplied the code | No on general pages. Yes if it loads on an onboarding page |
| Automatic website backups | Your host, sometimes kept for months | Follows whatever the backup contains |
One row deserves its own sentence. The anti-money-laundering rules no longer require you to keep a scan or photo of an identity document. You keep the details taken from it, and what you did to verify it. You do not keep the document. If an upload tool has been storing licences since July, you are expected to take reasonable steps to destroy them.
No. They are two separate requirements, and the second is the one small businesses miss. A collection notice goes to the person at or before the moment you collect their information. A privacy policy is a standing public document. The OAIC has said plainly that a privacy policy published on its own does not meet the notice requirement.
For an onboarding form, the notice has to tell the person:
The OAIC publishes a free template collection notice for reporting entities, and a free guide to writing a privacy policy. Both beat anything drafted from scratch by someone who has not read the rules.
A tracking pixel is a small piece of third-party code on a page. It reports what a visitor did back to the company that supplied it. Meta, Google and LinkedIn all offer one.
If your practice is covered only for anti-money-laundering handling, tracking code on your general pages sits outside the new obligation. That is the honest answer, and not the one you get from a product selling consent banners.
Two things narrow it. A pixel loading on a client onboarding page is collecting information in connection with a designated service. And if you are over the turnover threshold, or covered for another reason, the OAIC tracking pixel guidance applies across the whole site. Recent determinations went further. A general cookie banner is not enough where sensitive information is involved. Where tracking code loads as someone lands on a page, the notice has to be there at that moment.
Open the page where clients upload documents and look at what third-party code loads on it. Advertising and analytics tags added site-wide during a build will usually load there too, because nobody thought to exclude that page. Excluding it is a small change that removes the question.
An eligible data breach is one where personal information is lost, or accessed or disclosed without authorisation. It counts if a reasonable person would conclude it is likely to cause serious harm. You then have to tell the people affected and the OAIC.
The clock is specific. Where you suspect a breach but cannot yet be sure, you have up to 30 days to assess it. The Commissioner treats that as a ceiling, not a default. Once you have reasonable grounds to believe an eligible breach has happened, you notify as soon as practicable.
For a small practice, the breach usually does not start with a hacker. It starts with one of these.
The cheapest defence is holding less. Turn off form storage where the submission only needs to reach an inbox. Set a deletion schedule and put it in someone’s calendar. Move document uploads off the website if the files can sit somewhere with proper access control.
Since 10 June 2025 an individual has been able to sue for a serious invasion of privacy. It sits in Schedule 2 of the Privacy Act. The part that matters for a small business is simple. The person being sued does not have to be covered by the rest of the Act, so the exemption is no defence.
Two limits are worth knowing, because this gets overstated. The invasion has to be intentional or reckless, so a leak caused by a stale plugin will not usually meet the test. It also has to be serious.
The remedy is unusual. A claim can succeed without proof of loss, and damages can be awarded for emotional distress alone.
This is general information, current as at August 2026. It is not legal advice. Privacy obligations turn on the services your business provides. Check the current OAIC guidance, and get advice from your own lawyer or professional association, before relying on any of it.

New privacy policy rules take effect on 10 December 2026. They apply where a business has arranged for a computer program to use personal information to make a decision, or to substantially support one. The decision has to be one that could significantly affect a person’s rights or interests. The policy then has to describe the information used and the decisions involved.
For a conveyancer or an agent, this is not hypothetical. Automated identity verification and risk scoring is exactly what the rule describes. A third-party tool checks a client against a database and returns a pass, a fail or a flag. If that decides whether you can act for them, the policy has to explain it. Most firms will not know which tools do this until they ask the supplier.
The wider change is still only a promise. The Government has said it intends to remove the small business exemption for everyone. As at August 2026 no bill had been introduced and no start date set. Treat it as direction, not a deadline.
If your site takes documents, runs an onboarding form, or stores submissions nobody has read, this is a website job before it is a legal one. CJ Digital can trace what your site collects, where it ends up and who can reach it. Get in touch and we will start with the forms.
They started on 1 July 2026. That is the date the anti-money-laundering laws began applying to designated services. The businesses affected are real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones. From that date the Privacy Act applies to the information they handle for anti-money-laundering purposes, whatever their turnover.
No. The small business exemption still applies to a business with an annual turnover of $3 million or less. Removing it altogether is a government commitment rather than law. As at August 2026 no bill had been introduced and no start date had been set.
It is a poor idea, because the policy has to describe what your business does. A copied policy that misdescribes your handling is worse than a short accurate one. It is a public statement you can be held to. The OAIC publishes a free guide to writing a privacy policy, and a free template collection notice for reporting entities.
The Act asks for reasonable steps to make it available free of charge in a suitable form. In practice that means a page linked from the footer of every page, plus a link beside any form that collects personal information. A policy buried inside a PDF is harder to defend as a reasonable step.
Start by working out whether the website is holding them at all. Many upload tools keep a copy on the server as well as emailing it. The anti-money-laundering rules no longer require copies of identity documents to be kept for record-keeping. You are expected to take reasonable steps to destroy or de-identify copies you no longer need for another lawful purpose.

