In short
A privacy policy compliant with Australian Privacy Principle 1 under the Privacy Act 1988 (Cth) must clearly set out what personal information is collected, how it's used and disclosed, whether it's sent overseas, and how individuals can access, correct or complain about the handling of their information. It needs to reflect actual data practices, not a generic template, and should align with the Notifiable Data Breaches scheme obligations that apply once a breach occurs.
What APP 1 actually requires
Australian Privacy Principle 1 requires an organisation to have a clearly expressed and up-to-date privacy policy describing how it manages personal information, and to make it available free of charge in an appropriate form. This is more specific than most template policies deliver — it requires the kinds of personal information collected and held, how it's collected, the purposes of collection and use, how individuals can access and seek correction of their information, and how they can complain if they think the APPs have been breached. A policy that just states generic categories like 'we may collect information you provide' without describing the business's actual practices doesn't meet the standard and won't hold up if the Office of the Australian Information Commissioner ever reviews it.
Overseas disclosure and APP 8
If personal information is sent overseas — commonly to cloud hosting providers, payment processors or offshore support teams — APP 8 requires the policy to specify the countries the information may be disclosed to, if it's practicable to do so, and the business generally remains accountable for what an overseas recipient does with that information unless a specific exception applies. Many businesses using US-based SaaS tools for CRM, email marketing or analytics overlook this disclosure requirement entirely, and we map the actual data flows through the tech stack before drafting rather than assuming.
The Notifiable Data Breaches scheme
Under the Notifiable Data Breaches scheme, an entity that suffers a data breach likely to result in serious harm to affected individuals must notify both the OAIC and the affected individuals as soon as practicable. The privacy policy itself doesn't need to reproduce the entire breach response procedure, but it should reference how the business handles breaches and complaints, and we recommend the policy be paired with an internal breach response plan so the public-facing commitment matches what actually happens operationally when something goes wrong.
Small business exemption — and when it stops applying
Businesses with annual turnover under $3 million are generally exempt from the Privacy Act, but there are significant exceptions — including businesses that trade in personal information, provide health services, or are related to a larger entity that isn't exempt. Many small businesses assume the exemption applies to them when it doesn't, particularly health and fitness businesses and any business collecting sensitive information, and we check this threshold question before drafting rather than after.
Keeping the policy aligned with actual practice
A privacy policy is a representation to the public and the regulator about what you do with data, so it needs updating whenever a new tool, marketing channel or data-sharing arrangement is introduced. We draft with a structure that separates categories of information and purposes clearly, so future updates (a new payment processor, a new analytics tool) can be made without rewriting the whole document.
What the fixed fee covers
- Data flow mapping across your current tools and third-party processors
- APP 1-compliant privacy policy addressing collection, use, disclosure and overseas transfer
- Small business exemption check under the Privacy Act 1988 (Cth)
- Alignment with Notifiable Data Breaches scheme obligations
- Plain-English summary for publishing on your website or app
Mistakes we see
- Using a generic template that doesn't name the actual overseas countries data is sent to
- Assuming the small business exemption applies without checking the exceptions
- Never updating the policy after adding new marketing or analytics tools
- Having no internal breach response process behind a policy that promises one
- Failing to address sensitive information (health, biometric) separately where the business collects it
Who this is for
- Businesses launching a website, app or e-commerce store
- Businesses using overseas cloud or SaaS providers to store customer data
- Health, fitness and wellness businesses collecting sensitive information
- Businesses preparing for an OAIC complaint or audit
Frequently asked questions
- Does my small business need a privacy policy?
- If your annual turnover is under $3 million you may fall within the small business exemption, but exceptions apply if you trade in personal information, provide health services, or are related to a non-exempt entity. We check which category applies before assuming the exemption covers you.
- Do I need to name specific countries in my privacy policy?
- Yes, APP 8 requires you to specify the countries your information may be disclosed to overseas where it's practicable to do so, which means mapping your actual providers (hosting, email, payments) rather than using a vague 'may be disclosed overseas' statement.
- What happens if I have a data breach?
- If the breach is likely to result in serious harm, the Notifiable Data Breaches scheme requires you to notify the OAIC and affected individuals as soon as practicable, and your privacy policy should reflect that this process exists, backed by an actual internal response plan.
- Can I copy a competitor's privacy policy?
- No — a privacy policy is a factual statement about your specific data practices, and copying another business's policy risks misrepresenting what you actually do, which is itself a compliance and consumer law risk, not just a copyright issue.
- How often should the privacy policy be reviewed?
- We recommend a review whenever you add a new tool, processor or data use, and at least annually regardless, since privacy guidance from the OAIC and community expectations both continue to evolve.
Related
