Back to blog
/14 min read

Does Your Website Need a Privacy Policy? The $2.5M Risk

web-designsmall-businessaustraliaguides
Does Your Website Need a Privacy Policy? The $2.5M Risk

In October 2022, Optus and Medibank suffered data breaches exposing the personal information of millions of Australians. Parliament's response was immediate: the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 lifted maximum civil penalties from $2.22 million to $50 million for corporations — or, for individuals personally liable, $2.5 million per serious breach. If your business website collects so much as an email address through a contact form, you need to understand exactly where you stand under Australian law.

Who Actually Needs a Privacy Policy in Australia?

The short answer is: more businesses than you would expect. The Privacy Act 1988 (Cth) governs how Australian organisations collect, use, store, and disclose personal information. Its enforcement framework — the 13 Australian Privacy Principles (APPs) — applies to:

  • Any Australian Government agency
  • Any organisation with annual turnover above $3 million
  • All health service providers, regardless of turnover — a sole-practitioner GP, a physiotherapist, a dietitian, a psychologist are all covered
  • Businesses that trade in personal information — buying mailing lists, selling customer data, operating a loyalty program that shares member data with partners
  • Businesses that operate a residential tenancy database
  • Businesses related to a larger covered entity — a subsidiary or related company of a business over the threshold
  • Businesses that hold tax file numbers on their systems

The small business exemption — which currently shields businesses under $3 million annual turnover from the Act's full obligations — is living on borrowed time. The Attorney-General's Privacy Act Review Report (February 2023) explicitly recommended removing this exemption. Legislation to enact the Review's recommendations has been progressing through Parliament, and many commercial lawyers are already advising clients to comply with the APPs in full regardless of current turnover. Building compliance now costs far less than retrofitting it later.

Even if you're currently exempt from the Privacy Act, you are not exempt from the Australian Consumer Law (ACL). The ACL prohibits misleading or deceptive conduct — including making false representations about how you handle customer data. If your website implies you won't share data and then you share it, that is an ACL violation regardless of your annual revenue.

And then there is the international dimension: if you collect data from people in the European Union — a tourist booking your accommodation, an expat ordering from your online store — the General Data Protection Regulation (GDPR) applies to you under EU law. GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher.

The 13 Australian Privacy Principles: What They Mean for Your Website

The APPs are the operational core of the Privacy Act. Each one has direct implications for any business operating a website.

APPNameWhat it means for your website
1Open and transparent managementYou must have a clearly expressed, up-to-date privacy policy that is free, accessible, and available on request
2Anonymity and pseudonymityWhere practicable, give people the option to interact with you without identifying themselves
3Collection of solicited personal informationOnly collect information that is reasonably necessary — do not grab data you will never use
4Unsolicited personal informationIf you receive information you did not ask for, destroy or de-identify it if you are not allowed to collect it
5Notification of collectionAt the point of collection, notify people what you are collecting and why — a short disclosure near your contact form
6Use or disclosureOnly use data for the purpose you collected it for, or with consent, or for a directly related secondary purpose
7Direct marketingYou can only send marketing to someone who expected it — and you must provide an easy opt-out mechanism
8Cross-border disclosureIf you send data overseas (e.g. to US-based email platforms), your policy must disclose this and name which countries
9Government-related identifiersDo not adopt government identifiers (TFN, Medicare number) as your own customer identifiers
10Quality of personal informationTake reasonable steps to ensure personal information is accurate, current, and complete
11Security of personal informationProtect personal information from misuse, interference, loss, and unauthorised access — this means SSL certificates, strong passwords, and access controls
12Access to personal informationOn request, give individuals access to the personal information you hold about them
13Correction of personal informationOn request, correct inaccurate, out-of-date, or incomplete personal information promptly

APP 1 is the provision that directly creates the requirement for a published privacy policy. APP 8 is the one most Australian small business websites violate unknowingly: virtually every website sends data overseas without realising it. Google Analytics, Mailchimp, HubSpot, Facebook Pixel, Stripe — all are US-based services processing your visitors' data on servers outside Australia. Your privacy policy must disclose this explicitly.

