The ACL Clause Voiding Your 'No Refunds' Website Policy
The Legal Minimum for Australian Business Websites in 2026
The OAIC recorded 2,784 privacy complaints in 2022–23 — the highest annual figure since the Notifiable Data Breaches scheme became law in February 2018. The ACCC continues to pursue businesses publishing misleading refund policies, with civil penalties for Australian Consumer Law breaches reaching up to $50 million following a 2022 legislative uplift. What makes the vast majority of these enforcement outcomes preventable is simple: the businesses involved either had no legal documents on their website, or had copied terms from offshore templates that don't reflect Australian law.
This guide explains which legal documents Australian business websites are required to publish, what each must contain under the Privacy Act 1988 (Cth), the Australian Consumer Law (ACL) under the Competition and Consumer Act 2010 (Cth), and the Spam Act 2003 (Cth) — and what it costs to do it properly. It covers every type of Australian small business, from health practitioners and retail shops to tradespeople and hospitality operators.
This article is an educational resource and does not constitute legal advice. Engage a qualified Australian solicitor to prepare or review legal documents specific to your business.
At a Glance: 7 Legal Documents Every Australian Business Website Should Carry
| Document | Legally Required? | Who Needs It | Risk of Skipping It |
|---|---|---|---|
| Privacy Policy | Yes — for businesses with annual turnover exceeding $3 million, all health service providers, and other specified categories under the Privacy Act 1988 | Any site collecting personal data via forms, analytics, or cookies | OAIC investigation, civil penalty, mandatory data breach notification liability |
| Terms and Conditions | Not by statute — but without them, common law fills the gap unpredictably | All business websites; essential for e-commerce and service bookings | No contractual protection; disputes resolved by court-determined common law defaults |
| Refund and Returns Policy | Yes — must accurately reflect ACL consumer guarantees for all consumer-facing transactions | Any site selling goods or services to consumers | ACCC enforcement, misleading conduct finding, civil penalties up to $50 million |
| Disclaimer | No — but strongly recommended for professional services, health, finance, and trade | Any site publishing advice, recommendations, or professional content | Potential liability for reliance on website content |
| Cookie Policy / Consent Banner | Not under Australian law — but required for EU visitors under GDPR | Any site using Google Analytics, Meta Pixel, or advertising tags | GDPR exposure for EU visitors; consumer trust signal increasingly expected |
| Copyright Notice | No — copyright exists automatically under the Copyright Act 1968 | All sites with original content, photography, copy, or design | Harder to enforce ownership; content more likely to be reproduced without consequence |
| Accessibility Statement | Mandatory for Commonwealth and many state government sites; strongly recommended for commercial sites under the Disability Discrimination Act 1992 | Particularly important for retail, health, and hospitality sites | Disability discrimination complaints under the DDA 1992 |
Privacy Policy: The Legal Document Most Australian Websites Get Wrong
Under Australian Privacy Principle 1 (APP 1) of the Privacy Act 1988 (Cth), any organisation bound by the Act must maintain a clearly expressed, up-to-date privacy policy and make it freely available to anyone who requests it. For websites, a link in every page footer is the minimum standard. The OAIC's guidance is explicit: the policy must be genuinely readable by an ordinary person — not buried in legalese or accessible only through a secondary settings page.
Who Is Bound by the Privacy Act?
An organisation must comply if it meets any of the following:
- Annual turnover exceeds $3 million, including turnover of related bodies corporate under the same ABN group
- It is a health service provider — this includes sole-trader physiotherapists, massage therapists, nutritionists, and psychologists, regardless of turnover
- It is a credit reporting body, or a business that trades in personal information
- It handles tax file number (TFN) information
- It holds a Commonwealth contract or is a contracted service provider for a Commonwealth agency
The $3 million threshold catches growing businesses off guard. A multi-location café group, a trade business adding a second crew, or an e-commerce store gaining national traction can cross this threshold in a single financial year without any corresponding update to their website. From 2025 onward, the Federal Government has signalled a staged expansion of Privacy Act coverage to capture more small businesses — organisations currently below the threshold should treat compliance preparation as forward planning.
