1. Who must comply: the $3 million turnover test
  2. Small businesses that are covered anyway
  3. The core duty: a clearly expressed, up-to-date privacy policy
  4. The policy must reflect what your website actually collects
  5. What happens if you do not comply
  6. A practical privacy policy checklist
  7. When a privacy lawyer is worth the call
  8. The privacy step small businesses most often skip

That block of fine print at the bottom of most business websites, the one nobody reads, is a legal document. Since 12 March 2014, when the Australian Privacy Principles (APPs) replaced the earlier national principles, every entity covered by the Privacy Act 1988 (Cth) (the Act) has been required to have a clearly expressed and up-to-date policy about how it manages personal information. In other words, for many Australian businesses the privacy policy is not optional website furniture. It is a condition of operating lawfully.

This guide sets out who the requirement applies to, what the policy must say, what happens if you do not comply, and the practical steps to get it done. If you run a small or medium business and you have ever wondered whether the privacy policy matters, the answer depends on your turnover, what your business does, and how your website collects data.

Who must comply: the $3 million turnover test

The Act applies to "organisations", a term that covers businesses and not-for-profits (NFPs) of all kinds, from sole traders to companies. The starting point is a simple turnover test. Under section 6D(1) of the Act, a business is a "small business" if its annual turnover for the previous financial year was $3 million or less. A business that turns over more than $3 million is not a small business, and it must comply with the APPs, starting with the duty to have a privacy policy.

For a business that has not yet traded for a full financial year, the test looks at its projected turnover for the current year instead. New businesses should therefore estimate their full-year income before assuming they fall under the threshold.

Annual turnover is broader than gross sales. Section 6DA counts proceeds of sales of goods and services, commission income, rent, leasing and hiring income, interest, royalties, dividends and government bounties and subsidies. The Office of the Australian Information Commissioner (OAIC) adds that turnover means all income from all sources, but does not include assets held, capital gains or proceeds of capital sales. A business that rents out premises, for example, can cross the $3 million line on rental income even if its sales are modest.

Two further points are easy to miss. First, not-for-profits are treated the same way as businesses: an NFP with an annual turnover greater than $3 million is covered by the Act, as the OAIC explains in its guidance for not-for-profits and charities. Second, the test is applied to related companies as a group. Under section 6D(9), a body corporate is not a small business operator if it is related to a body corporate that carries on a business that is not a small business. So a subsidiary that turns over $500,000 is still covered if its parent group turns over more than $3 million.

Small businesses that are covered anyway

A business with turnover of $3 million or less is normally exempt from the Act as a "small business operator". But the exemption has a long list of carve-outs. Under section 6D(4), a small business is still covered if any of the following applies:

  • Health services: the business provides a health service to an individual and holds health information. The Act defines a health service very broadly, so businesses such as gyms, weight-loss clinics, childcare centres, private schools and allied health practices can easily be caught even though they do not think of themselves as health providers.
  • Trading in personal information: the business discloses personal information to someone else for a benefit, service or advantage, for example selling or swapping customer lists with a marketing company. The carve-out does not apply if the individual consented or the disclosure is required or authorised by law.
  • Commonwealth contracts: the business is a contracted service provider for a Commonwealth contract, including as a subcontractor, regardless of whether it is a party to the contract.
  • Credit reporting: the business is a credit reporting body or operates a residential tenancy database.
  • Employee associations: the business is an employee association registered or recognised under the Fair Work (Registered Organisations) Act 2009 (Cth).
  • Other prescribed categories: businesses prescribed by the Privacy Regulation 2013 (Cth), reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), protected action ballot agents, and businesses accredited under the Consumer Data Right system.
  • Related entities: the business is related to another business that the Act covers.

A small business can also choose to opt in to the Act under section 6EA, and many do because consumers treat a published privacy policy as a signal of trustworthiness. Separately, the Act does not generally apply to employee records that a business holds in relation to its current or former employees, which is why many policies focus on customer and website data.

The practical lesson is that "we turn over less than $3 million" is rarely the end of the analysis. A café that runs a small gym program, a retailer that sells its email list, or a family company inside a larger group can all be caught.

The core duty: a clearly expressed, up-to-date privacy policy

Australian Privacy Principle 1 (APP 1) is the foundation of the whole scheme. Its object is to ensure that covered entities manage personal information in an open and transparent way. Two obligations sit underneath it.

First, under APP 1.3, an APP entity must have a clearly expressed and up-to-date policy about the management of personal information. The Act does not prescribe a template, and the OAIC's guidance is that the policy should be a plain-language statement explaining, in simple terms, how the organisation handles personal information.

Second, under APP 1.4, the policy must contain all of the following:

  • the kinds of personal information the entity collects and holds;
  • how the entity collects and holds personal information;
  • the purposes for which the entity collects, holds, uses and discloses personal information;
  • how an individual can access the personal information the entity holds about them and seek correction of it;
  • how an individual can complain about a breach of the APPs, or of a registered APP code that binds the entity, and how the entity will deal with that complaint;
  • whether the entity is likely to disclose personal information to overseas recipients; and
  • if so, the countries in which those recipients are likely to be located, where it is practicable to specify them.

