Somewhere right now, a business owner is pasting a template privacy policy into their footer five minutes before launch and calling the legal pages done. This guide is the alternative: what Australian law actually asks of your website, which businesses the Privacy Act covers, what your terms can and cannot say and how to end up with pages that describe the business you really run. No scaremongering, no template worship, just the workflow.
The straight answer: the legal pages you need depend on what your website does
There is no single set of documents Australian law stamps onto every website. There are four different things people lump together as legal pages and they do different jobs.
1. Privacy policy. Explains how your organisation manages personal information overall. For businesses covered by the Privacy Act, known as APP entities, this is a legal requirement under Australian Privacy Principle 1 and it must be clearly expressed and kept up to date. It is a standing description of your information handling, not a contract and not a consent form.
2. Privacy collection notice. Tells people the relevant details at the moment their information is being collected, at a form, a checkout, a booking widget. APP 5 requires covered entities to take reasonable steps to notify people of specified matters at or before collection or as soon as practicable afterwards. It is not the same document as the privacy policy and later in this guide we cover why that distinction matters so much.
3. Terms and conditions. The contractual side. Terms set rules, responsibilities and commercial arrangements around your products, services or the use of the site itself. Business.gov.au describes terms and conditions as setting out the rights and obligations of the business and its customers, potentially covering payment, warranties, shipping, returns, privacy and dispute handling and recommends legal advice on what to include.
4. Everything else. Depending on what the site does: a returns policy, shipping policy, cancellation policy, booking conditions, subscription terms, a disclaimer, an acceptable use policy or a cookie and tracking notice. None of these are automatic. Each one earns its place by matching something the website actually does.
Document | Purpose | When relevant | Key point |
|---|---|---|---|
Privacy policy | Explains overall personal information management | Required for APP entities | Must remain current |
Collection notice | Explains a specific collection | APP 5 where applicable | Usually shown near the collection point |
Terms of use | Rules for using the website | Depends on the website | May form contractual terms |
Terms of sale | The sale or service relationship | Commercial websites | Cannot override consumer law |
Disclaimer | Clarifies the scope of information | Certain industries and content | Does not erase legal obligations |
If you want the one page version, here is the decision flow. Everything after this section is the detail behind it.
Question about your website | If the answer is yes |
|---|---|
Does the Privacy Act cover your business? | You need an APP privacy policy that meets APP 1 |
Do you collect personal information at specific points, like forms or checkout? | Review what collection notice belongs at each point |
Do customers buy, book or subscribe through the site? | Review contractual terms for those transactions |
Do you publish professional or informational content people might rely on? | Review whether a disclaimer is appropriate |
Do you run analytics, pixels or remarketing? | Audit the tracking stack and its privacy and consent implications |
Does your Australian business need a privacy policy?
Sometimes legally. Often practically. And not for exactly the same reason in every business, which is why the copied template approach fails: it answers a question nobody asked about your business specifically.
Businesses covered by the Privacy Act
The Privacy Act 1988 generally covers private sector organisations with an annual turnover above $3 million, along with businesses in specific categories regardless of turnover. If your business is covered, you are what the Act calls an APP entity and you generally need to comply with the 13 Australian Privacy Principles. The first of those, APP 1, requires a clearly expressed and up to date privacy policy about how you manage personal information.
Worth knowing before you shrug this off as paperwork: the regulator has moved from publishing guidance to checking. In early 2026 the Office of the Australian Information Commissioner began its first privacy policy compliance sweep, assessing organisations across several sectors against exactly these requirements. A policy that is missing, stale or vague is now the kind of thing that gets noticed, not just the kind of thing lawyers write articles about.
What about businesses under $3 million?
This is where most of the bad internet advice lives, in both directions. One camp says every website legally needs a privacy policy, which is not what the law says. The other camp says small businesses are exempt, full stop, which is not what the law says either.
The OAIC's current position is that most small businesses with an annual turnover of $3 million or less are not covered by the Privacy Act. But the exceptions are wide and they cover a lot of ordinary Australian businesses. Regardless of turnover, coverage extends to businesses that are, among other categories:
private health service providers, which is broader than doctors and includes areas like allied health, gyms with health programs and childcare in some circumstances
businesses that trade in personal information, meaning they buy or sell it for benefit, service or advantage
contracted service providers under Commonwealth contracts
operators of residential tenancy databases
credit reporting bodies
reporting entities and their authorised agents under anti money laundering law, for information handled in connection with those obligations
businesses accredited under the Consumer Data Right
businesses related to a larger organisation that is already covered
businesses that have voluntarily opted in to the Privacy Act
The category list stopped being a niche concern in July 2026. From 1 July 2026, anti money laundering obligations extended to a new group of businesses, including real estate professionals, lawyers, conveyancers, accountants and dealers in precious metals and stones. The OAIC's guidance for these reporting entities is blunt on the privacy consequence: they must comply with the Privacy Act when handling personal information for or in connection with their AML obligations and the small business exemption does not save them for that handling, even under $3 million turnover. A suburban real estate agency that never thought about the Privacy Act in twenty years of trading may now be inside it for part of its work, which is one of the reasons websites for real estate businesses have quietly become some of the most compliance sensitive builds we do.
