Privacy Information Notice Template for Australia
Generate a bespoke document
What is a Privacy Information Notice?
The Privacy Information Notice is a fundamental privacy compliance document required under Australian privacy law, specifically the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Organizations must provide this notice when collecting personal information to ensure transparency and maintain compliance with APP 5. The notice should be provided at or before the time of collection, or as soon as practicable afterward if collection from a third party occurs. It must detail the organization's identity, collection purposes, disclosure practices, overseas recipients (if any), and how individuals can access and correct their information. The document serves as both a legal compliance tool and a trust-building mechanism with stakeholders, requiring regular updates to reflect changes in data handling practices or legal requirements.
Trusted by high-performance teams
About the Privacy Information Notice
A Privacy Information Notice is a critical compliance document that you must provide when collecting personal information in Australia. Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), this notice serves as your legal obligation to inform individuals about how their personal information will be handled, ensuring transparency and maintaining their trust in your organization.
When do you need this document?
You need a Privacy Information Notice whenever you collect personal information from individuals, whether directly through forms, surveys, or applications, or indirectly through third parties. This includes situations such as when customers sign up for services, employees provide employment information, website visitors submit contact details, or when you receive personal information from business partners or data brokers. The notice must be provided at or before the time of collection, or as soon as practicable afterward if the information comes from a third party source.
Key legal considerations
Your Privacy Information Notice must comply with APP 5, which requires you to take reasonable steps to notify individuals about the collection of their personal information. The notice must clearly identify your organization and provide contact details for privacy inquiries. You must specify what personal information you collect, the purposes for collection and use, and who you may disclose the information to, including any overseas recipients. The notice should explain how individuals can access and correct their personal information, outline your complaint handling process, and detail the consequences of not providing requested information. If you're subject to the Notifiable Data Breaches scheme, consider including information about your data breach response procedures.
Legal requirements in Australia
Under Australian privacy law, your notice must be written in clear and plain language that individuals can reasonably understand. The Privacy Act 1988 requires covered entities with an annual turnover of $3 million or more, health service providers, and credit reporting bodies to comply with the APPs. Your notice must address APP 5's notification requirements and align with other relevant APPs, particularly APP 6 (use or disclosure) and APP 8 (cross-border disclosure of personal information). If your organization engages in direct marketing, ensure compliance with the Spam Act 2003 by including opt-out mechanisms. The Office of the Australian Information Commissioner (OAIC) provides guidance on best practices, and failure to provide adequate privacy notices can result in regulatory action, including civil penalties of up to $2.22 million for serious or repeated privacy violations.
GOVERNING LAW
Applicable law
This Privacy Information Notice is drafted to comply with Australia law. Key legislation includes:
Australian Privacy Principles (APPs): 13 principles under the Privacy Act that set out standards, rights and obligations for handling, holding, accessing and correcting personal information
Spam Act 2003: Regulates commercial electronic messages, requiring consent and opt-out facilities, relevant for privacy notices involving marketing communications
Notifiable Data Breaches (NDB) scheme: Part IIIC of the Privacy Act, requiring organizations to notify individuals and the OAIC when a data breach is likely to result in serious harm
Competition and Consumer Act 2010 (including Australian Consumer Law): Relevant for privacy notices as it prohibits misleading or deceptive conduct in privacy statements and data handling practices
State-specific Privacy Laws: Various state-level privacy laws that may apply depending on the jurisdiction, such as the Privacy and Personal Information Protection Act 1998 (NSW) for New South Wales
Healthcare Identifiers Act 2010: Specific requirements for handling healthcare identifiers and related personal information in the healthcare sector
General Data Protection Regulation (GDPR) considerations: While not Australian law, relevant if the organization deals with EU residents' data, as it influences Australian privacy notice standards and international data transfers
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

