Create my document
Login

Choose country

AustraliaAustraliaChoose country
Business

Privacy Policy Australia | Privacy Act 1988 & APP 1

APP privacy policy drafted to s.APP 1.4 of the Privacy Act 1988 (Cth). Covers overseas disclosure, access, correction and complaints. OAIC-aligned. Word & PDF.
4.5/512 reviews50 000+ downloadsInstant download
Share

A privacy policy is the document that tells the people you deal with what personal information you collect, why you collect it, and what happens to it once it is in your systems. In Australia this is not a courtesy notice. Under the Privacy Act 1988 (Cth) and Australian Privacy Principle 1, any business caught by the Act must have a clearly expressed, up to date APP privacy policy, and the content it has to contain is set by statute rather than left to your discretion. This template gives you a compliant, ready to publish policy drafted to APP 1.4, suitable for a website, an app, or any operation that collects data from Australian customers, users, or staff.

Most founders reach for a privacy policy when a payment provider, an app store, or a corporate client asks to see one before they will proceed. That is the wrong moment to discover yours is missing or that a copied US template does not match Australian law. A policy built for the General Data Protection Regulation or a California statute will use the wrong terminology, cite the wrong regulator, and skip the exact items the OAIC expects to see.

Compliant

2026 Legislation

50,000+ clients

trust us

Affordable

From $4.90 / doc

Secure payment

Instant download

Privacy Policy Australia | Privacy Act 1988 & APP 1

Secure payment

Fill in the template

What is a privacy policy under Australian law?

A privacy policy is the public facing statement required by APP 1.3, the first of the thirteen Australian Privacy Principles set out in Schedule 1 of the Privacy Act 1988 (Cth). Its job is to explain, in plain language, how your organisation handles personal information across the whole information lifecycle, from the moment you collect it through to storage, use, disclosure, and eventual destruction. The Office of the Australian Information Commissioner treats it as the anchor of what it calls open and transparent management of personal information, and it is meant to be understandable by an ordinary reader, not written in the register of a court pleading.

It is worth separating the privacy policy from two documents people confuse it with. It is not a collection notice, which is the shorter, situation specific notice you give someone at the point you actually collect their data under APP 5. And it is not your terms of service, which govern the commercial relationship rather than data handling. A well run business will have all three, and they should reference each other without repeating each other. A privacy policy that simply restates your terms and conditions does not satisfy APP 1, because it fails to describe the specific information flows the principle asks for. The template here is drafted as a standalone APP privacy policy, with the terms of service and collection notice left to their own documents where they belong. If you are still setting up the surrounding paperwork, our Australian business legal documents library covers the contracts that sit alongside it.

2

When do you need this document?

The most common trigger is a gatekeeper demanding one. Payment processors, the Apple and Google app stores, ad networks, and most enterprise procurement teams will not onboard you without a published privacy policy, and they often want a live URL rather than a draft. If you are launching a website or an app that collects so much as an email address, you are collecting personal information and the requirement is already live. Waiting until a client's legal team flags it during due diligence turns a routine document into a deal delay.

A second scenario is any business scaling past the A$3 million turnover threshold, at which point the Privacy Act 1988 (Cth) applies to you whether or not you have thought about it. Growth tends to be gradual, so the crossing point is easy to miss, and the safe move is to have a compliant policy in place before you get there rather than after. Businesses that handle sensitive information, meaning health records, biometric data, racial or ethnic origin, or political and religious affiliation, face a lower bar again, since some are caught regardless of size.

There are edge cases worth flagging. If you run any tool that makes automated decisions about people, you should be aware that from 10 December 2026 the Privacy Act will require your policy to disclose the kinds of personal information used in those computer programs and the kinds of decisions they make. Building that language in now saves a rewrite later. Employers should also note that recruitment and staff data handling is an area of active reform, so a policy that addresses how you treat applicant and employee information reads better to a regulator than one that stays silent. If you are hiring, pairing this with a compliant Australian employment contract keeps your data and your engagement paperwork consistent.

