1. What is actually at stake
    1. Are you actually covered?
  2. Step 1: Map what your website actually collects
  3. Step 2: Draft a privacy policy that covers what you actually do
  4. Step 3: Add collection notices where personal information is collected
  5. Step 4: Review your use-and-disclosure practices
  6. Step 5: Make the policy freely and easily accessible
  7. How Artificer Legal can help
  8. The thing most worth remembering

You built the contact form, connected the analytics, and launched. Somewhere in the rush you skipped the privacy policy — or copied something generic that bears no relation to what your site actually collects. Six months later a client asks where your privacy policy is, or you read something about the Privacy Act 1988 (Cth) and your stomach drops. You are not sure what you have been doing wrong, whether it matters, or where to start.

What is actually at stake

The Australian Privacy Principles (APPs), which form Schedule 1 of the Privacy Act 1988 (Cth), impose binding obligations on "APP entities" — a category that covers most private sector organisations above the $3 million annual turnover threshold, as well as a range of smaller operators caught by specific carve-outs regardless of size (more on those below).

For an APP entity, collecting personal information without a compliant privacy policy is not merely a housekeeping gap. APP 1.3 requires every APP entity to have a clearly expressed and up-to-date privacy policy describing how it manages personal information. APP 5 requires the entity to take reasonable steps to notify individuals about the collection of their personal information at or before the time that information is collected. Running a website with a contact form, a checkout, a newsletter sign-up, or third-party analytics tools — and no policy — means each of those obligations has potentially been breached every time a visitor provided their details or a cookie fired.

The exposure is not abstract. The Office of the Australian Information Commissioner (OAIC) can investigate complaints, conduct assessments, and — following the Privacy and Other Legislation Amendment Act 2024 (Cth) — pursue civil penalties for serious or repeated interferences with privacy. For businesses that have been collecting data at scale without disclosure, the risk is real.

Are you actually covered?

Before remediation, confirm whether the Act applies to your business. The threshold question is annual turnover: under s 6D of the Privacy Act 1988 (Cth), a business with annual turnover of $3 million or less in the previous financial year is ordinarily treated as a small business operator and sits outside the Act's reach.

However, even if your turnover is under $3 million, you are still covered if your business:

  • provides a health service and holds health information about individuals;
  • discloses personal information about individuals for a benefit, service, or advantage — or collects personal information from someone else in exchange for a benefit or service (the "trading in personal information" carve-out, which catches businesses that buy or share mailing lists or customer profiles);
  • provides services under a contract with a Commonwealth agency; or
  • is a related body corporate of an entity that is itself covered by the Act.

If any of these apply to your business, the size of your turnover is irrelevant — the Act applies now.

Step 1: Map what your website actually collects

Before you can write a compliant policy or issue meaningful collection notices, you need to know what personal information your site is already taking in. Work through this systematically:

  • Submitted data: contact forms, quote request forms, checkout pages, account registrations, newsletter sign-ups — any form where a visitor types their name, email address, phone number, postal address, or payment details.
  • Passively collected data: analytics platforms (Google Analytics, similar), advertising pixels (Meta Pixel, Google Ads tags, TikTok Pixel), and session recording tools all collect data about a visitor's device, IP address, browsing behaviour, and in some cases their approximate location. The OAIC has confirmed that tracking pixels and similar tools can constitute collection of personal information where that data is capable of identifying, or reasonably identifying, an individual.
  • Third-party integrations: live chat widgets, CRM auto-sync, booking systems, and embedded review widgets may collect and transmit personal information to offshore processors. If you deploy a third-party tool that collects personal information on your behalf, you remain responsible for how that data is handled — the contract with the third party needs to reflect that.

Document the output of this audit. The categories of personal information you collect, and the third parties you disclose it to, must be reflected accurately in your privacy policy. A policy that lists only what you wish you collected — rather than what you actually collect — is not compliant.

Step 2: Draft a privacy policy that covers what you actually do

APP 1.3 requires the policy to be clearly expressed and kept up to date. APP 1.4 sets out the minimum content, which must include:

  • the kinds of personal information the entity collects and holds;
  • how the entity collects and holds that personal information;
  • the purposes for which the entity collects, holds, uses, and discloses personal information;
  • how an individual may access their personal information and seek correction of it;
  • how an individual may complain about a breach of the APPs, and how the entity will deal with that complaint;
  • whether the entity is likely to disclose personal information to overseas recipients and, if practicable, which countries those recipients are in.

