Australian privacy policy requirements: A practical guide for businesses

Iconic view of Sydney Harbour Bridge with flags at sunset

Photo by Roy Ryu

A privacy policy is more than a page in your website footer. This guide explains whether your business may need one, what it should cover under the Australian Privacy Act, and how to make sure it reflects the way your business actually handles personal information.

A privacy policy should begin with how your business works

Having a privacy policy on your website does not necessarily mean your business meets its privacy obligations. Many businesses begin with a template, change the name, publish it and assume the work is complete.

A template can provide a useful structure, but the policy still needs to describe your actual practices. That means understanding what personal information you collect, where it is stored, why it is used, who receives it and what happens when it is no longer required.

The Office of the Australian Information Commissioner, or OAIC, recommends reviewing the organisation’s functions, systems, procedures and information-handling practices before drafting the policy. This gives the wording a reliable operational foundation. Work out whether the Privacy Act applies to your business

The Privacy Act generally applies to private-sector organisations with annual turnover above A$3 million. It also covers some smaller businesses, including certain health service providers, businesses that trade in personal information, Commonwealth contracted service providers, credit reporting bodies, related bodies corporate, and businesses that have voluntarily opted in. Whether the Act applies can depend on more than revenue, so it helps to complete an applicability assessment rather than rely on the turnover threshold alone. The OAIC provides a small-business privacy checklist, and legal advice may be appropriate where the position is unclear.

Businesses outside the Act may still face privacy expectations from customers, insurers, larger clients and commercial partners. Sound privacy practices can therefore remain valuable.

This article provides general information rather than legal advice. Each business should consider its own circumstances.

Understand what an APP privacy policy is meant to do

An APP privacy policy explains how an organisation manages personal information. Under Australian Privacy Principle 1, a covered organisation must have a clearly expressed and up-to-date policy that is available free of charge in an appropriate form, usually through its website.

The policy should help people understand what happens to their information. It should be specific, readable and easy to navigate.

The OAIC recommends simple language and content that reflects the organisation’s real practices. It also suggests testing whether the policy could be readily understood by a 14-year-old reader. Explain the personal information you collect and hold

The policy should describe the kinds of personal information the business usually collects and holds. Depending on the business, this could include contact details, account information, payment records, employment information, identity documents, website activity, device information or sensitive information such as health details.

The categories should reflect what the business genuinely handles. Listing every type of information a business could conceivably collect can make the policy less clear.

Explain how personal information is collected and held

Your policy should describe the usual ways information enters the business, including website forms, emails, phone calls, account registrations, onboarding, purchases, job applications and support requests. It should also cover indirect collection through referrals, business partners, public sources, analytics tools, cookies and third-party platforms.

The policy should explain broadly where information is held, such as cloud platforms, customer relationship management systems, accounting software, email, file storage and service providers. It can describe general security measures, but should avoid technical detail that could weaken those protections. Explain why information is collected, used and disclosed

People should be able to understand why their information is handled. Common purposes include delivering services, processing payments, communicating with customers, maintaining records, meeting legal obligations, improving services and carrying out permitted marketing.

This section should be particularly clear about uses or disclosures that may not be obvious from the original interaction. It can also identify the usual types of recipients, such as payment processors, cloud providers, professional advisers or delivery partners.

Explain how people can access or correct their information

The policy should state that individuals may request access to personal information held about them and ask for inaccurate information to be corrected. It should provide clear contact details and explain how a request can be made.

A role-based email address is usually easier to maintain than naming one employee. The OAIC notes that a generic contact point can remain stable as staff change. Explain how privacy complaints are handled

Your policy should explain how someone can raise a concern or make a complaint. It should identify where the complaint should be sent, outline the general process the business follows and explain any relevant escalation options.

The wording need not reproduce a detailed internal procedure. It should explain how the business will receive and respond to the issue.

Explain whether information is disclosed overseas

An APP privacy policy must state whether the business is likely to disclose personal information to overseas recipients. Where practicable, it should identify the countries in which those recipients are likely to be located. s can be easy to overlook because many everyday tools involve overseas storage, support or access. Cloud, marketing, payment and outsourced services may all form part of the information flow.

A sensible review considers where information is stored, processed, backed up or accessed, rather than looking only at the supplier’s head office. Supplier documentation and contracts can help identify these arrangements.

A privacy policy and a collection notice serve different purposes

A privacy policy describes the organisation’s overall approach to managing personal information. An APP 5 collection notice gives relevant information at or around the time a particular collection takes place.

