Six countries. One lost laptop. And the question only Australia asks.
In the summer of 2025, two directors of a Manchester window company thought they had found the exit.
Their business had spent months making marketing calls to people who had formally asked never to be called. The British regulator fined the company £150,000 for it. So the directors did what looks, from a certain angle, like the obvious move. They closed the company. No company, no fine.
The regulator disagreed with the arithmetic. The Insolvency Service followed the two of them out of the building, personally, and banned each of them from running any company at all for four years.
Closing the company didn't close the conversation.
I begin there, in Manchester, because it tells you something about how most of the developed world now thinks about businesses and the personal information they hold. The company is not a costume you can take off. In Britain, a director whose consent or neglect sits behind a data offence can be prosecuted in their own name. In Germany, a court went further still: in 2021, the Dresden higher regional court ordered a managing director to pay damages personally, as himself, for a data protection failure. In the United States, the trade regulator has written a chief executive's name directly into a data security order so that it follows him to whatever company he runs next.
None of this is a threat. It's a map. And the most interesting country on it, by a distance, is ours.
Let me run a much smaller misfortune through it.
One lost laptop, six cities
Picture a designer. Four hundred clients' names, emails, addresses and invoices on her laptop. She leaves it on a café table for ninety seconds, and it's gone.
Run that morning through six cities.
In London, a clock starts. If people could come to harm from the loss, her business has 72 hours to tell the Information Commissioner's Office, and the people affected need to hear from her too.
In Berlin, the same clock, the same duty, under the same European rulebook. And in the wrong circumstances, as that German court showed, the person running the business can answer for the failure personally.
In Toronto, Canadian law asks one question: does this loss create a real risk of significant harm? If so, the Privacy Commissioner of Canada gets a report and the clients get a phone call. Nobody asks how big her studio is.
In Auckland, New Zealand's Privacy Act asks nearly the same question in nearly the same words. Serious harm likely? Then the Office of the Privacy Commissioner is told, and so are the people whose details walked out the door.
In Austin, there is no single national rulebook, but the expectation doesn't thin out. Every American state has its own notification law, and the Federal Trade Commission has spent years demonstrating that "we're only a small company" is not a sentence it finds interesting.
Five cities. Five versions of the same idea: the law asks what you lost, and who it belongs to.
Then the laptop goes missing in Sydney.
And here, before any of those questions, Australian law asks one that no other country on the tour asks at all.
How much does your business earn?
The line through Australian small business
If the answer is three million dollars a year or less, then for most small businesses, the Privacy Act largely does not apply. No 72-hour clock. No mandatory phone call to the regulator. For the majority of Australia's sole traders and small operators, the designer's difficult morning is, in the eyes of the federal privacy rulebook, mostly her own business.
The two-person studio. The mortgage broker working from the spare room. The consultant whose whole practice fits in a carry-on. That is who the line was drawn around, and it has sat in the Privacy Act for a quarter of a century, and it makes us internationally strange. The countries we compare ourselves to draw no such line. We drew it in 2000, on the theory that privacy obligations were too heavy for small operators to carry.
Here is the remarkable part: almost nobody who lives under the line knows it exists. I have met owners who assumed they carried the full weight of the Privacy Act and quietly dreaded it. I have never met one who could tell me where the line actually sat.
You cannot be reassured by a line you've never heard of. You also cannot be misled by it. Until now.
Because now that you know it exists, the tempting conclusion is sitting right there: I'm under the line, so I'm safe.
And I know why that conclusion appeals, because it has a lifetime of evidence behind it. You have run your business under this line for years and the regulator has never called, no client has ever sued, nothing has ever happened. That evidence is real. I won't argue with it.
I'll just tell you what it actually proves.
What the line actually does
The line was never a wall. It was a hush.
It never stopped a laptop going missing. It never stopped a client caring that it did. It only meant that when it happened, the law stayed quiet about it. Silence is not protection. It's just the absence of a phone call.
And the hush was never as complete as it sounds. The line has always had gaps in it. Run a health service of any kind and the Privacy Act applies to you regardless of turnover. Trade in personal information and it applies. Handle tax file numbers and parts of it apply. The hush always had exceptions written into it.
Three more things have happened recently that matter far more.
Since June 2025, individuals can sue. Australia now has a statutory right to sue over serious invasions of privacy, where the invasion was intentional or reckless. It arrived quietly, and it does not check your turnover. Not every mistake becomes a lawsuit, and it was never meant to. But a client whose privacy is seriously invaded no longer needs the regulator to take an interest. The law now gives them an avenue of their own.
