Privacy Notice Template for Australia
Generate a bespoke document
What is a Privacy Notice?
A Privacy Notice is required for any organization operating in Australia that collects, uses, or handles personal information. This document must be provided to individuals at or before the time their personal information is collected, as mandated by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The notice should be easily accessible, written in clear language, and regularly updated to reflect any changes in data handling practices. It serves as a crucial compliance tool and helps build trust with stakeholders by providing transparency about how their personal information is managed. The document should address all aspects of data handling, from collection and use to storage and disposal, and must include information about individuals' rights to access and correct their personal information.
About the Privacy Notice
A Privacy Notice is a fundamental legal document that every Australian organization handling personal information must provide to individuals. Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you're legally required to inform people about how their personal information will be collected, used, stored, and disclosed before or at the time of collection.
When do you need this document?
You need a Privacy Notice if your organization collects any personal information from individuals in Australia. This includes businesses with an annual turnover exceeding $3 million, all health service providers, credit reporting bodies, and any organization that trades personal information. Whether you're collecting customer details for sales, employee information for HR purposes, or visitor data through your website, a Privacy Notice is mandatory. The document must be easily accessible and written in clear, plain language that ordinary people can understand.
Key legal considerations
Your Privacy Notice must address several critical elements to ensure compliance with Australian privacy law. You must specify what types of personal information you collect, including any sensitive information such as health records or financial data. The notice should explain your collection methods, whether directly from individuals or through third parties like social media platforms. You're required to detail the purposes for which you use personal information and identify any overseas recipients if you transfer data internationally. Additionally, you must inform individuals about their rights to access, correct, or complain about how their information is handled. Under the Notifiable Data Breaches scheme, you should also explain how you'll notify individuals if a data breach occurs that's likely to result in serious harm.
Legal requirements in Australia
The Privacy Act 1988 establishes 13 Australian Privacy Principles that govern how you handle personal information. APP 5 specifically requires you to provide notification about collection, making your Privacy Notice a legal necessity rather than just best practice. Your notice must be provided at or before collection and be easily accessible to individuals. If you're a health service provider, additional requirements under the Health Records Acts in various states may apply. The Spam Act 2003 also requires you to include information about electronic marketing communications and consent requirements. State-specific privacy laws, such as NSW's Privacy and Personal Information Protection Act 1998, may impose additional obligations depending on your location and sector. Your Privacy Notice should be regularly reviewed and updated to reflect changes in your data handling practices or applicable laws.
GOVERNING LAW
Applicable law
This Privacy Notice is drafted to comply with Australia law. Key legislation includes:
Privacy Amendment (Notifiable Data Breaches) Act 2017: Requires organizations to notify affected individuals and the Privacy Commissioner of eligible data breaches that are likely to result in serious harm
Spam Act 2003: Regulates commercial electronic messages and requires consent for sending marketing communications
State and Territory Privacy Laws: Various state-specific privacy laws that may apply depending on the jurisdiction, such as the Privacy and Personal Information Protection Act 1998 (NSW)
My Health Records Act 2012: Specific legislation governing the handling of health information in the My Health Record system
Healthcare Identifiers Act 2010: Regulates the use and disclosure of healthcare identifiers and related personal information
Competition and Consumer Act 2010 (including Australian Consumer Law): Contains provisions relating to misleading and deceptive conduct which may be relevant to privacy notices and statements about data handling
Telecommunications Act 1997: Contains provisions relating to the privacy of personal information in telecommunications
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it