What an Australian Privacy Policy Must Contain
APP 1.4 specifies the minimum required contents:
- The kinds of personal information the organisation collects and holds
- How the organisation collects and holds personal information
- The purposes for which it collects, holds, uses, and discloses personal information
- How an individual may access their information and seek correction
- How an individual may complain about a breach of the Australian Privacy Principles, and how the organisation will handle such a complaint
- Whether personal information is disclosed to overseas recipients, and if so, which countries
That last requirement is the most consistently overlooked by Australian small businesses. If your website uses Google Analytics (US), Mailchimp (US), HubSpot (US), Stripe (US), or Klaviyo (US) — which covers the majority of Australian small business websites — personal data is being transferred to servers offshore. APP 8 requires that before disclosing personal information to an overseas recipient, an organisation must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles. A privacy policy that does not mention Google Analytics or your US-based CRM is incomplete under Australian law.
Notifiable Data Breaches: Your Website's Obligation When Something Goes Wrong
Since February 2018, organisations covered by the Privacy Act have been required under the Notifiable Data Breaches (NDB) scheme to notify both the OAIC and affected individuals when a data breach is likely to result in serious harm — including financial loss, identity theft, and serious humiliation. Website incidents triggering notification obligations include: a contact form database exposed through a misconfigured server, an unpatched plugin that exfiltrates customer records, or a phishing attack on admin credentials providing access to customer data. Notification must be made as soon as practicable — the OAIC expects this within 30 days of the organisation becoming aware of a qualifying breach. Your privacy policy should reference the NDB scheme and provide a clear pathway for customers to report a suspected breach.
Terms and Conditions: Defining the Rules Before a Dispute Arises
Terms and conditions — also called "terms of service" or "terms of use" — are not mandated by any single Australian statute. But their absence creates a legal vacuum that common law fills on unpredictable terms. Without documented T&Cs, a customer who disputes a service, demands a refund outside your intended policy, or claims your work caused loss can rely on implied contractual terms that courts determine — often in the consumer's favour. A properly drafted set of T&Cs creates an enforceable contract with users, limits liability where Australian law permits, and establishes clear dispute procedures that keep disagreements out of NCAT, VCAT, and equivalent state consumer tribunals. For a service business like APX Trade Group — licensed electricians in Sydney, well-drafted T&Cs mean quoting procedures, scope change protocols, and payment terms are documented before work begins — and can be relied on if a customer disputes an invoice months later.
The 8 Core Clauses Every Australian Business Website T&Cs Should Include
1. Acceptance of Terms. Specify how a user is deemed to have agreed. A checkbox the user must tick before a form submits or a purchase completes (clickwrap acceptance) provides significantly stronger evidentiary weight than a footer notice users are deemed to accept by browsing (browsewrap). Australian courts have declined to enforce browsewrap terms where the link was not prominently displayed or users had no reasonable opportunity to read the document.
2. Service Description and Scope. What you provide, what you explicitly exclude, and any geographic or temporal limitations. Vague scope definitions are the primary source of commercial disputes for service businesses — if your T&Cs do not define what is included in a fixed-price project, a court will decide.
3. Payment Terms. Price, GST treatment (consumer-facing prices must display GST-inclusive amounts under the ACL's single-price rule), accepted payment methods, due dates, and late payment consequences.
4. Intellectual Property. Your website content, photography, copy, and design are automatically protected by the Copyright Act 1968. A clear IP clause deters infringement and simplifies enforcement. For service businesses producing work for clients, this clause should specify whether ownership of deliverables transfers on payment or is licensed.
5. Limitation of Liability. You can limit liability under Australian law, but you cannot exclude ACL consumer guarantees for consumer transactions. The standard commercial clause — limiting liability to the value of goods or services supplied — is enforceable for B2B transactions but ineffective against consumer claims for statutory guarantees.
6. Dispute Resolution. Specify the governing jurisdiction (an Australian state or territory) and whether parties must attempt mediation before proceedings. Any clause purporting to specify a non-Australian jurisdiction for consumer disputes is an unfair contract term — unenforceable and potentially subject to civil penalties.
7. Modifications Policy. Reserve the right to update your terms and specify how users will be notified. Courts have voided clauses purporting to bind users to future unilateral changes without reasonable notice and an opportunity to exit the arrangement.
