Somewhere right now, a business owner is pasting a template privacy policy into their footer five minutes before launch and calling the legal pages done. This guide is the alternative: what Australian law actually asks of your website, which businesses the Privacy Act covers, what your terms can and cannot say and how to end up with pages that describe the business you really run. No scaremongering, no template worship, just the workflow.

The straight answer: the legal pages you need depend on what your website does

There is no single set of documents Australian law stamps onto every website. There are four different things people lump together as legal pages and they do different jobs.

1. Privacy policy. Explains how your organisation manages personal information overall. For businesses covered by the Privacy Act, known as APP entities, this is a legal requirement under Australian Privacy Principle 1 and it must be clearly expressed and kept up to date. It is a standing description of your information handling, not a contract and not a consent form.

2. Privacy collection notice. Tells people the relevant details at the moment their information is being collected, at a form, a checkout, a booking widget. APP 5 requires covered entities to take reasonable steps to notify people of specified matters at or before collection or as soon as practicable afterwards. It is not the same document as the privacy policy and later in this guide we cover why that distinction matters so much.

3. Terms and conditions. The contractual side. Terms set rules, responsibilities and commercial arrangements around your products, services or the use of the site itself. Business.gov.au describes terms and conditions as setting out the rights and obligations of the business and its customers, potentially covering payment, warranties, shipping, returns, privacy and dispute handling and recommends legal advice on what to include.

4. Everything else. Depending on what the site does: a returns policy, shipping policy, cancellation policy, booking conditions, subscription terms, a disclaimer, an acceptable use policy or a cookie and tracking notice. None of these are automatic. Each one earns its place by matching something the website actually does.

Document

Purpose

When relevant

Key point

Privacy policy

Explains overall personal information management

Required for APP entities

Must remain current

Collection notice

Explains a specific collection

APP 5 where applicable

Usually shown near the collection point

Terms of use

Rules for using the website

Depends on the website

May form contractual terms

Terms of sale

The sale or service relationship

Commercial websites

Cannot override consumer law

Disclaimer

Clarifies the scope of information

Certain industries and content

Does not erase legal obligations

If you want the one page version, here is the decision flow. Everything after this section is the detail behind it.

Question about your website

If the answer is yes

Does the Privacy Act cover your business?

You need an APP privacy policy that meets APP 1

Do you collect personal information at specific points, like forms or checkout?

Review what collection notice belongs at each point

Do customers buy, book or subscribe through the site?

Review contractual terms for those transactions

Do you publish professional or informational content people might rely on?

Review whether a disclaimer is appropriate

Do you run analytics, pixels or remarketing?

Audit the tracking stack and its privacy and consent implications

Does your Australian business need a privacy policy?

Sometimes legally. Often practically. And not for exactly the same reason in every business, which is why the copied template approach fails: it answers a question nobody asked about your business specifically.

Businesses covered by the Privacy Act

The Privacy Act 1988 generally covers private sector organisations with an annual turnover above $3 million, along with businesses in specific categories regardless of turnover. If your business is covered, you are what the Act calls an APP entity and you generally need to comply with the 13 Australian Privacy Principles. The first of those, APP 1, requires a clearly expressed and up to date privacy policy about how you manage personal information.

Worth knowing before you shrug this off as paperwork: the regulator has moved from publishing guidance to checking. In early 2026 the Office of the Australian Information Commissioner began its first privacy policy compliance sweep, assessing organisations across several sectors against exactly these requirements. A policy that is missing, stale or vague is now the kind of thing that gets noticed, not just the kind of thing lawyers write articles about.

What about businesses under $3 million?

This is where most of the bad internet advice lives, in both directions. One camp says every website legally needs a privacy policy, which is not what the law says. The other camp says small businesses are exempt, full stop, which is not what the law says either.

The OAIC's current position is that most small businesses with an annual turnover of $3 million or less are not covered by the Privacy Act. But the exceptions are wide and they cover a lot of ordinary Australian businesses. Regardless of turnover, coverage extends to businesses that are, among other categories:

  • private health service providers, which is broader than doctors and includes areas like allied health, gyms with health programs and childcare in some circumstances

  • businesses that trade in personal information, meaning they buy or sell it for benefit, service or advantage

  • contracted service providers under Commonwealth contracts

  • operators of residential tenancy databases

  • credit reporting bodies

  • reporting entities and their authorised agents under anti money laundering law, for information handled in connection with those obligations

  • businesses accredited under the Consumer Data Right

  • businesses related to a larger organisation that is already covered

  • businesses that have voluntarily opted in to the Privacy Act

The category list stopped being a niche concern in July 2026. From 1 July 2026, anti money laundering obligations extended to a new group of businesses, including real estate professionals, lawyers, conveyancers, accountants and dealers in precious metals and stones. The OAIC's guidance for these reporting entities is blunt on the privacy consequence: they must comply with the Privacy Act when handling personal information for or in connection with their AML obligations and the small business exemption does not save them for that handling, even under $3 million turnover. A suburban real estate agency that never thought about the Privacy Act in twenty years of trading may now be inside it for part of its work, which is one of the reasons websites for real estate businesses have quietly become some of the most compliance sensitive builds we do.

