Documents

How to write a privacy policy

A privacy policy says in plain language what personal information a business collects, how and why, who receives it and where, how people can see or correct it, and how to complain. In Australia APP 1.4 lists those contents, and the policy has to be clearly expressed, kept up to date and free to read.

· Co-founder

7 min read · Published

To write a privacy policy, list what personal information the business really collects, how and why, who receives it and where they hold it, whether any of it goes overseas and to which countries, how people can access and correct their information, and how to complain. Australian Privacy Principle 1.4 names those contents. Write them in plain language with headings people can scan, publish the policy free of charge, and update it whenever the practice behind it changes.

Who needs one

The OAIC’s small business guidance says most businesses with an annual turnover of $3 million or less are not covered by the Privacy Act, but any business that provides a health service is covered regardless of turnover, and so are some others, such as businesses that trade in personal information. For a covered entity, APP 1.3 requires a clearly expressed and up to date privacy policy, and APP 1.5 requires it to be available free of charge in an appropriate form, usually on the website.

Even an uncovered business often needs one in practice. Payment providers, app stores and marketplaces ask for a policy link, and customers look for one before typing an address. The privacy policy example, for a fictional online plant nursery, is written as if the business were covered, which is the sensible default.

What APP 1.4 requires

The OAIC’s APP 1 guidelines list the information a privacy policy must include, as a minimum:

The OAIC’s guide to developing a privacy policy adds that the policy does not have to follow that order; the aim is to make the most important information easy to find.

Build it from a list of what you actually do

A policy is a set of true statements, so start from facts rather than a template. List every place personal information enters the business: checkout, newsletter signup, contact form, phone orders, photos sent for advice. Then list every system and supplier that receives it.

The example turns those lists into two tables. The collection table has five rows: name and address when someone orders, email and phone for order confirmation and opted in news, payment details handled by the payment provider and never stored, browsing data to run the site, and photos sent for plant advice. It then says outright that no sensitive information is collected.

The sharing table is the section most policies skip. It names five recipients by role, the payment provider, the courier, the email platform, the analytics service and the accountant, with what each receives, where it is held and why. It ends with a plain sentence: no one else receives your information, and it is never sold.

Purposes are numbered 4.1 to 4.6, from fulfilling orders to preventing fraud, and each points back to rows in the collection table. Marketing is purpose 4.3 and applies only to people who opted in, which is why the signup form matters as much as the policy: the newsletter signup form example shows an unticked consent line that matches a policy like this one. When collection and use reconcile line by line, the policy reads as a record rather than a promise.

The OAIC’s guidance on clear expression says to avoid jargon, legalistic and in house terms, use headings that help people find what applies to them, and write in a style suitable for the web. The example opens with a short “in plain words” callout: the business sells plants online, and the policy describes what it actually does.

Overseas disclosure

If any recipient holds data outside Australia, the policy has to say so and name the countries where practicable. The example states that three of the five services hold data in the United States, that the business checked how each protects personal information before using it, and, in a callout, that Australian privacy law makes the business responsible for what happens to the information overseas.

Check this row carefully. Email platforms, analytics tools, form builders and cloud storage often store data offshore, and the location can change when a supplier updates its terms.

Security, retention and access

Security and retention are not in the APP 1.4 list, but readers look for them and APP 11 requires reasonable steps to protect information and to destroy or de-identify it when no longer needed. Say who has access and how breaches are handled. The example says only the two owners and the store manager can access customer records, each with their own login and two factor authentication, and describes the steps under the Notifiable Data Breaches scheme. A business with more staff and systems usually backs these few lines with an internal information security policy that sets the detail, such as access rules and incident reporting times, so the public policy can stay short.

Retention reads best as a table with a reason for each period: order records kept 7 years because tax law requires it, the marketing list until someone unsubscribes, advice photos 12 months.

For access and correction, give a contact, a response time, how identity is checked and whether it costs anything. The example commits to 30 days, usually confirms identity by a reply from the email on the order, and makes access free unless someone asks for something unusual. Complaints go to the owner first, then to the OAIC.

Keeping it current, section by section

APP 1.3 requires the policy to be up to date, and the OAIC recommends regular review. The example ends with a version history: version 1.0 on 1 August 2025, and version 2.0 on 1 March 2027 adding the sharing table and retention periods. A dated history shows readers and regulators that the policy is maintained, and it tells you which wording applied when.

Set review triggers rather than relying on memory: a new supplier, a new form, a new kind of information or a move of any data offshore.

The table at the end of this article lists twelve sections, what each should say, which APP 1.4 item it answers, and how the nursery example handles it. Use the APP column to confirm nothing required is missing, and the last column as a model for specific wording. The note on privacy policy versus privacy notice explains the shorter notice that sits on each form.

Common mistakes

A copied template. It describes someone else’s suppliers and systems.

“Trusted third parties”. Name recipients by role and say where they hold data.