Credit, lending and adjacent services have carried this weight for longer, between credit reporting rules, AML obligations and the Consumer Data Right. It shapes what finance websites deal with that other sites do not: more sensitive enquiries, more identity information, more third parties touching the data.
What if the Privacy Act does not cover the business?
Then the Act's specific obligations, including the APP 1 privacy policy requirement, do not apply to you. That is a real legal difference and this article will not pretend otherwise. It is also not the end of the question, for three reasons.
First, your website is probably collecting personal information anyway: enquiry details, customer records, account information, analytics data, marketing lists, bookings, orders, uploaded files. A regional electrician with a simple quote form still holds names, phone numbers and addresses of people who expect them handled sensibly, which is exactly the standard we push in what tradie websites need to get right. Second, other obligations can exist independently of the Privacy Act: contracts you have signed, industry rules, state laws, overseas privacy laws if you sell into other markets and the requirements platforms and payment providers impose on the businesses using them. Third, the OAIC itself recommends that small businesses outside the Privacy Act still protect the personal information they hold, because good handling is good business regardless of coverage.
And there is the forward looking reason. The government has flagged further privacy reform and the small business exemption has been squarely in that conversation. Building your website as if customer information matters costs little now and saves a scramble later.
What counts as personal information on a website?
Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable. On a working website, that sweeps in more than most owners expect: names, emails, phone numbers, addresses, account details, order history, enquiry messages, support conversations, uploaded documents, booking details and technical identifiers like IP addresses or device information where they identify or can reasonably identify someone.
Sensitive information is a subset that needs extra care: health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric information and similar categories. For APP entities, collecting sensitive information generally requires the individual's consent along with the other requirements of APP 3, subject to statutory exceptions. The practical trap is that websites collect sensitive information without meaning to. A physio's booking form asking what the appointment is for is collecting health information. So, in some circumstances, is a tracking pixel firing on the page about a specific treatment, which we get to shortly.
Website feature | Information it may collect | What to review |
|---|---|---|
Contact form | Name, email, message contents | Collection notice and storage |
Newsletter signup | Email, marketing preferences | Consent and direct marketing rules |
Ecommerce checkout | Name, address, orders, payment references | Policy coverage and terms |
Booking system | Contact details, appointment context | Collection wording and third parties |
Analytics | Device and activity data | Whether it identifies people and disclosure |
Advertising pixel | Behaviour plus platform identifiers | APP obligations and pixel configuration |
Live chat | Contact details, conversation contents | Provider, storage and retention |
Job application form | CV and employment information | Recruitment privacy handling |
Health related form | Potentially sensitive information | Consent and a much higher standard of care |
Run your eye down that table against your own site. Most businesses find they are collecting through five or six of those features and their privacy policy mentions two.
What must an Australian APP privacy policy include?
APP 1.4 specifies the minimum contents. None of it is exotic, all of it must be true of your business specifically and the whole document must be clearly expressed, which is a legal requirement, not a style preference. Legalese that customers cannot follow fails the brief. The same skills that produce copy that reads like a human wrote it produce a privacy policy people can actually use.
1. What personal information you collect and hold
Name the actual categories your business handles: contact information, account details, purchase history, enquiry information, billing information, recruitment information if you hire through the site. The wording test is specificity.
Wording that does the job | Wording that does not |
|---|---|
We collect your name, contact details, order history and delivery address when you buy from us | We may collect personal information from time to time |
When you submit our quote form we collect your name, email, phone number and project details | We collect information you provide to us |
2. How you collect and hold it
List the real collection points: contact forms, checkout, account registration, phone and email, bookings, newsletter signups, events, job applications, your CRM, tracking technologies and any third parties who collect for you. Then describe, at a sensible altitude, how information is held, such as in Australian hosted systems or reputable cloud platforms with access controls. Describe the approach without publishing a map for attackers. Naming your exact software versions and security architecture in a public document creates risk rather than transparency.
3. Why you collect, hold, use and disclose it
The purposes: responding to enquiries, processing orders, delivering services, providing support, operating accounts, processing bookings, communicating about an engagement, improving services, marketing where permitted and meeting legal obligations. Two principles keep this honest. APP entities may only collect non sensitive personal information that is reasonably necessary for their functions or activities. And the policy explains your purposes, it does not launder them: writing a purpose into the document does not turn unnecessary collection into necessary collection. A privacy policy is a description, not a permission slip.
4. How people can access or correct their information
APPs 12 and 13 deal with access and correction of personal information held by APP entities. Your policy should say where requests go, what you need to verify the requester is who they claim to be and how the request will be handled. Keep the channel real: an inbox somebody actually monitors, not a role address nobody has opened since the site launched.
5. How privacy complaints can be made
APP 1.4 specifically requires the policy to explain how an individual can complain about a breach of the APPs and how your business will deal with that complaint. Include the contact method, the process and what the person can expect in response. Businesses that handle this well treat a privacy complaint like any other service failure: acknowledged quickly, investigated properly, answered plainly.
