Contract clause
Privacy clause in a service contract
A privacy clause is the short term in a customer facing contract or form that tells the individual what personal information is collected, why, who receives it and where the full privacy policy can be read. It works as a collection notice with consent attached, not as a full set of supplier data handling obligations.
Most people meet a privacy clause as the paragraph above a signature line or a tick box on a sign up form. Those few sentences carry the notice the Australian Privacy Principles expect at the moment of collection, so they need to be accurate rather than generic.
Indunil Asanka · Co-founder
4 min read · Published
Sample clause
the membership terms signed by new members of Crestwater Swim and Fitness, a fictional aquatic centre in Ballina
14. Your Privacy 14.1 Crestwater Swim and Fitness collects your name, contact details, date of birth, emergency contact and any health information you choose to give Crestwater in the pre exercise questionnaire. 14.2 Crestwater uses this information to manage your membership, to process payments through its direct debit provider, and to respond safely if you are injured or unwell at the centre. 14.3 If you do not provide your contact and payment details, Crestwater cannot activate your membership. 14.4 Crestwater discloses your payment details to its direct debit provider, which stores them in Australia, and does not otherwise disclose your information unless the law requires it. 14.5 Crestwater's Privacy Policy, available at reception and on its website, explains how to access or correct your information and how to complain about a privacy breach. 14.6 By signing this form you consent to Crestwater collecting and using the health information in clause 14.1 for the purposes in clause 14.2.
Sample wording, not legal advice.
Variants
Consent based, for sensitive information
The form collects health or other sensitive information, which generally needs the individual's consent to collect.
By ticking this box, you consent to the Practice collecting the health information you provide on this form, including your medical history, current medications and the reason for your visit, and using it to assess and treat you. You may withdraw this consent by telling reception in writing, but the Practice may then be unable to continue treating you. Information already used to provide care before the withdrawal is kept as part of your clinical record.
Notice based, for ordinary contact details
Only routine information is collected for an obvious purpose, so the clause informs rather than asks.
The Company collects your name, email address, phone number and delivery address so it can process your order, arrange delivery and contact you about that order. Your details are shared with the courier that delivers your goods and with the payment processor that handles your card. If you do not provide them the order cannot be fulfilled. The Privacy Policy on the Company's website explains how to access or correct your information or make a complaint.
Policy incorporated by reference
A business to business agreement where the individuals are contact people and the policy already covers every point.
Each party must handle any personal information it receives about the other party's personnel in accordance with the Privacy Act 1988 (Cth) and its published privacy policy, as amended from time to time. Each party must ensure that its own personnel whose details are given to the other party have been told that their details will be disclosed for the purpose of administering this agreement.
What to negotiate
Consent or notice
Businesses often ask for broad consent to everything because it feels safer. Consent bundled into membership terms, with no real choice, is weak evidence of agreement. The practical approach separates the two: a notice for routine information needed to provide the service, and a specific, separate consent for sensitive information such as health details.
How much detail belongs in the clause
Long clauses go unread, short ones leave out what the notice principle expects. The usual compromise lists the kinds of information, the main purposes, the key recipients and what happens if details are not provided, then refers to the privacy policy for access, correction and complaints. The clause should never contradict the policy it points to.
Changing the policy later
Businesses want to update the privacy policy without reissuing every signed contract. Individuals and business customers want to know about material changes. Incorporating the policy as amended from time to time is common, paired with a commitment to publish changes and to seek fresh consent before using information for a purpose that was not disclosed.
The risk of leaving it out
A business covered by the Privacy Act that collects details on a form without a privacy clause may not have given the notice APP 5 expects at or before collection. For health information, it may also lack the consent it needs, which leaves the collection itself open to challenge.
What the notice at collection has to cover
APP 5 requires an entity to take reasonable steps to tell an individual certain matters at or before the time it collects their personal information, or as soon as practicable afterwards. They include the entity's identity and contact details, the purposes of collection, the consequences if the information is not collected, the usual recipients, whether the information is likely to go overseas, and that the privacy policy explains access, correction and complaints. A privacy clause on a form is the most reliable way to give that notice, because it sits in front of the person at the moment they hand the information over.
