Why this is not the UK tool with the words changed
The Privacy Act 1988 is a different instrument from the UK GDPR, not a translation of it. It runs on 13 Australian Privacy Principles instead of GDPR articles, and it carries a small business turnover exemption with no European equivalent at all. A policy built by relabelling a UK template would hand an Australian reader a right to erasure the Act does not give, and skip the one question every Australian business should answer first: does the Act even apply to you.
The question worth answering before any of the rest
A business with annual turnover of $3 million or less is generally not covered by the Privacy Act at all, whatever industry it is in, unless one specific activity pulls it back in regardless of size. That list is the most useful thing on this page for a tradesperson, because it is the difference between a legal requirement and something published by choice. The Act still covers a small business, turnover or not, where it does any of the following:
- Provides a health service and holds health information, even as a sideline
- Trades in personal information, collecting or disclosing it for a benefit, service or advantage
- Delivers services as a contractor under a Commonwealth contract
- Operates a residential tenancy database
- Is a credit reporting body
- Reports under anti money laundering and counter terrorism financing law
- Is a registered employee association, or conducts a protected action ballot
- Holds accreditation under the Consumer Data Right system
- Is related to a business the Act already covers
Match none of those, and stay under the turnover figure, and the Act does not currently require a policy at all. Plenty of small businesses publish one anyway, because a client, a marketplace or a lender asks for it, and this tool builds the same document either way, telling you plainly which one you are doing.
Thirteen principles, not six lawful bases
There is no lawful basis to pick per purpose here, which is the first thing anybody arriving from a UK or EU privacy policy looks for and will not find. Collection has to be reasonably necessary for what the business does, sensitive information carries its own stricter consent test, and a secondary use needs one of a short, different list of reasons. The 13 Australian Privacy Principles, as the regulator's own quick reference page names them, are:
- Open and transparent management of personal information
- Anonymity and pseudonymity
- Collection of solicited personal information
- Dealing with unsolicited personal information
- Notification of the collection of personal information
- Use or disclosure of personal information
- Direct marketing
- Cross-border disclosure of personal information
- Adoption, use or disclosure of government related identifiers
- Quality of personal information
- Security of personal information
- Access to personal information
- Correction of personal information
Access and correction, not erasure
A generated policy that promises somebody the right to have their information deleted is promising something the Act does not give. Principles 12 and 13 cover access and correction: seeing what is held, and having it fixed if it is wrong. The obligation to get rid of information runs the other way. Principle 11 requires a business to destroy or de-identify it once it is no longer needed, whether or not anyone has asked, which is a duty on the business rather than a right handed to the individual.
If something goes wrong: the Notifiable Data Breaches scheme
Australia runs a Notifiable Data Breaches scheme alongside the Principles. An eligible data breach, one likely to result in serious harm, has to be reported to affected individuals and the Office of the Australian Information Commissioner as soon as practicable, once a covered business has reasonable grounds to believe it happened. It only applies once a business is covered by the Act in the first place, which is one more reason the exemption question above is worth answering honestly rather than skipping.
Complain to us first is not just politeness here
The OAIC expects somebody to raise a problem with the business before it will take a complaint, the reverse of the UK position, where a complainant never has to approach the business first. That makes a working contact method more than a formality here: it is the first place a complaint is meant to land.
A template, not legal advice
Every section here comes from a question answered on this page, and nothing is included by default: no overseas disclosure section unless there is one, no direct marketing section unless it happens. This is a template built from the Australian Privacy Principles, not legal advice, and it downloads in full, free, with no account and no paywall. Reading it before publishing is worth the ten minutes it takes.
Common questions
Why is this a separate tool from the UK privacy policy generator?
Because the Privacy Act 1988 is a different instrument, not a translation. It works on 13 Australian Privacy Principles rather than GDPR articles, and it carries a small business turnover exemption that UK and EU law has no equivalent for at all. A policy built by relabelling the UK tool would hand people a right to erasure the Act does not give, and skip the turnover question entirely.
Does the Privacy Act actually apply to my business?
Generally not, if your annual turnover is $3 million or less and none of a specific list of activities applies to you regardless of size: providing a health service, trading in personal information for a benefit or advantage, working as a Commonwealth contractor, running a residential tenancy database, credit reporting, anti money laundering reporting, a registered employee association, a protected action ballot, or Consumer Data Right accreditation. Match one of those, or pass the turnover figure, and the Act covers you whatever else is true.
My turnover is under $3 million and none of the carve-outs apply. Do I still need a policy?
Not one the law requires, no. Plenty of small businesses publish one anyway, because a client, a marketplace or a lender asks for it, or because it is good practice regardless of the legal position. This tool builds the same document either way, and says plainly on the page which situation applies to you.
What are the Australian Privacy Principles?
Thirteen principles covering everything from open management and anonymity through collection, use, disclosure, direct marketing, cross border disclosure, government identifiers, data quality and security, to access and correction. They are listed in full further down this page, by number and name, exactly as the OAIC's own quick reference page names them.
Does this give someone the right to have their information deleted?
No. Principles 12 and 13 cover access and correction, seeing what is held and having it fixed if it is wrong, not erasure on request, and it is the clearest way the Act differs from GDPR. The duty to get rid of information runs the other way: once a business no longer needs it, it has to destroy or de-identify it, whether or not anyone has asked.
What happens if personal information is compromised?
Where a business is covered by the Act, the Notifiable Data Breaches scheme requires it to tell affected individuals and the Office of the Australian Information Commissioner as soon as practicable, once it has reasonable grounds to believe the breach is likely to cause serious harm. A business the small business exemption covers is not caught by this scheme either, for the same reason it is not caught by the rest of the Act.
Do I complain to the business first, or go straight to the regulator?
The Office of the Australian Information Commissioner expects someone to raise it with the business first, and only takes a complaint once that has been tried. That is the reverse of the position in the UK, where a complainant never has to approach the business before the regulator. It is also why a working contact method matters more on an Australian policy than a decorative one.
Is this legal advice?
No. It is a template built from the Australian Privacy Principles, and it describes only what is entered into it. It cannot know what a particular business actually does, what a client has already agreed to, or what a regulator would say about a specific situation, so read it before publishing it and get it checked if anything in it turns on a real dispute.