6. Overseas disclosure
The policy must state whether you are likely to disclose personal information to overseas recipients and, where practicable, the countries involved. This clause went from theoretical to routine the moment businesses started running on overseas cloud software: CRMs, email platforms, marketing tools, support systems, analytics.
Two cautions. Do not mechanically list every country a cloud server might technically route data through; use, storage and disclosure to an overseas recipient can involve different legal analysis and the OAIC's guidance is the reference here, not guesswork. And do not write we never share your information while your enquiry data sits in an American CRM and your email list lives on an overseas marketing platform. That sentence is one subject access request away from embarrassment.
APP 1.4 requirement | The question your policy must answer |
|---|---|
Information collected and held | What personal information do we actually collect? |
Collection and storage | How do we receive it and where does it live? |
Purposes | Why do we need it and what do we do with it? |
Access and correction | How can someone see or fix their information? |
Complaints | How can someone complain and what happens then? |
Overseas disclosure | Do overseas recipients get it? |
Countries | Which countries, where practicable? |
Important 2026 change: automated decisions
These provisions, new APPs 1.7 to 1.9, were added by the Privacy and Other Legislation Amendment Act 2024 and commence on 10 December 2026. This article is written in August 2026, so the obligation is law that has passed but not yet started. If you are reading after that date, it is live.
Depending on the facts, arrangements worth reviewing against the new requirement include:
automated eligibility or application decisions
credit or finance decisions supported by software
certain insurance assessments
automated decisions about customer access, accounts or pricing
significant assessments where AI tools do the substantive work
Two ways to get this wrong. The first is ignoring it because your business feels too small for the word automated. The second is panicking that every AI feature on your website now triggers disclosure. Neither is right: the obligation turns on personal information feeding decisions that significantly affect people's rights or interests and the OAIC is preparing detailed guidance on where those lines sit. If your business runs anything that resembles the list above, this is a diary entry for legal review before December, not a reason to rip out your chatbot.
For everyone else, the practical takeaway is smaller: put a reminder in the calendar to recheck your privacy policy against the final OAIC guidance once this commences. Policies age and this is a dated, known change you can plan for.
A privacy policy is not the same as the notice beside your form
This distinction is worth the price of the whole article, because almost every small business website gets it wrong. The OAIC is explicit that an APP privacy policy is not a substitute for an APP 5 collection notice. They are different instruments doing different jobs.
The privacy policy is the broad document: how your organisation manages personal information generally. The collection notice is point of use information: what someone needs to know at the moment their details are being collected, at the contact form, the account signup, the job application, the quote form, the event registration, the patient intake form. A footer link to a policy nobody reads does not tell the person filling in your form, right now, what happens next with what they are typing.
What an APP 5 notice may need to explain
APP 5 sets the notification matters and generally requires reasonable steps at or before collection or as soon as practicable afterwards. Depending on the circumstances, the notice may need to cover:
who is collecting the information
why it is being collected
the main consequences if it is not provided
who it is usually disclosed to
how to find the privacy policy
how access, correction and complaints work
likely overseas disclosures
Reasonable steps scale with risk. A simple contact form can often do the job with a short, clear sentence near the button. A form collecting health, financial or other higher risk information needs proportionately more.
Example form setup
A form with a working notice | A form without one |
|---|---|
Name, email, tell us what you need help with, plus: We'll use these details to respond to your enquiry. For how we handle personal information, read our privacy policy. | Name, email, message. Submit. |
One honest sentence at the point of collection beats three paragraphs of boilerplate nobody sees. It also converts better, because stating what happens next reduces the hesitation that kills form completions, a pattern we unpack in designing forms that respect people's time and data. Trust wording and completion rates travel together.
Does an Australian website need a cookie banner?
Here is the section that corrects the most confidently wrong advice on the Australian internet. The short answer: Australia does not currently have a blanket rule equivalent to the EU model that requires every website to obtain consent for every non essential cookie before it loads. If you have been told your Australian site is breaking the law simply because it lacks an EU style consent popup, you have been given another country's homework.
The longer answer is that this is absolutely not a free pass on tracking. For businesses covered by the Privacy Act, the APPs can apply where tracking technologies collect, use or disclose personal information and the OAIC has published specific guidance on third party tracking pixels. The thrust of it: the business deploying the pixel is responsible for making sure it is configured and used compliantly, should understand how the product works before installing it, should be transparent about it in the privacy policy and notifications, should minimise what is collected and should review how data flows to the third party platform. The OAIC specifically warns against a set and forget approach, which is a fair description of how most pixels get installed.
When consent becomes particularly important
Sensitive information changes the rules. The OAIC says sensitive information must only be collected through a tracking pixel with the individual's consent and points to express consent given upfront where sensitive information is likely to be collected and disclosed to third party platforms. Sensitive information can be revealed by behaviour, not just by form fields: the pages someone visits on a health, medical, mental health or similar site can themselves say something sensitive about that person.
This stopped being theoretical in June 2026, when the Privacy Commissioner published determinations involving health sector websites whose advertising pixels had collected sensitive information, finding breaches of privacy obligations. The message for any business in health and adjacent fields is direct: do not deploy advertising pixels blindly on pages where a visit itself may reveal something sensitive about the visitor. It is a standing consideration in how we build patient facing websites in the health sector, where the marketing stack gets vetted as carefully as the booking flow.