Privacy clause or data protection clause
The two are easy to confuse because both mention privacy. A privacy clause speaks to the individual whose details are collected, usually a customer, member or patient, and explains what will happen to their information. A data protection clause governs what a supplier or partner may do with personal information it receives under a commercial contract, with use limits, security duties and breach reporting. A membership form needs the first. A payroll outsourcing agreement needs the second. Many service businesses need both, one in their customer terms and one in their supplier contracts.
Where it sits in a generated document
In generated customer terms the privacy clause is usually one of the last numbered clauses, just before the signature block. The generator writes every value as content, so the named payment provider and the storage location must be real before the document goes out. Where a signer block is added, each named party becomes one signer, which suits a membership form signed by a single member.
Documents that carry this clause
Privacy policy template written to the Australian Privacy PrinciplesA privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.
Service agreementBeacon Systems supports Harlow Freight’s IT for an initial 24 months from 1 October 2026 at $8,400 a month plus GST, with 40 hours included and $220 an hour beyond them. Twelve numbered clauses cover the services, a four level severity table, client duties, fees with a CPI adjustment, confidentiality, privacy, IP, a liability cap, termination and a three step dispute ladder.
IT support services agreement with response times by priorityManaged support is sold on a monthly fee and judged on how fast the phone gets answered when nobody can work. This agreement grades every ticket into four priorities with a published response and resolution target, credits the fee when the target is missed, and writes down exactly what the provider hands back on the way out.Questions people ask
Does every business contract need a privacy clause?
No. The clause matters where a business collects personal information from individuals, such as customers, members or patients, and is covered by the Privacy Act. Many small businesses with annual turnover of $3 million or less are not covered, although some are, including those providing health services. Contracts between businesses usually need a data protection clause instead.
Is ticking a box enough consent?
It can be, if the box is not pre ticked, the wording says clearly what is being agreed to, and the person has a genuine choice. A tick box buried in terms that must be accepted to buy anything is weaker. Consent for sensitive information such as health details works best as its own separate statement.
Can a privacy clause just link to the privacy policy?
A link alone rarely gives the notice APP 5 expects, because the individual has to go looking for the key points. The clause should state the main purposes, recipients and consequences on the form itself, then refer to the policy for access, correction and complaints. Short and specific works better than a bare reference.
Where should the clause appear on a form?
Before or beside the point where information is handed over or the form is signed, so it is seen at the time of collection. A clause placed only on a page the person never reaches, or after submission, does little. On a paper or PDF form, directly above the signature line is the usual spot.
Does the clause need to mention overseas recipients?
If the business is likely to disclose the information overseas, APP 5 expects the notice to say so and, where practicable, to name the countries. A cloud booking system or offshore payment processor can trigger this. The clause should match what the privacy policy says about overseas disclosure, and both should reflect the actual suppliers used.
What if the clause and the privacy policy disagree?
A disagreement means at least one of them misdescribes actual practice, and a notice that misstates what happens to information does not give the individual the notice APP 5 expects. Reviewing both together whenever a new supplier, system or purpose is added keeps the promise on the form consistent with what the business really does.
Put the clause in a finished document
The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.
Create a document with OneCraftRelated clauses
- Data protection clauseA data protection clause sets how a supplier handles personal information under the contract. Australian Privacy Act sample, UK GDPR and US variants.
- Marketing consent clause and opt in wordingA marketing consent clause records permission to send marketing messages. Australian Spam Act sample for an event form, with UK PECR and US CAN-SPAM points.
- Confidentiality clauseA confidentiality clause inside a wider contract, not a standalone NDA. Sample consulting wording, mutual and one way variants, the tail period and exceptions.
For everything the document generator can do, see the document maker.
Step by step in the builder: Create a document with AI, then Document builder components.
Written and checked by the OneCraft team. Last checked .