Privacy Ready
← Learn

What Must an Australian Privacy Policy Include Under the Privacy Act?

The short answer

Under APP 1 of the Privacy Act 1988 (Cth), a privacy policy must be freely available, written in plain language, and contain at minimum: what personal information you collect and how you collect it, the purposes for which you use and disclose it, how individuals can access and correct it, how they can complain, and whether you disclose to overseas recipients. From 10 December 2026, policies must also describe any automated decision-making processes that substantially affect individuals.

Free to access APP 1.3 — no login, fee, or registration to read it
Plain language APP 1.4 — clear and plain language required
Kinds of information APP 1.4(a) — what you collect and hold
How collected and held APP 1.4(b) — forms, email, cloud, paper files
Purposes APP 1.4(c)–(d) — why you collect, use, and disclose
Overseas recipients APP 1.4(e) — which countries if any
Access and correction APP 1.4(f)–(g) — how individuals exercise their rights
Complaint process APP 1.4(h) — how to complain and how you handle it
ADM disclosure (new) APP 1 amendment — required from 10 December 2026

What APP 1 actually requires

APP 1 has two distinct parts. APP 1.2 requires you to have and implement practices, procedures, and systems to comply with the APPs — not just to have a policy document, but to actually follow it. APP 1.3 requires the policy to be freely available to anyone without requiring them to pay, register, or provide personal information to access it.

APP 1.4 sets out the specific content. Your privacy policy must include:

  1. The kinds of personal information you collect and hold
  2. How you collect and hold personal information
  3. The purposes for which you collect, hold, use, and disclose personal information
  4. How an individual can access and request correction of the personal information you hold about them
  5. How to complain about a breach of the APPs, and how you handle complaints
  6. Whether you are likely to disclose personal information to overseas recipients, and if so, which countries

A concise, accurate 600–900 word policy is more useful — and more likely to be read — than a 4,000-word document copied from a US template.

What "plain language" means in practice

APP 1.4 requires the policy to be in "clear and plain language." The OAIC's guidelines specifically identify plain English as a requirement. In practice:

  • No undefined legal jargon
  • Short sentences and active voice
  • Organised with headings so readers can find the section they need
  • Written for the reading level of your actual audience

A policy stating "personal data may be utilised in furtherance of our legitimate operational objectives" fails this test. "We use your contact details to respond to your enquiry and process your order" passes it.

What changes on 10 December 2026 — the ADM addition

The Privacy and Other Legislation Amendment Act 2024 amends APP 1 to require disclosure of any automated decision-making process that makes, or substantially assists in making, a decision with a significant effect on an individual. From 10 December 2026, your privacy policy must describe:

  • That you use automated decision-making
  • The kinds of personal information used as inputs
  • The kinds of decisions made or substantially assisted by the process
  • Whether a human reviews the automated output before the decision is acted on

This applies to AI scoring tools, algorithmic approval workflows, automated hiring assessments, and similar systems.

A practical structure for a compliant privacy policy

  1. About this policy — who you are, what the policy covers
  2. What we collect — name, email, phone, payment details, usage data
  3. How we collect it — website forms, email, telephone, third-party sources
  4. Why we collect it — processing orders, invoicing, providing support
  5. Who we share it with — delivery providers, payment processors, cloud services
  6. Overseas recipients — if any tools you use are hosted offshore
  7. How we keep it secure — brief description of security measures
  8. How long we keep it — retention periods for different types of information
  9. Your rights — how to access, correct, and complain
  10. ADM disclosure — from 10 December 2026, where relevant
  11. Contact — your privacy contact email or name

Common mistakes that create non-compliance

  • Copying a US or UK template — the Privacy Act is Commonwealth Australian law; GDPR and CCPA language does not map to the APPs
  • No complaint process described — APP 1.4(h) specifically requires this; many templates omit it
  • An outdated policy — describing tools you no longer use, or missing services added since your last update
  • Inaccessible policy — buried behind a login or only available on request rather than publicly linked
  • No mention of overseas transfers — almost every business using cloud services transfers data offshore; if you use Google Workspace, Stripe, or Mailchimp, your policy must say so

Frequently asked questions

Does a privacy policy need to be a separate page, or can it sit inside Terms & Conditions?

A standalone privacy policy is strongly recommended. The OAIC's guidance emphasises clear, accessible disclosure. Embedding a privacy policy inside dense terms and conditions is likely to fail the "plain language" test and makes it difficult for individuals to find their rights.

Do I need a lawyer to write my privacy policy?

Not necessarily. The content requirements under APP 1.4 are specific and manageable. What the policy needs most is an accurate description of your actual data practices. Legal review of a draft is valuable for larger organisations or those handling sensitive data, but for most small businesses, writing it yourself using OAIC guidance as a framework is entirely feasible.

Can a cookie consent banner replace a privacy policy?

No — they serve different purposes. A cookie banner handles browser consent for tracking technologies; a privacy policy satisfies the APP 1 obligation to be transparent about your overall information practices. You likely need both if you use analytics or advertising cookies.

How often do I need to update my privacy policy?

Every time your data practices materially change — you add a new tool that processes personal information, begin collecting a new category of data, or start disclosing to a new type of recipient. A practical approach is a formal annual review, plus an immediate update whenever you adopt new technology.

What if someone complains my privacy policy is inadequate?

They can lodge a complaint with the OAIC. The OAIC will contact you, give you an opportunity to respond, and may attempt conciliation or investigate. In the first instance, most such complaints are resolved by the organisation updating its policy. Formal enforcement action is more likely where there has been a pattern of non-compliance or a serious underlying breach.

Use the free Privacy Policy Analyser to check your existing policy against APP 1 requirements and find the gaps before the OAIC does.

Analyse my privacy policy →