Credit, lending and adjacent services have carried this weight for longer, between credit reporting rules, AML obligations and the Consumer Data Right. It shapes what finance websites deal with that other sites do not: more sensitive enquiries, more identity information, more third parties touching the data.

What if the Privacy Act does not cover the business?

Then the Act's specific obligations, including the APP 1 privacy policy requirement, do not apply to you. That is a real legal difference and this article will not pretend otherwise. It is also not the end of the question, for three reasons.

First, your website is probably collecting personal information anyway: enquiry details, customer records, account information, analytics data, marketing lists, bookings, orders, uploaded files. A regional electrician with a simple quote form still holds names, phone numbers and addresses of people who expect them handled sensibly, which is exactly the standard we push in what tradie websites need to get right. Second, other obligations can exist independently of the Privacy Act: contracts you have signed, industry rules, state laws, overseas privacy laws if you sell into other markets and the requirements platforms and payment providers impose on the businesses using them. Third, the OAIC itself recommends that small businesses outside the Privacy Act still protect the personal information they hold, because good handling is good business regardless of coverage.

And there is the forward looking reason. The government has flagged further privacy reform and the small business exemption has been squarely in that conversation. Building your website as if customer information matters costs little now and saves a scramble later.

What counts as personal information on a website?

Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable. On a working website, that sweeps in more than most owners expect: names, emails, phone numbers, addresses, account details, order history, enquiry messages, support conversations, uploaded documents, booking details and technical identifiers like IP addresses or device information where they identify or can reasonably identify someone.

Sensitive information is a subset that needs extra care: health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric information and similar categories. For APP entities, collecting sensitive information generally requires the individual's consent along with the other requirements of APP 3, subject to statutory exceptions. The practical trap is that websites collect sensitive information without meaning to. A physio's booking form asking what the appointment is for is collecting health information. So, in some circumstances, is a tracking pixel firing on the page about a specific treatment, which we get to shortly.

Website feature

Information it may collect

What to review

Contact form

Name, email, message contents

Collection notice and storage

Newsletter signup

Email, marketing preferences

Consent and direct marketing rules

Ecommerce checkout

Name, address, orders, payment references

Policy coverage and terms

Booking system

Contact details, appointment context

Collection wording and third parties

Analytics

Device and activity data

Whether it identifies people and disclosure

Advertising pixel

Behaviour plus platform identifiers

APP obligations and pixel configuration

Live chat

Contact details, conversation contents

Provider, storage and retention

Job application form

CV and employment information

Recruitment privacy handling

Health related form

Potentially sensitive information

Consent and a much higher standard of care

Run your eye down that table against your own site. Most businesses find they are collecting through five or six of those features and their privacy policy mentions two.

What must an Australian APP privacy policy include?

APP 1.4 specifies the minimum contents. None of it is exotic, all of it must be true of your business specifically and the whole document must be clearly expressed, which is a legal requirement, not a style preference. Legalese that customers cannot follow fails the brief. The same skills that produce copy that reads like a human wrote it produce a privacy policy people can actually use.

1. What personal information you collect and hold

Name the actual categories your business handles: contact information, account details, purchase history, enquiry information, billing information, recruitment information if you hire through the site. The wording test is specificity.

Wording that does the job

Wording that does not

We collect your name, contact details, order history and delivery address when you buy from us

We may collect personal information from time to time

When you submit our quote form we collect your name, email, phone number and project details

We collect information you provide to us

2. How you collect and hold it

List the real collection points: contact forms, checkout, account registration, phone and email, bookings, newsletter signups, events, job applications, your CRM, tracking technologies and any third parties who collect for you. Then describe, at a sensible altitude, how information is held, such as in Australian hosted systems or reputable cloud platforms with access controls. Describe the approach without publishing a map for attackers. Naming your exact software versions and security architecture in a public document creates risk rather than transparency.

3. Why you collect, hold, use and disclose it

The purposes: responding to enquiries, processing orders, delivering services, providing support, operating accounts, processing bookings, communicating about an engagement, improving services, marketing where permitted and meeting legal obligations. Two principles keep this honest. APP entities may only collect non sensitive personal information that is reasonably necessary for their functions or activities. And the policy explains your purposes, it does not launder them: writing a purpose into the document does not turn unnecessary collection into necessary collection. A privacy policy is a description, not a permission slip.

4. How people can access or correct their information

APPs 12 and 13 deal with access and correction of personal information held by APP entities. Your policy should say where requests go, what you need to verify the requester is who they claim to be and how the request will be handled. Keep the channel real: an inbox somebody actually monitors, not a role address nobody has opened since the site launched.

5. How privacy complaints can be made

APP 1.4 specifically requires the policy to explain how an individual can complain about a breach of the APPs and how your business will deal with that complaint. Include the contact method, the process and what the person can expect in response. Businesses that handle this well treat a privacy complaint like any other service failure: acknowledged quickly, investigated properly, answered plainly.

