Back to Blog

Privacy Rules Are Tightening: A No-Jargon Checklist for Aussie SMBs

The Nerd Herd Team
22 September 2026
7 min read

Privacy Act reforms, AML changes, and a 10 December 2026 AI disclosure deadline. Practical MFA, data-map, and backup steps for Australian small businesses. Not legal advice.

PrivacyComplianceSecuritySmall Business

Australian privacy rules are no longer something only big companies think about. The first tranche of Privacy Act reforms is already in force. From 1 July 2026, anti-money-laundering changes pulled more than 100,000 extra small businesses under privacy obligations. And from 10 December 2026, many covered businesses must say in their privacy policy if software — including AI — helps make decisions that significantly affect people.

This is not legal advice. It is the IT hygiene regulators now treat as “reasonable steps”: MFA, knowing where customer data lives, patching, and backups you can restore. If your provider is not already doing this, that is the conversation to have.

What Is Actually Moving

Tranche 1 (the Privacy and Other Legislation Amendment Act 2024) brought a statutory privacy tort, stronger OAIC powers, and much higher penalties. The long-discussed removal of the $3 million small-business exemption is still being progressed — timing is a “when, not if” for planning, not a date to invent. Meanwhile, AML/CTF reforms have already dragged many professional-services firms into the Privacy Act regardless of turnover.

If you are not sure you are covered

Talk to your accountant or a privacy lawyer about your specific situation. From an IT chair, assume customer names, emails, invoices, and staff records need protecting whether or not a form has told you that yet. The technical work is the same.

“Reasonable Steps” in 2026 Means Technical Controls

Australian Privacy Principle 11 asks you to take reasonable steps to protect personal information. In 2026, a PDF policy on the website is not the whole story. Regulators look for MFA, least-privilege access, current patching, encryption, and an ability to say what happened if something goes wrong.

Know what you hold

Mailboxes, shared drives, the CRM, accounting, a leftover USB, staff laptops. Most businesses underestimate this by a factor of two. You cannot protect what you have not listed.

Hold less of it

APP 11.2 expects you to destroy or de-identify personal information you no longer need. Infinite “just in case” folders are a liability, not a backup strategy.

Lock the front door

MFA on email, remote access, finance, and the CRM. No exceptions for the owner. Password reuse across those systems is still how most incidents start.

Prove you can recover

Encrypted, tested backups. If ransomware or a deleted mailbox happens on a Friday, “we think OneDrive has it” is not a plan.

Essential Eight Is Changing — The Basics Are Not Optional

The Australian Signals Directorate has said the Essential Eight framework will be replaced over the next two years with a broader “Essentials” series covering enterprise IT, cloud, operational technology, and eventually AI agents. That is a recognition that 2017-era office networks are not the whole picture.

What still matters while the new series lands

  • Multi-factor authentication
  • Patch applications and operating systems
  • Restrict admin privileges
  • Regular, tested backups
  • Control what software can run

Aligning to those controls is still one of the clearest ways to show you took reasonable steps — even as the documented framework evolves.

The 10 December 2026 Disclosure

If you are covered by the Privacy Act and you use a computer program to make — or substantially help make — decisions that could significantly affect someone’s rights or interests, your privacy policy will need to say so. That can include AI screening, automated credit or pricing tools, chatbot triage, and some CRM “lead scoring.” It is deliberately broad.

IT homework before legal homework

List the tools that touch customer or staff data — Microsoft 365 Copilot, chatbots, hiring plugins, automated email. Your lawyer can write the policy. They cannot inventory a tenant they cannot see.

A No-Jargon Checklist for This Month

  • 1.Turn on MFA for email and every system that holds personal information.
  • 2.Write a one-page data map — systems, who can access them, where they live (Australia, overseas, a cupboard).
  • 3.Confirm backups restore for mail and files, not just that a backup job is “green.”
  • 4.List AI and automation that touches people — so the December privacy-policy wording is based on facts.
  • 5.Name who to call if a mailbox is compromised on a Sunday night.

Need the Technical Side Sorted?

We can turn on MFA, map where your data actually lives, and put backups and access controls in place — the “reasonable steps” part of the job.