Australia's First Privacy Compliance Sweep: Is Your Business Ready?
The short version: In January 2026, Australia's privacy regulator started checking businesses' privacy policies, without waiting for a data breach or a complaint. If your policy is missing what the law requires, you could face a penalty of up to $66,000. The good news? Getting compliant is simple once you know what to check.
Take a quick test here.
What is happening?
The Office of the Australian Information Commissioner (the OAIC) is Australia's privacy regulator. For years, it mostly stepped in after something went wrong: a data breach, a complaint, a news story.
That has changed. In January 2026, the OAIC launched its first ever "compliance sweep". It is reviewing the privacy policies of around 60 businesses to check they meet the requirements of the Privacy Act. No breach needed. No complaint needed. Just a spot check.
This is possible because of changes to the Privacy Act passed in 2024, which gave the regulator new powers, including the ability to issue fines of up to $66,000 for something as basic as a non-compliant privacy policy.
Who is being checked first?
The first sweep focuses on businesses that collect personal information face-to-face:
rental and property (like ID collected at open homes)
chemists and pharmacies
licensed venues
car rental companies
car dealerships
pawnbrokers and second-hand dealers
Not on the list? Don't relax just yet. The OAIC has made it clear that more sweeps are coming, and every business covered by the Privacy Act needs a compliant policy.
Does the Privacy Act apply to my business?
Usually, yes if your annual turnover is over $3 million. But many smaller businesses are also covered, no matter their turnover. This includes health service providers (pharmacies, allied health, even gyms collecting health information), businesses that buy or sell personal information, and tenancy database operators.
If you are not sure, it is worth finding out before assuming you are exempt.
A real-world example
Picture a suburban real estate agency.
At every open home, visitors write down their name, phone number and email. Rental applicants hand over payslips, bank statements and a copy of their driver's licence.
The agency has a privacy policy. It is a generic template downloaded years ago, and it simply says the agency "may collect personal information to provide services". Sounds fine, right?
Here is the problem. The policy never mentions:
that ID documents and financial records are collected from rental applicants
that applicants are checked against a tenancy database
that open-home contact details go onto a marketing list and get shared with a mortgage broking partner
how someone can see the information held about them, or make a complaint
whether information is stored with overseas cloud providers
Nothing has "gone wrong". No breach, no angry customer. But under the new rules, that vague policy is itself a compliance failure. If the OAIC reviewed it in a sweep, the agency could be ordered to fix it and could be fined up to $66,000.
The fix? A policy that clearly and honestly describes what the agency actually does with personal information. Simple, and much cheaper than the fine.
What must your privacy policy include?
The law sets out a minimum list. Your policy must explain:
what personal information you collect and hold
how you collect and store it
why you collect, use and share it
how someone can access or correct their information
how someone can make a complaint, and how you will handle it
whether you send information overseas (and where, if you can say)
It also needs to be written in plain language, kept up to date, and available for free on your website. A policy full of legal jargon, or one that no longer matches how your business actually works, does not pass.
Here is the best test: would an ordinary customer reading your policy understand what you collect, why you collect it, and what happens to it? If not, it needs work.
What is coming next?
Privacy rules in Australia are only getting stricter. From December 2026, privacy policies will also need to disclose any automated decision-making that significantly affects people (for example, automated tenant screening tools). If you are reviewing your policy now, build that in so you don't have to do this twice.
Key takeaways
The regulator is now spot-checking privacy policies. You don't need a data breach to get in trouble.
Fines of up to $66,000 apply for non-compliant policies.
Your policy must reflect what your business actually does, in words your customers can understand.
Review your policy now and plan for the December 2026 changes.
Not sure where your policy stands? Get in touch and we can review it for you.
This article provides general information only and is not legal advice. For advice tailored to your circumstances, contact Melissa Ajram Legal.