What Your Privacy Policy Must Actually Say

Under APP 1.4, your privacy policy must contain at minimum:

  1. The kinds of personal information you collect and hold — name, email address, phone number, IP address, payment details, health information
  2. How you collect it — directly from the individual, from third parties, or through automated tools such as cookies and analytics
  3. The purposes for which you collect, hold, use, and disclose it — responding to enquiries, sending invoices, marketing communications, site analytics
  4. How individuals can access their personal information — who to contact and what the process involves
  5. How individuals can seek correction of inaccurate information — the contact details and a reasonable timeframe for response
  6. How individuals can make a privacy complaint — your internal process, and the right to escalate to the Office of the Australian Information Commissioner (OAIC)
  7. Whether you disclose personal information to overseas recipients — and if so, which countries those recipients are located in

These are the legal minimums under the current Privacy Act. A robust policy for a contemporary website also addresses: cookies and tracking technologies, social media integrations, third-party platform links, data retention periods, and — if you have EU visitors — the right to erasure under GDPR.

The Data Your Website Is Already Collecting (Whether You Know It or Not)

This is where most small business owners get a rude shock. You may think you do not really collect data because you just have a basic website. Walk through your actual technology stack:

  • Google Analytics 4: Collects IP addresses, device information, and behavioural data. Data is processed on US servers by Google LLC.
  • Google Search Console: Shows you what queries visitors used — Google is processing your visitors' search behaviour.
  • Facebook Pixel / Meta Pixel: Sends visitor behaviour data to Meta's US servers for advertising targeting and attribution.
  • Contact forms: Name, email address, phone number — textbook personal information under the Privacy Act.
  • Online booking software (HotDoc, Calendly, Square Appointments): Name, email, sometimes health history — sent to third-party servers, often overseas.
  • Live chat widgets: Collect visitor messages and typically IP addresses in real time.
  • Shopify or WooCommerce checkout: Name, shipping address, payment details, and a complete purchase history.
  • Email marketing platforms (Mailchimp, Klaviyo, ActiveCampaign): Subscriber lists stored on US-based servers with significant personal data implications.

If any one of these applies to your website, you are collecting personal information, and you need a privacy policy — regardless of whether you consider yourself a data business.

Health and wellness businesses face an additional layer of obligation. Under the Privacy Act, health information is classified as "sensitive information" and attracts stricter protections than ordinary personal information. A physiotherapy clinic collecting intake forms online, a GP surgery using a booking system, a psychologist offering telehealth sessions — all are collecting sensitive information that requires explicit consent and heightened security measures. For websites for health and wellness practices, this means privacy policy and consent mechanisms need to go substantially beyond a generic small business template.

The Hidden Trap: Cross-Border Disclosure Under APP 8

APP 8 is the provision most Australian small business websites violate without realising it. If you disclose personal information to an overseas recipient, you remain responsible under Australian law for ensuring that recipient handles the data in accordance with the APPs — and if they fail to do so, you are liable, not just them.

"Disclose" means transmitting, making available, or sharing — which is exactly what happens when your contact form submissions go to Mailchimp (US), your payments are processed through Stripe (US), or your analytics data is logged by Google (US).

The solution is not to stop using these services. The solution is to:

  1. List each overseas service in your privacy policy by name and country
  2. Confirm each service has appropriate data protection safeguards in place (they almost all do — check their privacy documentation)
  3. Obtain clear informed consent from users before data is transmitted overseas, typically via a checkbox at your contact form

An example of a compliant disclosure reads: "We use Google Analytics (Google LLC, United States) to analyse website traffic. Personal data may be processed on servers located outside Australia. Google maintains appropriate data protection safeguards; their privacy practices are described at google.com/policies/privacy."