6. Overseas disclosure

The policy must state whether you are likely to disclose personal information to overseas recipients and, where practicable, the countries involved. This clause went from theoretical to routine the moment businesses started running on overseas cloud software: CRMs, email platforms, marketing tools, support systems, analytics.

Two cautions. Do not mechanically list every country a cloud server might technically route data through; use, storage and disclosure to an overseas recipient can involve different legal analysis and the OAIC's guidance is the reference here, not guesswork. And do not write we never share your information while your enquiry data sits in an American CRM and your email list lives on an overseas marketing platform. That sentence is one subject access request away from embarrassment.

APP 1.4 requirement

The question your policy must answer

Information collected and held

What personal information do we actually collect?

Collection and storage

How do we receive it and where does it live?

Purposes

Why do we need it and what do we do with it?

Access and correction

How can someone see or fix their information?

Complaints

How can someone complain and what happens then?

Overseas disclosure

Do overseas recipients get it?

Countries

Which countries, where practicable?

Important 2026 change: automated decisions

These provisions, new APPs 1.7 to 1.9, were added by the Privacy and Other Legislation Amendment Act 2024 and commence on 10 December 2026. This article is written in August 2026, so the obligation is law that has passed but not yet started. If you are reading after that date, it is live.

Depending on the facts, arrangements worth reviewing against the new requirement include:

  • automated eligibility or application decisions

  • credit or finance decisions supported by software

  • certain insurance assessments

  • automated decisions about customer access, accounts or pricing

  • significant assessments where AI tools do the substantive work

Two ways to get this wrong. The first is ignoring it because your business feels too small for the word automated. The second is panicking that every AI feature on your website now triggers disclosure. Neither is right: the obligation turns on personal information feeding decisions that significantly affect people's rights or interests and the OAIC is preparing detailed guidance on where those lines sit. If your business runs anything that resembles the list above, this is a diary entry for legal review before December, not a reason to rip out your chatbot.

For everyone else, the practical takeaway is smaller: put a reminder in the calendar to recheck your privacy policy against the final OAIC guidance once this commences. Policies age and this is a dated, known change you can plan for.

A privacy policy is not the same as the notice beside your form

This distinction is worth the price of the whole article, because almost every small business website gets it wrong. The OAIC is explicit that an APP privacy policy is not a substitute for an APP 5 collection notice. They are different instruments doing different jobs.

The privacy policy is the broad document: how your organisation manages personal information generally. The collection notice is point of use information: what someone needs to know at the moment their details are being collected, at the contact form, the account signup, the job application, the quote form, the event registration, the patient intake form. A footer link to a policy nobody reads does not tell the person filling in your form, right now, what happens next with what they are typing.

What an APP 5 notice may need to explain

APP 5 sets the notification matters and generally requires reasonable steps at or before collection or as soon as practicable afterwards. Depending on the circumstances, the notice may need to cover:

  • who is collecting the information

  • why it is being collected

  • the main consequences if it is not provided

  • who it is usually disclosed to

  • how to find the privacy policy

  • how access, correction and complaints work

  • likely overseas disclosures

Reasonable steps scale with risk. A simple contact form can often do the job with a short, clear sentence near the button. A form collecting health, financial or other higher risk information needs proportionately more.

Example form setup

A form with a working notice

A form without one

Name, email, tell us what you need help with, plus: We'll use these details to respond to your enquiry. For how we handle personal information, read our privacy policy.

Name, email, message. Submit.

One honest sentence at the point of collection beats three paragraphs of boilerplate nobody sees. It also converts better, because stating what happens next reduces the hesitation that kills form completions, a pattern we unpack in designing forms that respect people's time and data. Trust wording and completion rates travel together.

Does an Australian website need a cookie banner?

Here is the section that corrects the most confidently wrong advice on the Australian internet. The short answer: Australia does not currently have a blanket rule equivalent to the EU model that requires every website to obtain consent for every non essential cookie before it loads. If you have been told your Australian site is breaking the law simply because it lacks an EU style consent popup, you have been given another country's homework.

The longer answer is that this is absolutely not a free pass on tracking. For businesses covered by the Privacy Act, the APPs can apply where tracking technologies collect, use or disclose personal information and the OAIC has published specific guidance on third party tracking pixels. The thrust of it: the business deploying the pixel is responsible for making sure it is configured and used compliantly, should understand how the product works before installing it, should be transparent about it in the privacy policy and notifications, should minimise what is collected and should review how data flows to the third party platform. The OAIC specifically warns against a set and forget approach, which is a fair description of how most pixels get installed.

When consent becomes particularly important

Sensitive information changes the rules. The OAIC says sensitive information must only be collected through a tracking pixel with the individual's consent and points to express consent given upfront where sensitive information is likely to be collected and disclosed to third party platforms. Sensitive information can be revealed by behaviour, not just by form fields: the pages someone visits on a health, medical, mental health or similar site can themselves say something sensitive about that person.

This stopped being theoretical in June 2026, when the Privacy Commissioner published determinations involving health sector websites whose advertising pixels had collected sensitive information, finding breaches of privacy obligations. The message for any business in health and adjacent fields is direct: do not deploy advertising pixels blindly on pages where a visit itself may reveal something sensitive about the visitor. It is a standing consideration in how we build patient facing websites in the health sector, where the marketing stack gets vetted as carefully as the booking flow.

