Documents
How to write a privacy policy
A privacy policy says in plain language what personal information a business collects, how and why, who receives it and where, how people can see or correct it, and how to complain. In Australia APP 1.4 lists those contents, and the policy has to be clearly expressed, kept up to date and free to read.
Indunil Asanka · Co-founder
7 min read · Published
To write a privacy policy, list what personal information the business really collects, how and why, who receives it and where they hold it, whether any of it goes overseas and to which countries, how people can access and correct their information, and how to complain. Australian Privacy Principle 1.4 names those contents. Write them in plain language with headings people can scan, publish the policy free of charge, and update it whenever the practice behind it changes.
Who needs one
The OAIC’s small business guidance says most businesses with an annual turnover of $3 million or less are not covered by the Privacy Act, but any business that provides a health service is covered regardless of turnover, and so are some others, such as businesses that trade in personal information. For a covered entity, APP 1.3 requires a clearly expressed and up to date privacy policy, and APP 1.5 requires it to be available free of charge in an appropriate form, usually on the website.
Even an uncovered business often needs one in practice. Payment providers, app stores and marketplaces ask for a policy link, and customers look for one before typing an address. The privacy policy example, for a fictional online plant nursery, is written as if the business were covered, which is the sensible default.
What APP 1.4 requires
The OAIC’s APP 1 guidelines list the information a privacy policy must include, as a minimum:
- the kinds of personal information collected and held
- how it is collected and held
- the purposes for which it is collected, held, used and disclosed
- how a person can access their information and seek correction
- how a person can complain about a breach of the APPs, and how the complaint will be handled
- whether the entity is likely to disclose personal information to overseas recipients
- if so, the countries where those recipients are likely to be, where practicable
The OAIC’s guide to developing a privacy policy adds that the policy does not have to follow that order; the aim is to make the most important information easy to find.
Build it from a list of what you actually do
A policy is a set of true statements, so start from facts rather than a template. List every place personal information enters the business: checkout, newsletter signup, contact form, phone orders, photos sent for advice. Then list every system and supplier that receives it.
The example turns those lists into two tables. The collection table has five rows: name and address when someone orders, email and phone for order confirmation and opted in news, payment details handled by the payment provider and never stored, browsing data to run the site, and photos sent for plant advice. It then says outright that no sensitive information is collected.
The sharing table is the section most policies skip. It names five recipients by role, the payment provider, the courier, the email platform, the analytics service and the accountant, with what each receives, where it is held and why. It ends with a plain sentence: no one else receives your information, and it is never sold.
Purposes are numbered 4.1 to 4.6, from fulfilling orders to preventing fraud, and each points back to rows in the collection table. Marketing is purpose 4.3 and applies only to people who opted in, which is why the signup form matters as much as the policy: the newsletter signup form example shows an unticked consent line that matches a policy like this one. When collection and use reconcile line by line, the policy reads as a record rather than a promise.
The OAIC’s guidance on clear expression says to avoid jargon, legalistic and in house terms, use headings that help people find what applies to them, and write in a style suitable for the web. The example opens with a short “in plain words” callout: the business sells plants online, and the policy describes what it actually does.
Overseas disclosure
If any recipient holds data outside Australia, the policy has to say so and name the countries where practicable. The example states that three of the five services hold data in the United States, that the business checked how each protects personal information before using it, and, in a callout, that Australian privacy law makes the business responsible for what happens to the information overseas.
Check this row carefully. Email platforms, analytics tools, form builders and cloud storage often store data offshore, and the location can change when a supplier updates its terms.
Security, retention and access
Security and retention are not in the APP 1.4 list, but readers look for them and APP 11 requires reasonable steps to protect information and to destroy or de-identify it when no longer needed. Say who has access and how breaches are handled. The example says only the two owners and the store manager can access customer records, each with their own login and two factor authentication, and describes the steps under the Notifiable Data Breaches scheme. A business with more staff and systems usually backs these few lines with an internal information security policy that sets the detail, such as access rules and incident reporting times, so the public policy can stay short.
Retention reads best as a table with a reason for each period: order records kept 7 years because tax law requires it, the marketing list until someone unsubscribes, advice photos 12 months.
For access and correction, give a contact, a response time, how identity is checked and whether it costs anything. The example commits to 30 days, usually confirms identity by a reply from the email on the order, and makes access free unless someone asks for something unusual. Complaints go to the owner first, then to the OAIC.
Keeping it current, section by section
APP 1.3 requires the policy to be up to date, and the OAIC recommends regular review. The example ends with a version history: version 1.0 on 1 August 2025, and version 2.0 on 1 March 2027 adding the sharing table and retention periods. A dated history shows readers and regulators that the policy is maintained, and it tells you which wording applied when.
Set review triggers rather than relying on memory: a new supplier, a new form, a new kind of information or a move of any data offshore.
The table at the end of this article lists twelve sections, what each should say, which APP 1.4 item it answers, and how the nursery example handles it. Use the APP column to confirm nothing required is missing, and the last column as a model for specific wording. The note on privacy policy versus privacy notice explains the shorter notice that sits on each form.
Common mistakes
A copied template. It describes someone else’s suppliers and systems.
“Trusted third parties”. Name recipients by role and say where they hold data.
No overseas row. Offshore storage is common and has to be disclosed.
Promises nobody keeps. A deletion commitment the business cannot actually carry out makes the policy inaccurate.
