There is a legal minimum, and it is shorter than most people expect. APP 1.4 of the Privacy Act 1988 (Cth) lists what a privacy policy has to contain. Everything else in a good policy is there because the minimum does not describe a real business on its own.
Here is the list, in the order it appears in the Act, with what each one actually asks of you, and then the three sections that have grown up around it, none of which are in APP 1.4 and all of which a 2026 policy is judged on.
The seven things APP 1.4 requires
- The kinds of personal information you collect and hold. Not “your personal information&rdquo, the kinds. Names and emails are different from dates of birth, which are different again from health information or government identifiers.
- How you collect it, and how you hold it. Collected directly from the person, or from somewhere else? Held in a cloud service, on a laptop, in a filing cabinet?
- Why you collect, hold, use and disclose it. The purposes. This is the one that does the most work in practice, because APP 6 then limits you to those purposes.
- How someone asks for access to their information, and asks you to correct it. A named route, not a general contact page.
- How someone complains about a breach of the APPs, and how you will handle it. Both halves. A complaints address with nothing about what happens next does not satisfy this.
- Whether you are likely to disclose information overseas.
- And if so, the countries those recipients are in: named, where it is practicable to name them.
The automated-decision disclosure, from 10 December 2026
This is the one people have heard about and almost nobody has scoped. From 10 December 2026, APP 1.7 and APP 1.8 (inserted by the Privacy and Other Legislation Amendment Act 2024) require a privacy policy to describe decisions made or assisted by computer programs. It is much broader than “do you use AI”: a scoring tool, an eligibility rule, an automated approval or rejection can all count.
APP 1.7 is a three-limb test, and all three have to be met. Most of the advice circulating only asks the first one, which is why so many businesses think they are either obviously in or obviously out when they are neither:
Personal information is used in a computer program.
Not necessarily machine learning. A spreadsheet rule that reads a customer’s details counts as a computer program.
The program does something that plays a material role in making a decision.
This is the limb most often got wrong. “A person reviews it before we act” does not put a system out of scope. The OAIC’s guidance counts the program’s output regardless of whether it is advisory or determinative, a recommendation a human almost always follows is material.
The decision could reasonably be expected to significantly affect a person’s rights or interests.
And this is the limb that keeps ordinary software out. A spam filter and a booking-slot allocator make automated decisions about people and reach nobody’s rights or interests. Credit, eligibility, pricing, employment and access to a service generally do.
If all three are met, APP 1.8 then tells you what the policy has to set out, and it is three separate things, not one paragraph:
- The kinds of personal information those programs use.
- The kinds of decisions made solely by the program, with no person involved.
- The kinds of decisions where the program does something materially relevant to a decision a person still makes.
Nothing has to be published before 10 December 2026. But the disclosure has to describe systems you are already running, so the work is finding out what your software actually decides, which takes longer than writing it up. The full guide to the automated-decision disclosure is here.
The AML/CTF privacy disclosure, if you provide a designated service
This one is already in force, and it is the section most often missing from policies that otherwise look complete. On 1 July 2026 the anti-money-laundering regime took in a new group of designated services, real estate agency work, conveyancing, professional services that set up or administer companies and trusts, and dealing in precious metals and stones.
Whether it reaches you is two inputs and an output, and the two inputs are both in the AML/CTF Act 2006:
- You provide a designated service listed in section 6. The professional services are in table 6.
- That service has a geographical link to Australia under section 6(6), provided from Australia, or to customers in Australia.
- Together, those make you a reporting entity, and the Privacy Act then treats a reporting entity as an organisation whatever its turnover, for the personal information it handles for those services. The $3 million exemption does not help you here.
The privacy disclosure that follows covers four things: the identity documents you collect, that you cannot provide the service without them, how long you keep the verification records, and that you report to AUSTRAC without needing consent: including that you are not permitted to tell someone a suspicious matter report has been made about them.
The guide to the AML/CTF privacy disclosure is here.
Notifiable data breaches, and the 30-day clock
APP 1.4 does not require this either. But the Notifiable Data Breaches scheme in Part IIIC has applied since 2018, and a policy that says nothing about breaches is describing a business with no plan for one. Three things are worth stating, and they are the three the scheme actually turns on:
- That you assess a suspected eligible breach promptly, and within 30 days. The clock starts when you have reasonable grounds to suspect, not when you are sure.
- That if serious harm is likely, you notify both the person and the OAIC as soon as practicable: what happened, what information was involved, and what they should do about it.
- That if you can prevent the harm before it occurs, notification may not be required. That is a real part of the scheme, and saying so is more honest than promising to notify on every incident.
Saying this is reassuring precisely because most policies do not. The guide to breach notification is here.
What the list does not name, and a policy still needs
These are not in APP 1.4. They are in a policy that is actually about your business, and their absence is what makes a template obvious:
- Cookies, analytics and tracking. What your website loads, and what it sends elsewhere. The regulator has been explicit that a cookie banner is not consent for a tracking pixel.The June 2026 determinations are here.
- How long you keep things. APP 11.2 requires you to destroy or de-identify personal information you no longer need. A policy that never mentions retention is describing a business that keeps everything forever, which is rarely true and never a good look.
- Who to contact. A role and an email. “Contact us” linking to a form is not a privacy contact.
The test that matters
Read your policy next to what your website actually does. If the policy says you do not disclose information overseas and your mailing list is on a US platform, the policy is wrong, and it is wrong in writing, which is worse than silence. A policy is a representation about your business, and the Australian Consumer Law has something to say about representations that are not accurate.
That mismatch is the single most common finding we see. It is also the reason we sell the audit and the builder as two different products: one writes the policy, the other reads the live site and tells you whether the two agree.
General information, not advice. This is general information about Australian law, the same for every reader. It is not advice about your situation, and AegorIQ is not a law practice. If you are unsure which parts apply to you, your accountant or a lawyer can tell you.
Sources
- OAIC, Australian Privacy Principle 1: Open and transparent management of personal information
- OAIC: Read the Australian Privacy Principles
- OAIC, Automated decisions and privacy policies (from 10 December 2026)
- OAIC, Notifiable Data Breaches scheme (Privacy Act 1988, Part IIIC)
- AUSTRAC, New industries regulated by AUSTRAC from 1 July 2026
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006, s 6 designated services, s 6(6) geographical link