~100,000 Australian businesses are covered by the Privacy Act for the first time. Is yours one of them?
The turnover threshold changed on 1 July 2026. If you're affected, you need a compliant privacy policy, collection notices, and — if you use AI or automated tools — an ADM disclosure before 10 December. Privacy Ready generates every document you need, in an afternoon.
Last updated: 1 July 2026
From unknown compliance status to evidenced, in three steps.
Diagnose your exposure for free, build the documents you're missing, then maintain the evidence trail as you operate.
Diagnose
Run the free diagnostic tools (15 minutes, no account needed) to find out whether you are covered, which of your AI tools require ADM disclosure, and what is missing from your existing privacy policy.
Build
Answer a guided questionnaire in the complete workspace (45 minutes) to generate a hosted, versioned privacy policy covering all 13 APPs, including the ADM disclosure section required by 10 December 2026.
Maintain
Keep an append-only disclosure log as you operate, so that when a rights request, procurement questionnaire, or OAIC inquiry arrives you can pull the evidence pack and respond within an hour.
Three questions every newly regulated business needs to answer.
The Privacy Act isn't a checkbox. It's a set of documents and processes the OAIC can ask for at any time. Most SMEs can't answer any of these.
Am I actually covered?
The threshold changed on 1 July 2026. Getting the answer wrong is expensive — up to $50 million (or 30% of turnover) for a serious breach, and up to $66,000 per contravention otherwise.
What documents do I need?
A privacy policy covering all 13 APPs. Collection notices at every point of data collection. And — if you use AI or automated tools — an ADM disclosure section live before 10 December 2026.
How do I prove it?
Knowing you're compliant and being able to demonstrate it are different things. The OAIC, enterprise procurement teams, and individuals making rights requests all require evidence — not assurances.
What are the 13 Australian Privacy Principles?
The APPs are 13 legally binding rules in Schedule 1 of the Privacy Act 1988 (Cth) governing how organisations collect, use, store and disclose personal information. All 13 apply to every APP entity — there's no picking and choosing.
| Principle | Gap check (free) | Management (paid) | Output |
|---|---|---|---|
|
1
Open and transparent managementA publicly available privacy policy is required, describing how you collect, hold, use and disclose personal information — including ADM disclosure from 10 December 2026. |
Privacy Policy Check | Compliance Command Centre | Hosted policy URL & compliance certificate |
|
2
Anonymity and pseudonymityOffer individuals the option to deal with you anonymously or under a pseudonym, where lawful and practicable. |
Anonymous Options Check | Anonymity Exceptions Register | Anonymity exceptions register |
|
3
Collection of solicited informationOnly collect personal information that is reasonably necessary. Sensitive information — health, biometric, financial — requires explicit consent. |
Collection Necessity Check | Collection Register | Collection register |
|
4
Dealing with unsolicited informationDestroy or de-identify personal information you receive but didn't ask for and have no need to hold. |
Unsolicited Info Check | Unsolicited Info Log | Unsolicited info log |
|
5
Notification of collectionTell individuals what you're collecting and why, at or before the point of collection. |
Collection Notice Check | Collection Notice Manager | Published collection notice |
|
6
Use or disclosureLimit use and disclosure of personal information to the primary purpose it was collected for. |
ADM Exposure Scanner | ADM & Disclosure Manager | Disclosure log export (CSV/PDF) |
|
7
Direct marketingEvery marketing communication needs an easy opt-out. Sensitive information can't be used for marketing without consent. |
Direct Marketing Check | Marketing Consent Manager | Marketing consent register |
|
8
Cross-border disclosureTake reasonable steps to ensure overseas recipients — including cloud vendors — handle data consistently with the APPs. |
Third-Party Processor Checker | Processor & DPA Register | DPA status report |
|
9
Government related identifiersNever adopt a government-issued identifier, such as a TFN or Medicare number, as your own customer ID. |
Government ID Check | Identifier Exceptions Register | Identifier exceptions register |
|
10
Quality of personal informationTake reasonable steps to keep the personal information you hold accurate, up to date and complete. |
Data Quality Check | Data Quality Workflow Manager | Data quality report |
|
11
Security of personal informationProtect information from misuse, interference and loss, and destroy or de-identify it once it's no longer needed. |
Security Gap Check | Security & Breach Response Manager | NDB assessment report |
|
12
Access to personal informationRespond to access requests within 30 days. Refusal is only permitted on the narrow grounds set out in APP 12.3. |
Rights Request Generator | Rights Request Tracker | Response letter (PDF) |
|
13
Correction of personal informationCorrect inaccurate, out-of-date or misleading information on request, or note the individual's disputed claim. |
Rights Request Generator | Rights Request Tracker | Response letter (PDF) |
Learn about the privacy laws.
