Privacy Policy Generator Australia
The Privacy Act 1988, thirteen Australian Privacy Principles, and consumer guarantees that no refund policy can override.
APP 1.4 lists what an Australian privacy policy has to contain, which makes it one of the few regimes where the document itself is the regulated artefact rather than the processing behind it. The clause most often missing is the list of countries where overseas recipients are located.
Australian privacy law is built on the thirteen Australian Privacy Principles in the Privacy Act 1988, supervised by the OAIC. APP 1 is unusual and important: it requires a clearly expressed and up-to-date privacy policy as an obligation in its own right, with prescribed content - not merely as a by-product of transparency duties.
The 2024 reforms began a multi-year expansion. A statutory tort for serious invasions of privacy is now available, transparency obligations for automated decisions that significantly affect individuals are phased in, a Children’s Online Privacy Code is being developed, and the OAIC has gained more direct enforcement powers.
Alongside privacy, Australian Consumer Law imposes consumer guarantees that cannot be contracted out of. A "no refunds" sign is not merely unenforceable - it is itself a breach that the ACCC has repeatedly penalised.
What a privacy policy in Australia has to cover
The kinds of personal information collected and held, and how each is collected
Purposes of collection, holding, use and disclosure
How to access and correct information, and how to complain and what happens next
Whether information is likely to be disclosed overseas and to which countries
Automated decisions that significantly affect individuals, as the reforms now require
How Australia actually moves personal data
Overseas disclosure under APP 8
Sending personal information overseas makes you accountable for the recipient’s handling of it unless an exception applies, and APP 1 requires you to list the countries involved where practicable.
Government-related identifiers
Tax file numbers, Medicare numbers and driver licence numbers are restricted under APP 9, and the identity-verification breaches of recent years made this a live enforcement area.
Direct marketing under APP 7
Marketing to individuals requires either their expectation or consent, and every message must offer a simple opt-out - separate from and in addition to Spam Act duties.
Health and sensitive information
Sensitive information requires consent for collection under APP 3, and health service providers are covered by the Privacy Act regardless of turnover.
Automated decision-making
The reforms require privacy policies to disclose the use of automated decisions that significantly affect individuals, with the transparency obligation phasing in ahead of enforcement.
Third parties the draft will ask you about
Stripe · Afterpay · Zip · Australia Post · Xero · AWS ap-southeast-2 · Campaign Monitor · Atlassian · Telstra
The rules that apply
Privacy Act 1988 and the 13 APPs
Applies to businesses with turnover above AUD 3 million and to smaller businesses in specified categories including health service providers and those trading in personal information.
APP 1 - open and transparent management
Requires a clearly expressed, up-to-date and free privacy policy with prescribed content, including overseas disclosure countries.
Notifiable Data Breaches scheme
Eligible data breaches must be assessed within thirty days and notified to the OAIC and affected individuals where serious harm is likely.
Australian Consumer Law
Consumer guarantees on acceptable quality, fitness for purpose and description, which cannot be excluded, restricted or modified.
Spam Act 2003
Consent, sender identification and a functional unsubscribe for commercial electronic messages, enforced by ACMA with substantial penalties.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Meeting APP 1 in practice
Check whether the Privacy Act catches you
Turnover above AUD 3 million, or one of the categories where turnover is irrelevant.
Write the policy to APP 1.4 content list
Kinds of information, how collected and held, purposes, access and correction, complaints, overseas disclosure and countries.
Build the breach assessment runbook
Thirty days to assess, then notification to the OAIC and individuals where serious harm is likely.
Separate marketing consent from privacy consent
APP 7 and the Spam Act need their own records.
Align refund terms with consumer guarantees
State the guarantees first, then any additional voluntary policy.
Where this usually goes wrong
Advertising "no refunds"
Consumer guarantees survive any policy. The ACCC has penalised businesses for signage and terms that misrepresent a consumer’s rights, independently of whether a refund was refused.
Not listing overseas disclosure countries
APP 1.4(f) asks for the countries where recipients are likely to be located. "We may transfer data internationally" does not satisfy it.
Assuming the small-business exemption applies
It does not apply to health service providers, businesses trading in personal information, contracted service providers to the Commonwealth, or those that have opted in.
Treating the Spam Act and APP 7 as one rule
They are separate: the Spam Act governs the message, APP 7 governs the use of personal information for marketing. Compliance with one does not discharge the other.
No breach assessment process
The NDB scheme requires an assessment within thirty days of becoming aware of a suspected eligible breach. Without a procedure, the clock runs unnoticed.
Frequently asked questions
Does the Privacy Act apply to small businesses?
Generally only above AUD 3 million turnover, but there are important exceptions: health service providers, businesses that buy or sell personal information, credit reporting bodies and Commonwealth contractors are covered whatever their size.
Is a privacy policy legally required in Australia?
Yes for APP entities. APP 1.3 requires a clearly expressed and up-to-date policy about the management of personal information, available free of charge and in an appropriate form.
Can I refuse a refund if the customer changed their mind?
Yes - consumer guarantees do not cover change of mind. What you cannot do is state or imply that no refunds are ever available, because that misrepresents the guarantees that do apply to faulty or misdescribed goods.
What is the new privacy tort?
A statutory cause of action for serious invasions of privacy, which lets individuals sue directly rather than relying on an OAIC complaint. It changes the risk profile of intrusive tracking and surveillance practices.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator Australia
Answer a short questionnaire and get a draft written for Australia. Free to start, no card required.
Generate your privacy policyOther documents for Australia
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.