The Privacy and Other Legislation Amendment Act 2024 (Cth) (‘the Amendment Act’) has introduced the most significant changes to the Privacy Act 1988 (Cth) (‘the Privacy Act’) since it was enacted. Most provisions commenced on 10 December 2024, with two further changes of particular relevance to tech start-ups: the statutory tort for serious invasions of privacy, which commenced on 10 June 2025, and the new transparency obligations for Automated Decision-Making (ADM), which commence on 10 December 2026.
Start-ups that handle personal information, or that rely on algorithms or AI tools in their products, should turn their attention to both.
The Small Business Exemption
Section 6D of the Privacy Act currently exempts small business operators generally, entities with an annual turnover of $3 million or less from most obligations under the Privacy Act. Many start-ups assume this exemption applies to them by default. In practice, it often does not.
Under Sections 6D(4) and 6D(7), the exemption is instantly stripped from entities that:
- Trade in personal information: This includes common tech business models that sell, swap, or derive commercial benefit from user data, including many third-party analytics and ad-tech integrations.
- Provide a health service: This impacts any platform collecting health, wellness, medical, or biometric data.
- Are related to a non-exempt body corporate: If your start-up is structured under or alongside a larger corporate group that exceeds the threshold, the exemption fails.
The exemption itself is also under review. The Attorney-General’s Department has flagged its removal or narrowing as part of a second tranche of privacy reforms, expected to follow the changes already made under the Amendment Act. Start-ups should not treat the exemption as a long-term basis for avoiding compliance.
The Statutory Tort for Serious Invasions of Privacy
Schedule 2 to the Amendment Act inserted a new statutory tort into Australian law, commencing 10 June 2025. Under this tort, an individual has a cause of action against a person who has invaded their privacy where the invasion was intentional or reckless, and was serious in the circumstances, by either:
- Intruding upon their seclusion, or
- Misusing information relating to them
In a successful claim, a court may award damages, including for emotional distress, and may grant other relief such as an injunction.
This represents a materially different form of exposure compared to a traditional regulatory breach:
- Direct Right of Action: Previously, enforcement action in respect of a privacy interference was brought exclusively by the Office of the Australian Information Commissioner (OAIC). The statutory tort bypasses this by giving individuals a direct, personal right of action to sue in court.
- Dual Exposure: For start-ups handling sensitive categories of information such as health, financial, location, or biometric data—a serious data incident may now give rise to direct litigation brought by affected users, in addition to any regulatory response under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act.
Increased OAIC Enforcement Activity
The Amendment Act also expanded the OAIC’s enforcement powers, including new infringement notice powers for specified breaches of the Australian Privacy Principles (APPs).
In January 2026, the OAIC commenced a compliance sweep of privacy policies across a number of business sectors, assessing compliance with APP 1.3 and APP 1.4, which require an APP entity to have a clearly expressed, up-to-date privacy policy. While the current sweep is sector-specific, it reflects a broader shift toward proactive review of privacy policies, rather than enforcement only in response to complaints.
Automated Decision-Making Disclosure from 10 December 2026
The Amendment Act inserted new subclauses 1.7, 1.8 and 1.9 into APP 1, commencing 10 December 2026.
From that date, an APP entity that arranges for a computer program to use personal information to make a decision or to do a thing substantially and directly related to making a decision that could reasonably be expected to significantly affect an individual’s rights or interests, must include specified information about that use in its privacy policy.
This includes the kinds of personal information used, the kinds of decisions made, and how the system works, in language an ordinary reader can understand.
The obligation is broadly drawn. It is not limited to artificial intelligence systems and may extend to rule-based software and automated scoring tools. Decisions affecting credit, insurance, employment screening, pricing, or access to services are likely to fall within scope where personal information is used in the process.
The obligation applies to decisions made on or after 10 December 2026, regardless of when the underlying system was built or deployed. Start-ups using third-party software with embedded automated features should review those tools now, as the obligation will apply to them in the same way it applies to internally built systems.
What a Compliant Privacy Policy Needs to Address
A privacy policy that meets the current requirements of APP 1 should clearly set out:
- The kinds of personal information collected and the purpose for collecting it, consistent with the principle of data minimisation.
- How that information is stored and secured.
- The entities to which it may be disclosed, including overseas service providers.
- How an individual may access or correct their information or make a complaint.
- The entity’s processes under the NDB scheme.
From 10 December 2026, entities using ADM will also need to address their use of automated decision-making in the manner required by APP 1.7 to 1.9.
Next Steps
Start-ups should not wait until the small business exemption is removed, or until the ADM obligations commence, to review their privacy practices. A privacy policy review and a data flow audit including a review of any algorithmic or AI-enabled features in the product will put a start-up in a stronger position ahead of these deadlines.
At Warlows Legal, we assist founders, tech start‑ups, and technology vendors in navigating Australia’s tightening privacy framework. As specialists in Start‑ups and Technology Law, we can help you conduct data‑flow audits, draft compliant privacy policies, and manage the immediate compliance obligations under the new statutory tort and upcoming ADM deadlines. Early legal guidance is essential to mitigate litigation risk and ensure your platform remains structurally sound for future investment.




