- What a privacy policy and a privacy notice actually are
- What your privacy policy must contain
- What your collection notice should tell people
- Do you actually have to have a privacy policy?
- Where to put both documents on your website
- How Artificer Legal can help with your privacy documents
- The collection notice is where compliance actually bites
When a customer fills in the contact form on your website, they are usually met with two privacy documents at once: the privacy policy linked in the footer of the page, and a short banner or pop-up telling them their details will be looked after. The two look similar and are often treated as interchangeable, but they do different jobs under Australian privacy law, and only one of them is a strict legal requirement. If your business collects personal information through a website, knowing which is which matters long before a complaint arrives.
What a privacy policy and a privacy notice actually are
A privacy policy is the comprehensive document. It is usually a full page on your website that sets out what personal information you collect, how you collect and hold it, why you use it, who you share it with, and how individuals can access, correct or complain about the handling of their information.
A privacy notice is the short version. The term is not defined in the Privacy Act 1988 (Cth). It is the banner, pop-up or short paragraph that appears where you collect information, summarising the key points of the policy and linking to the full document.
So the practical differences are length, and where each one appears. The policy is the reference document that lives in the footer of every page; the notice is the brief prompt that appears at the moment someone is about to hand over their details.
The important nuance is that the law's actual notice requirement is the collection notice under APP 5 of Schedule 1 to the Privacy Act 1988 (Cth). When you collect personal information, APP 5 requires you to notify the individual of certain matters at or before the time of collection. The pop-up "privacy notice" that most websites use is really a way of satisfying that requirement online, not just a convenience for the reader.
What your privacy policy must contain
If your business is an APP entity, APP 1.3 of Schedule 1 to the Privacy Act 1988 (Cth) requires you to have a clearly expressed and up-to-date privacy policy. APP 1.4 then sets out what it must cover:
- Kinds of information: the types of personal information you collect and hold.
- How you collect it: how you collect and hold personal information, including through website forms, cookies and third parties.
- Purposes: the purposes for which you collect, hold, use and disclose personal information.
- Access and correction: how an individual can access their information and seek its correction.
- Complaints: how someone can complain about a breach of the Australian Privacy Principles or an APP code, and how you will deal with the complaint.
- Overseas recipients: whether you are likely to disclose personal information to overseas recipients and, if it is practicable to say, the countries they are likely to be in.
APP 1.5 adds that the policy must be available free of charge and in an appropriate form, in practice a link on your website. If you collect sensitive information, such as health information, be aware that it is a higher-protection category: APP 3.3 says you must not collect it without consent, and the collection must be reasonably necessary for your functions or activities.
What your collection notice should tell people
The notice at the point of collection is governed by APP 5. APP 5.1 requires you to take reasonable steps to notify individuals of certain matters at or before the time you collect their personal information, or as soon as practicable afterwards if that is not practicable. The matters in APP 5.2 include:
- your identity and contact details;
- the purposes for which you are collecting the information;
- the main consequences, if any, of the individual not providing it;
- who you usually disclose that kind of information to;
- whether collection is required or authorised by law;
- if you collected the information from someone other than the individual, the fact and circumstances of that collection;
- that your privacy policy explains how to access and correct information;
- that your privacy policy explains how to complain about a breach; and
- whether you are likely to disclose the information overseas and, if practicable, which countries.
Not every matter will be relevant to every collection. APP 5 requires the steps that are reasonable in the circumstances, so a short banner on a contact form that covers the purpose, your contact details, who you share with and a link to the policy will usually do the job.
Do you actually have to have a privacy policy?
The requirement in APP 1.3 applies to APP entities: broadly, agencies and the organisations covered by the Privacy Act. Under s 6D of the Act, a business is a small business if its annual turnover for the previous financial year was $3 million or less, and a small business operator is generally exempt from the Australian Privacy Principles.
But s 6D(4) removes that exemption for a business that:
- has had annual turnover above $3 million in a completed financial year;
- provides a health service and holds health information about individuals, other than in employee records;
- discloses personal information about another individual to someone else for a benefit, service or advantage (in other words, trades in personal information);
- provides a benefit, service or advantage to collect personal information about others from someone else;
- is a contracted service provider for a Commonwealth contract; or
- is a credit reporting body.
The definition of health service in s 6FB of the Act is broad: it covers any activity intended or claimed to assess, maintain or improve an individual's health. That means providers such as personal trainers and complementary therapists can be caught if they hold health information, even well below the turnover threshold.
So a small online retailer turning over under $3 million and collecting names, addresses and email addresses for orders is usually not an APP entity and is not legally required to publish a privacy policy. That does not mean it should not have one. Customers and commercial partners increasingly expect one, state and industry obligations can apply, and if your turnover passes $3 million, or you start handling health information, the obligation switches on. Building the documents early is cheaper than rebuilding your data handling later.
Where to put both documents on your website
The privacy policy belongs in the footer of every page, where it is one click away and available free of charge, as APP 1.5 contemplates. Because APP 1.3 requires the policy to be up to date, schedule a review whenever you change what you collect, whether that is a new analytics tool, a CRM or a marketing list, rather than once a year.
The notice belongs at the moment of collection: a short banner above or beside a form, a pop-up before the submit button, or an inline paragraph with a link to the policy. If your site uses cookies that collect personal information, the notice should cover them too, and separate rules can apply to consent for cookies depending on what they do, so it is worth checking the position with your lawyer.
How Artificer Legal can help with your privacy documents
The judgement calls here are exactly where a privacy lawyer adds value. Working out whether your business is an APP entity involves the turnover calculation and the health service and trading exceptions, which are not always obvious. Drafting a policy that meets every element of APP 1.4, and a collection notice that meets APP 5.2, means tailoring the wording to how your website actually collects data: the forms, the cookies, the third parties and any overseas service providers. Artificer Legal can review your existing documents for currency and gaps, draft compliant policy and notice wording, and advise on sensitive information, data breaches and overseas data flows before they become a problem.
The collection notice is where compliance actually bites
Most businesses assume the privacy policy is the compliance document and everything else is decoration. In practice, the obligation that bites at the moment a customer hands over their email address is the collection notice under APP 5, and a footer link alone does not satisfy it. If your website has only a policy and no notice at the point of collection, that is the gap to fix first.
The short version of all of this: the privacy policy is the comprehensive, legally required document that lives in your footer, and the privacy notice is the short, point-of-collection prompt that summarises it and satisfies the APP 5 notification obligation. Small businesses under $3 million turnover are usually exempt, but the threshold, health service and trading exceptions need checking, and both documents should be reviewed whenever your data handling changes.