The policy does not automatically replace notices on contact forms, account registrations, recruitment forms, newsletter sign-ups, event registrations or customer onboarding. The OAIC makes clear that a privacy policy is not, by itself, a substitute for APP 5 notification requirements. two documents can work together. A short collection notice can explain what matters for that interaction and link to the full privacy policy.

The policy needs to match what happens in practice

Privacy work becomes clearer when the policy is treated as a description of working practices. Before the wording can be accurate, the business needs to understand what information it holds, where it goes, who can access it, how long it is kept and how requests or complaints will be handled.

This is also where privacy and cybersecurity connect. A policy may say that personal information is protected appropriately, while the business still has shared accounts, missing multifactor authentication, former employees with access, unrestricted cloud folders or no reliable deletion process.

The document cannot compensate for processes and controls that have not been established. Reviewing the underlying practices first allows the business to close important gaps and then describe its arrangements accurately.

Follow a practical process

The work is easier to manage when it is broken into a clear sequence. Each step builds the information needed for the next, so the policy becomes the result of the review.

  1. Determine whether the Privacy Act applies. Consider turnover, business activities, the information handled and any relevant exceptions.
  2. Inventory the personal information you hold. Record information collected about customers, employees, applicants, contractors and other individuals.
  3. Map where the information goes. Identify the systems, devices, cloud services, providers and countries involved.
  4. Review your actual practices. Look at collection, access, sharing, security, retention, deletion, complaints and individual requests.
  5. Close important gaps. Improve unclear or insufficient practices before making public claims about them.
  6. Draft the policy in plain language. Make it specific, readable and easy to navigate.
  7. Publish it appropriately. Make it easy to find, free to access and available in another suitable form when reasonably requested.
  8. Assign ownership and keep it current. Review it when systems, vendors, overseas arrangements or information uses change, and include a visible last-updated date.

A scheduled change also deserves attention. From 10 December 2026, certain APP entities will need to include information about significant decisions made, or substantially assisted, by computer programs using personal information.

Watch for common privacy policy mistakes

Most problems come from a gap between the wording, the business’s real practices and the information a reader needs. These are useful signs to check during drafting and review.

  • The policy is copied from a generic template and includes practices that do not apply.
  • It describes protections or procedures that have not been implemented consistently.
  • It uses vague wording without explaining the usual purposes or recipients.
  • Overseas storage, access or disclosure has not been investigated.
  • The policy is being used in place of relevant collection notices.
  • The contact details depend on one employee and will quickly become outdated.
  • The policy has not been reviewed after new systems, vendors or tracking tools were introduced.
  • Important access, security, retention or breach-response gaps remain unresolved.

A good review should leave the business with clearer practices as well as clearer wording. This makes the policy easier to support when customers, staff or partners ask how their information is managed.

How BrightShield can support your business

BrightShield helps small and growing businesses turn privacy requirements into practical working processes. We help you understand how personal information moves through the business, identify operational and security gaps, and prepare documentation that reflects what is actually happening.

With BrightShield Guided, your team carries out the work with a clear process, practical templates and expert support. This can include assessing whether privacy requirements may apply, building an information inventory, mapping systems and overseas data flows, reviewing policy content, developing request and complaint procedures, and strengthening access, retention and security controls.

With BrightShield Complete, we take a more hands-on role. We can interview team members, map information across systems and suppliers, document current practices, prioritise gaps, coordinate security improvements, establish practical workflows and prepare policy content based on the business’s operations.

BrightShield does not provide legal opinions or guarantee compliance. Where legal interpretation or approval is needed, we can help prepare accurate operational information and draft content for review by an appropriately qualified lawyer.

A useful privacy policy grows from clear business practices

A good privacy policy begins with understanding the personal information your business holds and making deliberate decisions about how it is collected, protected, used, shared, retained and deleted. Once those practices are clear, the document becomes easier to write and more useful to the people who rely on it.

BrightShield can help you assess your current practices, build a prioritised improvement plan and put the supporting privacy and security processes in place. The result is a policy grounded in the way your business actually operates, with a clearer path for keeping it accurate over time.

Subscribe to our newsletter

Every week we publish a short email on a topic we think you'll find interesting. We know you're busy, so we keep it short, snappy, and relevant.

Let's Begin

Ready to understand your security risks?

Get a clear, practical view of your risks and a plan to fix them with a BrightShield Security Audit.