- Who must comply: the $3 million line and the exceptions
- Duty 1: publish a privacy policy with the content the Act prescribes
- Duty 2: tell people what you are collecting at the point of collection
- Duty 3: make the policy match what you actually do
- Duty 4: report eligible data breaches
- What happens if you get it wrong
- A compliance checklist
- When you need a lawyer
- The exemption assumption that will not survive the decade
If your business collects names, email addresses, phone numbers or any other information that identifies a person, your privacy policy is more than a page for the footer. Under the Privacy Act 1988 (Cth) (the Privacy Act), the policy is a legal document whose content the Act itself prescribes. For businesses the Act covers, having a compliant policy is not a nice-to-have. It is a duty, and it sits alongside duties about what you tell people when you collect their information and what you do when that information is lost or stolen.
The policy also happens to be one of the few pages on your site that customers actually read before they hand over their details. A clear, current policy that matches what you really do builds the trust that turns visitors into customers. One that is vague, copied or out of date invites complaints, regulator attention and reputational damage. This guide sets out who has to comply, the duties that apply, what happens if you get them wrong, and a checklist you can work through.
Who must comply: the $3 million line and the exceptions
The Privacy Act binds "APP entities", which for practical purposes means organisations and government agencies. Most private businesses are organisations, but there is a carve-out that matters to small operators. Under s 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover for the previous financial year was $3,000,000 or less, and a small business operator is generally exempt from the Act. Turnover is calculated broadly: s 6DA counts proceeds of sales, commission, rent and interest, among other income, and the OAIC's small business guidance confirms it includes income from all sources, not capital gains or asset sales.
That exemption is narrower than it sounds, because the Act already catches small businesses in a list of situations regardless of turnover. Under the OAIC's checklist, a small business must comply if it:
- Provides health services: including private hospitals, medical and allied health practitioners, pharmacists, child care centres and private schools.
- Trades in personal information: for example, selling or swapping a customer list without the individual's consent and without being required or authorised by law.
- Works under Commonwealth contracts: providing services to Australian Government agencies under a contract or subcontract.
- Operates a residential tenancy database: or runs a credit reporting business.
- Is an AML/CTF reporting entity: a category that expanded significantly on 1 July 2026 (see below).
- Is connected to a covered business: a related body corporate of a business the Privacy Act covers.
- Has opted in: small businesses can choose to be treated as organisations under s 6EA of the Privacy Act 1988 (Cth).
The change that caught many small businesses off guard arrived on 1 July 2026. Under the AML/CTF reforms, designated services provided by legal professionals, accountants, conveyancers, real estate professionals and dealers in precious stones and metals came under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), as AUSTRAC explains. Those businesses became reporting entities, and s 6E(1A) of the Privacy Act 1988 (Cth) treats a small business operator that is a reporting entity as an organisation for its AML-related activities. The OAIC has published guidance confirming those businesses now need APP compliance, including a privacy policy, even where their turnover is under the $3 million line.
The exemption itself has been under reform pressure for years, and the Government has flagged its removal as part of the ongoing privacy reform program. As at the date of writing it still applies, but it is not something to build a compliance strategy around. If you have assumed "we're too small for the Privacy Act", check the current position before relying on it.
Duty 1: publish a privacy policy with the content the Act prescribes
APP 1 of Schedule 1 to the Privacy Act 1988 (Cth) is the "open and transparent management" principle. Its core requirement is in clause 1.3: an APP entity must have a clearly expressed and up-to-date policy about how it manages personal information, known as the APP privacy policy.
Clause 1.4 lists what the policy must contain. At minimum it must set out:
- What you collect and hold: the kinds of personal information the entity collects and holds.
- How you collect and hold it: the ways information comes in, such as forms, cookies and third-party integrations, and where it is stored.
- Why you collect it: the purposes of collection, use and disclosure, including analytics, marketing and billing.
- Access and correction: how an individual can get access to their information and ask for corrections.
- Complaints: how an individual can complain about a privacy matter and how the entity will handle it.
- Overseas disclosure: whether the entity is likely to disclose personal information to recipients outside Australia and, if so, the countries concerned.