Employee records mixed in. The OAIC says a private sector employer’s handling of employee records is exempt when directly related to the employment relationship, so staff privacy usually belongs in the employee handbook, not the customer policy. A business that processes data for UK clients may also need a data processing agreement with each of them. For privacy terms inside a contract, the privacy clause page shows sample wording.
Build it
A document here is classified by scale before it is written: composed for one page, flow for two to five pages, and long for six or more, where the document is planned section by section. A table of contents is used only at long scale, with titles that match the headings exactly so page numbers resolve. Tables carry the collection, sharing and retention summaries, and callouts come in four variants: info, warning, success and danger.
Documents do not print citations, so references to the Privacy Act or the APPs are written into the text itself. The AI chat edits text only, so it can rewrite a purpose or a retention reason without touching the tables. The page on long document generation covers the longer scale, and the tutorial on document layout, spacing and page breaks covers keeping tables and headings together across pages.
| Section | What to say | APP 1.4 item | In the example |
|---|---|---|---|
| About this policy | Who you are, your ABN and address, what the policy covers | Supports all items | The nursery, its ABN and a plain words callout |
| What you collect | The kinds of personal information, and whether any is sensitive | 1.4(a) kinds collected and held | Five rows, with nothing sensitive collected |
| How you collect and hold it | Directly, through cookies, from others, and where it is stored | 1.4(b) how collected and held | Directly and through cookies, never bought from third parties |
| Why you use it | Each purpose, and any marketing only by consent | 1.4(c) purposes | Six numbered purposes, 4.1 to 4.6 |
| Who receives it | Each kind of recipient, what they get and where they hold it | 1.4(c) disclosure purposes | Five services with location, and a statement that data is never sold |
| Overseas disclosure | Whether information goes overseas and which countries | 1.4(f) and (g) overseas recipients | Three services holding data in the United States |
| Cookies and analytics | What is tracked and how to opt out | 1.4(a) and (b) | One analytics service and how to block it |
| Security | How it is protected and what happens after a breach | Good practice, APP 11 | Encryption, three people with access, the breach steps |
| Retention | How long each kind is kept and why | Good practice, APP 11 | 7 years for orders, until unsubscribe, 12 months for photos |
| Access and correction | How to ask, identity checks, response time, cost | 1.4(d) access and correction | 30 day responses, free unless something unusual is asked |
| Complaints | Who to contact, response time, and the regulator | 1.4(e) complaints | The owner first, then the OAIC |
| Changes and version history | How changes are published, with dated versions | Keeps the policy up to date under APP 1.3 | Two dated versions with what changed |
A finished example
A privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.
Read the privacy policy template written to the australian privacy principlesQuestions people ask
Does my small business legally need a privacy policy?
Not always. The OAIC says most businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but a business of any size is covered if it provides a health service, and some others are too. Even when the Act does not apply, app stores, payment platforms and marketplaces often require a policy before you can sell through them.
Can I copy a privacy policy template from another website?
You can borrow a structure, but not the content. A privacy policy is a set of statements about what your business actually does, so every line about systems, suppliers, locations and retention has to be checked against your own practice. A copied policy usually describes someone else's email platform, analytics and storage, which makes it inaccurate from day one.
How long should a privacy policy be?
As long as it takes to cover the APP 1.4 matters for your business, and no longer. The OAIC suggests avoiding unnecessary length and using a layered approach, with a short summary linking to the full policy. A small online shop can usually cover everything in four or five pages with tables for what is collected and who receives it.
What is the difference between a privacy policy and a privacy notice?
The policy describes how the business handles personal information in general and must be freely available. A collection notice is given at the point information is collected, on the form or at the counter, and explains what is happening to this person's information right now. Most businesses need both, and the notice can link to the policy for access and complaints.
How often should I update the privacy policy?
Review it at least once a year and whenever something changes behind it: a new supplier, a new analytics tool, a new kind of information, or data moving overseas. APP 1.3 requires the policy to be up to date, so a policy that still names a system you replaced is out of step with the law. Keep old versions with their dates.
Do I need a separate policy for employees?
Usually the customer policy should stay customer facing. The OAIC says a private sector employer's handling of employee records is exempt from the Privacy Act when it is directly related to the current or former employment relationship. Staff privacy is typically covered in the employee handbook or an internal policy, while job applicants are still covered by the customer or public policy.
Written by
Indunil Asanka · Co-founder
Builds the generation pipelines behind OneCraft: the slide, flyer and poster layout engines, the document grid and the render workers that turn a written brief into a finished file.
LinkedIn profileWritten and checked by the OneCraft team. Last checked .
Make your own document
Describe what you need and the generator writes and designs it, then you edit anything you like.
See what it can makeRead next
How to write a code of conduct
Write a code of conduct as a short set of standards, each turned into specific behaviours people can follow, with clear rules for conflicts of interest and gifts, a safe way to raise concerns, graded consequences for breaches, and an acknowledgement people sign. Values alone change nothing; observable behaviours and numbers do.
How to write a memorandum of understanding
Write an MOU as a short record of a shared purpose, what each party contributes, how you will coordinate, how long it runs, and one clause that names exactly which parts are legally binding. That last clause carries most of the risk, because an MOU that never states its own status leaves the question to whoever reads it in a dispute.
How to write a job description
Write a job description around what the role is for and how it will be judged: one purpose sentence, five to eight responsibilities each with a measure, a short list of essential and desirable criteria, the conditions including the pay band, and the reporting line. In Australia any pay rate you publish must meet the award or agreement minimum.
For the steps inside the builder, read the guideon this topic.