Cookie and tracking audit
Before configuring any banner or consent tool, work out what you are actually running. Identify every piece of the stack:
essential cookies that make the site function
analytics
advertising pixels
remarketing tags
embedded video players and their tracking
chat widgets
booking technology
CRM and email tracking
heatmaps and session recording tools
social media embeds
For each one, document the provider, what it collects, the purpose, how long data is kept where known, whether personal information is involved, any overseas recipients, whether consent is needed in your circumstances and whether people have a way to opt out. Yes, this is tedious. It is also thirty minutes with your tag manager open and it is the difference between a banner that reflects reality and a decoration.
If paid advertising is part of your stack, the people running your paid campaigns should be able to tell you exactly what the pixel collects, which events fire and what gets shared back to the platform. If they cannot, that is a finding in itself. A quick way to pressure test the whole account, tracking included, is to score your own Google Ads setup in a few minutes and see where the gaps cluster.
Technology | Blanket consent rule under Australian law? | What to review instead |
|---|---|---|
Essential session cookie | No blanket rule | Necessity and security |
Analytics | Not automatically | Whether personal information is involved, disclosure, transparency |
Advertising pixel | Not automatically in every circumstance | APP obligations, configuration, third party data flows |
Pixel that may collect sensitive information | Consent is particularly important | Express consent, necessity, whether it belongs on the page at all |
Tracking of overseas visitors | May engage other countries' laws | Applicable foreign regimes if you target those markets |
Your privacy policy should reflect the tracking technology actually installed
The OAIC's pixel guidance says privacy policies and collection notifications should contain clear and transparent information about third party tracking. Which means the vague sentence at the top of ten thousand Australian privacy policies fails on contact with reality:
Disclosure that matches reality | Disclosure that does not |
|---|---|
We use Google Analytics to understand site usage and advertising pixels that share behavioural information with the platforms we advertise on, for measurement and remarketing | We may use cookies to improve your experience |
Our booking system and live chat are provided by third parties who receive the details you enter | Third parties may collect some information |
Cover what is genuinely running: analytics, advertising platforms, remarketing, customer analytics, integrations. The disclosure should move when the stack moves. And know your own tools well enough to describe them, starting with getting Google Analytics 4 set up properly for a small business, because you cannot honestly disclose a system nobody in the business understands. Measurement is not just an advertising concern either, it feeds decisions across paid activity and the organic side of your marketing, so the stack tends to grow and every addition belongs in the review.
The mental model that keeps disclosure honest is a data map. Trace it once and the policy nearly writes itself:
Visitor → forms and tracking → website and CRM → email, marketing and cloud providers → storage and deletion
Follow one enquiry through your stack. Every stop on that path is something the privacy policy should be able to account for.
Does every Australian website need terms and conditions?
No and anyone selling you a mandatory terms package for a five page brochure site is selling, not advising. A simple informational website with no sales, no accounts and no bookings does not necessarily need a contractual terms document, though even brochure sites sometimes benefit from short terms of use covering content and acceptable use.
Terms become genuinely important, sometimes commercially critical, once the website does things: selling goods or services, taking online payments, handling bookings, running subscriptions or memberships, operating user accounts, delivering digital products, hosting content users upload, licensing downloads, recurring billing or any marketplace behaviour. At that point the terms are the contract that decides what happens when a delivery goes missing, a client cancels late or a subscriber disputes a charge. Business.gov.au's guidance is worth taking at face value here: terms set out both parties' rights and obligations across things like payment, warranties, shipping, returns, privacy and disputes and getting legal advice on what to include is the recommended path, not the cautious one.
The pattern worth noticing: the more the website transacts, the more the terms matter. Match the document to the transaction, not to what a competitor's footer looks like.
Terms of use and terms of sale are not always the same thing
Two documents hide under the label terms and conditions and conflating them produces pages that do neither job well.
Website terms of use may cover | Terms of sale or service may cover |
|---|---|
Access to the website itself | What is being supplied and its scope |
Acceptable use and prohibited behaviour | Pricing, payment timing and methods |
Intellectual property in site content | Delivery, shipping and timeframes |
Third party links and embedded content | Bookings, cancellations and rescheduling |
Accuracy and general disclaimers | Refunds, returns and remedies |
Suspension of access | Subscriptions and renewals |
General governing terms for visitors | Warranties, responsibilities and disputes |
A content site might only ever need the left column. An online store or booking business needs the right column doing real contractual work and may keep the two documents separate or combine them depending on complexity. What matters is that somebody decided, rather than a template deciding by default.
What might website terms and conditions include?
Depending on the business, well drafted terms typically deal with the areas below. Treat this as a coverage checklist for a conversation with a lawyer, not a drafting kit.