Cookie and tracking audit

Before configuring any banner or consent tool, work out what you are actually running. Identify every piece of the stack:

  • essential cookies that make the site function

  • analytics

  • advertising pixels

  • remarketing tags

  • embedded video players and their tracking

  • chat widgets

  • booking technology

  • CRM and email tracking

  • heatmaps and session recording tools

  • social media embeds

For each one, document the provider, what it collects, the purpose, how long data is kept where known, whether personal information is involved, any overseas recipients, whether consent is needed in your circumstances and whether people have a way to opt out. Yes, this is tedious. It is also thirty minutes with your tag manager open and it is the difference between a banner that reflects reality and a decoration.

If paid advertising is part of your stack, the people running your paid campaigns should be able to tell you exactly what the pixel collects, which events fire and what gets shared back to the platform. If they cannot, that is a finding in itself. A quick way to pressure test the whole account, tracking included, is to score your own Google Ads setup in a few minutes and see where the gaps cluster.

Technology

Blanket consent rule under Australian law?

What to review instead

Essential session cookie

No blanket rule

Necessity and security

Analytics

Not automatically

Whether personal information is involved, disclosure, transparency

Advertising pixel

Not automatically in every circumstance

APP obligations, configuration, third party data flows

Pixel that may collect sensitive information

Consent is particularly important

Express consent, necessity, whether it belongs on the page at all

Tracking of overseas visitors

May engage other countries' laws

Applicable foreign regimes if you target those markets

Your privacy policy should reflect the tracking technology actually installed

The OAIC's pixel guidance says privacy policies and collection notifications should contain clear and transparent information about third party tracking. Which means the vague sentence at the top of ten thousand Australian privacy policies fails on contact with reality:

Disclosure that matches reality

Disclosure that does not

We use Google Analytics to understand site usage and advertising pixels that share behavioural information with the platforms we advertise on, for measurement and remarketing

We may use cookies to improve your experience

Our booking system and live chat are provided by third parties who receive the details you enter

Third parties may collect some information

Cover what is genuinely running: analytics, advertising platforms, remarketing, customer analytics, integrations. The disclosure should move when the stack moves. And know your own tools well enough to describe them, starting with getting Google Analytics 4 set up properly for a small business, because you cannot honestly disclose a system nobody in the business understands. Measurement is not just an advertising concern either, it feeds decisions across paid activity and the organic side of your marketing, so the stack tends to grow and every addition belongs in the review.

The mental model that keeps disclosure honest is a data map. Trace it once and the policy nearly writes itself:

Visitor → forms and tracking → website and CRM → email, marketing and cloud providers → storage and deletion

Follow one enquiry through your stack. Every stop on that path is something the privacy policy should be able to account for.

Does every Australian website need terms and conditions?

No and anyone selling you a mandatory terms package for a five page brochure site is selling, not advising. A simple informational website with no sales, no accounts and no bookings does not necessarily need a contractual terms document, though even brochure sites sometimes benefit from short terms of use covering content and acceptable use.

Terms become genuinely important, sometimes commercially critical, once the website does things: selling goods or services, taking online payments, handling bookings, running subscriptions or memberships, operating user accounts, delivering digital products, hosting content users upload, licensing downloads, recurring billing or any marketplace behaviour. At that point the terms are the contract that decides what happens when a delivery goes missing, a client cancels late or a subscriber disputes a charge. Business.gov.au's guidance is worth taking at face value here: terms set out both parties' rights and obligations across things like payment, warranties, shipping, returns, privacy and disputes and getting legal advice on what to include is the recommended path, not the cautious one.

The pattern worth noticing: the more the website transacts, the more the terms matter. Match the document to the transaction, not to what a competitor's footer looks like.

Terms of use and terms of sale are not always the same thing

Two documents hide under the label terms and conditions and conflating them produces pages that do neither job well.

Website terms of use may cover

Terms of sale or service may cover

Access to the website itself

What is being supplied and its scope

Acceptable use and prohibited behaviour

Pricing, payment timing and methods

Intellectual property in site content

Delivery, shipping and timeframes

Third party links and embedded content

Bookings, cancellations and rescheduling

Accuracy and general disclaimers

Refunds, returns and remedies

Suspension of access

Subscriptions and renewals

General governing terms for visitors

Warranties, responsibilities and disputes

A content site might only ever need the left column. An online store or booking business needs the right column doing real contractual work and may keep the two documents separate or combine them depending on complexity. What matters is that somebody decided, rather than a template deciding by default.

What might website terms and conditions include?

Depending on the business, well drafted terms typically deal with the areas below. Treat this as a coverage checklist for a conversation with a lawyer, not a drafting kit.

