Data Governance Beyond Cyber Security: The Exposure Even Exempt Associations Have A new statutory privacy tort already applies regardless of your turnover or exemption status Many smaller associations, correctly, understand they currently sit below the $3 million turnover threshold this series has already identified as the general Privacy Act compliance line. What fewer boards understand is that this threshold has real exceptions already in force today, and a separate, already-legislated legal exposure that applies regardless of turnover at all.
01 The Exemption Still Stands, But It Is Genuinely Narrower Than Most Boards Assume 02 The Newer, Separate Exposure Every Association Already Faces 03 What This Means For A Board Right Now Use this resource as a board pre-read, discussion guide or governance review prompt.
The Exemption Still Stands, But It Is Genuinely Narrower Than Most Boards Assume Membership, Growth & Digital Transformation · 15 December 2026 The general small business exemption, based on the $3 million annual turnover threshold discussed earlier in this series, remains in place as current law, with no confirmed date set for its broader removal despite the government having agreed in principle to eventually abolish it entirely. Reform is clearly the direction of travel, but boards should plan for it as a direction, not a deadline, given the ongoing uncertainty and the Productivity Commission's own public criticism of parts of the proposed changes. What matters right now is that the exemption already carries real, current exceptions regardless of turnover. Businesses and organisations that are health service providers, that trade in personal information, or that hold Commonwealth contracts, are already covered by the full Privacy Act today, irrespective of size. An association connected to a health, allied health, or medical profession, even a small one, should confirm whether this specific carve-out already applies to it, rather than assuming the general turnover exemption automatically covers every organisation below the threshold.
The Newer, Separate Exposure Every Association Already Faces Independent of the small business exemption entirely, a statutory tort for serious invasions of privacy is now in force in Australia, giving individuals a direct legal pathway to sue over a serious privacy breach, regardless of the offending organisation's size or turnover. This is a meaningfully different exposure from the general Privacy Act compliance regime this series discussed earlier. A currently exempt small association cannot rely on that exemption to protect it from this specific action, since the statutory tort operates on its own footing, aimed directly at serious privacy harms rather than routine compliance obligations. Being below the $3 million turnover threshold protects
an association from the general Australian Privacy Principles compliance regime. It does not protect the organisation, or its directors, from an individual's direct legal action over a serious privacy breach, which now sits on entirely separate legal footing.
What This Means For A Board Right Now For organisations that are already covered, whether through the health information carve-out, turnover above the threshold, or another applicable exception, the penalties for serious or repeated non-compliance are severe: up to fifty million dollars, three times the benefit obtained from the breach, or thirty percent of adjusted turnover, whichever is highest. For organisations that remain exempt today, the clear direction of travel makes voluntary early preparation a sensible governance choice rather than a compliance obligation, particularly given how quickly the specific carve-outs already in force can catch an organisation that assumed the general exemption fully applied to it. •
Confirm precisely whether your association falls within an existing exception to the small business exemption, particularly the health information carve-out, rather than assuming the general turnover threshold automatically applies.
•
Understand that the statutory tort for serious invasions of privacy applies regardless of your association's size or exemption status, and build datahandling discipline around member and staff information accordingly.
•
Build a simple data inventory now, mapping what personal information your association holds, where it is stored, and who has access, regardless of current exemption status, given the clear direction of privacy reform.
•
Monitor the Tranche 2 reform process specifically rather than assuming today's exemption position is permanent, while avoiding over-investing in compliance for requirements that have not yet been legislated.
•
Connect this analysis directly to the cyber security discipline discussed earlier in this series, since data governance and cyber security are related but distinct obligations, addressing different risks even where the same underlying information is involved.
Privacy compliance in Australia is shifting, but it has not simply moved from exempt to covered overnight for every organisation. It has become a landscape of exceptions, a separate statutory exposure that already applies universally, and a clear reform direction worth preparing for early. A board that only checks the headline turnover threshold is checking half the picture.
This is one of the practical governance topics built into our Association CEO course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course → — Annie Gibbins General education — not legal, financial, tax, clinical or governance advice. Confirm specifics at the relevant primary source or with your own qualified adviser. Nexus Leadership is operated by Lipstick Consulting Pty Ltd · ABN 15 619 120 482.
CONTINUE YOUR LEARNING
Turn governance principles into practical board action. Self-paced learning, editable resources and strategic support for association leaders.
NEXUS LEADERSHIP Association Management Specialists nexusleadership.com.au
BOARDROOM
ACTION WORKSHEET Turn the article into evidence, a decision and an accountable next step.
Data Governance Beyond Cyber Security: The Exposure Even Exempt Associations Have Editable boardroom action record 1. What is the issue or decision? State the governance question in one clear sentence.
2. What evidence do we already have? Record the facts, source documents and stakeholder evidence available now.
3. What evidence is still needed? Identify the legal, regulatory, financial, member or operational information still required.
4. What is the agreed next action? Capture the owner, timeframe and how the matter will return to the board.
ACTION REVIEW OWNER DATE Name / DD / role MM / YYYY
BOARD DECISIO N Decision / resolutio n
Need support turning this topic into a board decision, policy or facilitated conversation?
Nexus Leadership works with association boards and CEOs through Strategy Days, Board Inductions, workshops and practical governance support.
Discuss governance support →