Area | What it typically covers |
|---|---|
Business identity | Legal entity, trading name, contact details, ABN where appropriate |
Products or services | What is supplied, eligibility, scope limits |
Pricing and payment | Prices, timing, recurring charges, taxes, fees, surcharges |
Delivery | Dispatch, delivery areas, shipping process, delays |
Cancellations and bookings | Cancellation windows, rescheduling, deposits, missed appointments |
Returns and refunds | Change of mind handling kept clearly separate from statutory consumer remedies |
Intellectual property | Site content, downloads, photography, trademarks, any customer licence |
User accounts | Account security, prohibited behaviour, suspension and termination |
Disclaimers | Tailored to the actual service, not blanket wording |
Liability | Needs careful legal drafting rather than aggressive boilerplate |
Disputes | Contact process, escalation, governing law where appropriate |
Changes | How and when terms may be updated |
Notice which two rows carry the most risk when copied from a template: returns and liability. Both interact directly with consumer law, which brings us to the section every Australian business owner should read twice.
Your website terms cannot override Australian Consumer Law
Whatever your terms say, consumers have guarantees under the Australian Consumer Law: goods of acceptable quality, fit for purpose, matching their description, services delivered with due care and skill. The ACCC's position is plain: businesses cannot take away these rights with contractual wording or signage, including by displaying a no refunds statement or claiming refunds stop after an arbitrary number of days. A term that pretends those rights do not exist is not just unenforceable on that point, it risks being misleading in its own right.
This is not a theoretical concern. The ACCC has taken court action over misleading refund and remedy representations and it reviewed more than 2,000 Australian retail websites, identifying returns wording with the potential to mislead consumers about their rights, including blanket restrictions on sale items, opened items and arbitrary reporting deadlines. Returns pages and checkout terms are visible, easy for a regulator to sweep and easy to get right once you accept the principle: your policy can be generous or minimal about change of mind, because change of mind is yours to set, but it cannot shrink the statutory remedies for faulty goods and services.
Unfair contract terms
The second guardrail. Since 9 November 2023, proposing, using or relying on unfair terms in standard form consumer and small business contracts has been prohibited and penalties can apply. A standard form contract is essentially one offered with no real room to negotiate, which describes most website terms exactly.
Terms that need particular legal care include:
rights for the business to cancel at will while the customer cannot
variation clauses that let one side rewrite the deal
excessive penalties for exiting
broad indemnities pushed onto the customer
automatic renewals with punishing exit mechanics
sweeping exclusions of responsibility
termination rights that only run one way
Deliberately, this article will not hand you a checklist that declares specific clauses fair or unfair, because fairness under this regime is assessed in context: the contract as a whole, the parties, the legitimate interests involved. That assessment is legal work. If your terms were downloaded, inherited or written in an afternoon years ago, a proper review is cheap insurance against a regime that now carries penalties.
Legal pages an Australian online store may need
Ecommerce concentrates every issue in this article into one website: personal information at checkout, marketing pixels, contractual terms, consumer guarantees, shipping promises and refund handling, all live at once. Depending on the store, the document set typically includes a privacy policy, terms of sale, a shipping policy, a returns and refunds policy, warranty information where relevant, subscription terms if you bill on repeat, tracking disclosure and clear contact information. Online businesses carry the same core consumer law responsibilities as physical ones. Selling through a website changes the channel, not the obligations.
A Melbourne boutique running a Shopify store and a national brand shipping from three warehouses need different depth in these documents, but neither gets to skip the returns and consumer guarantee question. The legal pages are one strand of a bigger launch picture and everything an Australian online store should check before launch puts them alongside the payments, shipping and platform decisions they depend on. It is also why the way we design online stores treats the returns page as a conversion page: shoppers read it before they buy and honest wording sells.
Legal pages for a service business website
Service businesses usually need a leaner set: a privacy policy where required or sensible, short website terms of use, booking and cancellation terms if the site takes appointments, payment terms and a disclaimer where the content warrants one.
The important distinction is what a website terms page is not. It is not automatically a substitute for a proper proposal, engagement agreement, retainer, consulting agreement or client service contract where the relationship needs one. An Adelaide consultancy selling $40,000 engagements through relationships should not be relying on footer terms written for website visitors to govern those engagements. The website terms govern the website; the engagement documents govern the work. Keeping that separation clean is part of what a professional services website should get right, along with handling confidential enquiries like the sensitive material they often are.
Booking heavy businesses sit in between. Cancellation windows, deposits and missed appointment handling belong in terms people actually see during booking, not buried three clicks away, which is a recurring theme in websites for restaurants and cafés that take bookings: the venues with the fewest booking disputes are the ones whose conditions were visible at the moment of booking.
What about website disclaimers?
A disclaimer clarifies the scope of your content: that information is general, that it is not professional advice for the reader's specific situation, that circumstances vary, that external links are provided for reference, that outcomes are not guaranteed. For accountants, lawyers, financial businesses, health businesses, consultants and educational publishers, a well written disclaimer is standard practice and genuinely useful, because it frames how content should be read.
Here is what a disclaimer is not: an immunity device. A disclaimer does not give a business permission to make misleading claims and it does not switch off obligations imposed by law. Australian businesses remain subject to prohibitions on false or misleading representations regardless of what the fine print says. If the marketing above the disclaimer overpromises, the disclaimer below it is not a shield, it is a decoration. Write the claims carefully and the disclaimer gets to do its real job: setting scope, not cleaning up.
