Do I need a privacy policy on my website?

Quick Answer

Legally, only if the Privacy Act 1988 covers your business, and most small Australian businesses aren’t covered. The exemption applies to businesses turning over $3 million or less. But several exceptions catch businesses off guard, and health service providers are covered regardless of turnover.

This is general information, not legal advice. If you’re unsure whether the Act applies to you, that’s a question for a lawyer or your industry association, not a blog post.

The main test is turnover. If your business has never had an annual turnover above $3 million in any financial year since 2002, the Privacy Act generally doesn’t apply. Turnover here means all income from all sources, not profit.

The exceptions are where it gets interesting for small businesses. Regardless of turnover, the Act covers health service providers, businesses that trade in personal information, Commonwealth contractors, credit reporting bodies, and businesses related to a larger company that’s already covered.

That health services exception is broader than most people assume. The OAIC defines it to include physical, emotional, psychological and mental health services, which pulls in allied health practices, complementary therapists, childcare centres, and private educational institutions, not just medical clinics. A physiotherapy or dental practice under the turnover threshold is very likely still covered.

Businesses can also opt in voluntarily, and the OAIC actively suggests considering it. The reasoning is straightforward: having a clear privacy policy signals that you handle client information carefully, which matters commercially in any industry where trust drives the buying decision.

Worth knowing that reform is under active discussion. The federal government has proposed removing the small business exemption entirely, which would bring roughly 95% of Australian businesses into scope. That hasn’t taken effect, but it’s a reasonable argument for putting a policy in place before it’s compulsory rather than scrambling afterwards.

The practical position: if you collect enquiry form submissions, run analytics, or store client details, having a privacy policy is good practice regardless of whether it’s legally required, in the same way website accessibility is worth getting right before someone complains rather than after. It costs very little to add compared to explaining its absence to a cautious prospect.

Related Questions

Not sure what your site should have in place?

We’ll flag the gaps during a discovery call, including those that aren’t strictly our department.