By Jamie Brennan · · 5 min read · Updated 7 September 2026

The new privacy law does not apply to your business. The one after it probably will

The Privacy Act exposure draft gives Australians a right to erasure, but only against big platforms, and the small business exemption survives it untouched. Removing that exemption is still on the government's list though, which hands small businesses something rare: advance warning.

Overhead shot of a woman's hands typing on a white laptop beside a coffee cup, notebook and phone.

On 31 August the Attorney-General’s Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, and the coverage has focused on one headline: Australians are getting a right to erasure, reported by Information Age. Consultation on the draft closes on 18 September.

Before anyone sells you a compliance package off the back of that, here is the part worth being precise about.

It is aimed squarely at the big platforms

The right to erasure applies to large social media, email, messaging, streaming, gaming and AI platforms. To be caught, a business needs annual revenue above $500 million or more than 2.5 million average monthly users.

Your clinic does not have 2.5 million monthly users. Neither does your building company.

There is a second layer too. Australia’s Privacy Act has a small business exemption, so businesses turning over less than $3 million a year sit outside most of it entirely. This exposure draft does not touch that exemption. So for a large share of Melbourne businesses, the honest summary of this reform is: it does not apply to you, and nothing about it requires you to do anything this month.

If someone tells you otherwise between now and Christmas, they are selling something.

The bit that does matter

Here is why it is still worth ten minutes of your attention.

Removing that small business exemption has been proposed, and the government supports it in principle. It is not in this bill, it is not law, and there is no start date. But it sits in the queue for a future tranche, and it has been inching forward for several years now.

That is an unusual situation to be in. Normally a rule change lands and you scramble. Here you can see it coming from a long way off, without a deadline attached. Advance warning with no penalty for using it well is about as good as regulatory news gets.

The other thing in the draft worth noting, because it signals direction, is a “fair and reasonable” test on how personal information gets collected and handled, alongside tighter consent standards and limits on selling personal information without clear permission. Even where those do not bind you today, they describe where the whole regime is heading: away from collect-everything-just-in-case.

The work, which you should do anyway

The thing that will eventually be required is not really a legal exercise. It is a mapping exercise, and it is one almost no small business has done.

Most of the businesses we look at collect personal information in four or five places without ever having written that down. A contact form. A booking widget. A mailing list signup. A quote request. Maybe a customer portal. Each one drops data somewhere: a CRM, a shared inbox, a spreadsheet, a form provider’s dashboard that nobody has logged into since it was set up.

So sit down for an hour and answer five questions.

  1. What personal information do you actually collect? Go through every form and integration on your site. Not what you think you collect, what the fields actually ask for. There is usually a surprise.
  2. Where does each one end up? Follow it. A form that emails you and also stores a copy with the form provider and also pushes to a CRM lives in three places, and most owners know about one.
  3. Who can see it? Staff, contractors, old employees whose access was never removed, and any third-party tool with a connection into your systems.
  4. How long do you keep it? For most businesses the honest answer is forever, because nobody ever decided otherwise. Enquiries from 2019 are still sitting there.
  5. Could you delete it if someone asked? Not legally must, just could. If the answer is “no idea”, that is the gap the future version of this law will care about.

That is the whole job. Not a policy document, not a consultant. A list.

Why this is worth doing without a law forcing it

Three reasons that have nothing to do with compliance.

It is the same discipline as knowing which systems your business cannot trade without, which we wrote about after the Mastercard and Google Drive outages. Knowing where your data lives and knowing what breaks when a tool goes down are the same underlying question, asked twice.

It matters more now that staff use AI tools. If a third of your team is quietly pasting things into chatbots, as the research on shadow AI suggests, then knowing what customer information exists and where it sits is the difference between a policy you can enforce and a hope.

And it is increasingly a trust signal. We argued last week that proving you are a real business has become active work rather than a by-product of looking professional. Being able to tell a customer plainly what you hold and how to get it removed sits in exactly that category.

The func.digital take

The temptation with any privacy story is to make it frightening, because fear sells audits. This one genuinely is not frightening. The reform in the headlines is aimed at companies with millions of users, and the small business exemption is still standing.

What is true is that the exemption is on borrowed time, probably measured in years rather than months, and the businesses that will find that transition painless are the ones that already know where their data lives. Not because they were diligent about compliance, but because knowing where your customer information sits is just a sign of a business that has its systems in order.

If you want that map drawn properly, tracing every form and integration to where the data actually lands, that is part of a free digital systems audit. No policy templates, no scare campaign, just a clear picture of what you are holding and where. Get in touch, and let’s find out before someone makes you.

Let's talk

Book your systems audit.

A clear read on your website, tools, and automation, and the highest-impact fixes to make first. No pitch, no obligation. We reply within one business day.