OAIC privacy policy sweep: what it means for your business
The OAIC is checking about 60 privacy policies across six sectors for APP 1.4 compliance, and here is what it means for your business.
Most compliance news does not arrive with a list of who is being looked at. The OAIC privacy policy sweep does, and if you take customer details across a counter, it is worth two minutes of your time.
In December 2025 the Office of the Australian Information Commissioner (OAIC) announced its first ever compliance sweep, reviewing the privacy policies of about 60 entities across six sectors from January 2026. It is checking whether those policies meet Australian Privacy Principle (APP) 1.4. The OAIC says non-compliance can attract penalties of up to $66,000.
Which sectors is the OAIC looking at?
Six, all chosen because they collect personal information face to face, often including identity documents:
Rental and property agencies
Chemists and pharmacists
Licensed venues
Car rental companies
Car dealerships
Pawnbrokers and second-hand dealers
The common thread is a counter, a form, and a customer who is not in a strong position to push back. The OAIC has pointed to that power imbalance, and to the fact that several of these sectors have had data breaches.
What is the OAIC actually checking?
APP 1.4 sets out what a privacy policy has to tell people: what you collect, how and why you collect it, how someone can access or correct it, how they can complain, and whether the information goes overseas. The sweep is a transparency check on the policy itself, not a full audit of your systems.
Privacy Commissioner Carly Kind put the reasoning plainly: "The first building block of better privacy practices is a clear privacy policy that transparently communicates how an individual can expect their information to be collected, used, disclosed and destroyed."
The Commissioner also made the point that when people are asked for their details in person, they often do not have all the information they need to make an informed decision, which leaves them open to having more collected than necessary.
Why this matters if you are not on the list
A sweep is a signal about where the regulator's attention is going. The OAIC has been clear that it is drawing on the broader set of enforcement tools it gained through the 2024 amendments to the Privacy Act 1988 (Cth), and that it will respond in a risk based and proportionate way where it finds problems. It has also said it hopes the sweep prompts businesses more generally to look at how robust their privacy practices really are.
In other words, this is the cheap moment to fix your policy. Fixing it after a regulator has read it is a different conversation.
Where the sweep is up to
The sweep began in January 2026. As at the end of August 2026 we have not seen the OAIC publish findings or outcomes from it, so treat the December 2025 announcement as the current public position and keep an eye on the OAIC newsroom.
What to do about it
1. Find your policy and read it end to end
Not skim. Read it as though you are the customer handing over your licence. If you cannot follow it, neither can they.
2. Check it against APP 1.4
Go point by point: kinds of information, how and why you collect it, use and disclosure, access and correction, complaints, and overseas disclosure. Anything missing is the gap the sweep is looking for.
3. Be specific about identity documents
If you sight, scan or copy a licence or passport, say so. Say why you need it, whether you keep a copy, how long you keep it, and what happens to it afterwards. This is the part most policies skip and it is squarely in scope.
4. Fix the counter, not just the page
A compliant policy sitting behind a website link does not help someone standing at your front desk. Make sure staff can point to it, and that whatever you say at the point of collection matches what the policy says.
5. Date it and diarise a review
Note when you last reviewed it, and set a reminder to check again in twelve months or whenever your systems change.
Common questions
How do I know if my business is one of the 60?
You will not know in advance. The OAIC named the sectors, not the businesses. If you are in one of the six, the sensible assumption is that you could be looked at.
What is APP 1.4?
It is the part of the Australian Privacy Principles that lists what a privacy policy must contain. It sits under APP 1, which is about managing personal information openly and transparently.
Does the $66,000 figure apply to a small business?
The OAIC's announcement refers to infringement notices and penalties of up to $66,000 for non-compliance. What applies in a given case depends on the entity and the circumstances, so if you are worried about your exposure, get advice rather than guessing.
What if the Privacy Act does not cover my business at all?
Then the sweep is not aimed at you, though it is worth confirming that properly rather than assuming, because some small businesses are covered regardless of turnover.
This is general information, not legal advice. Every business handles information a bit differently, so if you're not sure how this applies to yours, it's worth checking with a lawyer or privacy adviser.
Source: Privacy compliance sweep to put privacy policies under the spotlight, Office of the Australian Information Commissioner, published 9 December 2025.
Source: Office of the Australian Information Commissioner website – www.oaic.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. This summary is Savira's own and is not endorsed by the OAIC.