"Clearly expressed" is a legal standard, not a style preference. A policy written in dense legalese, or one that is years out of date, fails the standard the Act sets. Keep the language plain, structure it with headings, link it from your footer and from every form that collects information, and update it whenever your data practices change. Note also that the policy is a different document from the collection notice required at the point of capture, which is the next duty.
Duty 2: tell people what you are collecting at the point of collection
A privacy policy alone does not discharge your obligations at the moment you collect information. APP 5 of the Privacy Act 1988 (Cth) requires that at or before the time you collect personal information, or as soon as practicable afterwards, you take reasonable steps to notify the individual of the matters in clause 5.2. Those include:
- Who you are: the entity's identity and contact details.
- That collection is happening: including the fact of collection and its circumstances where you collect from someone other than the individual.
- Legal requirements: where collection is required or authorised by an Australian law or court order.
- Purposes: why the information is being collected.
- Consequences: the main consequences, if any, of not providing the information.
- Access, correction and complaints: how the individual can access and correct their information and complain.
- Overseas disclosure: whether the information is likely to be disclosed overseas and the countries involved.
This is why good forms carry a short collection notice or a link to one, rather than a bare "by submitting this form you agree to our privacy policy" line. The notice and the policy must also say the same things. If your policy promises one thing about how emails are used and your sign-up form implies another, you have a mismatch problem under both APP 5 and the broader accuracy duty below.
Duty 3: make the policy match what you actually do
The policy is a promise about your conduct, and the Act holds you to it. The substance the policy must accurately describe includes:
- APP 3, collection: only collect personal information that is reasonably necessary for your functions or activities, and do not collect sensitive information without consent.
- APP 6, use and disclosure: use or disclose information only for the purpose it was collected, unless the individual consents or an exception applies.
- APP 8, overseas disclosure: before disclosing information to a recipient outside Australia, take reasonable steps to ensure the recipient handles it in line with the APPs.
- APP 11, security: take reasonable steps to protect the information you hold from misuse, interference, loss and unauthorised access, and generally to destroy or de-identify information no longer needed.
A policy that promises "we never share your data" while your CRM sends data to an overseas processor, or that says "we only collect what we need" while your analytics tags capture everything, is a document that describes a business you are not running. That gap has legal teeth beyond the Privacy Act. A privacy policy is a statement made in trade or commerce, so s 18 of the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) applies: engaging in conduct that is misleading or deceptive, or likely to mislead or deceive, is prohibited. If your policy promises one practice and you follow another, customers and competitors can point to the gap, and the mismatch can be characterised as misleading conduct as well as an APP breach.
The practical answer is to map your data flows. List what you collect, where it comes from, which systems store it, where it is sent and who can access it, then draft the policy from that map. Revisit the map whenever you add a tool, change a processor or start a new marketing channel, because that is when policies silently become inaccurate.
Duty 4: report eligible data breaches
Part IIIC of the Privacy Act 1988 (Cth) creates the notifiable data breach scheme. An eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an entity, and the access, disclosure or loss is likely to result in serious harm to any affected individual (see the guide in s 26WA). The key steps:
- Suspected breach: if you have reasonable grounds to suspect an eligible data breach, s 26WH requires you to carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days.
- Believed breach: once you have reasonable grounds to believe an eligible data breach has happened, s 26WK requires you to prepare a statement describing the breach, the kinds of information involved and the steps individuals should take, and give it to the OAIC as soon as practicable.
- Notification: s 26WL requires you to notify the affected individuals, or if that is not practicable, publish the statement on your website.
- Remedial action: s 26WF provides an exception where you take action before the access or disclosure results in serious harm, such that a reasonable person would conclude there is no longer a likely risk of serious harm.
The 30-day assessment clock is the part businesses usually miss. A breach sits in a helpdesk ticket for weeks while the assessment window runs, and the "as soon as practicable" obligation to notify the OAIC is measured from when you become aware, not from when you finish tidying up. A documented breach response plan, agreed in advance, is what lets you run the assessment inside the window instead of discovering it after.
