Privacy Disclosure Notice Template for Australia

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Privacy Disclosure Notice?

A Privacy Disclosure Notice is a mandatory document under Australian privacy law that organizations must provide to individuals when collecting their personal information. This document is essential for compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), particularly APP 1 and APP 5. Organizations should use this notice to inform individuals about how their personal information will be collected, used, disclosed, and protected. The notice must be clear, current, and readily available, typically provided before or at the time of collecting personal information. It should be regularly reviewed and updated to reflect any changes in data handling practices or regulatory requirements. The document is particularly crucial in light of increased regulatory scrutiny and growing public awareness of privacy rights in Australia.

Frequently Asked Questions

Is a Privacy Disclosure Notice legally required under Australian law?

Yes, under the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs), organizations must provide individuals with clear notification about how their personal information is collected, used, and disclosed. Failure to provide adequate privacy disclosure can result in penalties from the Office of the Australian Information Commissioner (OAIC) and potential compensation claims.

Can I be fined if my Privacy Disclosure Notice is missing or incomplete in Australia?

Yes, the OAIC can impose civil penalties up to $2.22 million for serious or repeated privacy breaches, including inadequate disclosure practices. Even minor non-compliance can result in enforceable undertakings, regulatory action, and reputational damage. Incomplete notices may also expose you to individual compensation claims under the Privacy Act.

How is a Privacy Disclosure Notice different from a Privacy Policy in Australia?

A Privacy Disclosure Notice is provided at the point of collection and explains specific collection practices for that interaction, while a Privacy Policy is a comprehensive document covering all privacy practices organization-wide. The Notice must be given before or at collection time under APP 5, whereas the Policy can be made available through your website or other accessible means.

Which Australian Privacy Principles must my Privacy Disclosure Notice comply with?

Your notice must primarily comply with APP 1 (open and transparent management) and APP 5 (notification of collection). It should also align with APP 6 (use or disclosure) and APP 12 (access and correction rights). The notice must be written in clear, plain English and cover all mandatory elements specified in these principles.

How long does it typically take to prepare a compliant Privacy Disclosure Notice?

For straightforward businesses, creating a basic notice from a template takes 2-4 hours, but comprehensive legal review can take 1-2 weeks. Complex organizations handling health records, credit information, or operating across multiple jurisdictions may need several weeks of legal consultation. Regular updates are also required when collection practices change.

Must I update my Privacy Disclosure Notice when Australia's privacy laws change?

Yes, you must keep your notice current with legislative changes and your actual collection practices. The Privacy Legislation Amendment Act 2023 introduced new requirements that may affect your disclosure obligations. Regular reviews every 12-18 months are recommended, with immediate updates required when collection purposes or disclosure practices change.

Common mistakes businesses make with Privacy Disclosure Notices in Australia?

The most frequent errors include using generic templates without customization, failing to provide notices at collection points, using overly broad language about data use, and not updating notices when practices change. Many businesses also forget to include mandatory elements like complaint procedures, overseas disclosure information, and specific contact details for privacy inquiries.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Australia

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Privacy Disclosure Notice

You need a Privacy Disclosure Notice to comply with Australian privacy law whenever your organization collects personal information from individuals. This essential document ensures transparency and builds trust while meeting your legal obligations under the Privacy Act 1988 and Australian Privacy Principles.

When do you need this document?

You must provide a Privacy Disclosure Notice before or at the time of collecting personal information from individuals. This applies when you collect information through website forms, customer registrations, employee applications, surveys, or any other data gathering activities. If you operate a business website, mobile app, or handle customer data in any capacity, you need this notice prominently displayed and easily accessible. The document is also required when you change your data handling practices or collect information for new purposes.

Key legal considerations

Your Privacy Disclosure Notice must clearly explain what personal information you collect, how you collect it, and why you need it. You must detail how the information will be used, who it may be disclosed to, and whether disclosure is mandatory or optional. Include information about data storage, security measures, and retention periods. The notice should explain individuals' rights to access and correct their personal information, and provide clear contact details for privacy enquiries or complaints. Ensure you address cross-border data transfers if you share information overseas, and include details about third-party service providers who may handle the data.

Legal requirements in Australia

Under the Privacy Act 1988, your notice must comply with Australian Privacy Principle 1 (open and transparent dealing) and APP 5 (notification requirements). The document must be written in clear, plain English that individuals can reasonably understand. You're required to make the notice readily available and easily accessible, typically through your website's privacy policy page. If you experience a data breach that may cause serious harm, you must have procedures in place for notifying affected individuals under the Notifiable Data Breaches scheme. State and territory privacy laws may impose additional requirements, particularly for health information or government agencies. Regular reviews and updates are essential to maintain compliance as your business practices evolve or privacy laws change.

GOVERNING LAW

Applicable law

This Privacy Disclosure Notice is drafted to comply with Australia law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it