A privacy policy is meaningless if the business does not protect the data
APP 11 requires covered entities to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. And whether or not the Privacy Act covers you, the logic is identical: a beautifully drafted policy describing information you then leave exposed is worse than useless, because it documents that you knew what you were holding.
For a typical business website, reasonable protection looks like: HTTPS everywhere, hosting that takes security seriously, multi factor authentication on administrator accounts, access restricted to people who need it, software and plugins kept updated, working backups, secure storage of form submissions, deleting information you no longer need and vetting the third parties who receive data. On the most common platform for Australian small business sites, that translates into locking down a WordPress site properly and into backing up your website before something forces you to. Retention deserves special mention because it is free risk reduction: information you deleted on schedule cannot leak.
What happens if personal information is exposed?
Briefly, because this is a planning point rather than a breach response guide. Entities covered by the scheme may have obligations under the Notifiable Data Breaches framework where an eligible data breach is likely to result in serious harm to individuals. The time to understand whether that applies to you is before anything happens.
The sensible pre work for any business: maintain a simple incident response process, know who assesses whether a breach is serious, know exactly who and what has access to website data, keep your developer's and host's emergency contacts current and get privacy and legal advice promptly when something does occur. Businesses that stumble here usually stumble on the basics, nobody knew who had admin access, nobody knew where form data was stored, rather than on the legal fine print.
Your legal pages need updating when the website changes
Legal pages describe a moving system. The OAIC expects APP privacy policies to be kept up to date, not treated as launch documents and the same logic applies to terms: they are accurate on the day they are written and drift from there.
Review the privacy policy when the website gains new forms, a new CRM, an advertising pixel, remarketing, a new analytics system, an AI chatbot, a booking system, ecommerce, subscriptions, systems serving international customers or new offshore providers. Review the terms when pricing models, shipping, subscriptions, cancellation policies, delivery models, warranties, the product range or payment arrangements change.
Two moments deserve a standing rule. The first is any remarketing addition: pixels change what your site collects at the same time as they change what you spend, so before one goes in, get the full picture on Google Ads costs and update the tracking disclosure in the same sprint. The second is any rebuild or replatform: data flows change with the platform, which is why the privacy review sits inside the full checklist for a website redesign rather than after it and why it pays to understand how the major website platforms stack up on data handling before you commit, not after the migration.
A workable rhythm for most businesses: legal pages get a look every time the technology or business model changes and a scheduled review at least annually even if nothing obvious moved. Somebody owns the diary entry. Unowned reviews do not happen.
Website legal and privacy QA checklist
Run this before launch and after any significant change. It slots into the checklist we work through before launch day as the legal and privacy pass and every row is a yes, no or needs advice, written down, with a name against it.
Privacy Act coverage
Check | Status |
|---|---|
Checked whether the Privacy Act applies to the business | |
Small business exemption and category exceptions reviewed against current OAIC guidance | |
AML/CTF position reviewed if the business provides designated services | |
Professional advice obtained where coverage is unclear |
Privacy policy
Check | Status |
|---|---|
Current privacy policy published and easy to find | |
Business and legal entity correctly identified | |
Categories of personal information listed and true | |
Collection methods explained, including tracking | |
Purposes for collection, use and disclosure explained | |
Access and correction process included | |
Complaints process included | |
Overseas disclosures reviewed and stated | |
Policy dated, with a review reminder in someone's calendar | |
10 December 2026 automated decision requirement reviewed where relevant |
Forms
Check | Status |
|---|---|
Every form has a clear purpose | |
Unnecessary fields removed | |
Sensitive information avoided unless genuinely necessary | |
Appropriate collection wording at each form | |
Privacy policy linked where people provide details | |
Marketing consent separated from service communication where appropriate |
Tracking
Check | Status |
|---|---|
Analytics tools documented | |
Pixels and remarketing tags documented | |
Sensitive pages audited for what fires on them | |
Consent requirements assessed for the actual stack | |
Overseas data flows assessed | |
Tracking disclosures in the policy match what is installed | |
A way to opt out of targeted advertising considered |
Terms
Check | Status |
|---|---|
Business name and legal entity accurate | |
Payment terms accurate | |
Cancellation and booking conditions accurate | |
Shipping and delivery wording accurate | |
Returns wording preserves Australian Consumer Law rights | |
Subscription and renewal terms accurate | |
Unfair contract term risks reviewed | |
Legal review completed where the risk warrants it |
Website footer
Check | Status |
|---|---|
Privacy policy linked | |
Terms linked where they exist | |
Returns and shipping policies linked for stores | |
Disclaimer linked where relevant | |
Accessibility statement linked where one exists | |
Every footer link opens the current version, not a draft or a dead page |
Only include what genuinely applies; a footer stacked with irrelevant documents reads as template theatre. Accessibility runs on the same logic as privacy, real practice first, statement second and the accessibility side of Australian website compliance walks through it the same way this guide walks through privacy. If you want a fast read on where you stand, run a two minute accessibility check while the QA hat is on.