Regulatory-grade explanations of the concepts behind the tools — classification tables, frameworks, and exactly what a regulator checks.
Does the Privacy Act Apply to My Australian Small Business?
From 1 July 2026, 100,000+ Australian small businesses lose the Privacy Act exemption. Find out if your business is affected and what you need to do now.
Read the guide →What Is ADM Disclosure and Does My Australian Business Need One?
ADM disclosure obligations commence 10 December 2026 under Australian privacy law. Find out if your software or AI tools require disclosure in your privacy policy.
Read the guide →What Counts as a Notifiable Data Breach in Australia?
A notifiable data breach in Australia requires OAIC notification within 30 days if serious harm is likely. Learn the NDB threshold, the assessment process, and penalties.
Read the guide →Australian Privacy Act Explained: The 13 APPs (2026 Guide)
The Privacy Act 1988 (Cth) sets 13 Australian Privacy Principles. Plain-English guide to each APP, the 10 December 2026 ADM disclosure change, and penalties up to $50M.
Read the guide →How to Respond to a Privacy Access Request in Australia
Under APP 12 of Australia's Privacy Act, businesses must respond to personal information access requests within 30 days. Learn the steps, fees, and refusal rules.
Read the guide →And 17 more
Browse the full library of guides and frameworks.
Feedback from our beta users.
We had no idea the ADM disclosure rules applied to the scheduling tool we use. The scanner flagged it in about two minutes.
Went from “not sure if this applies to us” to a published privacy policy in an afternoon.
The disclosure log is what sold me — one place to point to if the OAIC ever asks.
Frequently asked questions.
Am I covered by the Privacy Act?
The turnover threshold changed on 1 July 2026, bringing ~100,000 Australian SMEs under the Privacy Act for the first time. Use our free business applicability check to get a plain-English verdict based on your industry, revenue, and data types.
What documents do I need to comply with the Privacy Act?
You need a privacy policy covering all 13 Australian Privacy Principles (APPs), collection notices at every point of data collection, and — if you use AI or automated decision-making tools — an ADM disclosure section live before 10 December 2026.
How do I prove Privacy Act compliance?
Privacy Ready generates a compliance evidence pack and signed certificate showing your systems, disclosures, policy version, and last review date — shareable with clients, procurement teams, and the OAIC.
What are the penalties for Privacy Act non-compliance?
A serious or repeated breach of the Privacy Act 1988 (Cth) carries a penalty of up to $50 million, 3x the benefit obtained, or 30% of adjusted turnover — whichever is greatest. Non-serious contraventions carry a penalty of up to $66,000 per contravention.
Two plans. No feature gates.
Free gives you clarity. Complete gives you everything else. No module upgrades, no per-seat limits on outputs.
- ✓ Privacy Policy Check
- ✓ Anonymous Options Check
- ✓ Collection Necessity Check
- ✓ Unsolicited Info Check
- ✓ Collection Notice Check
- ✓ ADM Exposure Scanner
- ✓ Direct Marketing Check
- ✓ Third-Party Processor Checker
- ✓ Government ID Check
- ✓ Data Quality Check
- ✓ Security Gap Check
- ✓ Rights Request Generator
- ✓ Compliance Command Centre
- ✓ Anonymity Exceptions Register
- ✓ Collection Register
- ✓ Unsolicited Info Log
- ✓ Collection Notice Manager
- ✓ ADM & Disclosure Manager
- ✓ Marketing Consent Manager
- ✓ Processor & DPA Register
- ✓ Identifier Exceptions Register
- ✓ Data Quality Workflow Manager
- ✓ Security & Breach Response Manager
- ✓ Rights Request Tracker
- ✓ Up to 5 team seats
- ✓ Privacy obligations calendar