8. Termination. Under what circumstances you can suspend or terminate access, and how users can cancel. Since November 2023, automatic renewal clauses without clear cancellation rights are a civil penalty risk under the ACL's unfair contract terms provisions — not merely a term that gets severed, but a provision that can attract a fine.
Australian Consumer Law: The Rules Your T&Cs Cannot Override
The Australian Consumer Law (ACL), contained in Schedule 2 of the Competition and Consumer Act 2010 (Cth), provides consumer guarantees that cannot be excluded, restricted, or modified by contract for consumer transactions. This is the most commonly violated aspect of website compliance and the area where ACCC enforcement is most active. Consumer guarantees require that goods be of acceptable quality, match their description, and that services be provided with due care and skill and achieve any result the consumer made clear they wanted. Any T&C clause saying "no refunds under any circumstances" or "all sales are final" is legally void under the ACL — and publishing it is itself a potential breach of the ACL's misleading conduct provisions. Civil penalties for corporations were increased in 2022 to a maximum of $50 million, or three times the value of the benefit obtained, or 30% of adjusted turnover during the breach period — whichever is greatest. For individuals, the maximum is $2.5 million.
An ACL-compliant refund statement reads: "Our goods come with guarantees that cannot be excluded under the Australian Consumer Law. You are entitled to a replacement or refund for a major failure and to compensation for any other reasonably foreseeable loss or damage." The ACCC provides template language for both goods and services on its website — use it as your starting point. Under the ACL, a person is a "consumer" for any transaction where the price is $100,000 or less, or where the goods or services are ordinarily acquired for personal, domestic, or household use. Most B2C website transactions fall squarely within this definition.
Industry-Specific Legal Requirements
Health and Wellness Practices
Health service providers face the most stringent compliance obligations of any small business category. Under the Privacy Act 1988, they are bound regardless of turnover — a sole-trader remedial massage therapist or naturopath must have a compliant privacy policy from the moment they publish a website with a contact form. Health information is classified as "sensitive information" under the APPs, requiring explicit consent before collection, stricter storage obligations, and stronger protections against disclosure to third parties. For websites for health and wellness practices, compliant legal documentation must be designed into the site architecture before the first patient submits a form — not added as an afterthought.
Hospitality, Food, and Beverage Businesses
Food businesses with online ordering need T&Cs addressing allergen disclosure obligations, delivery scope and timeframes, perishable goods policies, and the moment at which a contract is formed. A business like ZenPacks Australia — eco-friendly food packaging selling to both trade buyers and retail customers needs separate commercial and consumer terms — ACL consumer guarantees apply differently to B2B transactions above $100,000 versus B2C transactions where they cannot be excluded at any price point. Allergen information is a legal requirement under the Australia New Zealand Food Standards Code — updating it when formulations change is a food safety obligation, not a courtesy.
Retail and E-Commerce
Online retail carries the highest ACL compliance exposure of any category. Beyond consumer guarantees, e-commerce T&Cs must address whether product images constitute binding representations under ACL section 29 (they do), how pricing errors are handled, and what your policy is for goods damaged in transit. For websites for retail shops, the most critical compliance issue is the returns and exchange policy — it must never contradict ACL guarantees, and must clearly distinguish between statutory rights and your voluntary change-of-mind policy.
Tradespeople and Service Businesses
Licensed tradespeople need T&Cs addressing quoting procedures, scope change protocols, payment milestones, and licensing disclosures. In NSW, residential building work over $20,000 requires a written contract compliant with the Home Building Act 1989. A tradie website's T&Cs cannot substitute for these statutory contracts — but should clearly inform customers that a formal contract will be provided before work commences, and specify the licence number and insurance details the business holds.
The Hidden Risk of Copy-Paste Terms and Conditions
This is the section most compliance guides skip: why generic T&C templates fail Australian businesses specifically.
1. Jurisdiction mismatch. Any clause specifying "the laws of California" or any non-Australian jurisdiction is unenforceable for Australian consumer transactions. A clause restricting a consumer's access to Australian tribunals is an "unfair contract term" under the ACL — it does not merely get severed, it potentially attracts civil penalties of up to $50 million. Many offshore T&C generators produce exactly this. Using them without Australian legal review is a false economy.
