Almost every business website collects personal information. A contact form collects names, email addresses and phone numbers. A newsletter sign-up collects email addresses. An online store collects delivery addresses and order histories. Analytics and advertising tools collect information about visitors’ devices and behaviour, often through cookies. Apps may collect location, contacts or usage data.
A privacy policy tells people what you collect, why, how you use and protect it, who you share it with and how they can access or complain about it. For some businesses it is a legal requirement. For all businesses it is a matter of trust, and increasingly a practical requirement of advertising platforms, app stores, payment providers and larger customers.
This article explains why privacy policies matter, how Australian privacy law applies to small businesses, what a good policy should contain, and how to keep your practices consistent with your policy. It is general information, not legal advice.
Why a privacy policy matters
Legal compliance. Under the Privacy Act 1988 (Cth), organisations covered by the Act must manage personal information in line with the 13 Australian Privacy Principles (APPs). APP 1 requires them to have a clearly expressed and up-to-date privacy policy.
Trust. Customers are more willing to share information with businesses that explain clearly what they will do with it. Data breaches and misuse of data have made people more cautious.
Platform requirements. Many advertising platforms, app stores, payment gateways and software services require you to publish a privacy policy if you use their tools to collect information from users.
Customer and contract requirements. Larger customers, especially in regulated industries and government, may require suppliers to demonstrate sound privacy and data-handling practices.
Clarity inside the business. Writing a privacy policy forces you to work out what information you actually collect, where it is stored, who has access and how long you keep it. Many businesses discover data they did not know they held.
Does the Privacy Act apply to your business?
The Privacy Act applies to Australian Government agencies and to organisations with an annual turnover of more than $3 million. Many small businesses with turnover of $3 million or less are exempt, but there are important exceptions. The Act still applies to small businesses that, among others:
- Provide a health service and hold health information.
- Trade in personal information, for example by buying or selling it.
- Are contracted service providers to the Australian Government.
- Are credit reporting bodies, or are related to a larger business that is covered.
- Have chosen to opt in to coverage.
Check the Office of the Australian Information Commissioner (OAIC) guidance to confirm whether your business is covered. Privacy law has been changing. Reforms passed in late 2024 added new measures, including a statutory tort for serious invasions of privacy, and further changes have been proposed, including to the small business exemption. Review your position periodically.
Even if your business is currently exempt, adopting good privacy practices and publishing a clear policy is sensible. It builds trust, satisfies platform and customer requirements, and prepares you for growth or legal change. Other laws may also apply regardless of the Privacy Act, including the Spam Act 2003 for marketing emails and messages, consumer law, and overseas laws such as the EU’s General Data Protection Regulation if you target customers in other jurisdictions.
What a good privacy policy covers
1. What information you collect
Describe the kinds of personal information you collect and hold. Typical categories include:
- Information people give you: names, contact details, company, enquiry details, delivery addresses, account registrations and subscriptions.
- Information about other people that users provide, such as a referral or an additional contact.
- Transaction information: orders, payments (often handled by a payment provider) and history.
- Information collected automatically: IP addresses, device and browser information, pages viewed and similar log information.
- Cookies and similar technologies used for site functions, analytics or advertising.
2. How you collect it
Explain whether you collect information directly from individuals (forms, emails, calls), automatically (cookies, logs), or from third parties (partners, public sources, platforms).
3. Why you collect and use it
State the purposes clearly: responding to enquiries, providing quotes and services, processing orders, managing accounts, sending updates people have agreed to receive, improving your website, meeting legal obligations and so on. Collect only what you need for those purposes. Collecting information you do not need increases risk and erodes trust.
If you use information for direct marketing, explain how people can opt out. Under the Spam Act, commercial electronic messages generally require consent, must identify the sender and must include a working unsubscribe facility.
4. Who you disclose it to
Explain the kinds of third parties that receive personal information. These commonly include IT and hosting providers, email and form-handling services, payment processors, delivery companies, professional advisers, and anyone you are legally required to disclose information to. If you sell or share information for others’ marketing, say so clearly, and check whether that makes the Privacy Act apply to you.
5. Overseas disclosure
Many cloud services store or process data overseas. If personal information is likely to be disclosed to overseas recipients, say so and, where practicable, name the countries. Explain how you protect it, for example by using reputable providers with appropriate security and contractual safeguards. Covered organisations have obligations under APP 8 when disclosing personal information overseas.
6. Security
Describe in general terms how you protect information: secure hosting, encrypted connections, access controls, MFA, staff training and reputable service providers. Do not over-promise, because no system is perfectly secure. Under APP 11, covered organisations must take reasonable steps to protect personal information and to destroy or de-identify it when it is no longer needed.
7. Retention
Explain how long you keep information, or the criteria you use, such as “for as long as needed to respond to your enquiry and for our business records, then securely deleted”.
8. Access, correction and deletion
Explain how people can ask to access the information you hold about them, ask for it to be corrected, or ask you to delete their account or information where appropriate. Under APPs 12 and 13, covered organisations must generally provide access and correct inaccurate information on request, subject to limited exceptions.
