- Who must have an APP privacy policy
- The kinds of personal information you collect and hold
- How information is collected and held
- Purposes for collection, use, and disclosure
- Disclosure to third parties
- Overseas disclosures
- Access and correction
- Complaints
- The Notifiable Data Breaches obligation
- Optional and situational clauses
- Where Artificer Legal can help you get the policy right
- The clause that decides whether the policy works
You have received a template privacy policy — or a client or platform has asked you to provide one — and you are trying to work out whether it will actually hold up. The document looks long enough. But length is not the problem. The problem is whether the clauses it contains are accurate, complete, and matched to what your business actually does.
An APP privacy policy is the document required by Australian Privacy Principle 1 (APP 1) under the Privacy Act 1988 (Cth). It is not a terms and conditions document, a cookie notice, or an internal data-handling procedure. It is a public-facing statement of how your organisation collects, uses, holds, and discloses personal information, written so that individuals can find out what you do before they hand their data over. APP 1.4 sets out the minimum contents. Everything else in a well-drafted policy exists to give those mandatory items enough context to be useful.
Who must have an APP privacy policy
The obligation to maintain an APP privacy policy falls on APP entities — organisations and government agencies covered by the Privacy Act 1988 (Cth).
The starting point for private-sector businesses is the small business exemption: a private-sector organisation with an annual turnover of $3 million or less is generally not an APP entity. But the exemption is riddled with carve-outs. A business under the threshold is still covered if it:
- provides a health service (any size)
- trades in personal information for a benefit, service, or advantage
- holds tax file number information
- provides services under a contract with a Commonwealth agency
- is an accredited entity under the Consumer Data Right
- is a related body corporate of a larger covered entity
For businesses that fall outside the Act, a privacy policy remains commercially necessary. Payment processors, app stores, and enterprise clients routinely require one as a condition of doing business.
The kinds of personal information you collect and hold
APP 1.4(a) requires the policy to describe the kinds of personal information the entity usually collects and holds. The word "kinds" matters: it does not require a complete enumeration of every field in every form, but it does require honest categories.
For most businesses, those categories include:
- identity and contact details (names, addresses, email, phone)
- transaction and payment data
- account and login credentials
- device and usage data (IP addresses, cookies, analytics identifiers)
- correspondence and support records
If the business collects sensitive information — health information, biometric data, racial or ethnic origin, religious beliefs, sexual orientation — that must be called out separately. Sensitive information attracts heightened consent requirements under APP 3. Burying it in a generic "personal information" clause without distinction is a common drafting error and one the Office of the Australian Information Commissioner (OAIC) flags in assessments.
Trap: describing only the information you intended to collect. Analytics pixels, chat widgets, booking systems, and payment processors often collect additional data as a side effect of their operation. If those tools run on your site or platform, their outputs are your responsibility.
How information is collected and held
APP 1.4(b) requires the policy to explain how information is collected and held. Collection methods to cover include website forms, account sign-ups, checkout flows, phone and email enquiries, third-party platforms, cookies and tracking pixels, and indirect collection via referrals or data enrichment.
The holding side — how and where personal information is stored, and for how long — is often underdeveloped. Statements like "we take reasonable steps to protect your information" satisfy almost nothing. A better approach identifies the general type of environment (cloud-hosted systems, access-controlled databases), who has access, and what triggers retention or de-identification. Say enough to let a reader understand the general risk profile without disclosing your full security architecture.
Purposes for collection, use, and disclosure
This clause sets the boundary for what you can lawfully do with personal information. APP 6 restricts use and disclosure to the primary purpose of collection, or a secondary purpose the individual would reasonably expect, or one of the statutory exceptions. Your policy's purposes clause defines that primary purpose.
Typical purposes for a small to medium business include:
- providing and improving your services
- processing orders, payments, and deliveries
- responding to enquiries and customer support
- sending service updates and transactional communications
- marketing and promotional communications (where the individual has consented)
- fraud prevention and security
- legal and regulatory compliance
Variant the other side pushes: broad, open-ended purposes (for example, "any purpose related to our business or operations") that effectively eliminate the boundary APP 6 is meant to create. That breadth may also be inconsistent with the requirement under APP 1.4 that the policy be "clearly expressed."
Disclosure to third parties
Most businesses share personal information with third parties even if they do not "sell data." Typical recipients include cloud hosting providers, payment processors, logistics and courier partners, marketing and analytics platforms, professional advisers, and contractors. APP 1.4 does not separately mandate a disclosure clause as a distinct requirement, but the purposes and how-we-hold clauses together should be clear about who receives data and in what capacity.
The practical trap is incompleteness. Businesses that use a large number of SaaS tools often list only the obvious recipients (payment gateway, couriers) and omit the analytics stack, email marketing tools, customer support software, and help-desk systems that process personal information daily. A mismatch between what the policy says and what the toolchain actually does is the most common cause of privacy complaints.
Overseas disclosures
APP 8 imposes accountability obligations when personal information is disclosed to an overseas recipient: the disclosing entity remains responsible for how the overseas recipient handles the information unless the individual has consented or an exception applies. APP 1.4(f) requires the policy to state whether the entity discloses personal information to overseas recipients and, if it is practicable to specify, which countries.