Area

What it typically covers

Business identity

Legal entity, trading name, contact details, ABN where appropriate

Products or services

What is supplied, eligibility, scope limits

Pricing and payment

Prices, timing, recurring charges, taxes, fees, surcharges

Delivery

Dispatch, delivery areas, shipping process, delays

Cancellations and bookings

Cancellation windows, rescheduling, deposits, missed appointments

Returns and refunds

Change of mind handling kept clearly separate from statutory consumer remedies

Intellectual property

Site content, downloads, photography, trademarks, any customer licence

User accounts

Account security, prohibited behaviour, suspension and termination

Disclaimers

Tailored to the actual service, not blanket wording

Liability

Needs careful legal drafting rather than aggressive boilerplate

Disputes

Contact process, escalation, governing law where appropriate

Changes

How and when terms may be updated

Notice which two rows carry the most risk when copied from a template: returns and liability. Both interact directly with consumer law, which brings us to the section every Australian business owner should read twice.

Your website terms cannot override Australian Consumer Law

Whatever your terms say, consumers have guarantees under the Australian Consumer Law: goods of acceptable quality, fit for purpose, matching their description, services delivered with due care and skill. The ACCC's position is plain: businesses cannot take away these rights with contractual wording or signage, including by displaying a no refunds statement or claiming refunds stop after an arbitrary number of days. A term that pretends those rights do not exist is not just unenforceable on that point, it risks being misleading in its own right.

This is not a theoretical concern. The ACCC has taken court action over misleading refund and remedy representations and it reviewed more than 2,000 Australian retail websites, identifying returns wording with the potential to mislead consumers about their rights, including blanket restrictions on sale items, opened items and arbitrary reporting deadlines. Returns pages and checkout terms are visible, easy for a regulator to sweep and easy to get right once you accept the principle: your policy can be generous or minimal about change of mind, because change of mind is yours to set, but it cannot shrink the statutory remedies for faulty goods and services.

Unfair contract terms

The second guardrail. Since 9 November 2023, proposing, using or relying on unfair terms in standard form consumer and small business contracts has been prohibited and penalties can apply. A standard form contract is essentially one offered with no real room to negotiate, which describes most website terms exactly.

Terms that need particular legal care include:

  • rights for the business to cancel at will while the customer cannot

  • variation clauses that let one side rewrite the deal

  • excessive penalties for exiting

  • broad indemnities pushed onto the customer

  • automatic renewals with punishing exit mechanics

  • sweeping exclusions of responsibility

  • termination rights that only run one way

Deliberately, this article will not hand you a checklist that declares specific clauses fair or unfair, because fairness under this regime is assessed in context: the contract as a whole, the parties, the legitimate interests involved. That assessment is legal work. If your terms were downloaded, inherited or written in an afternoon years ago, a proper review is cheap insurance against a regime that now carries penalties.

Legal pages an Australian online store may need

Ecommerce concentrates every issue in this article into one website: personal information at checkout, marketing pixels, contractual terms, consumer guarantees, shipping promises and refund handling, all live at once. Depending on the store, the document set typically includes a privacy policy, terms of sale, a shipping policy, a returns and refunds policy, warranty information where relevant, subscription terms if you bill on repeat, tracking disclosure and clear contact information. Online businesses carry the same core consumer law responsibilities as physical ones. Selling through a website changes the channel, not the obligations.

A Melbourne boutique running a Shopify store and a national brand shipping from three warehouses need different depth in these documents, but neither gets to skip the returns and consumer guarantee question. The legal pages are one strand of a bigger launch picture and everything an Australian online store should check before launch puts them alongside the payments, shipping and platform decisions they depend on. It is also why the way we design online stores treats the returns page as a conversion page: shoppers read it before they buy and honest wording sells.

Legal pages for a service business website

Service businesses usually need a leaner set: a privacy policy where required or sensible, short website terms of use, booking and cancellation terms if the site takes appointments, payment terms and a disclaimer where the content warrants one.

The important distinction is what a website terms page is not. It is not automatically a substitute for a proper proposal, engagement agreement, retainer, consulting agreement or client service contract where the relationship needs one. An Adelaide consultancy selling $40,000 engagements through relationships should not be relying on footer terms written for website visitors to govern those engagements. The website terms govern the website; the engagement documents govern the work. Keeping that separation clean is part of what a professional services website should get right, along with handling confidential enquiries like the sensitive material they often are.

Booking heavy businesses sit in between. Cancellation windows, deposits and missed appointment handling belong in terms people actually see during booking, not buried three clicks away, which is a recurring theme in websites for restaurants and cafés that take bookings: the venues with the fewest booking disputes are the ones whose conditions were visible at the moment of booking.

What about website disclaimers?

A disclaimer clarifies the scope of your content: that information is general, that it is not professional advice for the reader's specific situation, that circumstances vary, that external links are provided for reference, that outcomes are not guaranteed. For accountants, lawyers, financial businesses, health businesses, consultants and educational publishers, a well written disclaimer is standard practice and genuinely useful, because it frames how content should be read.

Here is what a disclaimer is not: an immunity device. A disclaimer does not give a business permission to make misleading claims and it does not switch off obligations imposed by law. Australian businesses remain subject to prohibitions on false or misleading representations regardless of what the fine print says. If the marketing above the disclaimer overpromises, the disclaimer below it is not a shield, it is a decoration. Write the claims carefully and the disclaimer gets to do its real job: setting scope, not cleaning up.

