Australia's First Privacy Compliance Sweep: Is Your Business Ready?

The short version: In January 2026, Australia's privacy regulator started checking businesses' privacy policies, without waiting for a data breach or a complaint. If your policy is missing what the law requires, you could face a penalty of up to $66,000. The good news? Getting compliant is simple once you know what to check.

Take a quick test here.

What is happening?

The Office of the Australian Information Commissioner (the OAIC) is Australia's privacy regulator. For years, it mostly stepped in after something went wrong: a data breach, a complaint, a news story.

That has changed. In January 2026, the OAIC launched its first ever "compliance sweep". It is reviewing the privacy policies of around 60 businesses to check they meet the requirements of the Privacy Act. No breach needed. No complaint needed. Just a spot check.

This is possible because of changes to the Privacy Act passed in 2024, which gave the regulator new powers, including the ability to issue fines of up to $66,000 for something as basic as a non-compliant privacy policy.

Who is being checked first?

The first sweep focuses on businesses that collect personal information face-to-face:

  • rental and property (like ID collected at open homes)

  • chemists and pharmacies

  • licensed venues

  • car rental companies

  • car dealerships

  • pawnbrokers and second-hand dealers

Not on the list? Don't relax just yet. The OAIC has made it clear that more sweeps are coming, and every business covered by the Privacy Act needs a compliant policy.

Does the Privacy Act apply to my business?

Usually, yes if your annual turnover is over $3 million. But many smaller businesses are also covered, no matter their turnover. This includes health service providers (pharmacies, allied health, even gyms collecting health information), businesses that buy or sell personal information, and tenancy database operators.

If you are not sure, it is worth finding out before assuming you are exempt.

A real-world example

Picture a suburban real estate agency.

At every open home, visitors write down their name, phone number and email. Rental applicants hand over payslips, bank statements and a copy of their driver's licence.

The agency has a privacy policy. It is a generic template downloaded years ago, and it simply says the agency "may collect personal information to provide services". Sounds fine, right?

Here is the problem. The policy never mentions:

  • that ID documents and financial records are collected from rental applicants

  • that applicants are checked against a tenancy database

  • that open-home contact details go onto a marketing list and get shared with a mortgage broking partner

  • how someone can see the information held about them, or make a complaint

  • whether information is stored with overseas cloud providers

Nothing has "gone wrong". No breach, no angry customer. But under the new rules, that vague policy is itself a compliance failure. If the OAIC reviewed it in a sweep, the agency could be ordered to fix it and could be fined up to $66,000.

The fix? A policy that clearly and honestly describes what the agency actually does with personal information. Simple, and much cheaper than the fine.

What must your privacy policy include?

The law sets out a minimum list. Your policy must explain:

  1. what personal information you collect and hold

  2. how you collect and store it

  3. why you collect, use and share it

  4. how someone can access or correct their information

  5. how someone can make a complaint, and how you will handle it

  6. whether you send information overseas (and where, if you can say)

It also needs to be written in plain language, kept up to date, and available for free on your website. A policy full of legal jargon, or one that no longer matches how your business actually works, does not pass.

Here is the best test: would an ordinary customer reading your policy understand what you collect, why you collect it, and what happens to it? If not, it needs work.

What is coming next?

Privacy rules in Australia are only getting stricter. From December 2026, privacy policies will also need to disclose any automated decision-making that significantly affects people (for example, automated tenant screening tools). If you are reviewing your policy now, build that in so you don't have to do this twice.

Key takeaways

  • The regulator is now spot-checking privacy policies. You don't need a data breach to get in trouble.

  • Fines of up to $66,000 apply for non-compliant policies.

  • Your policy must reflect what your business actually does, in words your customers can understand.

  • Review your policy now and plan for the December 2026 changes.

Not sure where your policy stands? Get in touch and we can review it for you.

This article provides general information only and is not legal advice. For advice tailored to your circumstances, contact Melissa Ajram Legal.

Next
Next

Most Commercial Disputes Never See a Courtroom. Here's Why Yours Probably Won't Either