For businesses using global SaaS infrastructure — US-hosted cloud storage, EU-based analytics, Singapore data centres — this clause cannot simply say "we may disclose overseas." It should at minimum identify the likely regions or countries. Do not promise that overseas recipients comply with standards equivalent to the APPs unless you have contractual protections in place: APP 8.1 assumes you have taken reasonable steps to ensure that, and a comfort statement without those protections creates liability.
Access and correction
APP 1.4(d) and (e) require the policy to explain how an individual can access their personal information and how they can request correction of inaccurate data. APPs 12 and 13 give individuals enforceable rights, and your policy must describe a usable path to exercise them.
The clause needs: a specific contact (an email address or postal address, not "contact us"); the form in which requests should be made; an indicative timeframe (APP 12.4 requires a response within 30 days where practicable); and how refusals are handled. Under APP 12, refusal is possible in defined circumstances — prejudice to law enforcement, third-party privacy, commercially sensitive joint deliberations. The policy should acknowledge that and tell the individual what happens next.
Complaints
APP 1.4(e) requires the policy to explain how an individual can complain about a breach of the APPs and how the entity will deal with the complaint. An individual can also complain to the OAIC directly if unsatisfied with internal handling.
At minimum, the clause must:
- name the contact for privacy complaints
- describe the internal process (acknowledgement, investigation, outcome)
- state that an unresolved complaint can be referred to the OAIC
Variant to watch for in templates: a complaints clause that refers only to an internal process with no mention of the OAIC. That omission does not limit the individual's right to go to the regulator, but it does create an impression that internal resolution is the only option.
The Notifiable Data Breaches obligation
The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth) applies to all APP entities. When an eligible data breach occurs — one likely to result in serious harm to an affected individual — the entity must:
- carry out an assessment and take all reasonable steps to complete it within 30 calendar days
- if the breach is eligible, notify the OAIC and affected individuals
The notification statement to the OAIC under s 26WK must include: the identity and contact details of the entity; a description of the breach; the kinds of information involved; and the recommended steps for affected individuals.
A privacy policy is not required to reproduce the NDB scheme in full, but it should tell readers what to expect if a breach occurs — that there is a response process, that notification may occur, and how to contact the entity in that event. Businesses that have never experienced a breach often skip this section. Those that have experienced one understand why it matters.
Optional and situational clauses
The following clauses come up regularly for Australian businesses and are worth including where the trigger applies:
- Children's privacy: where the business offers services to or knowingly collects information from individuals under 18, the Privacy and Other Legislation Amendment Act 2024 (Cth) introduced additional protections for children's personal information that will have flow-on implications for policy drafting.
- Employee records carve-out: the Privacy Act's employee records exemption (s 7B(3)) can create confusion — state clearly whether the policy covers employees, contractors, or only customers.
- Opt-out and marketing preferences: where direct marketing is a purpose, describe the unsubscribe and opt-out mechanism. This intersects with obligations under the Spam Act 2003 (Cth).
- Cookies and tracking technologies: a separate cookie notice or a dedicated section in the privacy policy covering cookies, pixels, and session tracking — particularly relevant for businesses running advertising campaigns or re-targeting.
- Automated decision-making: from December 2026, APP entities will be required to disclose in their privacy policy whether personal information is used in automated decision-making processes that could significantly affect individual rights or interests.
Where Artificer Legal can help you get the policy right
Most disputes and OAIC complaints arise not from missing clauses but from clauses that do not match how the business actually operates. When we review or draft a privacy policy, the focus is on:
- mapping actual data flows before drafting so the policy describes what you do, not an idealised version of it
- flagging purposes or disclosures that are overstated or understated
- identifying third-party tools and overseas recipients the business may have overlooked
- testing the access and complaints process for practical workability
- advising on the small business exemption and whether opting in is strategically preferable
- updating existing policies for the Privacy and Other Legislation Amendment Act 2024 (Cth), including the statutory tort for serious invasions of privacy (commenced 10 June 2025) and the enhanced civil penalties under s 13G (maximum $50 million, or the greater of three times the benefit obtained or 30% of adjusted annual turnover for a body corporate)
A policy drafted for a five-person startup will not serve a 50-person business with a global SaaS stack. If your business is growing, the policy needs to grow with it.
The clause that decides whether the policy works
The purposes clause is the one that matters most in a dispute — and the one most often drafted too broadly or too narrowly. If it is too broad, it offers no real constraint on use and may be challenged as inconsistent with APP 1's requirement that the policy be "clearly expressed." If it is too narrow, it creates a mismatch with what the business actually does and exposes the business to complaints any time it uses information in a way the clause does not anticipate.
A privacy policy is, at its core, a record of a bargain with your customers: here is what we collect, here is what we do with it, here is how you can control it. The policy works when that record is honest. It fails when it describes a business that does not exist.
Key points: APP 1.4 requires an APP privacy policy to cover the kinds of information collected, how it is collected and held, the purposes of collection, access and correction procedures, complaints, and overseas disclosures. The $3 million small business exemption has significant carve-outs including health service providers and TFN holders. The NDB scheme imposes a 30-day assessment obligation. The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a statutory tort for serious invasions of privacy (from 10 June 2025) and enhanced civil penalties under s 13G. The purposes clause is the one that matters most — draft it precisely, and the rest of the policy has a foundation.