A privacy policy is meaningless if the business does not protect the data

APP 11 requires covered entities to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. And whether or not the Privacy Act covers you, the logic is identical: a beautifully drafted policy describing information you then leave exposed is worse than useless, because it documents that you knew what you were holding.

For a typical business website, reasonable protection looks like: HTTPS everywhere, hosting that takes security seriously, multi factor authentication on administrator accounts, access restricted to people who need it, software and plugins kept updated, working backups, secure storage of form submissions, deleting information you no longer need and vetting the third parties who receive data. On the most common platform for Australian small business sites, that translates into locking down a WordPress site properly and into backing up your website before something forces you to. Retention deserves special mention because it is free risk reduction: information you deleted on schedule cannot leak.

What happens if personal information is exposed?

Briefly, because this is a planning point rather than a breach response guide. Entities covered by the scheme may have obligations under the Notifiable Data Breaches framework where an eligible data breach is likely to result in serious harm to individuals. The time to understand whether that applies to you is before anything happens.

The sensible pre work for any business: maintain a simple incident response process, know who assesses whether a breach is serious, know exactly who and what has access to website data, keep your developer's and host's emergency contacts current and get privacy and legal advice promptly when something does occur. Businesses that stumble here usually stumble on the basics, nobody knew who had admin access, nobody knew where form data was stored, rather than on the legal fine print.

Your legal pages need updating when the website changes

Legal pages describe a moving system. The OAIC expects APP privacy policies to be kept up to date, not treated as launch documents and the same logic applies to terms: they are accurate on the day they are written and drift from there.

Review the privacy policy when the website gains new forms, a new CRM, an advertising pixel, remarketing, a new analytics system, an AI chatbot, a booking system, ecommerce, subscriptions, systems serving international customers or new offshore providers. Review the terms when pricing models, shipping, subscriptions, cancellation policies, delivery models, warranties, the product range or payment arrangements change.

Two moments deserve a standing rule. The first is any remarketing addition: pixels change what your site collects at the same time as they change what you spend, so before one goes in, get the full picture on Google Ads costs and update the tracking disclosure in the same sprint. The second is any rebuild or replatform: data flows change with the platform, which is why the privacy review sits inside the full checklist for a website redesign rather than after it and why it pays to understand how the major website platforms stack up on data handling before you commit, not after the migration.

A workable rhythm for most businesses: legal pages get a look every time the technology or business model changes and a scheduled review at least annually even if nothing obvious moved. Somebody owns the diary entry. Unowned reviews do not happen.

Website legal and privacy QA checklist

Run this before launch and after any significant change. It slots into the checklist we work through before launch day as the legal and privacy pass and every row is a yes, no or needs advice, written down, with a name against it.

Privacy Act coverage

Check

Status

Checked whether the Privacy Act applies to the business

Small business exemption and category exceptions reviewed against current OAIC guidance

AML/CTF position reviewed if the business provides designated services

Professional advice obtained where coverage is unclear

Privacy policy

Check

Status

Current privacy policy published and easy to find

Business and legal entity correctly identified

Categories of personal information listed and true

Collection methods explained, including tracking

Purposes for collection, use and disclosure explained

Access and correction process included

Complaints process included

Overseas disclosures reviewed and stated

Policy dated, with a review reminder in someone's calendar

10 December 2026 automated decision requirement reviewed where relevant

Forms

Check

Status

Every form has a clear purpose

Unnecessary fields removed

Sensitive information avoided unless genuinely necessary

Appropriate collection wording at each form

Privacy policy linked where people provide details

Marketing consent separated from service communication where appropriate

Tracking

Check

Status

Analytics tools documented

Pixels and remarketing tags documented

Sensitive pages audited for what fires on them

Consent requirements assessed for the actual stack

Overseas data flows assessed

Tracking disclosures in the policy match what is installed

A way to opt out of targeted advertising considered

Terms

Check

Status

Business name and legal entity accurate

Payment terms accurate

Cancellation and booking conditions accurate

Shipping and delivery wording accurate

Returns wording preserves Australian Consumer Law rights

Subscription and renewal terms accurate

Unfair contract term risks reviewed

Legal review completed where the risk warrants it

Website footer

Check

Status

Privacy policy linked

Terms linked where they exist

Returns and shipping policies linked for stores

Disclaimer linked where relevant

Accessibility statement linked where one exists

Every footer link opens the current version, not a draft or a dead page

Only include what genuinely applies; a footer stacked with irrelevant documents reads as template theatre. Accessibility runs on the same logic as privacy, real practice first, statement second and the accessibility side of Australian website compliance walks through it the same way this guide walks through privacy. If you want a fast read on where you stand, run a two minute accessibility check while the QA hat is on.

Suggested legal pages by website type

A starting map, not a verdict. The privacy column in particular depends on whether the Privacy Act covers the business, which is the first question, not a footnote.

