Membership, Growth & Digital Transformation · 15 December 2026
Many smaller associations, correctly, understand they currently sit below the $3 million turnover threshold this series has already identified as the general Privacy Act compliance line. What fewer boards understand is that this threshold has real exceptions already in force today, and a separate, already-legislated legal exposure that applies regardless of turnover at all.
The Exemption Still Stands, But It Is Genuinely Narrower Than Most Boards Assume
The general small business exemption, based on the $3 million annual turnover threshold discussed earlier in this series, remains in place as current law, with no confirmed date set for its broader removal despite the government having agreed in principle to eventually abolish it entirely. Reform is clearly the direction of travel, but boards should plan for it as a direction, not a deadline, given the ongoing uncertainty and the Productivity Commission's own public criticism of parts of the proposed changes. What matters right now is that the exemption already carries real, current exceptions regardless of turnover. Businesses and organisations that are health service providers, that trade in personal information, or that hold Commonwealth contracts, are already covered by the full Privacy Act today, irrespective of size. An association connected to a health, allied health, or medical profession, even a small one, should confirm whether this specific carve-out already applies to it, rather than assuming the general turnover exemption automatically covers every organisation below the threshold.
The Newer, Separate Exposure Every Association Already Faces
Independent of the small business exemption entirely, a statutory tort for serious invasions of privacy is now in force in Australia, giving individuals a direct legal pathway to sue over a serious privacy breach, regardless of the offending organisation's size or turnover. This is a meaningfully different exposure from the general Privacy Act compliance regime this series discussed earlier. A currently exempt small association cannot rely on that exemption to protect it from this specific action, since the statutory tort operates on its own footing, aimed directly at serious privacy harms rather than routine compliance obligations. Being below the $3 million turnover threshold protects an association from the general Australian Privacy Principles compliance regime. It does not protect the organisation, or its directors, from an individual's direct legal action over a serious privacy breach, which now sits on entirely separate legal footing.
What This Means For A Board Right Now
For organisations that are already covered, whether through the health information carve-out, turnover above the threshold, or another applicable exception, the penalties for serious or repeated non-compliance are severe: up to fifty million dollars, three times the benefit obtained from the breach, or thirty percent of adjusted turnover, whichever is highest. For organisations that remain exempt today, the clear direction of travel makes voluntary early preparation a sensible governance choice rather than a compliance obligation, particularly given how quickly the specific carve-outs already in force can catch an organisation that assumed the general exemption fully applied to it.
- Confirm precisely whether your association falls within an existing exception to the small business exemption, particularly the health information carve-out, rather than assuming the general turnover threshold automatically applies.
- Understand that the statutory tort for serious invasions of privacy applies regardless of your association's size or exemption status, and build data-handling discipline around member and staff information accordingly.
- Build a simple data inventory now, mapping what personal information your association holds, where it is stored, and who has access, regardless of current exemption status, given the clear direction of privacy reform.
- Monitor the Tranche 2 reform process specifically rather than assuming today's exemption position is permanent, while avoiding over-investing in compliance for requirements that have not yet been legislated.
- Connect this analysis directly to the cyber security discipline discussed earlier in this series, since data governance and cyber security are related but distinct obligations, addressing different risks even where the same underlying information is involved.
Privacy compliance in Australia is shifting, but it has not simply moved from exempt to covered overnight for every organisation. It has become a landscape of exceptions, a separate statutory exposure that already applies universally, and a clear reform direction worth preparing for early. A board that only checks the headline turnover threshold is checking half the picture.
This is one of the practical governance topics built into our Association CEO course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →
— Annie