APP 1.5 and 1.6 deal with availability. An APP entity must take reasonable steps to make the policy available to anyone who asks, and must give a person a copy on request, free of charge, in a form appropriate to their needs. There is no legal requirement to publish the policy on a website. But for a business that operates online, the website is the obvious and standard place to make the policy freely accessible, and it is where consumers, the OAIC and the courts will look first. A privacy policy buried in a customer portal, or only produced after a written request, is poor evidence of the "open and transparent" management the principle demands.

The policy must reflect what your website actually collects

This is where most privacy policies go wrong: they describe what the business would like to do, not what its website actually does.

The Act defines personal information, in section 6(1), as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in material form. A name and email address are obvious examples. But the definition also captures data your website collects without any form-filling. IP addresses, device and browser details, approximate location, session times, pages visited and cookie identifiers can all amount to personal information where they allow an individual to be reasonably identified. Depending on how a site is configured, a visitor can be identifiable from this metadata alone.

Third-party tools widen the net. A typical site runs Google Analytics, advertising pixels, social media share widgets or customer support chat, each of which receives visitor data and passes it to a separate company, frequently one located overseas. If your hosting provider stores data in data centres in other countries, that is another overseas data flow. Under APP 8, an APP entity that discloses personal information to an overseas recipient must take reasonable steps to ensure the recipient does not breach the APPs, and there are limited exceptions. That is exactly why APP 1.4 requires the policy to say whether the entity is likely to disclose personal information overseas and, where practicable, to name the countries.

The result is that drafting a policy is a mapping exercise, not a writing exercise. Before you put words on the page, you need to know every way personal information enters your business: website forms, analytics, pixels, payment processors, customer relationship software, payroll and marketing lists. When you change tools, add a widget or move hosting, the policy needs to change with it, because APP 1.3 requires the policy to be up to date and APP 1.2 requires you to take reasonable steps to implement practices, procedures and systems that actually deliver the promises the policy makes.

What happens if you do not comply

A privacy policy is not an abstract formality, because the regulator treats the APPs as enforceable law. The OAIC can investigate complaints about how a business handles personal information, conciliate disputes, and make determinations against the business. It can also commence its own investigations without waiting for a complaint.

The financial exposure is significant. Under section 13G, serious interference with an individual's privacy attracts a maximum civil penalty for a body corporate of the greatest of $50 million, three times the value of the benefit obtained from the conduct, or 30% of adjusted turnover during the breach period. Whether an interference is serious depends on factors such as the sensitivity of the information, the number of people affected and whether the conduct was repeated or continuous. For individuals, the maximum is $2.5 million. Breaching APP 1.3 or APP 1.4 (the duty to have a policy and the duty to include the required content) is itself a civil penalty provision under section 13K, which also opens the door to infringement notices and compliance notices from the regulator.

There is also the Notifiable Data Breaches scheme in Part IIIC of the Act. If a business has reasonable grounds to believe an eligible data breach has occurred, it must prepare a statement, give it to the OAIC, and notify affected individuals as soon as practicable. The scheme has applied to breaches since 22 February 2018. A business that never wrote down what data it holds, and where, cannot quickly work out who to notify when the breach happens, which is one reason the regulator and the market treat a current policy as evidence of basic hygiene.

A practical privacy policy checklist

If you are covered by the Act, or think you might be, work through these steps:

  • Confirm coverage: Check last financial year's turnover on the section 6DA basis, then work through the small business carve-outs, including whether your group or parent is covered.
  • Map every data flow: List every place personal information enters your business, including website forms, analytics, pixels, payment processors, marketing lists and payroll, and every third party it is shared with.
  • Draft the policy against APP 1.4: Cover all seven content items in plain language, and be specific about overseas disclosure and the countries involved.
  • Publish it where people can find it: Link the policy from your website footer and from anywhere you collect personal information, and make it printable or downloadable.
  • Build the complaints process: Name a person responsible for privacy, and set out internally how complaints under the APPs will be received and answered.
  • Review on change: Update the policy whenever you add a tool, change hosting, or start a new marketing activity, and schedule a full review at least annually.
  • Prepare for the breach: Have a data breach response plan so that, if the Notifiable Data Breaches scheme applies, you can prepare the statement and notify affected individuals without delay.

When a privacy lawyer is worth the call

A lawyer earns their fee in three situations. First, scoping: if your business sits near a boundary, such as a health-related service, a customer-list sale, or a group structure, a lawyer can confirm whether the Act applies to you at all, and that analysis changes everything downstream. Second, drafting: a lawyer can turn your data-flow map into a policy that satisfies every limb of APP 1.4 and matches your actual practices, and can review the contracts with the third parties and overseas processors your policy depends on. Third, trouble: if the OAIC contacts you about a complaint or a breach notification is due, a lawyer can manage the response, the statement and any negotiations with the regulator.

The privacy step small businesses most often skip

The two surprises in this area are the health services carve-out and the customer-list carve-out. A gym, a weight-loss clinic or a childcare centre rarely believes it is a health service provider, and a retailer rarely thinks of selling its email list as "trading in personal information", yet both are classic ways a small business loses the exemption. The second most common failure is treating the policy as a one-time document: businesses draft it once, file it, and never update it when they add a tracking pixel or move hosting.

The first action to take this week is not drafting anything. It is answering one question: based on last financial year's turnover and the carve-outs above, is your business an APP entity? If the answer is yes, the privacy policy on your website is not decoration; it is a compliance document with a specific required content, and it needs to be true. A short, honest policy that names your analytics provider and the countries your data reaches is worth more than a long, aspirational one that describes a business that does not exist.