Website type

Privacy policy

Terms

Other likely documents

Simple brochure site

Depends on coverage and what is collected

Often useful, context dependent

Disclaimer where relevant

Lead generation site

Often important

Often useful

Collection wording at forms

Professional services

Often important

Service specific

Disclaimer, engagement terms kept separate

Ecommerce

Usually strongly advisable, legally required for APP entities

Strongly advisable

Returns, shipping, warranties

Booking website

Often important

Strongly advisable

Cancellation and booking conditions

Membership site

Often important

Strongly advisable

Membership and subscription terms

Health website

Privacy obligations particularly important

Depends on the model

Collection wording, health specific care

Common website privacy and legal mistakes

Fourteen we see repeatedly, most of them cheap to fix once named.

Copying a competitor's privacy policy

You inherit their systems, their third parties and their mistakes and describe none of your own. If it promises things you do not do or omits technology you run, the copy is worse than no policy.

Saying the Privacy Act applies to every small business automatically

It does not and pretending otherwise erodes trust in the parts of the document that are legally required. Work out coverage first, then write.

Treating the privacy policy as the form collection notice

They are different instruments. The policy is the general document; APP 5 wording lives at the point of collection, where the person actually is.

Installing Meta Pixel without reviewing what data it receives

Pixels are code from a third party, running on your pages, sending data to that third party. Understand the configuration before it goes live, especially around form fields and page context.

Using GDPR cookie wording without understanding the Australian setup

An EU consent popup pasted onto an Australian site often promises a legal framework that does not apply here while missing the obligations that do. Different homework.

Listing third parties the business no longer uses

A policy naming a CRM you abandoned two years ago tells everyone the document is decorative. Update the list when the stack changes.

Forgetting overseas service providers

The overseas disclosure section exists precisely because your email platform, CRM and support tools probably are not Australian. Check where the data actually goes.

Saying we never share information when cloud providers receive it

Absolute claims fail fast. If enquiries land in overseas software, describe that honestly instead of denying it.

Collecting unnecessary sensitive information

Every sensitive field raises the stakes for consent, security and breach consequences. If the appointment type does not need to be in the form, take it out.

Using no refunds wording that conflicts with consumer rights

Blanket refund bans misdescribe rights consumers hold under the Australian Consumer Law and can themselves be misleading. Set your change of mind policy freely; leave the statutory remedies alone.

Treating a disclaimer as protection from misleading claims

A disclaimer sets scope. It does not neutralise an overpromise sitting two paragraphs above it. Fix the claim, not the fine print.

Using a legal template without matching it to actual operations

Templates can provide structure, but every clause still has to be true of your business. The gap between template and reality is exactly where disputes live.

Changing website tracking without updating privacy disclosures

New pixel, new disclosure. Marketing and legal pages drift apart because they are owned by different people; put them in the same change process.

Leaving legal pages untouched for five years

The site changed, the tools changed and since 2023 the contract law around standard form terms changed too. A dated policy with no review rhythm is a snapshot of a website that no longer exists.

Our honest take: your policies should describe the business you actually run

The best privacy policy is not the longest one and the best terms page is not the one with the most legal furniture. The best versions are accurate: they say what the website collects, why, which third parties receive it, what customers are buying, what each side can expect and they stay silent on rights that cannot be contracted away rather than pretending to remove them.

A copied policy can create more risk than a missing one, because it makes representations. It promises processes you do not run and omits systems you do. Accuracy is also the cheapest it will ever be at the start: decide what the site collects while you are planning a website before anyone designs anything and the legal pages become a description of decisions already made instead of an archaeology project after launch.

The compliance picture, honestly drawn, is a stack. The policy is one layer near the top; everything below it has to be real:

Understand what data the website handles

Minimise collection to what you genuinely need

Notify people at the point of collection

Protect what you hold

Use and disclose it only for real purposes

Give people access and correction

Delete what you no longer need

Keep the policy matching all of the above

Privacy compliance is more than a policy. Each layer depends on the ones above it and the document at the bottom only works if the practice behind it exists.

FAQs

Does every Australian website need a privacy policy?

Not by law. APP entities covered by the Privacy Act are legally required to have one. Businesses outside the Act are not, though many publish one anyway because they hold customer information and want to handle it credibly.

Does the Privacy Act apply to small businesses?

Mostly not, currently, where annual turnover is $3 million or less. But wide category exceptions apply regardless of turnover, including health services, trading in personal information and AML reporting entities, so coverage has to be checked, not assumed.

What must an Australian privacy policy contain?

For APP entities, at minimum the APP 1.4 matters: what personal information you collect and hold, how, why, access and correction, complaints handling and likely overseas disclosures with countries where practicable. All clearly expressed and current.

What are the Australian Privacy Principles?

Thirteen principles in the Privacy Act that govern how covered entities handle personal information across its lifecycle, from collection through use, disclosure, security, access and correction.

What is the $3 million Privacy Act threshold?

Small businesses, defined as annual turnover of $3 million or less, are generally outside the Privacy Act unless an exception applies. Turnover counts income from all sources, not assets or capital proceeds.

Which small businesses are covered regardless of turnover?