What Happens If You Don't Have a Privacy Policy?

Penalties are the extreme end of a spectrum that begins much closer to everyday reality. Here is the realistic escalation path:

  1. A customer makes a complaint to the OAIC. The Office of the Australian Information Commissioner investigates. Most complaints are resolved through conciliation — typically requiring you to update your practices, apologise, or destroy improperly collected data.
  2. The OAIC issues a determination. They may require specific changes to your practices and can order compensation payments to the complainant. Individual compensation determinations of $5,000–$20,000 are not unusual.
  3. Serious or repeated interference triggers the civil penalty regime: up to $50 million for corporations, up to $2.5 million for individuals.
  4. Criminal penalties apply in the most serious cases — intentional or reckless disclosure of sensitive information for financial benefit.

For most small businesses, the realistic exposure is not a multi-million dollar fine — it is a costly OAIC investigation, forced remediation, reputational damage, and potential compensation payments to affected individuals. The OAIC's 2023–24 Annual Report recorded over 2,900 privacy complaints from the public, a figure that has trended upward each year since the Notifiable Data Breaches scheme was introduced in 2018.

There is also the customer trust dimension. A 2023 OAIC community attitudes survey found that 83% of Australians say they are concerned about the privacy of their personal information online. A missing or inadequate privacy policy signals that you have not considered your customers' data rights — which is a meaningful conversion barrier, particularly in sectors handling sensitive information like health, finance, and legal services.

Privacy Policy vs. Terms and Conditions: What's the Difference?

These are two separate documents serving two separate legal purposes, and conflating them is a common mistake that leaves businesses exposed on both fronts.

DocumentPurposeLegally required?Who it primarily protects
Privacy PolicyExplains how you collect and handle personal informationYes, if the Privacy Act applies to youThe individual (their data rights)
Terms & ConditionsSets out the contractual relationship between you and your customersNo, but strongly advisableThe business (limits liability, defines scope of service)
Cookie PolicyDiscloses what cookies you use and whyRequired under GDPR; best practice for Australian sitesBoth parties
DisclaimerLimits liability for advice, content, or resultsNo, but essential for health, legal, and financial sitesThe business

Businesses handling highly sensitive client data need all four — and sometimes more. Websites for law firms must account for legal professional privilege, solicitor–client confidentiality obligations under their state Law Society rules, and specific trust account disclosure requirements when any online payment processing is involved. A generic website privacy policy template is materially inadequate for a legal practice website.

Free Templates vs. Lawyer-Drafted Policies: A Real Cost Breakdown

OptionCostTime to implementCompliance levelSuitable for
Free template (OAIC guidance documents)$01–2 hours to customise correctlyBasic — only if thoroughly customisedSimple service businesses with minimal data collection
Paid policy generator (Iubenda, Termly, GetTerms.io)$27–$129 AUD/year30–60 minutesGood — templates updated as law changesMost small businesses with standard data practices
Lawyer-drafted, standard$500–$1,5001–2 weeksExcellent — specifically tailored to your businessHealth providers, financial services, higher data volumes
Lawyer-drafted, comprehensive$1,500–$5,000+2–4 weeksComprehensive — covers GDPR, state laws, industry codesRegulated industries, businesses with significant EU traffic

The practical recommendation for most Australian small businesses: use a paid policy generator for a straightforward service or retail website, and invest in a lawyer-drafted policy if you operate in health, childcare, financial services, or legal — or if you collect sensitive information of any kind. For websites for childcare centres, children's data attracts additional protections under both the Privacy Act and state-based education and care legislation, and the Australian Children's Education and Care Quality Authority (ACECQA) has specific information management requirements your policy must reflect.

