Do I Need a Privacy Policy for My Small Business?
What APP 1 actually requires, the 11 elements a compliant policy must cover, and the free tools to check yours.
Yes, if the Privacy Act 1988 (Cth) covers your business — which almost every Australian business will from 1 July 2026. APP 1 requires a clearly expressed, publicly accessible privacy policy covering 11 specific elements. From 10 December 2026, businesses using automated decision-making must also add a dedicated disclosure section.
Last updated: 2 July 2026
Quick reference
| Governing principle | APP 1 — Open and transparent management of personal information |
| Required elements | 11 specific elements, including collection, storage, disclosure and complaint-handling practices |
| Who needs one | Almost every Australian business, from 1 July 2026 |
| New requirement, Dec 2026 | ADM disclosure section, if you use automated decision-making (APP 1.3) |
Where small businesses get this wrong
The most common gap isn't having no policy at all — it's having an outdated or generic one. A policy copied from a GDPR template or a five-year-old boilerplate rarely references the Privacy Act 1988 (Cth) by name, the 13 Australian Privacy Principles, or how to lodge a complaint with the OAIC — all required under APP 1.
The second gap is scope: a policy might cover the main website but not a separate booking system, a contact form, or a third-party CRM that also collects personal information. APP 1 requires the policy to reflect every way the business actually collects and holds personal information, not just the primary channel.
Relevant free tools
Analyse your existing privacy policy against APP 1 requirements.
Find out if the Privacy Act covers your business and which APPs apply.
Check your collection notices cover everything APP 5 requires.
Related Privacy Act questions
When to check your privacy policy
- — Your policy hasn't been updated since before the 2024 reform
- — You're newly covered by the 1 July 2026 exemption removal and don't have one yet
- — You use AI or automated tools and haven't added an ADM disclosure section
- — Your policy was copied from a template that doesn't mention the Privacy Act 1988 (Cth)
- — You've added a new data-collection channel since the policy was last written
Frequently asked questions
Do I need a privacy policy for my small business?
Yes, if the Privacy Act 1988 (Cth) covers your business — which almost every Australian business will from 1 July 2026. APP 1 requires covered entities to have a clearly expressed, publicly accessible privacy policy — a website contact form or client intake process without one is a compliance gap.
What must an Australian privacy policy include?
APP 1 requires 11 specific elements, including: the kinds of personal information collected and held, how it's collected and held, the purposes of collection, whether it's disclosed overseas and to which countries, and how an individual can access, correct, or complain about handling of their information.
Does my privacy policy need an ADM disclosure section?
Yes, from 10 December 2026, if you use AI or automated tools that make or substantially assist a decision affecting an individual. APP 1.3 requires a dedicated section listing each system, the decisions it affects, and how a person can seek human review.
Can I just copy a template from another country?
No. Generic or GDPR-style templates typically don't reference the Privacy Act 1988 (Cth), the 13 Australian Privacy Principles, or the Australian-specific ADM disclosure obligation that applies from 10 December 2026. A policy missing these references does not satisfy APP 1.
Run the free privacy policy checker to see exactly which of the 11 required elements your current policy is missing.
Check my privacy policy →