2. Consumer guarantee exclusions. The most common error in copy-paste T&Cs is a blanket "no liability" or "all sales final" clause — void under the ACL for consumer transactions. Publishing such language is itself deceptive: the ACCC's enforcement priorities explicitly include "false claims about consumer rights," and a live policy misrepresenting ACL rights has attracted enforcement action against businesses that never intended to mislead anyone.
3. Missing Australian Privacy Principles disclosures. US and UK templates reference GDPR or the California Consumer Privacy Act but omit the Australian Privacy Principles entirely. The APP 1.4 disclosures — particularly the list of countries to which personal data is disclosed — are simply absent. A business using a UK GDPR template believing it is covered for Australian privacy law is materially exposed to OAIC investigation.
The practical fix: start with an Australian-law template from LawPath or LegalVision, then have an Australian solicitor review and customise it for your specific industry and data practices. The review step is where generic templates break down — a template drafted for "a generic online retailer" will miss the health information obligations applying to a beauty therapist, or the building contract requirements applying to a renovation business.
What It Costs to Do This Properly
| Option | Typical Cost (AUD) | What You Get | Suitable For |
|---|---|---|---|
| Free online generator (US or generic) | $0 | Untailored template, often wrong jurisdiction, no ACL compliance | Not recommended for any Australian business |
| Australian legal template platform (LawPath, LegalVision) | $99–$299 per document | ACL-compliant base template, basic customisation, downloadable | Very low-risk sole traders with simple, single-category offerings |
| Solicitor-drafted full suite (T&Cs, privacy policy, refund policy, disclaimer) | $1,500–$3,000 | Customised to your business, industry-specific, enforceable in Australian courts | Any business with significant online revenue, customer data, or professional liability |
| Annual legal review of existing documents | $200–$500 per review | Updated for legislative changes, new services, platform changes, ACCC guidance | Any business whose T&Cs are more than 12 months old |
The total cost for a compliant legal document suite — privacy policy, T&Cs, refund policy, and disclaimer — prepared by an Australian solicitor sits at approximately $1,500–$3,000. A single customer complaint escalated to NCAT or VCAT typically costs more in time and professional fees than this investment many times over. An annual review is not optional — it is routine maintenance, no different from renewing your domain. If your site runs on a website care plan ($24.95 + GST/month), updating your legal pages as legislation evolves is part of standard site maintenance.
Where to Display Legal Documents for Maximum Enforceability
Placement directly affects enforceability. Australian courts have declined to enforce T&Cs that were difficult to locate or not linked at the point of contract formation.
- Footer links on every page: Privacy Policy, Terms and Conditions, and Refund Policy must appear in the site footer — the minimum standard cited in OAIC and ACCC guidance.
- At the point of contract formation: A mandatory checkbox linking to T&Cs before an enquiry form submits, a booking is confirmed, or a purchase completes provides the strongest evidentiary basis for acceptance.
- In confirmation emails: Transactional emails should reference the key T&C terms relevant to that transaction and link to the full document.
- On quotes, invoices, and estimates: Any document your website generates should cite your T&Cs by URL and state they form part of the agreement.
A Practical Website Legal Compliance Checklist
- Confirm whether your business is bound by the Privacy Act — annual turnover, business category, Commonwealth contract obligations
- Commission or purchase an Australian-law privacy policy listing all third-party data processors, including US-based SaaS tools
- Publish the privacy policy in the footer, accessible from every page on the site
- Commission or purchase T&Cs covering service scope, payment terms, IP ownership, liability limits, and dispute resolution under an Australian jurisdiction
- Review your refund and returns policy against ACL consumer guarantee language; remove any "no refunds" language for consumer transactions
- Add an industry-appropriate disclaimer if your site publishes professional advice, health information, or financial content
- Implement a mandatory checkbox at all points of contract formation — enquiry forms, bookings, purchases — linking directly to your T&Cs
- If your site has EU visitors and uses tracking cookies, implement a cookie consent management solution and update your privacy policy for GDPR
- Set a calendar reminder for an annual legal review
Frequently Asked Questions
Is it a legal requirement to have terms and conditions on an Australian business website?