9. Children
If your products or services are not intended for children, say so. If children may use your services, consider additional care in what you collect and how you obtain consent. Children’s online privacy is an area of active regulatory development in Australia, and overseas laws may impose specific age-based rules.
10. Cookies and tracking
Explain what cookies and similar technologies you use, and why. Common categories include:
- Essential: needed for the site to work, such as security, forms and shopping carts.
- Analytics: understanding how visitors use the site.
- Advertising and retargeting: showing ads to people who have visited the site, often through third-party platforms.
Explain how visitors can control cookies through browser settings or a consent tool. Australia does not have an EU-style cookie consent law, but if cookies collect personal information, privacy obligations apply. If you target visitors in the EU or UK, their cookie consent rules may apply.
Retargeting is a good example of why transparency matters. A visitor looks at products on one site and later sees ads for those products on social media. To many people, this feels uncomfortable. Explaining it openly, and offering choices, maintains trust.
11. Complaints and contact
Provide a clear way to ask questions or complain, such as an email address or contact form, and explain how complaints are handled. Tell people that if they are not satisfied, they may be able to complain to the OAIC.
12. Updates
State when the policy was last updated and how changes will be communicated.
Make your practices match your policy
A privacy policy is a promise. A policy that says one thing while the website does another creates legal and reputational risk. To keep them aligned:
- Map your data. List every place personal information enters the business: website forms, email, phone, social media, online store, CRM, accounting system, recruitment and so on. Note where it is stored, who can access it and how long it is kept.
- Review your tools. Check what each plugin, analytics script, advertising pixel, chat widget and form service collects, and where it sends data.
- Minimise. Remove form fields, tools and stored data you do not need.
- Secure. Apply access controls, MFA and secure configurations, and choose reputable providers.
- Train staff on handling personal information, including not sending spreadsheets of customer data through unsecured channels.
- Plan for breaches. Know how you would respond to a data breach. Covered organisations must notify affected individuals and the OAIC of eligible data breaches likely to result in serious harm under the Notifiable Data Breaches scheme.
- Review regularly, at least annually and whenever you add a new tool or process.
A worked example: a small manufacturer’s website
A small manufacturer’s website has a quote request form, a newsletter sign-up, an analytics tool and an embedded map. Its review finds:
- The quote form collects name, company, email, phone and project details, and sends them by email through a form-handling service. This is reasonable and necessary.
- The form also asked for date of birth, a leftover from a template. This field is removed.
- The newsletter tool stores subscribers in an overseas cloud service. The policy is updated to disclose this and describe the safeguards.
- An old advertising pixel from a past campaign is still on the site, sending visitor data to an ad platform. It is removed.
- Quote request emails are kept indefinitely in a shared inbox. A retention rule is introduced: enquiries that do not become customers are deleted after two years.
The business then publishes a clear, accurate policy that matches what the site actually does. The exercise takes a day and reduces both risk and clutter.
Common privacy mistakes in small businesses
- Collecting more than needed: long forms asking for information that is never used.
- Forgotten tools: old tracking pixels, plugins and integrations still collecting data long after a campaign or trial ended.
- Unsecured sharing: customer lists sent as spreadsheet attachments, stored on personal devices or left in shared folders with broad access.
- No retention rules: years of enquiries, CVs and customer records kept indefinitely “just in case”.
- Shared logins to systems containing personal information, so access cannot be controlled or traced.
- Marketing without consent: adding enquirers or business-card contacts to newsletters without permission, or omitting unsubscribe links.
- Ignoring requests: not responding when someone asks what information you hold or asks to be removed.
- Policy drift: the website changes but the policy does not.
Each of these is easy to fix once identified, and fixing them reduces both legal risk and the damage if a breach ever occurs.
Writing style
Privacy policies are often unreadable legal documents. Plain-language policies are more useful and more trustworthy:
- Use headings that match people’s questions: “What we collect”, “How we use it”, “Who we share it with”, “Your choices”.
- Use short sentences and everyday words.
- Be specific about your actual practices rather than copying a generic template.
- Consider a short summary at the top, with detail below.
You can see a plain-language example in GoCore’s own privacy policy.
Frequently asked questions
Can I copy a template? A template is a starting point, but it must be adapted to what your business actually does. Generic templates often describe practices you do not follow and miss tools you do use.
Do I need a lawyer? For a simple website, many businesses write their own policy using OAIC guidance. If you handle sensitive information, such as health information, trade in data, operate internationally or are covered by the Privacy Act, legal advice is worthwhile.
Where should the policy be published? Link it in the website footer and near forms that collect personal information, and make it available in apps and on request.
Summary
A privacy policy explains what personal information you collect, why, how you use, share and protect it, and how people can access it or complain. The Privacy Act and its 13 principles apply to many businesses, including some small ones, and privacy law continues to evolve. Even where it is not strictly required, a clear and accurate policy builds trust and meets platform and customer expectations. Map your data, minimise what you collect, secure what you keep, review your website tools and make sure your practices match your promise.
Sources: small-business training notes on privacy policies for websites and mobile apps, updated with Australian requirements under the Privacy Act 1988 and the Australian Privacy Principles as described by the Office of the Australian Information Commissioner. This article is general information, not legal advice.