Categories include private health service providers, businesses trading in personal information, Commonwealth contracted service providers, residential tenancy database operators, credit reporting bodies, AML reporting entities for AML related handling, Consumer Data Right accredited businesses, related entities of covered organisations and businesses that opt in. The OAIC checklist is the place to confirm.

Is a privacy policy the same as a privacy collection notice?

No. The policy is the general document about how the organisation manages personal information; the APP 5 notice delivers the relevant details at the point where information is collected. One does not substitute for the other.

Do Australian websites need a cookie banner?

No blanket rule requires one on every site. What matters is whether your tracking collects, uses or discloses personal information and whether you are transparent about it. Sensitive information sharply raises the bar, potentially to express consent.

Do I need consent before using Meta Pixel?

Not automatically in every circumstance, but you need to understand what it collects and disclose it and consent becomes particularly important where sensitive information is likely to be collected, such as on health related pages. Configuration and page placement matter as much as the banner.

Does my website need terms and conditions?

Not every informational site does. Once the site sells, books, bills or runs accounts, terms become important because they are the contract governing those transactions.

Can I copy terms from another website?

It is a bad idea. Their terms describe their business, their pricing and their risks and copying can import wording that is wrong or unfair for yours. Templates can offer structure; the content has to be yours and higher risk businesses should get terms drafted or reviewed professionally.

Can my terms say no refunds?

Blanket no refunds wording risks misleading consumers about rights they hold under the Australian Consumer Law, which your terms cannot remove. You can set change of mind policy however you like, provided it is honest and clearly separate from statutory remedies for faulty goods and services.

What should ecommerce terms include?

Typically identity and contact details, pricing and payment, shipping and delivery, returns handled consistently with consumer guarantees, warranties, subscription mechanics if relevant, liability drafted properly and a dispute process.

Do I need to disclose overseas cloud providers?

APP entities must state whether personal information is likely to go to overseas recipients and, where practicable, the countries. Most modern software stacks make this section genuinely relevant and the analysis of use versus disclosure follows OAIC guidance rather than guesswork.

How often should a privacy policy be updated?

Whenever the website's technology or the business model changes, plus a scheduled review at least annually. The Privacy Act expects covered entities to keep the policy up to date, not to publish it once.

What changes on 10 December 2026?

New APP 1 transparency requirements commence. APP entities using computer programs that draw on personal information to make or substantially and directly contribute to, decisions significantly affecting individuals' rights or interests will need to disclose in their privacy policy the kinds of information used and the kinds of decisions involved.

Do I need a website disclaimer?

If you publish professional or informational content people might rely on, a disclaimer clarifying that information is general is sensible and standard. It frames scope; it does not authorise misleading claims or remove legal obligations.

Should a lawyer review my website policies?

Where the business carries meaningful privacy, contractual or regulatory risk, yes: ecommerce at scale, subscriptions, health information, finance, anything AML captured or terms that do heavy commercial lifting. For a simple site, at minimum make sure every sentence in the documents is true of your business.

Next steps: pick your path

Path 1: audit what you have. Open your website next to this article's QA checklist and work through it honestly: coverage, policy, forms, tracking, terms, footer. Fold it into auditing your own website in about half an hour and you will know within an afternoon whether your legal pages describe your actual website or a template's imaginary one.

Path 2: build it in from the start. If a new site or rebuild is coming, make privacy, data collection, tracking and legal pages part of the QA process rather than a footer job after the design is signed off. Our full guide to how the whole website build process fits together treats them as launch criteria, which is where they belong.

Path 3: get it handled. If you would rather someone built this thinking in from day one, that is how we work: a web design team that asks what your site collects before it builds the forms and flags where legal advice is the right call instead of pretending an agency can certify compliance. Send us the pages you are not sure about and we will tell you straight what looks fine, what needs work and what needs a lawyer.

Sources and further reading

Privacy Act 1988, the legislation itself on the Federal Register, including the Australian Privacy Principles.

OAIC APP guidelines, Chapter 1, privacy policy requirements under APP 1, including the automated decision obligations commencing 10 December 2026.

OAIC small business guidance, who is covered regardless of turnover, with the small business privacy checklist.

OAIC tracking pixels and privacy obligations, the regulator's guidance on third party pixels, transparency, minimisation and sensitive information.

OAIC privacy guidance for AML/CTF reporting entities, privacy obligations for reporting entities, including businesses captured from 1 July 2026.

ACCC consumer rights and guarantees, the guarantees that contractual wording and no refunds signage cannot remove.

ACCC guidance on contracts and unfair contract terms, standard form contracts and the unfair terms regime in force since 9 November 2023.

Business.gov.au legal essentials, plain English overview of terms and conditions, contracts and other legal obligations for Australian businesses.

General information only. Rules vary by situation, particularly around advertising claims, privacy, reviews and consumer law. If you're unsure about compliance, get professional advice.

AK
Written by

Ajay K.

Ajay K is the founder of Elev8d. A psychology grad turned marketer, he writes plain English guides on SEO, ads and web design. Reader, adrenaline seeker & self confessed introverted extrovert.