Privacy policies

What has to be in an Australian privacy policy.

There is a legal minimum, and it is shorter than most people expect. Here is the list, plus the three sections that have arrived around it: the automated-decision disclosure, the AML/CTF privacy disclosure, and notifiable data breaches.

There is a legal minimum, and it is shorter than most people expect. APP 1.4 of the Privacy Act 1988 (Cth) lists what a privacy policy has to contain. Everything else in a good policy is there because the minimum does not describe a real business on its own.

Here is the list, in the order it appears in the Act, with what each one actually asks of you, and then the three sections that have grown up around it, none of which are in APP 1.4 and all of which a 2026 policy is judged on.

10 Dec 2026
Automated decisions
APP 1.7 and 1.8 commence. If software makes or materially assists decisions that significantly affect people, your policy has to describe it.
1 Jul 2026
AML/CTF privacy disclosure
Already in force. New designated services made real estate agents, conveyancers, accountants and lawyers AUSTRAC reporting entities: and organisations under the Privacy Act, whatever their turnover.
30 days
Notifiable data breaches
Part IIIC has been in force since 2018. The clock to assess a suspected eligible breach, and the thing most policies still do not mention.

The seven things APP 1.4 requires

A policy can satisfy every line of that list and still not describe your business. The list is a floor, not a specification.

The automated-decision disclosure, from 10 December 2026

This is the one people have heard about and almost nobody has scoped. From 10 December 2026, APP 1.7 and APP 1.8 (inserted by the Privacy and Other Legislation Amendment Act 2024) require a privacy policy to describe decisions made or assisted by computer programs. It is much broader than “do you use AI”: a scoring tool, an eligibility rule, an automated approval or rejection can all count.

APP 1.7 is a three-limb test, and all three have to be met. Most of the advice circulating only asks the first one, which is why so many businesses think they are either obviously in or obviously out when they are neither:

01

Personal information is used in a computer program.

Not necessarily machine learning. A spreadsheet rule that reads a customer’s details counts as a computer program.

02

The program does something that plays a material role in making a decision.

This is the limb most often got wrong. “A person reviews it before we act” does not put a system out of scope. The OAIC’s guidance counts the program’s output regardless of whether it is advisory or determinative, a recommendation a human almost always follows is material.

03

The decision could reasonably be expected to significantly affect a person’s rights or interests.

And this is the limb that keeps ordinary software out. A spam filter and a booking-slot allocator make automated decisions about people and reach nobody’s rights or interests. Credit, eligibility, pricing, employment and access to a service generally do.

If all three are met, APP 1.8 then tells you what the policy has to set out, and it is three separate things, not one paragraph:

Nothing has to be published before 10 December 2026. But the disclosure has to describe systems you are already running, so the work is finding out what your software actually decides, which takes longer than writing it up. The full guide to the automated-decision disclosure is here.

The AML/CTF privacy disclosure, if you provide a designated service

This one is already in force, and it is the section most often missing from policies that otherwise look complete. On 1 July 2026 the anti-money-laundering regime took in a new group of designated services, real estate agency work, conveyancing, professional services that set up or administer companies and trusts, and dealing in precious metals and stones.

Whether it reaches you is two inputs and an output, and the two inputs are both in the AML/CTF Act 2006:

The privacy disclosure that follows covers four things: the identity documents you collect, that you cannot provide the service without them, how long you keep the verification records, and that you report to AUSTRAC without needing consent: including that you are not permitted to tell someone a suspicious matter report has been made about them.

This is a privacy disclosure, not an AML/CTF compliance program. Your AUSTRAC obligations (enrolment, customer due diligence, reporting) are a separate regime, and describing them in a privacy policy does not discharge any of them.

The guide to the AML/CTF privacy disclosure is here.

Notifiable data breaches, and the 30-day clock

APP 1.4 does not require this either. But the Notifiable Data Breaches scheme in Part IIIC has applied since 2018, and a policy that says nothing about breaches is describing a business with no plan for one. Three things are worth stating, and they are the three the scheme actually turns on:

Saying this is reassuring precisely because most policies do not. The guide to breach notification is here.

