Compliance
Does your website need a privacy policy?
Most Australian small businesses assume the answer is yes and then use a generic template that describes obligations they don't have and misses the ones they do. The actual position is more specific than that, and it is changing — the small business exemption has been under sustained review, and building on it is a short-term plan.
Rather just ask someone? Talk to usIn short
The Privacy Act 1988 generally applies to businesses with annual turnover above $3 million, plus specific categories regardless of turnover — health service providers, businesses that trade in personal information, and government contractors among them. If it applies, Australian Privacy Principle 1 requires a clear, current, freely available privacy policy.
This is a plain-English summary written by developers, not legal advice. It is general information and does not account for your circumstances. For anything that turns on your specific obligations, talk to a lawyer.
- The small business exemption, and why not to rely on it
- Businesses with an annual turnover of $3 million or less are generally exempt from the Privacy Act, which is unusual internationally and has been criticised for years. Important carve-outs mean many small businesses are covered anyway: health service providers of any size, anyone who buys or sells personal information, contractors delivering Australian Government contracts, credit reporting bodies, and businesses related to a larger one. Removing the exemption has been on the reform agenda through successive tranches, so treat it as a concession that may not last rather than a permanent position.
Who it applies to
General position under the Privacy Act 1988. Your circumstances may differ — this is the point at which to ask a lawyer rather than a developer.
- Turnover above $3 million Covered
- The Australian Privacy Principles apply in full, including the requirement for a privacy policy.
- Health service providers Covered at any size
- Including allied health, dental, psychology and similar — turnover is irrelevant.
- Trades in personal information Covered at any size
- If you buy or sell personal information, the exemption does not apply.
- Australian Government contractors Covered at any size
- Where you provide services under a Commonwealth contract.
- Everyone else under $3m Generally exempt
- Exempt from the Act — but not from consumer law, contractual obligations, or overseas rules like the GDPR.
- Selling to the EU or UK Separate obligations
- The GDPR can apply regardless of Australian turnover if you target or monitor people there.
What actually works
Work out whether you're actually covered
Turnover, then the carve-outs, then whether you handle anyone outside Australia. Most businesses have never done this and are guessing in one direction or the other.
A policy has to describe what you actually do
What you collect, why, how you hold it, who you disclose it to, whether anything goes overseas, and how someone can access, correct or complain about their information. A template naming laws that don't apply to you is worse than useless — it's a documented misdescription.
Analytics and pixels are collection
Google Analytics, Meta Pixel, session recording, chat widgets. If your policy doesn't mention them and your site loads them, the policy is inaccurate. Session recording deserves specific attention because it can capture far more than people assume.
Know the notifiable breach rules before you need them
Covered entities must assess a suspected eligible data breach and, where it is likely to cause serious harm, notify affected individuals and the OAIC. Deciding how you'd do that during an incident is the wrong time to work it out.
Collect less
The cheapest compliance measure available. Data you never collected cannot be breached, cannot be requested, and cannot be mis-described. Look at your forms and delete the fields nobody has ever used.
Know where the data physically is
Cross-border disclosure has its own obligations. Most modern stacks put data in Australian regions if you ask at setup and somewhere else if you don't. It's a five-minute decision at the start and a migration later.
Keep it current, and make it easy to find
Linked in the footer of every page, free to read, no login. Review it when you add a tool, change a form or start handling something new — a policy describing a site you had three years ago is a liability.
What a policy should cover
The substance an Australian privacy policy generally needs. Have a lawyer review it if your circumstances are at all unusual.
- What kinds of personal information you collect, and how
- Why you collect it and what you use it for
- Who you disclose it to, including named third-party services
- Whether information is disclosed overseas, and to which countries
- How it's held and protected
- How someone can access and correct their information
- How to make a complaint, and how you'll handle it
- Cookies, analytics and tracking, described specifically
- Your contact details for privacy enquiries
- The date it was last reviewed
When this isn't your problem
We build websites; we're not lawyers, and a generated policy from us or anyone else is a starting point rather than compliance. What we can do is tell you accurately what your site collects and where it goes — which is the part most policies get wrong, because the person writing it never asked the developer.
Want us to look at it?
Send us your site and what you're trying to improve. We'll tell you what we'd do first — including when the honest answer is that you don't need us.
Common questions
If annual turnover is $3 million or less you're generally exempt from the Privacy Act — unless you fall into a carve-out such as health services, trading in personal information, or Commonwealth contracting. Many exempt businesses publish one anyway, because customers and partners increasingly expect it.
As a starting point. The failure mode is a template describing collection you don't do and omitting the services you actually run. At minimum, make it match the tools genuinely loading on your site — and take advice if you handle health, financial or children's information.
There's no Australian equivalent of the EU cookie consent rules, so a banner isn't legally required here in the way it is there. If you have EU or UK visitors the GDPR may apply. Either way, your policy should describe what you're loading and why.
If you're covered by the Act, you must assess a suspected eligible breach promptly and, where serious harm is likely, notify affected individuals and the OAIC. Practically: contain it, work out what was accessed, take advice, and don't delete evidence.
Also worth a look
- Does Your Website Need to Be Accessible in Australia?
- Should You Put AI on Your Website?
- Your Website Gets Traffic But No Enquiries
- Weighing up who should build it, and what it should cost?
Last reviewed . Figures are indicative Australian ranges, not quotes.