Documents · Compared

Privacy policy against privacy notice

A privacy policy is the standing document describing how an organisation handles personal information overall, and it has to be available to anybody who asks. A privacy notice, often called a collection notice, is the short statement given to a person at the point their information is collected, telling them what is being collected and why.

Australian privacy law treats these as two separate obligations, and satisfying one does not satisfy the other. A link to the policy at the bottom of a form is not a collection notice.

· Co-founder

6 min read · Published

The obligation in three jurisdictions
AustraliaEUUnited Kingdom
Standing documentPrivacy policy, APP 1Privacy information, articles 13 and 14Privacy information under the UK GDPR
At the point of collectionCollection notice, APP 5The same articles, given at collectionThe same, given at collection
Must beClearly expressed and up to date, free to obtainConcise, transparent, intelligible, plain languageConcise, transparent, intelligible, plain language
Named contentsKinds of information, purposes, disclosure, overseas recipients, access, complaintsIdentity, purposes, legal basis, recipients, retention, rightsThe same as the EU list
TimingAt or before collection, or as soon as practicableAt the time of collection from the personAt the time of collection from the person

The two obligations do different work

The policy is about the organisation and is written once. It answers the question of how this business handles personal information in general, and it has to be available free of charge to anybody who wants it, usually as a page on the website. The notice is about a moment. It answers the question of what is happening to me, right now, as I fill this in, and it belongs next to the fields being completed rather than behind a link. That difference explains why a notice can be six lines long while a policy runs to several pages. It also explains why they cannot substitute for each other: a person filling in a patient intake form is not going to read a policy, and a person researching a business is not helped by a notice written for one form.

What a collection notice has to tell somebody

Under the Australian Privacy Principles the notice covers who is collecting, how to contact them, what is being collected and why, whether the collection is required by law, who the information will usually be disclosed to, whether it will go overseas and roughly where, and how the person can access it or complain. That reads like a lot for a short notice, and the way through is plain sentences in the order the reader cares about. What you are giving, what it is for, who else sees it, and what to do if you are unhappy. Anything the person would be surprised by belongs near the top, particularly overseas disclosure and any secondary use such as marketing.

Where organisations get caught out

The most common failure is a policy that describes an organisation from three years ago, listing systems that were replaced and omitting the analytics, the chat tool and the offshore support desk that have since been added. The second is a notice that only exists on the web form, while the same information is also collected by phone and on paper with nothing said. The third is a policy that promises more than the organisation does, such as a deletion commitment nobody has implemented. Health information carries extra obligations and a lower tolerance for vagueness, so a clinic reusing a generic retail policy is taking a real risk. Review both documents on a set date each year and after any change to a system that touches personal information.

Writing them so somebody reads them

The legal tests in Australia, the EU and the UK all use the same language about clarity: the material has to be clearly expressed, concise and intelligible. In practice that means short sentences, headings phrased as the questions people actually ask, and no defined terms unless they are unavoidable. Put the specifics in rather than hedging with words like may and including but not limited to, because a document that could describe any organisation tells the reader nothing about this one. A table of what is collected, why, and who receives it is often the clearest way to present the core of a policy, and it makes the annual review much faster because the gaps are visible.

Building both as documents

A privacy policy is a long structured document with numbered sections, a running header and a version date, and at that scale it can carry a table of contents whose headings match the sections exactly. Tables carry the collection and disclosure summary, and callouts have four variants, which is enough to mark the notifiable breach process and the complaints path without inventing extra styles. A collection notice is a single short block, so it gets no cover and no letterhead. Documents never print citations, so any reference to a statute or a principle is written into the body as content.

Keeping the two documents in step

The two drift apart the moment either one is edited alone. A practical control is a single register of collection points, listing every form, phone script and paper document that gathers personal information, what each one collects and which notice sits on it. When the policy is reviewed, the register is the checklist, and any collection point without a notice is visible immediately. It also solves the reverse problem, which is a notice promising something the policy does not support. Keep one owner for both documents, usually whoever is accountable for privacy rather than whoever built the form, and put the review date on the face of each. Where a service is delivered through a third party, such as an online booking tool, the register should record whose notice the customer actually sees, because it is often not the one the business thinks.

Questions people ask

Does a small business need a privacy policy?

Many small businesses under the annual turnover threshold are not covered by the Privacy Act, but there are important exceptions, including health service providers and businesses that trade in personal information. Even when not covered, having a policy is increasingly expected by customers and by enterprise clients running supplier checks, so the practical answer is usually yes.

Can the collection notice just link to the policy?

A link alone does not satisfy the separate obligation to notify at collection. The workable pattern is a short notice on the form covering the key points, with a link to the full policy for anybody who wants the detail. Putting the whole policy on the form is the other failure, since nobody reads it and the important points disappear.

What has to be said about overseas disclosure?

If personal information is likely to be disclosed to recipients overseas, the person should be told, and the countries named where it is practicable to do so. This catches more organisations than they expect, because cloud hosting, support desks and analytics tools frequently sit outside Australia even when the business does not.

How often should a privacy policy be updated?

Review it annually and whenever a new system, vendor or data flow is introduced. Keep the version date visible on the document. If a change materially affects how information is used, telling affected people rather than silently republishing is the safer course, and in some cases consent may be needed for the new use.

Is a privacy policy the same as terms and conditions?

No. Terms set the contract between the business and the customer; the privacy policy describes information handling and is a compliance document rather than a bargain. Merging them makes both harder to read and can create an argument that privacy commitments are contractual promises, which is usually not what the organisation intended.

What happens after a data breach?

Under the notifiable data breach scheme, an eligible breach likely to result in serious harm must be assessed promptly and, if it qualifies, notified to the regulator and to affected individuals. The policy should say the organisation has a process; the process itself is an internal document with names, timeframes and a decision path.

Make one with documents

The button opens the generator with this use case already described. Change the wording to match your own.

Create a document with OneCraft

Related questions

Step by step in the builder: Create a document with AI, then Every document component and when to use it.

Sources

Written and checked by the OneCraft team. Last checked .