1. What counts as personal information
  2. The Australian Privacy Principles
  3. Who is legally required to have a privacy policy
    1. The $3 million threshold
    2. Businesses below $3 million that are still covered
  4. What your privacy policy must contain
  5. What happens if you get it wrong
  6. Situations where businesses commonly get this wrong
  7. How Artificer Legal can help
  8. Key takeaways

Most Australian businesses collect personal information from their customers every day — names, email addresses, phone numbers, payment details. What many business owners do not realise is that once you collect that information, the law imposes obligations on how you handle it, and in many cases requires you to have a written privacy policy.

This article explains what personal information is under Australian law, when a privacy policy is legally required, what it must contain, and what happens if you get it wrong. It also covers the situations where a business below the usual legal threshold is still caught by the rules — a trap many small businesses walk into without knowing.

What counts as personal information

Under the Privacy Act 1988 (Cth), personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It does not matter whether the information is true or false, or whether it is recorded in a material form.

That definition is deliberately broad. Common examples include:

  • names and contact details (phone numbers, email addresses, physical addresses)
  • dates of birth
  • financial information such as bank account or credit card details
  • tax file numbers
  • health and medical information
  • photos and video footage that identify a person

The "reasonably identifiable" element is important. Even information that seems anonymous can become personal information if, when combined with other details you hold, it would allow you to identify someone. When in doubt, treat information as personal information and handle it accordingly.

The Australian Privacy Principles

The Privacy Act 1988 (Cth) sets out 13 Australian Privacy Principles (APPs), which are the cornerstone of Australia's privacy framework. The APPs cover how organisations must collect, hold, use, disclose, and provide access to personal information. They apply to what the Act calls "APP entities."

The APPs are not a rigid checklist — they are principles-based, which means there is some flexibility in how you implement them depending on your business model. However, that flexibility does not remove the obligation to comply; it simply means the way you comply can be tailored to your circumstances.

Breaching the APPs can expose your business to investigation by the Office of the Australian Information Commissioner (OAIC), enforceable undertakings, and civil penalty proceedings in the Federal Court.

Who is legally required to have a privacy policy

An APP entity must have a clearly expressed and up-to-date privacy policy. Whether your business is an APP entity depends primarily on your annual turnover.

The $3 million threshold

If your business has an annual turnover of more than $3 million, you are an APP entity and the Privacy Act 1988 (Cth) applies to you in full. You must have a privacy policy and comply with all 13 APPs.

Businesses below $3 million that are still covered

This is where many small business operators are caught out. Even if your annual turnover is $3 million or less, you may still be an APP entity — and therefore legally required to have a privacy policy — if your business falls into one of these categories:

  • Health service providers. Any business that provides a health service and holds health information is covered by the Privacy Act 1988 (Cth) regardless of turnover. Health service providers include medical, dental, allied health, and other businesses delivering health-related services.
  • Businesses that trade in personal information. If your business buys or sells personal information, or provides a benefit, service, or advantage in exchange for personal information, you are covered. A common example is selling a list of customer contact details to a third party for direct marketing purposes.
  • Businesses that have opted in. Under s 6EA of the Privacy Act 1988 (Cth), a small business can voluntarily elect to be treated as an APP entity. Businesses do this to signal their commitment to privacy to customers and partners. If you have opted in, the full obligations apply to you just as they would to a larger business.

If none of these exceptions apply and your turnover is $3 million or less, you are not currently required by federal law to have a privacy policy. However, there may be state or territory obligations in specific sectors, and contractual obligations imposed by larger business partners (such as platform operators or payment processors) may require one regardless.