What happens if you get it wrong
The enforcement picture has teeth. An individual can complain to the OAIC, which can investigate, conciliate and, if necessary, make determinations about your handling of personal information. Those determinations can require you to do things, including compensating the individual, and the OAIC can also start its own investigations without waiting for a complaint.
Civil penalties are the sharper end. Under s 13G of the Privacy Act 1988 (Cth), a serious interference with privacy is a civil penalty provision: for an individual the maximum penalty is $2,500,000, and for a body corporate it is the greatest of $50,000,000, three times the value of any benefit obtained from the conduct, or 30% of the body's adjusted turnover during the breach turnover period. Less serious interferences attract up to 2,000 penalty units under s 13H. Add to that the exposure under s 18 of the Australian Consumer Law for a policy that promises one thing and delivers another, and the cost of a mismatched policy can be measured in regulator action and court proceedings, not just unhappy customers.
There is also the quieter cost. Privacy complaints surface as negative reviews, and customers who do not trust how you handle data do not convert. A business that treats its privacy policy as a compliance afterthought tends to discover the cost in lost sales, and in search visibility, over time.
A compliance checklist
Work through this and you will cover the core duties:
- Scope check: confirm whether the Privacy Act covers you, including the health services, trading-in-information and AML/CTF reporting entity exceptions.
- Data flow map: document what you collect, why, where it is stored and who it is shared with, including overseas processors.
- Policy content: check your privacy policy against the APP 1.4 list and update it so it is clearly expressed, current and accurate.
- Collection notices: make sure every form and capture point notifies individuals of the APP 5 matters, consistently with the policy.
- Consent and tracking: align your cookie banner and analytics setup with what the policy says, and only run optional tracking after opt-in where required.
- Breach plan: document who assesses a suspected breach, how the 30-day assessment runs, and who prepares the statement to the OAIC.
- Review cycle: schedule a review whenever you change tools, processors or marketing practices, and update the "last updated" date.
A further change is already on the books: from 10 December 2026, the Privacy and Other Legislation Amendment Act 2024 (Cth) adds new privacy policy content requirements around automated decision-making, so if your business uses software that makes decisions about people, the policy will need to say more. Confirm the current position before that date.
When you need a lawyer
A privacy lawyer's role starts before any document is drafted. A practitioner can confirm whether the Act covers your business, including the exceptions and the new AML/CTF reporting entity position, and can work out what applies to your particular data flows. They can then draft a privacy policy and collection notices that meet the APP 1 and APP 5 content requirements in plain English, check the policy against your actual systems, and set up a breach response plan that fits the 30-day assessment framework. If a breach or complaint has already landed, a lawyer can run the eligible data breach assessment, prepare the statement to the OAIC, and manage the regulator relationship.
The judgement calls are where assistance pays for itself: whether information is personal information, whether a suspected breach meets the serious harm threshold, whether an overseas disclosure arrangement is defensible, and whether your policy language will hold up if a customer, the OAIC or the ACCC scrutinises it.
The exemption assumption that will not survive the decade
The single most expensive mistake in Australian privacy compliance is the assumption that the Act does not apply to you. It drives everything else: no policy, no collection notices, no breach plan, no one responsible when something goes wrong. The $3 million exemption was always narrower than it sounded, and from 1 July 2026 it stopped protecting thousands of small businesses in the legal, accounting, conveyancing, real estate and precious metals sectors that became AML/CTF reporting entities. If your business was newly caught on that date, your privacy policy and collection notices should already exist, and your breach plan should be ready. If they do not, the duty that matters most for you this month is the scope check: establish whether you are covered, then treat every other duty in this guide as applying to you.
The position in summary: the Privacy Act imposes a policy duty (APP 1), a notification duty at collection (APP 5), an accuracy duty that ties the policy to your real practices (the APPs and s 18 of the Australian Consumer Law), and a breach reporting duty (Part IIIC). Each has prescribed content, each has a timeframe, and each is enforced through complaints, determinations and civil penalties that now reach into nine figures. A privacy policy built on a data flow map, written in plain English and reviewed on a schedule is the document that satisfies all of them at once.