One critical warning about free templates: a privacy policy that does not accurately describe your actual data practices is worse than no policy at all. It is a documented false representation — exactly the kind of misleading conduct the ACL penalises. A template must be genuinely customised to your business, naming the specific services you use, the specific types of data you collect, and the specific countries your data is sent to. A copy-paste job that describes a different business's data practices creates legal exposure, not legal cover.

The Google and SEO Dimension: How Privacy Affects Your Rankings

Privacy compliance and search visibility are more tightly linked than most business owners realise. Google has been explicit in its Search Quality Evaluator Guidelines that it evaluates websites — particularly those in health, legal, finance, and other high-stakes categories — on trustworthiness. A missing privacy policy is a direct signal against trust.

More measurably: Google Chrome and Safari display prominent security warnings for websites without valid SSL certificates. SSL encrypts data in transit between your site and visitors — which is the technical prerequisite for APP 11 compliance (security of personal information). A website without HTTPS is transmitting your contact form submissions unencrypted across the internet, which is a Privacy Act breach and a Google ranking penalty simultaneously.

Google Analytics is itself a compliance pressure point: Google's Terms of Service for Analytics explicitly require you to have a privacy policy that discloses your use of their product, including a link to Google's own privacy policy. Google can and does suspend Analytics access for non-compliant accounts. If your Google Analytics stops working and you cannot diagnose why in Google Search Console, a missing or non-compliant privacy policy disclosure is one of the first things to check.

Google's E-E-A-T framework (Experience, Expertise, Authoritativeness, Trustworthiness) — the quality model underpinning its ranking systems — specifically rewards trust signals. For any business website in a YMYL category, the presence of a clear, comprehensive privacy policy is one of those signals. Its absence is a flag against you.

The Clause Most Australian Privacy Policies Are Missing

Most privacy policy templates — even paid ones — omit a disclosure that matters: what happens to your data if the business is sold or wound up. Under APP 6, data can only be used for the purpose it was collected, or a directly related purpose. A business sale or asset transfer creates a new purpose that requires either fresh consent from every individual in your database, or a specific contractual arrangement.

Your policy should include a clause along these lines: "In the event of a business acquisition, merger, or asset sale, personal information held by us may be transferred to the acquiring entity as part of that transaction. We will notify affected individuals via email or a prominent website notice prior to any such transfer, and the acquiring entity will be bound by obligations consistent with this privacy policy."

This matters practically across many industries. Hospitality businesses, for example, frequently change hands with customer data — email lists, loyalty program records, booking histories — included in the sale. Eco-conscious suppliers like ZenPacks Australia work across a network of cafés and restaurants where customer and supplier data flows through multiple commercial relationships. Getting the data handling chain documented correctly in your policy is something to do proactively, not after a complaint forces the issue.

How to Publish and Maintain Your Privacy Policy

Writing the policy is step one. Where and how you publish it has its own compliance requirements.

Where it must appear

  • Footer link on every page — labelled clearly as "Privacy Policy", not buried under a generic "Legal" dropdown with six other documents
  • At every point of collection — a disclosure notice near each contact form, booking form, and email signup field
  • During checkout if you sell products or services online
  • In email marketing — the Australian Spam Act 2003 requires commercial electronic messages to identify the sender and include an unsubscribe mechanism; linking to your privacy policy is best practice and required under some platform terms

How often it needs updating

Your privacy policy is a living document, not a set-and-forget page. It requires updating when:

  • You add a new third-party service to your website — a new analytics tool, a new CRM, a new booking system
  • Privacy law changes — and with the Privacy Act Review underway, significant changes are coming
  • You start collecting a new category of information — adding a video testimonial form, for example, means you are now processing video data
  • You change how you use data — for example, starting to send marketing emails to a list that originally opted in only for service notifications

Keeping your policy current is one of the underappreciated benefits of a website care plan ($24.95 + GST/month): having a professional monitor your site for technical changes that trigger policy obligations, rather than discovering 18 months after adding a new plugin that you have been non-compliant the entire time.