What your privacy policy must contain

Under APP 1, an APP entity's privacy policy must clearly set out:

  • the kinds of personal information the business collects and holds
  • how the business collects and holds that information
  • the purposes for which the business collects, holds, uses, and discloses personal information
  • whether the business is likely to disclose personal information to overseas recipients, and if so, in which countries those recipients are located
  • how an individual can access and seek correction of the personal information you hold about them
  • how an individual can make a complaint about a breach of the APPs and how you will handle that complaint

The policy must be freely available — ordinarily by publishing it on your website — and kept up to date. A privacy policy buried in fine print or behind a login does not satisfy the requirement to make it "available free of charge and in an appropriate form."

What happens if you get it wrong

The OAIC is the federal regulator responsible for enforcing the Privacy Act 1988 (Cth). Its enforcement powers range from investigations and determinations through to civil penalty proceedings in the Federal Court.

Since December 2022, the maximum civil penalty for a serious or repeated interference with privacy is the greater of $50 million, three times the benefit obtained from the conduct, or 30% of the business's adjusted annual turnover during the breach period. In 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties following a data breach affecting over 223,000 individuals — the first time civil penalties were imposed under the Privacy Act 1988 (Cth).

Beyond the financial exposure, APP entities are also subject to the Notifiable Data Breaches scheme. If a data breach occurs that is likely to result in serious harm to the individuals whose information was involved, you must notify both affected individuals and the OAIC. Failing to do so is itself a breach of the Act.

Situations where businesses commonly get this wrong

Even businesses that understand they need a privacy policy frequently make mistakes in practice. Common problems include:

  • Having a policy but not following it. A privacy policy creates a commitment. If your policy says you will not share customer data with third parties, but you then share it with a marketing partner, you are in breach — of your policy and potentially of the APPs.
  • Not updating the policy. Business practices change. If you start collecting new types of information, expand overseas, or change how you store data, your policy must be updated to reflect that.
  • Publishing a template without tailoring it. Generic privacy policy templates found online are not always consistent with Australian law, and they rarely reflect the actual data practices of your business. A policy that does not accurately describe what your business does provides little protection and may itself constitute a misleading representation.
  • Overlooking the overseas disclosure obligation. If you use offshore cloud storage, overseas software-as-a-service providers, or send data to an overseas parent company, you may be disclosing personal information to overseas recipients. This must be disclosed in your policy, and APP 8 imposes obligations about how you handle those cross-border data flows.
  • Assuming the small business exemption always applies. As set out above, the $3 million threshold comes with meaningful exceptions. A small allied health provider or a business that monetises its customer list may be fully covered regardless of revenue.

Privacy compliance is not a once-and-done exercise, and the consequences of getting it wrong have grown substantially since the civil penalty amendments commenced in late 2022. A lawyer experienced in Australian privacy law can assist by:

  • assessing whether your business is currently an APP entity and identifying any obligations you may have overlooked
  • drafting or reviewing a privacy policy that accurately reflects your data collection and handling practices and complies with APP 1
  • advising on cross-border data flows and whether your use of overseas service providers triggers disclosure obligations under APP 8
  • reviewing your data storage and security practices against APP 11's requirement to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access
  • preparing a data breach response plan so that if something goes wrong, you can meet the 30-day assessment obligation under the Notifiable Data Breaches scheme

If you are unsure whether your business needs a privacy policy, or if you have one that has not been reviewed recently, it is worth getting a straightforward assessment before the OAIC asks questions.

Key takeaways

Privacy obligations under Australian law turn on whether your business is an APP entity — but the threshold is not just about size. Even if your annual turnover is under $3 million, you may still be fully covered by the Privacy Act 1988 (Cth) depending on what your business does.

If you are an APP entity:

  • You must have a privacy policy that is clearly expressed, up to date, and freely available
  • Your policy must cover the specific matters required by APP 1, including overseas disclosures and complaints handling
  • You are subject to the Notifiable Data Breaches scheme
  • Serious or repeated breaches can attract civil penalties of up to $50 million

Even if you are not legally required to have a privacy policy, publishing one demonstrates to customers, suppliers, and business partners that you take data handling seriously — and that matters in an environment where privacy expectations are rising and regulatory appetite for enforcement is clearly increasing.