Savira - Making Compliance Easy
Reference

Privacy policy requirements in Australia: what to include

What your privacy policy has to include under Australian privacy law, in plain English, plus a quick checklist to see if yours is up to scratch.

Privacy policies5 min read

Content: If your business collects customer details, your privacy policy is the one document anyone can actually check. Customers read it, bigger clients ask for it during procurement, and the regulator starts there. The good news is that the privacy policy requirements in Australia are not mysterious. The Office of the Australian Information Commissioner (OAIC) sets them out plainly.

A privacy policy is a plain language statement explaining how your business handles personal information. If the Privacy Act 1988 (Cth) covers you, you must have one, keep it up to date, and make it easy to find. It has to cover a set list of things, from what you collect through to how someone complains.

What is a privacy policy, exactly?

The OAIC describes a privacy policy as a statement that explains, in simple language, how an organisation handles someone's personal information. That word "simple" is doing real work. A policy full of defined terms and cross references technically exists, but it is not doing the job it was written for.

Your privacy policy is the standing, general description of how you handle information. It is not the same as the short notice you give someone at the moment you collect their details, like the line under a form explaining why you need their phone number. Most businesses need both, and the two should agree with each other.

Does your business need one?

The Privacy Act 1988 (Cth) covers organisations operating in Australia with an annual turnover of more than $3 million, plus a number of others that are covered no matter how small they are. That second group catches more small businesses than people expect, including health service providers and businesses that buy or sell personal information.

If you are not sure which side of the line you sit on, it is worth working it out properly rather than assuming. Even where the Act does not apply, a privacy policy is a sensible thing to have, because customers and larger clients increasingly ask for one before they will deal with you.

What are the privacy policy requirements in Australia?

The OAIC sets out what a policy needs to tell people. In plain terms:

  • Who you are. Your business name and how to contact you about privacy.

  • What you collect. The kinds of personal information you collect and hold, described specifically enough to be useful.

  • How you collect it and where you keep it. Forms, phone calls, your website, a third party, and where the information ends up.

  • Why you collect it. The purposes you collect, hold, use and disclose it for.

  • Who you share it with. How you use and disclose the information, including any suppliers involved.

  • How someone gets access. How a person can ask for the information you hold about them, and ask you to correct it.

  • How someone complains. How to make a privacy complaint to you, and what you will do with it.

  • Whether it leaves the country. Whether you are likely to disclose personal information overseas, and which countries.

  • Anything else worth saying. For example how long you keep information, or whether you need to sight identity documents.

Write it about your actual business. A policy copied from another site will list things you do not do and miss things you do, and that gap is exactly what gets noticed.

Where does your privacy policy have to live?

It has to be easy to get hold of, and free. In practice that means a clearly linked page on your website. The OAIC also points out that policies turn up as printed documents and on mobile screens, and that if someone without internet access asks for a paper copy, you should be able to send one.

If a customer reads your policy and cannot make sense of it, the OAIC's advice to them is to ask you directly. Worth keeping in mind when you are deciding how plainly to write it.

When do you have to update it?

Whenever your information handling changes. A new booking system, a new email marketing tool, a supplier based overseas, or a new type of information you have started collecting: each of those is a reason to revisit the policy. The OAIC also expects you to let people know when the policy has changed, whether that is on your website, by email, or by post.

A quiet annual review is a good habit even when nothing obvious has changed, because these things drift.

A quick check on your own policy

  1. Open your policy and read it the way a customer would. Can you tell what the business collects and why, in under two minutes?

  2. Compare it with what you actually do today, including every tool that touches customer data.

  3. Check that each of the nine points above is answered somewhere, not just implied.

  4. Make sure your contact details and complaints process are current and actually monitored.

  5. Note the date you reviewed it, and set a reminder for next year.

This is live territory at the moment. The OAIC began its first privacy policy compliance sweep in January 2026, checking policies in six sectors against the transparency requirements. If yours has not been looked at in a few years, now is a sensible time.

Common questions

Do I need a privacy policy if my turnover is under $3 million?

Not automatically, but plenty of small businesses are covered anyway because of what they do rather than what they earn. Check whether one of the exceptions applies to you before deciding you are exempt.

Can I copy another business's privacy policy?

You can look at one for structure, but the content has to describe your business. A copied policy usually describes systems you do not use and misses the ones you do.

Does it have to be on my website?

It has to be readily available and free of charge. For almost every business, a linked page on the website is the practical answer, with another format available if someone asks for it.

How often should I review it?

Any time your information handling changes, and once a year regardless.

This is general information, not legal advice. Every business handles information a bit differently, so if you're not sure how this applies to yours, it's worth checking with a lawyer or privacy adviser.

Source: What is a privacy policy?, Office of the Australian Information Commissioner, last updated 5 September 2024.

What is a privacy policy?

Published 5 September 2024

Source: Office of the Australian Information Commissioner website – www.oaic.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. This summary is Savira's own and is not endorsed by the OAIC.