Create my document
Login

Choose country

AustraliaAustraliaChoose country
Non-Profit

Charity Policy Pack | ACNC & Privacy Act 1988

Complaints, privacy and financial controls policies drafted to the ACNC Governance Standards and Privacy Act 1988. Editable Word and PDF for Australian NFPs.
4.7/517 reviews50 000+ downloadsInstant download
Share

Funders no longer take your word for it. When a grant-maker, philanthropic trust, or government department runs due diligence on your not-for-profit, they ask to see written policies: how you handle complaints, how you protect personal information, and how money moves through the organisation. A grant-ready policy pack answers those three questions in board-approved documents that an auditor or program officer can read in five minutes. This page explains the complaints handling, privacy, and financial controls policies Australian NFPs and ACNC-registered charities are expected to hold, what the ACNC Governance Standards and the Privacy Act 1988 (Cth) actually require, and how to adopt them without paying a firm to draft each one from scratch.

Most committees discover the gap at the worst possible moment: mid-application, with a deadline looming, when the funder's checklist asks for policies nobody has ever written down. These templates close that gap.

Compliant

2026 Legislation

50,000+ clients

trust us

Affordable

From $4.90 / doc

Secure payment

Instant download

Charity Policy Pack | ACNC & Privacy Act 1988

Secure payment

Fill in the template

What is a grant-ready policy pack for an Australian NFP?

A grant-ready policy pack is a bundle of the operational policies that funders, banks, and insurers routinely request before releasing money or cover. It is not a constitution and it does not replace one. Your constitution or rules set out who governs the organisation and how decisions are made at the member and committee level. A policy pack sits underneath that, governing the day-to-day conduct that a grant agreement cares about: what happens when someone complains, who can approve a payment, and how you look after the personal data of members, donors, and clients.

The three policies in this pack are the ones that appear on almost every funder due diligence template. A complaints handling policy shows you take feedback seriously and resolve disputes fairly, which the ACNC treats as a marker of accountability to members. A privacy policy is a legal obligation for many organisations under the Australian Privacy Principles and a trust signal for everyone else. A financial controls policy covers cash handling, payment approvals, and reimbursements, and it is the single document a grant acquittal officer will look for first. Together they demonstrate that your committee has thought about risk before something goes wrong, not after. That distinction is exactly what separates a funded application from a rejected one.

2

When do you need this document?

The most common trigger is a live grant application. A funder sends through a due diligence checklist, and buried in it is a request for your complaints, privacy, and financial policies, board-approved and dated. Committees that have never written these down suddenly have days to produce them. Adopting the pack in advance means you attach the documents rather than scramble, and it signals to the assessor that governance is business as usual for you, not a fire drill.

The second trigger is a close call that exposes a gap. A reimbursement goes to the wrong account, a member complains and nobody knows who should respond, or a spreadsheet of donor details is emailed to the wrong recipient. In practice, most disputes and losses trace back to a process that was never written down, so people improvised. A policy pack turns improvisation into a repeatable procedure your treasurer and secretary can point to.

Onboarding staff or scaling up volunteers is a third. Once you employ people under the Fair Work Act 2009 (Cth) or run a roster of volunteers with access to funds and personal data, informal habits stop being defensible. Our volunteer agreement and handbook template pairs naturally with a privacy and complaints policy so everyone knows the rules before they start. An edge case worth flagging: a bank tightening its know-your-customer checks can demand a financial controls policy before it will keep your account open, independent of any grant. And insurers pricing a directors and officers policy increasingly ask to see complaints and privacy procedures as part of underwriting.

3

Key clauses included in this pack

  • The complaints handling procedure sets out how a complaint is received, acknowledged, investigated, and closed, with realistic timeframes and a clear escalation path to the committee where the first responder cannot resolve it. It records who owns each stage so a complaint does not stall, and it includes a confidential channel for sensitive matters involving vulnerable people, which the ACNC's safeguarding expectations treat as essential.
  • The privacy policy is drafted to APP 1 and describes what personal information you collect, why, how it is stored and secured, when it is disclosed, and how an individual can access or correct their record. It names a contact point for privacy queries and complaints, which the Australian Privacy Principles require, and states your position on overseas disclosure where you use cloud tools hosted offshore.
  • The data breach response plan operationalises the Notifiable Data Breaches scheme, mapping the 30-day assessment window, the harm test, and the notification steps to the OAIC and affected individuals. It assigns a responsible person so the clock does not start running while everyone waits for the board to meet.
  • The financial controls policy covers cash handling at events, the dual-approval threshold for payments, delegation limits, and the reimbursement process for volunteers and staff. It ties spending back to the committee's authority and gives your treasurer a defensible line to hold when someone asks for an out-of-process payment.
  • The conflict of interest handling built into the approval workflow requires declarations and proper abstentions to be recorded, which the ACNC looks for when it reviews how a charity manages related-party transactions.
4

