Guide · Rules & costs
Does your website need a privacy policy, and what goes in it?
Which small businesses must have a privacy policy under the Privacy Act, what it must cover, where to publish it, and the penalties for getting it wrong.

Plenty of small business websites carry a “Privacy” link in the footer that leads to a page copied from somewhere else, or to nothing at all. Whether that matters depends first on whether the Privacy Act covers your business. If it does, the Act sets out what the policy must say, and the regulator can now fine you without going to court if it doesn’t.
Who must have one
The requirement sits in Australian Privacy Principle (APP) 1.3 in the Privacy Act 1988: an “APP entity must have a clearly expressed and up‑to‑date policy (the APP privacy policy) about the management of personal information by the entity.” It applies to every business the APPs cover.
Most small businesses aren’t covered. Under section 6D of the Act, a business is a small business if its annual turnover for the previous financial year is $3,000,000 or less. The OAIC’s small business page says turnover “includes all income from all sources”, but not assets held, capital gains or proceeds of capital sales. Its checklist asks whether turnover has been more than $3 million in any financial year since 2002; on our reading of section 6D, a business that has passed the threshold stays covered even if turnover later falls.
Regardless of turnover, the OAIC says the Act covers any business that is:
- a health service provider that holds health information. The OAIC’s rights and responsibilities page lists examples including medical practitioners, pharmacists, allied health professionals, naturopaths, chiropractors, gyms, weight loss clinics, child care centres and private schools
- trading in personal information, such as selling a customer list or swapping it for another list (generally, where done without consent)
- a contractor providing services under a Commonwealth contract
- a credit reporting body
- a residential tenancy database operator, anti-money laundering reporting entity or protected action ballot agent (for those activities)
- a registered or recognised employee association, or accredited under the Consumer Data Right
- related to a covered business, prescribed by regulation, or opted in.
Opting in is voluntary. Section 6EA lets a small business choose to be treated as an organisation under the Act. The OAIC says opting in is free, and that applications from businesses without a privacy policy “will be declined”. Your trading name and ABN then go on a public register.
What the policy must contain
APP 1.4 lists the minimum. The policy must say:
- the kinds of personal information you collect and hold
- how you collect and hold it
- the purposes for which you collect, hold, use and disclose it
- how people can access their information and ask for it to be corrected
- how people can complain about a breach of the APPs (or a registered APP code that binds you), and how you’ll deal with the complaint
- whether you’re likely to disclose personal information to overseas recipients and, if so, the countries where they are likely to be, if it’s practicable to list them.
The OAIC’s APP guidelines, chapter 1, explain what it expects under each heading. This is guidance, not the Act itself, but it’s how the regulator reads the law:
- What and how. Describe information in general terms, such as “contact details”, listing sensitive information such as health information separately. Explain how you store and secure it without giving details that would weaken your security.
- Access and correction. At a minimum, say that people can ask for access and correction, and give the position title, phone number, postal address and email address of a contact person. The OAIC suggests a generic email address that won’t change when staff leave.
- Complaints. Give the procedure and contact details for complaining to you. The guidelines say a complaint should usually be made to you in writing first, with a reasonable time (usually 30 days) to respond, before it goes to an external dispute resolution scheme you belong to or to the OAIC.
- Overseas. A likely disclosure counts if it’s your current practice or you have established plans.
The OAIC says a policy should be easy to understand and avoid jargon and legalistic terms. It suggests adding a “last updated” note and reviewing the policy regularly, for example as part of annual planning. Its Guide to developing an APP privacy policy adds that a policy should not be “simply based on a generalised template used by a different entity”, should avoid vague words such as “may”, and should be understandable by a 14-year-old.
Illustrative wording only, not legal advice. A line covering access and correction might read: “You can ask for a copy of the personal information we hold about you, or ask us to correct it. Contact our Privacy Officer at [generic email address], on [phone number] or at [postal address].” Your policy has to describe what your business actually does.
Where to publish it
APP 1.5 requires you to take reasonable steps to make the policy available free of charge and in an appropriate form. A note in the Act says a business “will usually make its APP privacy policy available on the entity’s website”. The OAIC says the policy should be prominently displayed and easy to download, suggesting a link on each page of the site. If you have no online presence, it suggests a copy at your premises or a printout on request. Under APP 1.6, if someone asks for a copy in a particular form, you must take reasonable steps to provide it.
From 10 December 2026: automated decisions
From 10 December 2026, a covered business that has arranged for a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect someone’s rights or interests, using their personal information, must say so in its policy. It must describe the kinds of personal information used and the kinds of decisions involved. We covered this change in Privacy Act changes: what applies now, what starts in December, what’s proposed.
What happens if it’s missing or incomplete
Since 11 December 2024, section 13K of the Act makes breaching APP 1.3 (having a policy) or APP 1.4 (its contents) a civil penalty provision for which infringement notices or compliance notices can be issued. From 10 December 2026, the automated-decision content under APP 1.7 is added to that list. When it announced a compliance sweep in December 2025, the OAIC said businesses with non-compliant privacy policies may face compliance and infringement notices and penalties of up to $66,000. APP 1.5, publishing the policy, is not on the section 13K list, but it is still an APP obligation.
That December 2025 announcement described the OAIC’s first compliance sweep, due to begin in the first week of January 2026, checking the privacy policies of about 60 businesses in six sectors that collect information in person, including rental and property, chemists, licensed venues and car dealerships, against APP 1.4.
Not covered? You may still need one
Being outside the Act doesn’t mean no service provider will ask. Google’s Analytics terms of service say: “You must post a Privacy Policy and that Privacy Policy must provide notice of Your use of cookies, identifiers for mobile devices … or similar technology used to collect data.” The terms also require you to disclose your use of Google Analytics and how it collects and processes data. On our reading, that applies to any site using the standard Google Analytics service, whether or not the Privacy Act covers the business.
This is general information, not legal advice.
Checklist
- Work out whether the Privacy Act covers you. Run the OAIC’s Privacy Checklist for Small Business, checking turnover over $3 million since 2002, health services and trading in personal information.
- List what personal information you hold. Note what you collect, how you store it and why you need it.
- Cover the six required topics. Make sure your policy states what you collect, how, why, how people access and correct it, how to complain, and whether data is likely to go overseas.
- Name a contact for privacy requests. Give a position title, phone number, postal address and a generic email address that won’t change when staff leave.
- Link the policy from every page. Put a prominent “Privacy” link on each page of your site, keep it free to access, and give a copy in another form, such as a printout, if someone asks.
- Add a “last updated” date. Review the policy regularly, for example as part of annual planning, so it matches what the business actually does.
- Check your automated decisions by 10 December 2026. If software uses personal information to make, or substantially help make, decisions that could significantly affect people’s rights or interests, describe the kinds of information and decisions in the policy.
- Check your Google Analytics disclosure. If your site uses Google Analytics, make sure your policy discloses that you use it, its cookies, and how it collects and processes data.
Tick items as you go. Your ticks stay in this browser.
Sources 9 sources
- OAIC: Australian Privacy Principles guidelines, Chapter 1: APP 1 Open and transparent management of personal information
- Federal Register of Legislation: Privacy Act 1988 (compilation of 4 June 2026)
- Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024
- OAIC: Small business
- OAIC: Rights and responsibilities
- OAIC: Opting in to the Privacy Act
- OAIC: Guide to developing an APP privacy policy
- OAIC: Privacy compliance sweep to put privacy policies under the spotlight (9 December 2025)
- Google: Google Analytics Terms of Service

