1. Who has to comply: are you an APP entity?
    1. The $3 million turnover threshold
    2. Exceptions that catch small NFPs anyway
  2. The core duty: a clearly expressed, up-to-date privacy policy
  3. What your policy must contain
  4. Making the policy available
  5. Beyond the policy: the rest of the APPs
  6. What happens if you do not comply
  7. A practical compliance checklist
  8. Where a lawyer can help
  9. The trap: small charities that assume they are exempt

Most Australian not-for-profits (NFPs) and charities handle personal information every day: donor names and bank details, volunteer contact details, client records, and sometimes sensitive information about a person's health or circumstances. Whether you must publish a privacy policy comes down to one question: is your organisation an APP entity under the Privacy Act 1988 (Cth) (the Act)? If it is, you must have a privacy policy that meets a legal standard, and the Act sets out exactly what it must contain.

This article covers who the obligation applies to, the turnover threshold that usually decides it, the exceptions that catch NFPs below that threshold, what your policy must say, what else the Act requires of you, and what happens if you do not comply.

Who has to comply: are you an APP entity?

The Act regulates how organisations handle personal information through the 13 Australian Privacy Principles (APPs) in Schedule 1 of the Act. An APP entity is either an agency or an organisation.

For NFPs, the relevant category is organisation. Under s 6C of the Act, an organisation is an individual, body corporate, partnership, unincorporated association or trust, unless it is a small business operator, a registered political party, an agency, or a State or Territory authority.

Most NFPs are caught by this definition on structure alone. An incorporated association, a company limited by guarantee, an unincorporated association or a charitable trust is squarely within s 6C(1). The real question for most charities is whether the small business operator carve-out applies.

The $3 million turnover threshold

A small business operator is an entity that carries on one or more small businesses, where a small business has an annual turnover of $3,000,000 or less (s 6D of the Act). Turnover is measured against the previous financial year; for a business that only started in the current year, the test is whether current-year turnover is $3,000,000 or less.

Turnover means income, not profit. Under s 6DA, annual turnover includes proceeds of sales, commission, rent, leasing and hiring income, government bounties and subsidies, interest, royalties and dividends, and other operating income. The Office of the Australian Information Commissioner (OAIC) summarises it as all income from all sources, but not assets held, capital gains or the proceeds of capital sales. For an NFP this matters: grants, government subsidies, fundraising income and fees all count towards the threshold even though the organisation makes no profit.

Exceptions that catch small NFPs anyway

An entity is not a small business operator, and so must comply with the APPs regardless of turnover, if it falls into one of the categories in s 6D(4) of the Act. The ones that most commonly catch NFPs and charities are:

  • Health service providers: an entity that provides a health service and holds health information, other than in an employee record, is covered (s 6D(4)(b)). This pulls in many community organisations: counselling services, disability support providers, aged care providers, community health centres, and private schools.
  • Trading in personal information: an entity that discloses personal information to someone else for a benefit, service or advantage is covered (s 6D(4)(c)). Selling or renting a donor list to another organisation is the classic example. Disclosing with the individual's consent or as required by law does not count.
  • Collecting personal information for a benefit: an entity that provides a benefit, service or advantage to collect personal information from someone else is covered (s 6D(4)(d)).
  • Commonwealth contractors: an entity that is a contracted service provider for a Commonwealth contract is covered (s 6D(4)(e)).
  • Related bodies corporate: a body corporate that is related to a body corporate carrying on a business that is not a small business is covered (s 6D(9)). If your NFP is part of a group with a commercial arm above the threshold, the whole group is likely within the Act.

The OAIC's small business guidance lists additional categories, including operators of residential tenancy databases, employee associations, and businesses accredited under the Consumer Data Right system. A small business operator can also choose to opt in to the Act voluntarily, which some NFPs do to reassure donors and partners.

Two other carve-outs are worth knowing even if your NFP is clearly an APP entity. First, the Act exempts certain acts and practices of organisations under s 7B, which in broad terms takes the handling of employee records out of the APPs, so your privacy policy generally does not need to cover staff files. Second, if your organisation is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the Act applies to those activities even below the turnover threshold (s 6E).

The core duty: a clearly expressed, up-to-date privacy policy

If your NFP is an APP entity, APP 1.3 of the Act requires you to have a clearly expressed and up-to-date policy about how you manage personal information. The object of APP 1, stated in APP 1.1, is to ensure APP entities manage personal information in an open and transparent way.

APP 1.2 imposes a related duty that is easy to miss: you must take such steps as are reasonable in the circumstances to implement practices, procedures and systems that will ensure compliance with the APPs, and that will let you deal with inquiries and complaints from individuals about your compliance. A privacy policy that sits unread on your website while your staff collect donor details on paper forms is not compliance. The OAIC expects the policy to reflect how the organisation actually operates.