Regional considerations

Because incorporated associations are regulated at state and territory level, the financial controls and complaints elements should sit comfortably alongside your specific Associations Incorporation Act rather than contradict it. In New South Wales, associations operate under the Associations Incorporation Act 2009 (NSW), administered by NSW Fair Trading, which sets financial reporting tiers by revenue and expects committee members to manage funds responsibly. A financial controls policy that reflects your tier's audit or review obligations reads as deliberate rather than boilerplate.

In Victoria, the Associations Incorporation Reform Act 2012 (Vic) is administered by Consumer Affairs Victoria and includes model rules that many associations adopt; your complaints and grievance procedure should dovetail with the dispute resolution mechanism in those rules rather than duplicate or override it.

In Queensland, the Associations Incorporation Act 1981 (Qld), overseen by the Office of Fair Trading, sets its own reporting levels and grievance procedure requirements, and the model rules there also address internal dispute handling. If your constitution already contains a dispute clause, your standalone complaints policy must complement it, not conflict with it, or you risk a member arguing the wrong process was followed.

Charities registered with the ACNC face the same Commonwealth Governance Standards regardless of which state they incorporated in, so the privacy and financial elements travel unchanged across borders. What shifts state to state is the incorporating law layer beneath them. If your not-for-profit is a company limited by guarantee, the state Associations Acts fall away entirely and the Corporations Act 2001 (Cth) governs, which changes the reporting and audit context your financial controls policy should reference. Our incorporated association constitution aligned to the state Acts is the document to check your policy pack against before you adopt it.

5

How to complete this policy pack

You begin by telling the form what structure you are: an incorporated association, a company limited by guarantee, or an unincorporated group planning to formalise. From there the pack adjusts the financial reporting language and the statutory references so an incorporated association in Queensland does not end up citing the Corporations Act. You then indicate whether you are ACNC-registered, which switches on the Governance Standards framing and the safeguarding language in the complaints procedure.

Next you set your financial control thresholds. You choose the dollar figure above which a second signatory is required, name the roles that hold delegated authority, and confirm how reimbursements are claimed and approved. The privacy section asks what categories of personal information you actually collect and whether you use any overseas-hosted software, so the APP-facing clauses match your real practice rather than a generic template. The last step is the part committees skip and regret: you take the pack to a properly convened meeting, record the resolution adopting each policy, and date it. A funder wants to see not just the policy but the minute approving it. Our AGM minutes and resolutions pack gives you the resolution wording to do that cleanly, and the full Australian non-profit and charity document library rounds out anything the pack does not cover.

6

Common mistakes to avoid

The mistake that costs the most is adopting a policy that describes an organisation you are not. A privacy policy promising encryption and access logs you do not have is worse than none, because the OAIC actively checks whether a policy reflects actual practice, and a funder who catches the mismatch stops trusting the rest of your application. Write the policy to what you genuinely do, then improve the practice. The second recurring error is treating the pack as a filing exercise. Policies that are never approved at a meeting, never dated, and never communicated to volunteers carry no weight when a grant officer asks for evidence they are in force. The document and the minute adopting it are a pair; one without the other proves little.

A third mistake is letting the complaints policy and the constitution's dispute clause drift apart. When they prescribe different steps, a disgruntled member will argue you followed the wrong one, and the ambiguity alone can sink a resolution or a registration. The fourth is underestimating the data breach clock. Committees assume they can wait until the next board meeting to decide whether a breach is serious, but the Notifiable Data Breaches scheme runs a 30-day assessment window from awareness, and stalling for a quorum is not a defence. Assign one responsible person now. Finally, avoid the temptation to lift a corporate policy off the internet. A twenty-page enterprise privacy policy confuses a five-volunteer op-shop and signals to a funder that the committee does not understand its own scale.

Key takeaways

Due diligence

Funders want policies, not promises

Grant-makers, banks and insurers commonly ask for three written, board-approved documents: complaints handling, privacy, and financial controls. This pack is designed to be read quickly by an auditor or program officer and shows how your organisation deals with disputes, protects personal information, and controls payments and reimbursements. It does not replace your constitution; it sits underneath it and governs day-to-day conduct.