State-Based Privacy Laws: The Layer Most Guides Miss

The Privacy Act 1988 is federal legislation, but state and territory privacy frameworks operate concurrently and can apply to your business depending on how you operate:

  • New South Wales: Privacy and Personal Information Protection Act 1998 (PPIPA) — applies to NSW Government agencies and entities they contract with
  • Victoria: Privacy and Data Protection Act 2014 — applies to Victorian Government organisations and their contractors
  • Queensland: Information Privacy Act 2009 — applies to Queensland Government agencies
  • Victoria (health): Health Records Act 2001 — applies to private sector health service providers in Victoria, layering on top of the federal Privacy Act

For most private businesses operating under their own banner, the federal Privacy Act is the primary obligation. But businesses that contract with state government bodies — delivering facilities services, managing government records, running state-funded programmes — may find state privacy laws apply to any government-related data they handle. A licensed electrical contractor like APX Trade Group in Sydney working on government building projects, for instance, may be handling data covered by NSW PPIPA obligations for the duration of those government contracts. It is worth confirming the applicable framework with your legal adviser if you undertake government work.

The Notifiable Data Breaches Scheme: When Things Go Wrong

Since February 2018, organisations covered by the Privacy Act have been required to notify both the OAIC and affected individuals when a notifiable data breach occurs. A notifiable data breach is defined as one that is likely to result in serious harm to any individual whose information was involved.

Serious harm includes financial harm (payment card data exposed), physical harm, psychological harm, embarrassment (health or relationship data exposed), and reputational damage to the individual. Failing to notify is itself a breach of the Privacy Act and can attract its own penalties.

For website owners, a data breach is not necessarily a sophisticated cyberattack. Common scenarios include: a contact form plugin storing submissions in a database that was accidentally left publicly accessible; a WooCommerce vulnerability exposing order records; a staff member emailing a customer database to a personal account; or a shared hosting account being compromised and customer data extracted. These incidents occur on unmanaged websites every week across Australia.

Your privacy policy should describe your data breach response process in plain terms: who to contact, how quickly you will act, and your obligation to notify the OAIC and affected individuals. Even a one-paragraph internal procedure is better than silence on the subject.

Frequently Asked Questions

Does my business need a privacy policy if I'm under $3 million turnover?

Currently, most businesses under $3 million annual turnover are exempt from the Privacy Act 1988 unless they are health service providers, trade in personal information, or hold tax file numbers. However, this exemption is expected to be removed under proposed Privacy Act reforms. Even while exempt, you remain subject to the Australian Consumer Law's prohibition on misleading conduct around data handling, and Google's own Terms of Service require a privacy policy if you run Google Analytics — which includes the vast majority of business websites.

What is the OAIC and what power does it have over my business?

The Office of the Australian Information Commissioner is Australia's federal privacy regulator. It investigates complaints, conducts compliance audits, issues determinations requiring you to change practices or pay compensation, and can seek civil penalties in the Federal Court of up to $2.5 million for individuals and $50 million for corporations in cases of serious or repeated breaches. Most matters resolve through conciliation without reaching court, but the OAIC has been actively ramping up enforcement activity since the 2022 legislative changes.

Can I just copy a privacy policy from another website?

You should not. A privacy policy copied from another business will describe that other business's data practices — not yours. A policy that does not accurately reflect what you actually collect, how you use it, and which third-party services you transmit it to is a false representation. Under the Australian Consumer Law, that false representation creates liability independent of the Privacy Act. Use another policy as a structural reference if you like, but every specific detail must be rewritten to match your actual operations.

Do I need a cookie consent banner on my Australian website?

Under Australian law alone, a consent banner is not strictly mandatory — Australia has no direct equivalent to the EU's ePrivacy Directive. However, if your website is accessible to EU residents (and essentially every public website is), GDPR requires informed consent before non-essential cookies are placed. Google Analytics, Facebook Pixel, and most marketing tools use non-essential cookies, meaning GDPR applies to your use of them for any EU visitor. Adding a consent banner is now considered baseline practice for Australian business websites with any international audience, and it signals to Australian visitors that you take data privacy seriously.