3

Key clauses included in our template

  • The kinds of personal information collected clause describes in general terms what you gather, distinguishing ordinary personal information like contact details and account data from sensitive information such as health or biometric data, which the Privacy Act 1988 (Cth) treats to a higher standard. Listing these categories plainly is the first thing the OAIC looks for under APP 1.4(a).
  • The collection and holding methods clause explains how information reaches you, whether directly from the individual, through cookies and analytics, or from third party referrals, and how you then store and secure it. The drafting deliberately avoids revealing security detail that would undermine the protection itself, in line with the OAIC's own caution.
  • The purposes clause sets out why you collect, use, and disclose information, which is the heart of APP 1.4(c). It covers your core service, plus the range of recipients such as payment providers and hosting partners, without publishing routine internal housekeeping like billing and auditing that the guidance says you need not detail.
  • The access and correction clause tells individuals they have a right under APPs 12 and 13 to see and fix their information, and gives a durable contact point such as a privacy@ email that survives staff changes. This is a hard requirement under APP 1.4(d), not an optional courtesy.
  • The complaints clause explains how someone raises a privacy concern with you, the roughly 30 day window you have to respond, and the escalation path to the OAIC if they remain unsatisfied. It satisfies APP 1.4(e) and signals that you take breaches seriously.
  • The overseas disclosure clause states whether personal information is likely to go to recipients outside Australia and names the likely countries, which matters because so much cloud infrastructure sits offshore. Under APP 1.4(f) and (g) this is one of the most frequently missed items, particularly by businesses using US based hosting.
4

State and territory considerations

Privacy in Australia runs on two tracks, and the split confuses people who expect a single national scheme. The Privacy Act 1988 (Cth) is Commonwealth law and applies to private sector businesses across every state and territory uniformly, so a compliant APP privacy policy works nationwide for a commercial operator. The complication arises with public sector and health information, where states run their own regimes on top of the federal Act.

New South Wales governs its public agencies through the Privacy and Personal Information Protection Act 1998 (NSW) and health data through the Health Records and Information Privacy Act 2002 (NSW). A private business selling to NSW government or handling NSW health records may find these state statutes reaching into its contracts, so a policy that references them where relevant is stronger than one that assumes the Commonwealth Act is the whole story.

Victoria operates the Privacy and Data Protection Act 2014 (Vic) for its public sector and the Health Records Act 2001 (Vic) for health information. Victorian contractors delivering services to state departments are routinely bound to comply with these instruments through their service agreements, which means the obligation can attach even to a small private supplier.

Queensland applies the Information Privacy Act 2009 (Qld), which sets its own privacy principles for state agencies and, by extension, for the private contractors they engage. Businesses tendering for Queensland government work should expect the tender documents to require alignment with that Act.

For most private businesses operating purely in the commercial market, the federal APPs remain the controlling framework and the template is drafted to them. The state overlays matter chiefly when you deal with a government body or handle health records, and in those cases the safer course is to check the specific instrument that applies to that dealing.

5

How to fill out this privacy policy

You start by identifying the entity that will own the policy, meaning the legal name and ACN or ABN of the business that collects the data, because the policy speaks in that entity's voice. From there you work through the categories of personal information you actually handle, and the guiding principle is honesty over completeness: describe what you really collect rather than pasting in a generic list that mentions data you never touch. If you gather sensitive information, you flag it separately, since the Privacy Act 1988 (Cth) holds it to a higher standard.

Next you set out your collection methods and your purposes, then your access, correction, and complaints process, giving a stable contact point that will not break when staff move on. The overseas disclosure section is where you name your cloud and analytics providers and the countries they sit in, which for most Australian businesses means at least the United States. You then decide where the policy lives, and the OAIC expects it published free of charge, prominently linked, and easy to find, usually a footer link on every page. Once it is live, treat it as a document you revisit, not one you file and forget. If you are assembling a wider compliance set, our general business documents catalogue helps you see what else your setup calls for.

6

Common mistakes to avoid

The single most common error is using an overseas template. A privacy policy written for the GDPR talks about data controllers, lawful bases, and supervisory authorities, none of which are the language of Australian law, and it will name the wrong regulator while omitting the specific APP 1.4 items the OAIC requires. It looks compliant to an untrained eye and fails the moment anyone knowledgeable reads it. The related mistake is treating the policy as boilerplate that nobody checks, then describing practices you do not follow, which is worse than saying nothing because it creates a documented gap between your words and your conduct.

The second cluster of errors is about the mandatory content. Businesses routinely skip the overseas disclosure disclosure even though almost every modern operation uses offshore cloud hosting, and they forget to give a durable complaints and access contact, listing a named employee who has since left. Another frequent failure is never updating the policy, so it describes a product and a data flow that stopped existing two years ago. An out of date policy is not a compliant policy under APP 1.3, which requires it to be current. Finally, many businesses under the A$3 million threshold assume they are exempt and skip the exercise entirely, forgetting that the statutory tort introduced in 2025 can reach them anyway, and that a payment provider or app store will demand a policy regardless of what the Privacy Act technically requires of them. Getting the core business contracts and your privacy policy sorted together avoids the scramble when a counterparty asks.