What the list does not name, and a policy still needs

These are not in APP 1.4. They are in a policy that is actually about your business, and their absence is what makes a template obvious:

The test that matters

Read your policy next to what your website actually does. If the policy says you do not disclose information overseas and your mailing list is on a US platform, the policy is wrong, and it is wrong in writing, which is worse than silence. A policy is a representation about your business, and the Australian Consumer Law has something to say about representations that are not accurate.

That mismatch is the single most common finding we see. It is also the reason we sell the audit and the builder as two different products: one writes the policy, the other reads the live site and tells you whether the two agree.

General information, not advice. This is general information about Australian law, the same for every reader. It is not advice about your situation, and AegorIQ is not a law practice. If you are unsure which parts apply to you, your accountant or a lawyer can tell you.

The builder

Every one of these, asked as a question about your business.

The builder works through the list above and the parts the list does not name. The automated-decision section is scoped with all three limbs of APP 1.7, not just the first. The AML/CTF disclosure is reached by asking which services you actually provide, not by asking you to decide whether you are a reporting entity. And the breach section says what you will do in the 30 days. $59, one off.

Common questions

What has to be in an Australian privacy policy?

APP 1.4 requires seven things: the kinds of personal information you collect and hold; how you collect and hold it; the purposes for which you collect, hold, use and disclose it; how someone asks for access and correction; how someone complains and how you will handle it; whether you are likely to disclose information overseas; and the countries those recipients are in.

Does my privacy policy have to mention automated decisions or AI?

From 10 December 2026, yes, if all three limbs of APP 1.7 are met: personal information is used in a computer program, the program plays a material role in making a decision, and the decision could reasonably be expected to significantly affect someone's rights or interests. It is broader than AI (a scoring tool, an eligibility rule or an automated approval can all count) and a person reviewing the output does not put the system out of scope. APP 1.8 then requires your policy to set out three things: the kinds of personal information those programs use, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something materially relevant to the decision a person makes.

What is the automated decision-making disclosure starting 10 December 2026?

It is a new section your privacy policy must contain if you use computer programs to make or materially assist decisions that could significantly affect people. It comes from APP 1.7 and APP 1.8, inserted by the Privacy and Other Legislation Amendment Act 2024, and it commences on 10 December 2026. Nothing has to be published before 10 December 2026, but the disclosure has to describe systems you are already running, so the work is finding out what your software decides rather than writing the paragraph.

Do I need an AML/CTF privacy disclosure in my privacy policy?

You do if you are an AUSTRAC reporting entity, which happens when you provide a designated service listed in section 6 of the AML/CTF Act and that service has a geographical link to Australia. Since 1 July 2026 the designated services include real estate agency work, conveyancing, professional services that set up or administer companies and trusts, and dealing in precious metals and stones. The privacy disclosure covers the identity documents you collect, that you cannot provide the service without them, how long you keep the verification records, and that you report to AUSTRAC without needing consent and are not permitted to tell someone a suspicious matter report has been made about them. It is a privacy disclosure only. It does not discharge your AUSTRAC obligations, which are a separate regime.

What should a privacy policy say about notifiable data breaches?

APP 1.4 does not require it, but if the Notifiable Data Breaches scheme in Part IIIC applies to you, a policy that says nothing about breaches is describing a business with no plan. The useful version states three things: that you assess a suspected eligible breach promptly and within 30 days, that if you conclude serious harm is likely you will notify both the affected people and the Office of the Australian Information Commissioner as soon as practicable, and that if you can prevent the harm before it occurs notification may not be required.

Does a privacy policy have to say how long we keep information?

APP 1.4 does not list retention, but APP 11.2 requires you to destroy or de-identify personal information you no longer need. A policy that never mentions retention describes a business that keeps everything forever, which is rarely true.

Does a privacy policy need to name the countries we send data to?

Yes, where it is practicable to name them. APP 1.4 requires both whether you are likely to disclose personal information to overseas recipients and the countries in which those recipients are located.

Is a privacy policy template enough?

A template can satisfy every line of APP 1.4 and still not describe your business. The risk is not the missing clause, it is the clause that is present and wrong: a policy saying you do not disclose information overseas while your mailing list sits on a US platform is an inaccurate representation about your business, in writing.