No overseas row. Offshore storage is common and has to be disclosed.

Promises nobody keeps. A deletion commitment the business cannot actually carry out makes the policy inaccurate.

Employee records mixed in. The OAIC says a private sector employer’s handling of employee records is exempt when directly related to the employment relationship, so staff privacy usually belongs in the employee handbook, not the customer policy. A business that processes data for UK clients may also need a data processing agreement with each of them. For privacy terms inside a contract, the privacy clause page shows sample wording.

Build it

A document here is classified by scale before it is written: composed for one page, flow for two to five pages, and long for six or more, where the document is planned section by section. A table of contents is used only at long scale, with titles that match the headings exactly so page numbers resolve. Tables carry the collection, sharing and retention summaries, and callouts come in four variants: info, warning, success and danger.

Documents do not print citations, so references to the Privacy Act or the APPs are written into the text itself. The AI chat edits text only, so it can rewrite a purpose or a retention reason without touching the tables. The page on long document generation covers the longer scale, and the tutorial on document layout, spacing and page breaks covers keeping tables and headings together across pages.

Privacy policy sections: what each should say and the APP 1.4 item it answers, with how the online nursery example handles it. General information for Australian businesses, not legal advice.
SectionWhat to sayAPP 1.4 itemIn the example
About this policyWho you are, your ABN and address, what the policy coversSupports all itemsThe nursery, its ABN and a plain words callout
What you collectThe kinds of personal information, and whether any is sensitive1.4(a) kinds collected and heldFive rows, with nothing sensitive collected
How you collect and hold itDirectly, through cookies, from others, and where it is stored1.4(b) how collected and heldDirectly and through cookies, never bought from third parties
Why you use itEach purpose, and any marketing only by consent1.4(c) purposesSix numbered purposes, 4.1 to 4.6
Who receives itEach kind of recipient, what they get and where they hold it1.4(c) disclosure purposesFive services with location, and a statement that data is never sold
Overseas disclosureWhether information goes overseas and which countries1.4(f) and (g) overseas recipientsThree services holding data in the United States
Cookies and analyticsWhat is tracked and how to opt out1.4(a) and (b)One analytics service and how to block it
SecurityHow it is protected and what happens after a breachGood practice, APP 11Encryption, three people with access, the breach steps
RetentionHow long each kind is kept and whyGood practice, APP 117 years for orders, until unsubscribe, 12 months for photos
Access and correctionHow to ask, identity checks, response time, cost1.4(d) access and correction30 day responses, free unless something unusual is asked
ComplaintsWho to contact, response time, and the regulator1.4(e) complaintsThe owner first, then the OAIC
Changes and version historyHow changes are published, with dated versionsKeeps the policy up to date under APP 1.3Two dated versions with what changed

A finished example

A privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.

Read the privacy policy template written to the australian privacy principles

Questions people ask

Does my small business legally need a privacy policy?

Not always. The OAIC says most businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but a business of any size is covered if it provides a health service, and some others are too. Even when the Act does not apply, app stores, payment platforms and marketplaces often require a policy before you can sell through them.

Can I copy a privacy policy template from another website?

You can borrow a structure, but not the content. A privacy policy is a set of statements about what your business actually does, so every line about systems, suppliers, locations and retention has to be checked against your own practice. A copied policy usually describes someone else's email platform, analytics and storage, which makes it inaccurate from day one.

How long should a privacy policy be?

As long as it takes to cover the APP 1.4 matters for your business, and no longer. The OAIC suggests avoiding unnecessary length and using a layered approach, with a short summary linking to the full policy. A small online shop can usually cover everything in four or five pages with tables for what is collected and who receives it.

What is the difference between a privacy policy and a privacy notice?

The policy describes how the business handles personal information in general and must be freely available. A collection notice is given at the point information is collected, on the form or at the counter, and explains what is happening to this person's information right now. Most businesses need both, and the notice can link to the policy for access and complaints.

How often should I update the privacy policy?

Review it at least once a year and whenever something changes behind it: a new supplier, a new analytics tool, a new kind of information, or data moving overseas. APP 1.3 requires the policy to be up to date, so a policy that still names a system you replaced is out of step with the law. Keep old versions with their dates.

Do I need a separate policy for employees?

Usually the customer policy should stay customer facing. The OAIC says a private sector employer's handling of employee records is exempt from the Privacy Act when it is directly related to the current or former employment relationship. Staff privacy is typically covered in the employee handbook or an internal policy, while job applicants are still covered by the customer or public policy.

Written by

Indunil Asanka · Co-founder

Builds the generation pipelines behind OneCraft: the slide, flyer and poster layout engines, the document grid and the render workers that turn a written brief into a finished file.

LinkedIn profile

Sources

Written and checked by the OneCraft team. Last checked .

Make your own document

Describe what you need and the generator writes and designs it, then you edit anything you like.

See what it can make

Read next

For the steps inside the builder, read the guideon this topic.