Privacy Act changes: what a small practice actually needs to do

What the draft Privacy Amendment (Personal Data Protection) Bill 2026 proposes, read from the front desk of a small practice holding client files.

Back to the blog
Privacy Act changes: what a small practice actually needs to do

If you run a vet clinic, a law firm or a travel agency, you hold a lot of personal information about your clients. Names, addresses, phone numbers, sometimes passports, pet records or family matters. It sits in inboxes, in practice software and on shared drives.

The Attorney-General’s Department has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 for consultation.

It’s a draft. It hasn’t been introduced to Parliament, and the consultation page doesn’t say when it might be. What follows is how it reads to someone who looks after small practices’ IT. It isn’t legal advice.

First question: does the Privacy Act cover you now?

According to the OAIC, a small business is one with annual turnover of $3 million or less, and most small businesses aren’t covered by the Act. Some are covered whatever their turnover, including health service providers and businesses that trade in personal information.

The draft does change the part of the Act that deals with trading in personal information, which it describes as disclosing it for money or for direct marketing. Whether your business ends up covered is a question for your accountant or lawyer once the final Bill is out, and worth asking if you’re anywhere near that line.

Covered or not, the rest of the draft is a fair guide to what good practice looks like.

One “fair and reasonable” test

The draft replaces several existing principles with a single test: collecting, using or sharing personal information has to be fair and reasonable in the circumstances, and lawful. It lists factors to weigh up:

  • Would a reasonable person expect it?
  • Does it relate to what your business actually does?
  • Are you open about how and why you’re doing it?
  • Could you get the job done with less information?
  • Does the person have a genuine choice?
  • Is the privacy impact in proportion to the benefit?
  • If the person is a child, their best interests come first.

For a front desk, the one I’d dwell on is “could you do it with less”. Copying a client’s whole driver’s licence when you only needed to sight it is the sort of habit that factor asks about.

Knowing what you hold

The security principle gets more specific. Under the draft, a business would need to be able to identify the personal information it holds, consider destroying information it no longer needs and then destroy or de-identify it, and regularly check that its security and destruction steps are working.

This is where privacy turns into an IT job. Old client folders on a shared drive, a former staff member’s mailbox full of attachments, scanned ID sitting in someone’s Downloads folder. You can’t protect or delete what nobody knows is there.

72 hours to tell the regulator

For businesses covered by the Act, the draft sets a clear deadline. Once you have reasonable grounds to believe an eligible data breach has happened, you’d have 72 hours to give the Information Commissioner a statement. An incomplete statement is allowed, with the rest to follow.

Seventy-two hours goes quickly, especially if it starts on a Friday afternoon. Knowing who you’d call, and having logs that show what happened, matters more than any policy document.

What’s still open

Plenty. The commencement dates in the draft are blank, and the consultation paper says further transition provisions will be added once settled. Some measures in the paper, such as rules for smart glasses and connected vehicles, don’t have draft wording yet. Nothing here asks you to change anything today.

One job worth doing now

Make a list of everywhere client personal information lives in your business: shared and personal inboxes, practice software, shared drives and OneDrive, paper files, scanned copies, and old laptops in a cupboard. Whatever passes, that list is where you start.

If you’d like help working out what’s on it, get in touch.

Michael Kriewaldt

Michael Kriewaldt is the founder of Bastion IT, the managed IT and cybersecurity provider formed when Time Out! Computers and Gray Area Consulting came together. Bastion is SMB1001 Gold certified.

Published September 16, 2026

Want a second opinion on your IT?