The courts have started treating security as part of running a business properly. When the Federal Court dealt with a financial advice firm whose cyber arrangements were inadequate (ASIC v RI Advice, 2022), it didn't treat the problem as an IT matter. It treated it as a failure to run the business to the standard the law requires of it. That way of thinking does not stop at any turnover threshold, and it gives every director a plain reason to treat security as part of running the business well.
And your clients never signed the exemption. This is the one that decides things in practice. The accountant deciding whether to keep referring you, the clinic deciding whether you keep their patient files, the corporate client whose procurement form now asks how you protect their information: none of them ask which side of three million dollars you sit on. Trust between businesses is becoming a form, and the form doesn't have a turnover question on it.
The exemption is a line in a statute. Your clients have never read it.
The line is dissolving
Which brings me to the news, and the reason I'm writing this now.
On the first of July 2026, the line quietly stopped applying to a very large group of Australian small businesses. Under the new anti-money-laundering rules, real estate professionals, many lawyers and accountants, and a range of other services became reporting entities, and for the client information that work involves, the exemption no longer shields them. The privacy regulator's own estimate is that the change reaches more than one hundred thousand small businesses. Most of them, I would gently suggest, have not yet had a reason to notice.
And the rest of the line is on the drawing board. The federal government has been reviewing the Privacy Act for years, and removing the small business exemption entirely is on the published agenda. In February 2026, the Attorney-General confirmed the next round of reform is progressing. No date has been set. But the direction has been agreed in principle for some time, and it has pointed the same way for years.
The line is dissolving. Gradually, then all at once.
So here is the position I'd take, and the one I take myself.
Behave as if the line is already gone.
Not because fear demands it. Because it's cheap, it's mostly things worth doing anyway, and because every city on the tour, from London to Auckland, is asking small businesses for the same short list.
Three things to do this week
1. Find out which side of the line you're actually on, today. Five minutes. Annual turnover of three million or less? Then check the gaps: do you provide any health service, handle tax file numbers, trade in personal information, or do work that the new anti-money-laundering rules capture, like real estate, legal, accounting or trust services? Any yes, and some or all of the Privacy Act already applies to you, exemption or not. The Office of the Australian Information Commissioner's website has the plain-language version. If you're still unsure after five minutes there, it's a one-question email to your solicitor: does the Privacy Act apply to us today? One question. Not a research project.
2. Adopt the four habits that travel. Strip away the legal language and London, Berlin, Toronto, Auckland and Austin all want the same things from a small business: know what client information you actually hold and where it lives, put a second lock on the accounts that matter, keep the machines current, and keep backups that can't be torn down with the device. That list satisfies every regulator on the tour, and it satisfies the only judges who were never bound by the exemption in the first place: your clients.
3. Write the two sentences you'd send. The hardest requirement in every jurisdiction is the same one: telling people. So draft it now, on a calm Tuesday. Two sentences: what happened, and what you're doing about it. You will probably never send them. But the owner who has drafted those sentences calmly is a different person on the bad Thursday than the one composing them for the first time at midnight. It is the smallest incident plan that exists: honesty, pre-written.
I keep mine in the same drawer as the insurance certificate. Both are documents I intend to die never having used.
If a device with client information goes missing
The calm version, in order:
- Change the passwords that lived on it, starting with email. Then use your email account's security page to sign out of all sessions, so the device stops being a key.
- Use the remote tools. Find My Mac, Find My Device on Windows and Android: locate it, lock it, and if it's clearly gone, wipe it.
- Write down what was on it. Whose information, how sensitive, how far back. Ten minutes now; every later step depends on this list.
- Ask the harm question honestly. Is someone likely to be seriously harmed by what was on that device? Names and emails are one thing. Financial records, health details or identity documents are another.
- If the Privacy Act applies to you and serious harm is likely, the notifiable data breach scheme asks you to tell the OAIC and the people affected. If it doesn't apply to you, points 4 and 3 still tell you exactly who deserves a phone call anyway.
- If it was stolen rather than lost, or you see signs someone is using it, report it to police, and call the Australian Cyber Security Hotline on 1300 CYBER1. It answers around the clock.
None of this requires panic. All of it requires the list from step 3, which is why step 3 exists.
Where the line meets your business
I'll be straight about the limit of everything above. The five-minute check tells you where the line sits today. It cannot tell you what's actually on your machines, whether your second locks are really on, or whether your backups would truly hold. Knowing the law's question is not the same as knowing your answer.
You can do a surprising amount of this yourself, and I'd encourage you to. But the most common thing found when someone finally looks is quiet: an account missing its second lock, a backup nobody has ever tested, client files on a device nobody had counted. The part that's hard to see from the inside is the whole reason the Ransomware Readiness Check exists. We sit down for thirty minutes, map what client information you actually hold, check whether the accounts that matter are properly locked and whether your backups would truly hold, then hand you a short plain-English list of what to improve first. It's a readiness check, not legal advice. It costs $149, it's ours, and you're welcome to weigh my enthusiasm accordingly. You leave knowing. Understand your exposure. Know what matters most.