Suggested legal pages by website type
A starting map, not a verdict. The privacy column in particular depends on whether the Privacy Act covers the business, which is the first question, not a footnote.
Website type | Privacy policy | Terms | Other likely documents |
|---|---|---|---|
Simple brochure site | Depends on coverage and what is collected | Often useful, context dependent | Disclaimer where relevant |
Lead generation site | Often important | Often useful | Collection wording at forms |
Professional services | Often important | Service specific | Disclaimer, engagement terms kept separate |
Ecommerce | Usually strongly advisable, legally required for APP entities | Strongly advisable | Returns, shipping, warranties |
Booking website | Often important | Strongly advisable | Cancellation and booking conditions |
Membership site | Often important | Strongly advisable | Membership and subscription terms |
Health website | Privacy obligations particularly important | Depends on the model | Collection wording, health specific care |
Common website privacy and legal mistakes
Fourteen we see repeatedly, most of them cheap to fix once named.
Copying a competitor's privacy policy
You inherit their systems, their third parties and their mistakes and describe none of your own. If it promises things you do not do or omits technology you run, the copy is worse than no policy.
Saying the Privacy Act applies to every small business automatically
It does not and pretending otherwise erodes trust in the parts of the document that are legally required. Work out coverage first, then write.
Treating the privacy policy as the form collection notice
They are different instruments. The policy is the general document; APP 5 wording lives at the point of collection, where the person actually is.
Installing Meta Pixel without reviewing what data it receives
Pixels are code from a third party, running on your pages, sending data to that third party. Understand the configuration before it goes live, especially around form fields and page context.
Using GDPR cookie wording without understanding the Australian setup
An EU consent popup pasted onto an Australian site often promises a legal framework that does not apply here while missing the obligations that do. Different homework.
Listing third parties the business no longer uses
A policy naming a CRM you abandoned two years ago tells everyone the document is decorative. Update the list when the stack changes.
Forgetting overseas service providers
The overseas disclosure section exists precisely because your email platform, CRM and support tools probably are not Australian. Check where the data actually goes.
Saying we never share information when cloud providers receive it
Absolute claims fail fast. If enquiries land in overseas software, describe that honestly instead of denying it.
Collecting unnecessary sensitive information
Every sensitive field raises the stakes for consent, security and breach consequences. If the appointment type does not need to be in the form, take it out.
Using no refunds wording that conflicts with consumer rights
Blanket refund bans misdescribe rights consumers hold under the Australian Consumer Law and can themselves be misleading. Set your change of mind policy freely; leave the statutory remedies alone.
Treating a disclaimer as protection from misleading claims
A disclaimer sets scope. It does not neutralise an overpromise sitting two paragraphs above it. Fix the claim, not the fine print.
Using a legal template without matching it to actual operations
Templates can provide structure, but every clause still has to be true of your business. The gap between template and reality is exactly where disputes live.
Changing website tracking without updating privacy disclosures
New pixel, new disclosure. Marketing and legal pages drift apart because they are owned by different people; put them in the same change process.
Leaving legal pages untouched for five years
The site changed, the tools changed and since 2023 the contract law around standard form terms changed too. A dated policy with no review rhythm is a snapshot of a website that no longer exists.
Our honest take: your policies should describe the business you actually run
The best privacy policy is not the longest one and the best terms page is not the one with the most legal furniture. The best versions are accurate: they say what the website collects, why, which third parties receive it, what customers are buying, what each side can expect and they stay silent on rights that cannot be contracted away rather than pretending to remove them.
A copied policy can create more risk than a missing one, because it makes representations. It promises processes you do not run and omits systems you do. Accuracy is also the cheapest it will ever be at the start: decide what the site collects while you are planning a website before anyone designs anything and the legal pages become a description of decisions already made instead of an archaeology project after launch.
The compliance picture, honestly drawn, is a stack. The policy is one layer near the top; everything below it has to be real:
Understand what data the website handles |
Minimise collection to what you genuinely need |
Notify people at the point of collection |
Protect what you hold |
Use and disclose it only for real purposes |
Give people access and correction |
Delete what you no longer need |
Keep the policy matching all of the above |
Privacy compliance is more than a policy. Each layer depends on the ones above it and the document at the bottom only works if the practice behind it exists.
FAQs
Does every Australian website need a privacy policy?
Not by law. APP entities covered by the Privacy Act are legally required to have one. Businesses outside the Act are not, though many publish one anyway because they hold customer information and want to handle it credibly.
Does the Privacy Act apply to small businesses?
Mostly not, currently, where annual turnover is $3 million or less. But wide category exceptions apply regardless of turnover, including health services, trading in personal information and AML reporting entities, so coverage has to be checked, not assumed.
What must an Australian privacy policy contain?
For APP entities, at minimum the APP 1.4 matters: what personal information you collect and hold, how, why, access and correction, complaints handling and likely overseas disclosures with countries where practicable. All clearly expressed and current.
What are the Australian Privacy Principles?
Thirteen principles in the Privacy Act that govern how covered entities handle personal information across its lifecycle, from collection through use, disclosure, security, access and correction.
