Liability limited by a scheme approved under Professional Standards Legislation


Latest Accounting News
Write a business plan
Two Cautionary Tales About Resources Important to Anyone Using a Domain Name or Website
What Are the Privacy Policy Requirements for Australian E-Commerce Businesses?
Privacy Compliance Sweep 2026: Is Your Business Ready?
Foreign investor fined $370k as ATO cracks whip on land banking
The AI moment in accounting will follow a familiar pattern
Latest Intergenerational Report points to stubborn productivity issues that AI cannot fix
Check out the smartest species on earth: Data from 200M BC to 2026
Steps to close a business
Paid parental leave super contributions have started
How Do I Write Legally Compliant Terms and Conditions for My Business?
Don’t get caught out at tax time with your multiple jobs
Division 296 tax on large super balances
More of the same with latest missive from Treasury
'No place to hide': ATO puts contractors on notice over $1bn in missing TPAR payments
Check out the largest castles by country
ATO no longer treating debt the same as during COVID
Warning for early lodger this tax time!
Global companies turn to cost-cutting amid ongoing inflation
Don’t get caught out at tax time with your multiples jobs
Does Your Small Business Need to Follow AML Privacy Rules?
SMEs warned as ATO ramps up tax debt collection
Taxpayer given 35% penalty for BAS recklessness
How Our Diets have Changed.
Tips to help you this tax time
Tax Time Checklists Individuals; Company; Trust; Partnership; and Super Funds
ATO warns millions of Australian chasing tax deductions to stop making 'unusual' claims
Impersonation scams are on the rise
Components of a cyber security plan
Social Security Payments and Their Effect on Discretionary Trusts
LRBA ban no better for housing supply or retirement, accountants clap back
The evolution of the world's languages
Privacy Compliance Sweep 2026: Is Your Business Ready?

The privacy commissioner has launched their first-ever compliance sweep in January 2026.



 


The privacy commissioner has launched their first-ever compliance sweep in January 2026.


Privacy policies of selected businesses are under the microscope, and businesses with non-compliant policies could receive significant penalties. This article explains the privacy compliance sweep, who is being targeted, and how you can ensure your privacy policy is compliant.


What Is the Privacy Compliance Sweep?


Australian businesses should be transparent about the personal information they collect and how they handle it. The privacy commissioner has identified that customers are especially vulnerable when asked for information face-to-face. This is because, unlike online forms where customers can review privacy policies in their own time, in-person requests often pressure people to respond quickly without having full information about how their data will be used. Therefore, the sweep will initially target businesses that collect information during in-person interactions.


When customers can not properly review privacy policies, you may over-collect personal information and use it in ways customers did not expect or agree to. The privacy commissioner’s goal is to ensure you are transparent about how you use personal information.


Who Is Being Targeted?


All businesses covered by Australian privacy laws must have a compliant privacy policy. However, this initial sweep is targeting six specific sectors.


The privacy commissioner has selected these sectors because they commonly collect personal information in person, including identification documents, and these sectors have experienced many privacy breaches.


The six sectors under review are:


  • rental and property;
  • chemists and pharmacists;
  • licensed venues;
  • car rental companies;
  • car dealerships; and
  • pawnbrokers and second-hand dealers.

The privacy commissioner will review approximately 60 businesses from these sectors for compliance with privacy policy requirements. This is the first compliance sweep of its kind, and more targeted reviews are likely to follow.


What Do You Need to Do?


If you do not have a privacy policy, you need to have one prepared. If you already have one, now is the time to review it and make sure it is compliant.


What Your Privacy Policy Must Include


Australian privacy laws set out the minimum requirements that a privacy policy must include. This includes that your privacy policy must explain:


  • the personal information you collect and hold;
  • how you collect and hold personal information;
  • why you collect, use and disclose personal information;
  • how customers can access the personal information you hold about them;
  • how to submit a complaint; and
  • whether you send personal information overseas.

Making Your Policy Clear and Accessible


Your privacy policy must be clearly expressed and up to date. This means the privacy policy:


  • is written in simple language that a 14-year-old could understand;
  • uses headings so people can find information easily;
  • is specific to your business, not a generic template;
  • is not too long or written in vague language;
  • is available free of charge on your website; and
  • is updated regularly when your privacy practices change.

What Happens if Your Privacy Policy Does Not Comply?


The privacy commissioner can issue compliance notices requiring you to fix issues with your policy.


Key Takeaways


The first privacy compliance sweep is underway as of January 2026, targeting businesses that collect personal information in person. More sweeps are likely to follow as privacy regulation strengthens across Australia. To be compliant, you need to make sure you have a robust and clear privacy policy in place for your business that meets the requirements. Good privacy practices build customer trust by demonstrating you protect their personal information.


 


 


 


By: Lauren McKee | 27 January 2026 | legalvision.com.au




20th-October-2026