Key takeaways

LEGAL DUTY

An APP privacy policy is mandatory

If your business is caught by the Privacy Act 1988 (Cth), having a clearly expressed, up to date APP privacy policy is not optional. The requirement sits in Australian Privacy Principle (APP) 1.3, and the policy needs to be written for ordinary readers, not as legal boilerplate. A copied US or EU template can miss what the OAIC expects and leave you non-compliant.

REQUIRED CONTENT

APP 1.4 sets the minimum inclusions

APP 1.4 lists the items your policy must cover, so you cannot just describe things in broad marketing terms. It needs to explain what personal information you collect and hold, how you collect and hold it, and the purposes for collection, use and disclosure. It must also cover access and correction, your complaints process, and any likely overseas disclosures, including the countries involved.

PRACTICAL SETUP

Do not confuse policy, notice and terms

A privacy policy is not a collection notice and it is not your terms of service. The policy is the public statement about your full information lifecycle under APP 1, while a collection notice under APP 5 is given at the point you collect data. If your “privacy policy” just restates your terms and conditions, it will not describe the information flows APP 1 requires, and it can fail compliance checks from app stores, payment providers or corporate clients.

Frequently Asked Questions

The template is drafted to Australian Privacy Principle 1 and covers each of the seven mandatory content items listed in APP 1.4, so a business that completes it honestly will have a policy that meets the transparency obligations of the Privacy Act 1988 (Cth). A privacy policy is a public statement of your practices rather than a contract between two parties, so "binding" works differently here: what binds you is the Privacy Act itself, and the policy is how you demonstrate compliance with it. The document holds up to regulatory scrutiny only if the practices it describes match what you actually do, which is why you should complete it against your real data handling rather than aspirationally.

Strictly under the Privacy Act 1988 (Cth), businesses below the A$3 million annual turnover threshold are generally not APP entities, with exceptions for health service providers and businesses trading in personal information. In practice you almost certainly still need one. The statutory tort for serious invasions of privacy, which commenced on 10 June 2025, can be used against small businesses that are not APP entities at all. Beyond that, payment processors, app stores, and corporate clients routinely refuse to work with any business that lacks a published policy, so the commercial requirement bites well before the legal one does.

You receive the document in both Microsoft Word and PDF. The Word version is the working file you edit to insert your business details, your data categories, your overseas providers, and your contact points, since every clause has placeholders drafted to APP 1.4. The PDF is the clean, ready to publish version. Most businesses publish the finished policy as a web page linked from the site footer, which is what the OAIC expects under APP 1.5, and keep the PDF as the signed off record of what was published and when.

APP 1.3 requires the policy to be up to date, so there is no fixed interval but a clear standard: it must reflect your current practices at all times. The OAIC suggests reviewing it at least annually as part of your planning cycle, and additionally whenever something material changes, such as a new analytics tool, a new overseas provider, or a new category of data collected. Noting the last updated date on the policy is good practice. Businesses that make automated decisions should note that new disclosure obligations under APP 1.7 commence on 10 December 2026 and will require a review before then.

Yes, and this is one of the most frequently missed requirements. Under APP 1.4(f) and (g), your policy must state whether you are likely to disclose personal information to overseas recipients and, where practicable, name the countries where those recipients are likely to be located. Because most Australian businesses use cloud hosting, payment gateways, or analytics tools based in the United States or Europe, the answer is usually yes. The template includes a dedicated clause for this, and completing it accurately is one of the clearest signals to a regulator that the policy was drafted for Australian conditions rather than copied from abroad.

They serve different moments. A privacy policy is the standing, comprehensive statement required by APP 1.3 that describes how you handle personal information across your whole operation, and it lives publicly on your website. A collection notice, required under APP 5, is the shorter, targeted notice you give an individual at the actual point you collect their information, telling them why you are collecting it right then and what you will do with it. You need both, and they should complement rather than duplicate each other. This template is the privacy policy; the collection notice is a separate, situation specific document.

Yes. The Privacy and Other Legislation Amendment Act 2024 (Cth) gave the OAIC a tiered enforcement regime that includes infringement notices and compliance notices aimed squarely at administrative failures, and failing to have a policy containing the statutorily prescribed APP 1.4 information is exactly the kind of breach that category targets. The OAIC has signalled increased enforcement, and it has run compliance sweeps checking privacy policies in higher risk sectors. For a business caught by the Act, an absent or non-compliant policy is a standalone risk, separate from any actual data breach.

4.5/5

12 verified reviews · 50 000+ downloads

Privacy Policy Australia | Privacy Act 1988 & APP 1
  • Immediate access to the document
  • PDF + Word download
  • Compliant with 2026 legislation
  • Reviewed by lawyers
Fill in the template
Secure payment
Updated on July 21, 2026

You might also like

Service Agreement Template Australia
Partnership Agreement AU