A generic template downloaded from the internet — or one that lists categories of information you do not actually collect — will not satisfy these requirements. The policy must describe your business's actual practices. If your site uses Meta Pixel and passes email addresses to a US-based advertising platform, your policy needs to say so, including that recipients are located in the United States.

The OAIC's guide to developing an APP privacy policy is the primary reference for what the policy must address.

Step 3: Add collection notices where personal information is collected

A privacy policy sitting in the footer satisfies APP 1.3 — but it does not satisfy APP 5. Under APP 5, an APP entity must take reasonable steps to notify individuals of specified matters at or before the time it collects their personal information, or as soon as practicable after.

In practice, for a website this means:

  • A notice at or near each form where personal information is submitted — not buried in the footer, but visible at the point of collection. The notice should identify your business, state the purpose of collection, explain what happens if the information is not provided, and indicate who you are likely to disclose it to.
  • If you use cookies or tracking technologies, your policy and a visible cookie disclosure should explain what is being collected passively and why. This is particularly important where the data collected by third-party pixels is shared with offshore advertising platforms, because that constitutes a cross-border disclosure of personal information under APP 8.

The notice does not need to be lengthy — a short, plain-language statement with a link to the full privacy policy is usually sufficient — but it must be present and it must be accurate.

Step 4: Review your use-and-disclosure practices

Collecting personal information is not the end of your obligations. Under APP 6, an APP entity can only use or disclose personal information for the primary purpose for which it was collected, or for a secondary purpose in limited circumstances (such as where the secondary purpose is directly related to the primary purpose and the individual would reasonably expect it, or where the individual has consented).

Check whether your business is:

  • passing contact form submissions to a third-party CRM or email marketing platform — is this clearly disclosed as a purpose at the point of collection?
  • using behavioural data gathered via analytics to retarget visitors with advertising — was this disclosed as a purpose when the data was collected?
  • sharing customer lists with related entities or suppliers — does your policy and collection notice cover this?

If your current practices go beyond what you have disclosed, you need to either bring the disclosure up to the practice level or bring the practice back to the disclosure level.

Step 5: Make the policy freely and easily accessible

Under APP 1.3, the policy must be freely available. In practice, this means:

  • published on your website with a link in the footer on every page;
  • accessible without requiring a login or account creation;
  • available in an accessible format (not locked inside a ZIP file or a link that returns a 404 error).

Check the link actually works. It is surprisingly common for a business to have drafted a policy but published it at a broken or redirected URL.

Correctly mapping what your business collects, identifying which carve-outs apply, and drafting a policy that accurately describes your practices — rather than a generic document that creates a false sense of compliance — requires a working knowledge of both the APPs and how your business actually operates.

Artificer Legal works with Australian businesses to audit existing data collection practices, identify the obligations that apply, and draft privacy policies and collection notices that reflect the real picture. Where your business uses third-party tracking or advertising tools, we can advise on the cross-border disclosure obligations and what your contracts with those providers need to say. If your business has been collecting personal information without adequate disclosure and you are concerned about retrospective exposure, we can help you assess the risk and structure a remediation response.

The thing most worth remembering

The gap that creates the most exposure is not the absence of a policy on the website — it is the mismatch between what the policy says and what the business actually does. A policy that was drafted once and never updated, or that was copied from another business's site, almost always lags behind the tools the business has deployed since. The moment you add an analytics platform, a Facebook Pixel, a new CRM integration, or a booking widget, your privacy obligations change — and the policy needs to change with them.

The practical approach is to treat the privacy policy as a living document, reviewed whenever you add or change a tool that touches personal information. That habit — not the one-time act of publishing a policy — is what keeps an Australian business on the right side of the Australian Privacy Principles.

The core obligations are: map what you collect (Step 1); draft a policy that reflects that accurately (Step 2); give notice at the point of collection under APP 5 (Step 3); ensure your downstream use and disclosure matches what you have told people (Step 4); and make the policy easy to find (Step 5). If your business falls within the Act — whether because your turnover exceeds $3 million or because one of the s 6D carve-outs applies — each of these is a legal requirement, not a best practice.