And a WISECLICK membership is the standing version of the same idea: the accounts watched, the machines kept current, and backups locked the moment they're written, beyond the reach of a missing laptop. The list every city on the tour asks for, running quietly in the background of your business, whichever side of the line the law says you're on this year.
Because here is how this story ends. The exemption will keep dissolving, on the government's timetable, not yours. And when the line finally goes, there will be two kinds of Australian small business: the ones getting it done in a hurry once the timetable is finally set for them, and the ones who stepped over it years earlier, on an ordinary Tuesday, on their own terms, and barely remember the line was ever there.
The businesses that treat the line as already gone are the ones for whom its removal will be a non-event.
Frequently asked questions
Is my small business really exempt from the Privacy Act?
Mostly, if your annual turnover is $3 million or less: the Act largely does not apply to most small business operators. But the exemption has always had gaps. It does not apply if you provide a health service, trade in personal information, or handle tax file numbers (for those parts of the law), and since 1 July 2026 it no longer shields the personal information that captured businesses (many real estate, legal, accounting and trust services) handle in that regulated work. The OAIC's website has the current plain-language checklist, and your solicitor can settle your specific position in one conversation. (Current as at August 2026.)
What's changing, and when?
Two things. The first has already happened: the anti-money-laundering reforms that commenced on 1 July 2026 brought the client information handled in that regulated work under the Privacy Act for an estimated one hundred thousand plus small businesses, regardless of turnover. It reaches the regulated work; it does not automatically extend to every corner of the business. The second is on the way: the government has agreed in principle that the small business exemption should eventually go, subject to consultation and support for small business, and in February 2026 the Attorney-General confirmed the next tranche of reform is progressing. No commencement date has been announced: a direction of travel, not a deadline.
Can I personally be fined or sued if my business loses client data?
In Australia, the Privacy Act's penalties are aimed at the business, not at you personally, and losing a device is not a crime. Personal exposure here runs through two separate doors, and both are narrower than the overseas stories might suggest. Directors have a duty to run the company with care and diligence, and courts now treat security arrangements as part of that. And the statutory tort applies to whoever seriously and deliberately or recklessly invades someone's privacy, which is a different thing from being the director of a company that lost a laptop. The British and German cases in this piece happened under different laws in different systems; they show the direction of the world, not the current Australian rulebook. If your structure or exposure is unusual, this is a conversation worth having with your solicitor.
I sell to customers in Europe or the UK. Do their rules reach my Australian business?
They can. The European and British rulebooks apply to businesses anywhere in the world that deliberately offer goods or services to people there, or monitor their behaviour. An Australian online store shipping to London can owe duties under British law that it does not owe under Australian law. Where they apply, the large fines you read about land on the business, not automatically on its directors.
What is the statutory tort of serious invasion of privacy?
Since 10 June 2025, Australians have been able to sue directly over serious invasions of their privacy, where the invasion was intentional or reckless and serious. It sits entirely outside the small business exemption: it's a right belonging to the person whose privacy was invaded, whatever the size of the business involved.
Is this the same $3 million as the ransomware payment reporting rule?
Same number, different rule. Under the Cyber Security Act 2024, businesses with turnover above $3 million that make a ransomware payment must report it within 72 hours. That obligation is about paying criminals; this piece is about the Privacy Act and personal information. The matching figure is a coincidence of drafting, not a philosophy, and the two rules face opposite ways: the exemption sits at three million or less, while the reporting duty starts above it. We'll return to the reporting rules properly in a future piece.
My clients are in New Zealand. Does their Privacy Act reach me?
It can. New Zealand's Privacy Act applies to businesses carrying on business in New Zealand, whether or not they have an office there. If NZ clients are a real part of your work, their notifiable breach rules are worth knowing, and they have no small business line at all.
Where do I check my own position?
The OAIC (oaic.gov.au) for the Privacy Act and the exemption; the Australian Signals Directorate (cyber.gov.au) for the practical security standard; each overseas regulator for its own rulebook (the ICO for the UK, the FTC and state attorneys-general for the US, the OPC for Canada, the OPC NZ for New Zealand). And the Ransomware Readiness Check for the question none of them can answer: what your own setup would actually do when it matters most.
One dispatch a week. Worth the coffee it's read with.
Calm, plain-English cybersecurity for people who run real businesses from a laptop.
Stay protected, my friends.
— The Most Secure Man Alive

Leave a comment
This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.