ACNC standards

Policies evidence Governance Standards compliance

If you are ACNC-registered, the ACNC Governance Standards shape what “good” looks like on paper. Governance Standard 2 is about being accountable to members, and a clear complaints process is one practical way the ACNC expects you to show that accountability. Governance Standard 5 places duties of care, diligence and good faith on Responsible People, and financial controls help demonstrate those duties are being carried out.

Privacy Act

APP duties and breach deadlines apply

Privacy obligations come from the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Many NFPs become APP entities if turnover exceeds A$3 million, and some smaller organisations are still caught where they handle health or sensitive information. APP 1 requires a clear, current, publicly available privacy policy, and APP 11 requires reasonable security. If the Notifiable Data Breaches scheme applies, suspected eligible breaches must be assessed within 30 days and notified as required.

Frequently Asked Questions

They become binding on your organisation when your committee or board formally adopts them by resolution at a properly convened meeting and records that decision in the minutes. Until then they are drafts with no internal force. The privacy policy also carries external legal weight: if the Privacy Act 1988 (Cth) applies to you, a published APP 1 policy creates obligations you can be held to by the OAIC. The financial controls and complaints policies bind your people because the organisation has resolved to operate by them, which is precisely the evidence a funder or auditor is looking for when they ask whether a policy is actually in effect.

Turnover above A$3 million makes you an APP entity automatically, but the threshold is not the whole test. Charities that provide health services, trade in personal information, or handle certain sensitive data are caught under the Privacy Act 1988 (Cth) regardless of size. Even where you fall outside the Act, the ACNC encourages every charity to follow the Australian Privacy Principles as a marker of good governance, and most funders now expect a privacy policy as standard due diligence. Adopting one is the safer position: it costs little, closes a common application gap, and demonstrates the care and diligence your Responsible People owe under Governance Standard 5.

If the Notifiable Data Breaches scheme applies to you, the clock is 30 days from when you become aware of a suspected eligible breach to complete your assessment of whether serious harm is likely. That window sits in Part IIIC of the Privacy Act 1988 (Cth). Once you confirm an eligible breach has occurred, you must notify the OAIC and affected individuals as soon as practicable, which the regulator reads as days rather than weeks. The data breach response plan in this pack maps those steps and assigns a responsible person so the assessment starts immediately rather than waiting for the next committee meeting.

The privacy and complaints elements travel well across states because privacy sits under Commonwealth law and complaints handling is largely about process rather than jurisdiction. The financial controls policy needs a light adjustment because incorporated associations answer to different Acts: the Associations Incorporation Act 2009 (NSW), the Associations Incorporation Reform Act 2012 (Vic), and the Associations Incorporation Act 1981 (Qld) each set their own reporting and grievance requirements. The template lets you select your state so the statutory references and financial reporting language match. If you are a company limited by guarantee, the Corporations Act 2001 (Cth) applies uniformly and state selection falls away.

Every policy in the pack is provided in editable Word format and clean PDF format. The Word version is the working document you customise: you set your financial thresholds, name your responsible people, tailor the complaints escalation path, and adjust the privacy clauses to the information you actually collect. The PDF is the tidy version you attach to a grant application or hand to your bank. Because the files are fully editable, you can revise a policy as your organisation grows without retyping it from scratch, which matters because these documents should be reviewed and re-approved periodically rather than adopted once and forgotten.

They are drafted to the three areas that appear most often on funder checklists: complaints handling, privacy, and financial controls including cash handling, approvals, and reimbursements. What turns a good policy into a passing one is the evidence around it. Grant officers want the policy, the dated resolution adopting it, and some sign that it is lived rather than shelved. Attach the board-approved version, keep your minutes in order, and reference the policy in your reimbursement and complaint records. A complete charity governance pack covering the broader Governance Standards strengthens the picture further where a funder asks for more than these three policies.

A yearly review is the practical baseline, ideally timed to your annual general meeting so you can re-approve them with a fresh resolution in the same sitting. Beyond the annual cycle, review a policy whenever the thing it governs changes: new privacy legislation, a shift in how you handle money, a merger, first employees, or a breach or complaint that exposed a weakness. Regulators and funders both read a policy that names a review date and shows evidence of updates as a sign of an active committee, whereas a document that has not been touched since it was downloaded years ago signals the opposite.

4.7/5

17 verified reviews · 50 000+ downloads

Charity Policy Pack | ACNC & Privacy Act 1988
  • Immediate access to the document
  • PDF + Word download
  • Compliant with 2026 legislation
  • Reviewed by lawyers
Fill in the template
Secure payment
Updated on July 22, 2026

You might also like

Volunteer Agreement Template
Conflict of Interest Pack Australia