My website is on Wix, Squarespace, or Shopify — does the platform handle privacy compliance for me?

No. The platform provides infrastructure; you remain the data controller. You are the entity collecting personal information, and you are legally responsible for how it is handled. Wix, Squarespace, and Shopify each offer privacy policy templates as starting points — these are generic frameworks that require customisation to your specific business, your specific third-party integrations, and your specific data practices. Using the platform's template unmodified is better than nothing, but it is not compliant in itself.

How long must I keep personal information before I can delete it?

The Privacy Act does not prescribe universal retention periods, but APP 11.2 requires you to destroy or de-identify personal information when you no longer need it for any purpose for which you are permitted to use it. Tax law generally requires financial records to be kept for five years from the date of the transaction. Health records have mandatory retention periods under state and territory legislation — typically seven years for adults from the date of last service, or until the patient turns 25 if they were a child when treated, whichever is longer. Your privacy policy should state your retention period for each category of data you hold, even if it is simply "as long as required by law, then securely deleted."

Does having a privacy policy help my Google rankings?

Not directly — Google does not rank pages based on the presence of a privacy policy. But the indirect effects are significant. Having HTTPS (required for APP 11 compliance) eliminates Google Chrome's security warning and improves Core Web Vitals scores. For health, legal, and financial websites, Google's Quality Rater Guidelines assess trustworthiness explicitly, and a visible, comprehensive privacy policy is a documented trust signal. Its absence is an active negative for E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness), the quality framework Google's ranking systems are built around. Businesses in any YMYL category without a credible privacy policy are at a structural disadvantage in organic search.

What is a data processing agreement and do I need one?

A data processing agreement (DPA) is a contract between you and a third-party service provider that processes personal information on your behalf — your email marketing platform, your CRM vendor, your analytics provider. GDPR formally requires DPAs with all processors. Under the Australian Privacy Act, while the term DPA is not used, APP 8 requires you to ensure overseas recipients handle data in accordance with the APPs, which in practice means having appropriate contractual protections in place. Most major platforms — Google, Mailchimp, Salesforce, Stripe — offer standard DPAs; you typically activate them through your account settings. For any service handling personal data on your behalf, signing or accepting the DPA is prudent risk management.

What the Upcoming Privacy Act Reforms Mean for Your Website

The Privacy Act Review Report delivered to the Attorney-General in February 2023 contained 116 recommendations that would materially reshape privacy obligations for Australian businesses. The key proposed changes affecting small business websites include:

  • Removal of the small business exemption — meaning all businesses, regardless of annual turnover, would be covered by the full Privacy Act framework
  • A new "fair and reasonable" test for data collection — even where consent exists, collection must be objectively fair and reasonable given the circumstances
  • A right to erasure — individuals could request deletion of their personal information, similar to GDPR's right to be forgotten
  • A direct right of action — allowing individuals to sue in court for serious privacy interferences without needing to go through the OAIC first
  • A statutory tort of serious invasion of privacy — creating an entirely new legal cause of action that does not require a Privacy Act breach
  • Expanded definition of personal information — to explicitly include technical identifiers such as IP addresses, device identifiers, and location data

If these reforms pass in full, the compliance threshold for every Australian business website rises significantly. Businesses that have already built compliant privacy policies, implemented proper consent mechanisms, and documented their data practices will find the transition to the new framework straightforward. Those who have deferred the work will face remediation costs that are materially higher than simply doing it now.

If your business needs a professionally built website with the right legal page structure from day one, weauto builds websites for Australian businesses from $99 + GST, live in 5 business days.

Related reading


Ready to get online?

weauto builds professional websites for Australian local businesses — live in 5 business days for $99 + GST.