No single Australian law requires every website to publish terms and conditions. However, two related documents carry statutory force: a privacy policy is mandatory under the Privacy Act 1988 for businesses with annual turnover exceeding $3 million and for all health service providers; and a refund policy must accurately reflect ACL consumer guarantees for any site selling to consumers — meaning a misleading or absent returns page is itself a legal breach. Operating without T&Cs is not illegal, but it removes your primary contractual protection and leaves disputes to common law defaults courts determine, typically in the consumer's favour.
Do I need a privacy policy if my business earns under $3 million per year?
If your business is a health service provider, you must have a privacy policy regardless of turnover — there is no small business exemption for health. If you are not a health provider and turnover is genuinely under $3 million, you are currently exempt from most Privacy Act obligations. Three caveats: (1) The Federal Government has signalled expanding Privacy Act coverage to more small businesses from 2025 onward. (2) If your website has EU-based visitors and uses tracking tools such as Google Analytics or Meta Pixel, GDPR applies independently. (3) Customers increasingly expect a privacy policy — its absence measurably affects conversion rates on contact forms and checkout pages.
Can I copy terms and conditions from another Australian business website?
No. Website content, including legal documents, is protected by copyright under the Copyright Act 1968 from the moment of creation. Reproducing another business's T&Cs without authorisation is copyright infringement. Beyond the legal risk, copied T&Cs are drafted for a different business with a different risk profile and different industry-specific obligations — a clause protecting a software company provides no protection for a physio practice handling sensitive health information.
Do ACL consumer guarantees apply to B2B transactions on my website?
Under the ACL, a person is a "consumer" for transactions where the price is $100,000 or less, or where the goods or services are ordinarily acquired for personal, domestic, or household use. B2B transactions above $100,000 for goods or services used exclusively in trade can contractually modify consumer guarantees. For most small business websites, the majority of transactions fall within the consumer definition — separate T&C documents for business buyers and consumer buyers is the cleanest solution for businesses serving both segments.
What is an unfair contract term under Australian law?
Under the ACL, a term in a standard-form contract is "unfair" if it: (a) causes a significant imbalance in the parties' rights and obligations, (b) is not reasonably necessary to protect the legitimate interests of the party relying on it, and (c) would cause detriment if applied. Common examples include unilateral rights to vary pricing without notice, automatic renewal clauses without clear opt-out mechanisms, and asymmetric termination rights. From November 2023, unfair contract terms became a civil penalty provision — a business can be fined for including an unfair term, not merely have it declared void. The maximum civil penalty is $50 million for corporations.
Does my Australian website need to comply with GDPR?
If your website is accessible to EU residents and you offer goods or services to them, or monitor their behaviour through analytics or advertising cookies, GDPR applies regardless of where your business is located. For most local Australian businesses with a clearly domestic audience, GDPR is not a practical concern. For e-commerce businesses shipping internationally or any site with significant global traffic, GDPR compliance requires a cookie consent management platform, a GDPR-specific privacy notice, and a documented process for handling subject access requests within 30 days.
How often should I update my website's terms and conditions?
Review and update your legal documents whenever: you add a new product or service category; your data practices change (new CRM, payment processor, analytics tool, or mailing list provider); relevant legislation changes; or you receive a customer complaint revealing a gap in your existing terms. As a minimum, conduct an annual review. The two triggers most businesses miss: moving to a new website platform (which changes how customer data is processed), and changes in ACCC enforcement guidance flagging new categories of non-compliant refund language or subscription terms.
What should my refund policy say to be ACL-compliant?
Your refund policy must accurately reflect ACL consumer guarantees. The ACCC's recommended language for goods reads: "Our goods come with guarantees that cannot be excluded under the Australian Consumer Law. You are entitled to a replacement or refund for a major failure and to compensation for any other reasonably foreseeable loss or damage. You are also entitled to have the goods repaired or replaced if the goods fail to be of acceptable quality and the failure does not amount to a major failure." You may add a voluntary change-of-mind returns policy on top of this, but it must be clearly presented as a separate, voluntary benefit — not as a substitute for statutory rights.
When your new website is built to Australian standards — including properly placed, compliant legal pages — Weauto delivers it from $99 + GST, live in 5 business days.
Related reading
weauto builds professional websites for Australian local businesses — live in 5 business days for $99 + GST.