What your policy must contain

APP 1.4 sets out the minimum contents of an APP privacy policy. It must cover:

  • the kinds of personal information the entity collects and holds
  • how the entity collects and holds personal information
  • the purposes for which the entity collects, holds, uses and discloses personal information
  • how an individual may access personal information held about them and seek correction
  • how an individual may complain about a breach of the APPs (or a registered APP code that binds the entity), and how the entity will deal with such a complaint
  • whether the entity is likely to disclose personal information to overseas recipients
  • if it is likely to do so, the countries in which those recipients are likely to be located, where it is practicable to specify them

For an NFP, that last item is more than a formality. If you use a cloud-based donor management system with servers overseas, or an international payment processor for online donations, you are likely disclosing personal information to overseas recipients and your policy should say where. APP 8 imposes separate obligations on cross-border disclosures, so check what your software providers actually do with the data before you draft.

The drafting itself matters. The policy must be clearly expressed, so plain language, short sentences and headings all help. Provide the contact details of the person or team that handles privacy inquiries and complaints, and consider linking to the APPs so readers can see the standards you are held to. The OAIC publishes free guidance on drafting privacy policies, and its privacy management plan template is a useful starting point.

Making the policy available

APP 1.5 requires you to take reasonable steps to make the policy available free of charge and in an appropriate form. In practice that means publishing it on your website. APP 1.6 goes further: if someone requests a copy in a particular form, you must take reasonable steps to give them a copy in that form. That could mean a printed copy for a donor who does not use the internet, or a version that is accessible to people with disability.

Beyond the policy: the rest of the APPs

The privacy policy is the most visible part of APP 1, but an APP entity must comply with all 13 principles. The rest of the APPs regulate the whole life cycle of the personal information you hold: what you may collect and when, telling individuals at or before collection what you are collecting and why (APP 5), how you may use and disclose information (APP 6), direct marketing and the requirement to offer a simple opt-out (APP 7), keeping information secure, allowing individuals to access their information, and correcting it (APP 13).

For charities, APP 7 deserves particular attention because fundraising sits at the centre of what you do. You can use personal information for direct marketing in limited circumstances, but you must always give individuals a simple way to opt out and must respect that choice.

What happens if you do not comply

Non-compliance can be raised with the OAIC in a number of ways. An individual can complain to the OAIC about how your organisation handled their personal information. The OAIC can investigate and conciliate complaints, and can make determinations. It can also commence its own Commissioner-initiated investigations, so a breach does not need a complainant to trigger scrutiny.

The Act backs this up with civil penalties. Under s 13G, a serious interference with privacy attracts a maximum penalty for a body corporate of the greatest of $50,000,000, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover during the breach turnover period. For individuals the maximum is $2,500,000. Other interferences with privacy carry a maximum of 2,000 penalty units under s 13H.

Critically for this topic, the policy itself is directly enforceable. Under s 13K, breaching APP 1.3 (failing to have an APP privacy policy) or APP 1.4 (having a policy that does not contain the required information) is a civil penalty provision for which the OAIC can issue infringement notices or compliance notices. In other words, you can be penalised for having no policy, or an inadequate one, even if no personal information has actually been mishandled.

A practical compliance checklist

Working through the following will put most NFPs in a sound position:

  • Confirm your status: Work out whether you are an APP entity: your structure, your turnover for the previous financial year, and whether any exception in s 6D(4) applies. If you are part of a group, check the related body corporate rule.
  • Draft the policy: Cover every item in APP 1.4, in plain language.
  • Publish it: Make it available free of charge on your website, and be ready to provide copies in other forms on request.
  • Make it true: Update the policy whenever your practices change, and make sure the people collecting data actually follow it.
  • Build the supporting systems: APP 1.2 requires practices, procedures and systems: staff training, a complaints process, and a named contact for privacy inquiries.
  • Review it regularly: The OAIC expects a current policy. Schedule a review at least annually and after any change to your systems, software or services.

Where a lawyer can help

The threshold questions are where NFPs most often go wrong, and they are exactly where a lawyer adds value. If your turnover is close to $3,000,000, if you provide any kind of health service, if you share data with partner organisations, or if your NFP sits within a group structure, a lawyer can confirm whether you are an APP entity and whether any exception applies. A lawyer can also review your draft policy against APP 1.4 and the OAIC's expectations, check what your cloud and payment providers do with data before you commit to statements about overseas disclosure, and advise if you receive a complaint or a notice from the OAIC.

The trap: small charities that assume they are exempt

The mistake that costs NFPs most is assuming that being small means being exempt. A community counselling service with $200,000 in annual income holds health information and is an APP entity regardless of turnover. A small charity that rents its donor list to a marketing company is trading in personal information and is caught by s 6D(4)(c). Both must have a compliant privacy policy today.

There is also a clear direction of travel. The federal government has announced plans to remove the small business exemption from the Act as part of its privacy reform agenda. At the time of writing the exemption remains in force, but the reform has bipartisan momentum, and changes to the anti-money laundering regime from 1 July 2026 will already bring some additional businesses within the Act. Treating privacy compliance as optional because you are under the threshold is a short-term position.

So the first action this week is simple: run the status test. Identify your structure, add up your turnover, and check the exceptions. If you are an APP entity, draft the policy now; APP 1.3 and APP 1.4 are enforceable on their own. If you are genuinely exempt, publishing a short privacy policy anyway is cheap insurance, because it builds donor trust and positions you ahead of reforms that are likely to remove the exemption entirely.