The Privacy Act small business exemption is narrowing. From 1 July 2026, businesses that were previously exempt will need privacy policies, data breach processes, and NDB scheme compliance. Get a gap analysis now, not when the deadline hits.
Guarantee: Under 3 critical gaps found? You don't pay.
Sound familiar?
The exemption is ending
Businesses under $3M turnover that handle personal information are coming under the Privacy Act from July 2026. If you collect customer data, employee records, or health information, you're likely affected.
Penalties are serious
Maximum penalties under the Privacy Act are now $50 million, three times the benefit obtained, or 30% of domestic turnover, whichever is greater. $420,000 for individuals.
Data breach notification is mandatory
The Notifiable Data Breaches scheme requires you to notify the OAIC and affected individuals within 30 days of a breach likely to cause serious harm. You need a response plan before a breach happens, not after.
Not sure where your gaps are?
Free 3-minute scorecard. Covers Privacy Act essentials including APPs and NDB readiness.
APPs, NDB scheme, and data handling reviewed together. One engagement, one report, one person accountable. Written so your leadership team can actually read it.
Included if relevant to your business:
Typical Big 4 engagement
$30,000+
Your price
$6K-$8K
Delivered in 1-2 weeks. Not 6-8.
Under 3 critical gaps found? You don't pay.
Zero risk. I've never had to honour this.
Free scorecard
2 minutes. See where your business stands on Privacy Act basics. No email needed.
Take the scorecardDeep assessment
1-2 weeks, fixed price. I review your data handling, privacy policies, and breach readiness against all 13 APPs.
Compliance report
Gap analysis with prioritised remediation plan. Written for your leadership team, not just your IT department.
Newly regulated businesses
You're under $3M turnover and haven't had to think about the Privacy Act before. July 2026 changes that.
Health service providers
You handle patient data. You're already covered by the Privacy Act but may not be compliant. The penalties have increased significantly.
Businesses handling employee data
Employee records are personal information under the Privacy Act. If you're collecting tax file numbers, health records, or sensitive information, you need to comply.
Online businesses
If you collect customer data through your website, app, or online services, the Privacy Act applies. This includes analytics, marketing data, and customer accounts.

I'm a senior software engineer with 10+ years in platform infrastructure. CNCF maintainer. ASD Cyber Security Partner. I do the assessment myself. No juniors, no handoffs, no 200-page report written by a graduate who's never seen production code.
You talk to me, I do the work, I write the report. That's why it costs $6K instead of $30K.
If you handle personal information and your turnover is over $3M (or will be from July 2026 for businesses under $3M), yes. Health service providers, businesses that trade in personal information, and government contractors are already covered regardless of turnover.
The 13 APPs govern how organisations collect, use, store, and disclose personal information. They cover everything from transparency and anonymity to cross-border disclosure and data quality.
The Notifiable Data Breaches scheme requires you to notify the OAIC and affected individuals when a data breach is likely to result in serious harm. You have 30 days to assess and 72 hours to report if notifiable.
Three ways. First, I do the work myself. No juniors, no handoffs. You get a senior engineer with 10+ years experience, not a team where the partner shows up for the pitch and a graduate does the assessment. Second, it costs $6-8K instead of $30K+. Third, it takes 1-2 weeks instead of 6-8. Same rigour, less overhead.
From December 2026, businesses using automated systems to make decisions that significantly affect individuals must provide transparency about how those decisions are made. The gap analysis covers this if relevant to your business.
Start with the free scorecard. Or book a scoping call and I'll walk through what the Privacy Act changes mean for your business.
Taking on 2-3 Privacy Act assessments per month. First in, first served.