What is the $3 million Privacy Act threshold?
Small businesses, defined as annual turnover of $3 million or less, are generally outside the Privacy Act unless an exception applies. Turnover counts income from all sources, not assets or capital proceeds.
Which small businesses are covered regardless of turnover?
Categories include private health service providers, businesses trading in personal information, Commonwealth contracted service providers, residential tenancy database operators, credit reporting bodies, AML reporting entities for AML related handling, Consumer Data Right accredited businesses, related entities of covered organisations and businesses that opt in. The OAIC checklist is the place to confirm.
Is a privacy policy the same as a privacy collection notice?
No. The policy is the general document about how the organisation manages personal information; the APP 5 notice delivers the relevant details at the point where information is collected. One does not substitute for the other.
Do Australian websites need a cookie banner?
No blanket rule requires one on every site. What matters is whether your tracking collects, uses or discloses personal information and whether you are transparent about it. Sensitive information sharply raises the bar, potentially to express consent.
Do I need consent before using Meta Pixel?
Not automatically in every circumstance, but you need to understand what it collects and disclose it and consent becomes particularly important where sensitive information is likely to be collected, such as on health related pages. Configuration and page placement matter as much as the banner.
Does my website need terms and conditions?
Not every informational site does. Once the site sells, books, bills or runs accounts, terms become important because they are the contract governing those transactions.
Can I copy terms from another website?
It is a bad idea. Their terms describe their business, their pricing and their risks and copying can import wording that is wrong or unfair for yours. Templates can offer structure; the content has to be yours and higher risk businesses should get terms drafted or reviewed professionally.
Can my terms say no refunds?
Blanket no refunds wording risks misleading consumers about rights they hold under the Australian Consumer Law, which your terms cannot remove. You can set change of mind policy however you like, provided it is honest and clearly separate from statutory remedies for faulty goods and services.
What should ecommerce terms include?
Typically identity and contact details, pricing and payment, shipping and delivery, returns handled consistently with consumer guarantees, warranties, subscription mechanics if relevant, liability drafted properly and a dispute process.
Do I need to disclose overseas cloud providers?
APP entities must state whether personal information is likely to go to overseas recipients and, where practicable, the countries. Most modern software stacks make this section genuinely relevant and the analysis of use versus disclosure follows OAIC guidance rather than guesswork.
How often should a privacy policy be updated?
Whenever the website's technology or the business model changes, plus a scheduled review at least annually. The Privacy Act expects covered entities to keep the policy up to date, not to publish it once.
What changes on 10 December 2026?
New APP 1 transparency requirements commence. APP entities using computer programs that draw on personal information to make or substantially and directly contribute to, decisions significantly affecting individuals' rights or interests will need to disclose in their privacy policy the kinds of information used and the kinds of decisions involved.
Do I need a website disclaimer?
If you publish professional or informational content people might rely on, a disclaimer clarifying that information is general is sensible and standard. It frames scope; it does not authorise misleading claims or remove legal obligations.
Should a lawyer review my website policies?
Where the business carries meaningful privacy, contractual or regulatory risk, yes: ecommerce at scale, subscriptions, health information, finance, anything AML captured or terms that do heavy commercial lifting. For a simple site, at minimum make sure every sentence in the documents is true of your business.
Next steps: pick your path
Path 1: audit what you have. Open your website next to this article's QA checklist and work through it honestly: coverage, policy, forms, tracking, terms, footer. Fold it into auditing your own website in about half an hour and you will know within an afternoon whether your legal pages describe your actual website or a template's imaginary one.
Path 2: build it in from the start. If a new site or rebuild is coming, make privacy, data collection, tracking and legal pages part of the QA process rather than a footer job after the design is signed off. Our full guide to how the whole website build process fits together treats them as launch criteria, which is where they belong.
Path 3: get it handled. If you would rather someone built this thinking in from day one, that is how we work: a web design team that asks what your site collects before it builds the forms and flags where legal advice is the right call instead of pretending an agency can certify compliance. Send us the pages you are not sure about and we will tell you straight what looks fine, what needs work and what needs a lawyer.
Sources and further reading
Privacy Act 1988, the legislation itself on the Federal Register, including the Australian Privacy Principles.
OAIC APP guidelines, Chapter 1, privacy policy requirements under APP 1, including the automated decision obligations commencing 10 December 2026.
OAIC small business guidance, who is covered regardless of turnover, with the small business privacy checklist.
OAIC tracking pixels and privacy obligations, the regulator's guidance on third party pixels, transparency, minimisation and sensitive information.
OAIC privacy guidance for AML/CTF reporting entities, privacy obligations for reporting entities, including businesses captured from 1 July 2026.
ACCC consumer rights and guarantees, the guarantees that contractual wording and no refunds signage cannot remove.
ACCC guidance on contracts and unfair contract terms, standard form contracts and the unfair terms regime in force since 9 November 2023.
Business.gov.au legal essentials, plain English overview of terms and conditions, contracts and other legal obligations for Australian businesses.
General information only. Rules vary by situation, particularly around advertising claims, privacy, reviews and consumer law. If you're unsure about compliance, get professional advice.