It’s a question that comes up almost every time we get close to finishing a website build. “Do I actually need a Privacy Policy?”
For a lot of the community organisations and regional businesses I work with, it’s not really an abstract question. It’s a board member asking, right before a funding acquittal, whether the paperwork side of the website is sorted. It’s an EO who’s just been asked by a funder to confirm the organisation handles data properly, and realises she doesn’t actually know what the website’s footer says.
My answer is almost always the same. Yes, of course you do.
There’s more nuance to the legal answer than that. But nuance is exactly what gets lost when this question gets asked in a hurry, right before a site goes live, so it’s worth actually working through.
First, what exactly is a Privacy Policy?
A Privacy Policy explains what personal information your organisation collects, why you collect it, what you do with it, who you might disclose it to, and what rights people have over their own information. The Office of the Australian Information Commissioner describes it as a statement explaining, in simple language, how an organisation handles personal information.
For organisations covered by the Privacy Act 1988, it isn’t optional. Australian Privacy Principle 1 requires a “clearly expressed and up-to-date” policy about how personal information is managed. Not a policy that existed once. A current one.
Read the Privacy Act 1988 on the Federal Register of Legislation(opens in new tab)
“But my organisation is tiny. Does the Privacy Act even apply to me?”
Generally, organisations with annual turnover above $3 million are covered. Plenty of the community organisations and small regional businesses I work with sit under that line, and aren’t automatically covered by the Act.
But there are exceptions, and they catch more organisations than you’d expect. Health services are covered regardless of turnover, and “health service” gets defined more broadly than most people assume, it can extend to allied health, disability support and aged care providers who wouldn’t necessarily think of themselves that way. Organisations that trade in personal information are covered. So are organisations related to another entity that’s already covered by the Act.
So “we’re small” isn’t, by itself, an answer either way. It’s worth a five-minute check against the OAIC’s small business guidance(opens in new tab) if you’re not sure which side of the line you sit on, particularly if you’re in health, aged care, disability services or community welfare.
None of that is the main reason to have one anyway.
Your website probably collects more information than you realise
Think about a fairly ordinary small-business website.
It might have:
- a contact or quote request form
- an email newsletter signup
- online bookings
- Google Analytics
- Google Maps
- embedded YouTube videos
- Meta advertising or tracking technology
- Google Ads conversion tracking
- an e-commerce checkout
- membership or login functionality
- third-party CRM, booking or marketing integrations.
Your website isn’t simply displaying a few pages of text anymore.
It’s interacting with people, collecting information and potentially sending data to other platforms.
Even something as simple as a contact form might collect someone’s name, email address, phone number, business name and details about why they’re contacting you.
Depending on your website and configuration, other technologies can collect technical information about visitors and their devices as well.
A Privacy Policy gives your visitors somewhere to go to understand what’s happening.
Google Analytics requires one
Here’s one that often surprises people.
If you run Google Analytics, and most business websites do, Google’s own terms require you to have an appropriate Privacy Policy and disclose your use of cookies and visitor tracking. That applies regardless of your turnover or the Privacy Act exemptions above. Google isn’t asking whether the Privacy Act covers you. It’s asking whether you’ve told your visitors what’s happening to their data, full stop.
So even if you’ve determined that your particular small business isn’t legally required to have an APP Privacy Policy under Australia’s Privacy Act, that doesn’t automatically mean you can forget about privacy disclosures.
If your website uses third-party tools, you also need to consider the terms under which you’re using those tools.
Read Google’s Analytics terms(opens in new tab)
“Nobody reads Privacy Policies anyway”
You’re right. Most people don’t read Privacy Policies, and that’s fine. It isn’t a marketing page written to be read by hundreds of people, or even by very many at all. It’s a governance document. It matters on the one occasion someone actually asks, a customer wondering what happens to their enquiry, a funder confirming your organisation handles data properly before signing off on a grant, a partner organisation checking your paperwork before a joint program goes ahead. That’s the moment it’s there for, and it’s a bad moment to discover you don’t have one, or that the one you have describes a website you replaced two years ago.
It’s also a small trust signal in its own right. If someone hands over their name, phone number and the reason they’re contacting you through a form on your site, I think it’s reasonable for them to expect you can tell them, in plain language, what happens to it next.
Having one doesn’t excuse bad practice
This is worth saying plainly, because it’s easy to treat “get a Privacy Policy” as the finish line. It isn’t. A beautifully written policy doesn’t give you licence to collect everything imaginable and hold onto it forever. For organisations covered by the Privacy Act, the Australian Privacy Principles go further than disclosure, they cover how information is collected, used, disclosed, secured, accessed and corrected, and government guidance is clear that information you no longer need should generally be destroyed or de-identified, not kept indefinitely just because it’s there.
So the more useful internal conversation isn’t “do we have a Privacy Policy.” It’s “what are we actually collecting, why, where does it go, who has access to it, and how long are we keeping it.” Answer that honestly first. The policy is just where you write the answer down.
What about Website Terms?
Worth separating out, because people often confuse the two. A Privacy Policy is about how you handle people’s information. Website Terms of Use cover the rules around using your site itself, things like intellectual property, how third-party links are treated, the accuracy of information published, and limits on liability. An e-commerce store, a membership site or anything accepting user-generated content needs this more than a simple brochure site does, but it’s a different document doing a different job, and a generic copy-paste version of either rarely fits the site it’s sitting on.
It’s not a set-and-forget document
This is the part people miss most often. A Privacy Policy written when the site first launched doesn’t stay accurate on its own. You add online bookings next year. You start advertising on Meta. You bring in a new CRM or an email marketing platform. You start taking payments online. Each one of those changes what you’re actually collecting or who you’re sharing it with, and the policy is supposed to keep up. The Australian Privacy Principles specifically require it to stay current, not just exist somewhere in the footer.
In practice, almost nobody goes back and checks. The policy quietly drifts out of date at the same rate the website does, and nobody notices until someone asks.
What it actually costs to get right
There are a few ways to handle it. A free template is better than nothing, but it’s written for someone else’s business, and it’s the first thing to go stale once your site changes, because nobody’s watching it.
A solicitor is the right call if you’re handling sensitive information, operating in a regulated industry, working internationally, or your privacy obligations are genuinely complex. That’s proper legal advice, priced accordingly, and worth it when the stakes are actually that high.
For most of the community organisations and small regional businesses I work with, neither is quite right, a template that goes stale, or legal fees sized for a problem they don’t have. So we manage it as an ongoing service instead, through a platform called Termageddon, at $180 a year. It covers your Privacy Policy, Website Terms, and Cookie Policy together, and it updates them automatically when the laws or your website change, rather than waiting for someone to remember. It’s the same idea as an electrical safety certificate. Nobody re-reads it, but you’d notice fast if it went missing during an audit.
So, do you need one?
Strictly, under the Privacy Act, maybe not. Plenty of small organisations are technically exempt.
But that’s the wrong question. The better one is whether a website collecting enquiries, running analytics, and talking to Google and Meta on your behalf should be able to tell people what it’s doing with their information. To me, that’s an easy yes, and it’s exactly the sort of thing a funder or a board member expects to already be handled. It’s part of running a responsible website.
Not sure if yours is sorted? Flick me an email and I’ll take a look →
This article provides general information about websites and privacy considerations. It isn’t legal advice. Privacy obligations vary depending on your organisation, activities, industry and the information you collect. If you’re unsure of your legal obligations, speak to an appropriately qualified legal professional.
