Australia

Australian Privacy Policy Template

A free, ready-to-publish privacy policy that complies with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles.

Free · No signup · PDF & DOCX export · GDPR / CCPA / UK / CA / AU / LGPD / DPDP

No account or signup required
GDPR & CCPA clauses included
Clauses for AI tools & SaaS
Free PDF & DOCX export
Page last updated · May 2026

Australian businesses with annual turnover over $3M (and many smaller businesses, including health and online sellers) must comply with the Privacy Act. Our template covers the Australian Privacy Principles in plain English.

What's included

  • All 13 Australian Privacy Principles
  • OAIC complaint procedure
  • Cross-border data transfer disclosures
  • Notifiable Data Breaches scheme
  • Cookies and online tracking
  • Free PDF & DOCX download

Why you need this

  • Required by the Privacy Act 1988 for many Australian businesses
  • Required for any business handling health information
  • Required by Australian e-commerce regulators
  • Builds buyer trust in the Australian market

How the Australian Privacy Act applies to smaller businesses

The Privacy Act 1988 and the 13 Australian Privacy Principles apply to APP entities — broadly, agencies and organisations with turnover above the small-business threshold, plus specific categories regardless of size, such as health service providers and businesses that trade in personal information. Many small operators fall outside the Act but choose to comply voluntarily, and platforms and enterprise customers increasingly expect it.

APP 1 requires a clearly expressed and up-to-date policy that is available free of charge, which is why the document is usually the first thing a reviewer looks for.

  • What you collect and why (APP 3 and APP 5 notice)
  • Overseas disclosure — name the countries where your providers process data (APP 8)
  • Access and correction process (APP 12 and 13)
  • Complaint handling, including escalation to the OAIC
  • Direct marketing and opt-out (APP 7)

Notifiable data breaches and complaints

Entities covered by the Act must assess suspected eligible data breaches and notify affected individuals and the OAIC where serious harm is likely. Your policy is the right place to publish the contact point that handles privacy complaints, and to explain that unresolved complaints can be taken to the OAIC. Australian privacy law has been under active reform, so review the wording periodically rather than treating it as final.

Not legal advice. PolicyGenie is a self-help document tool, not a law firm. The templates and articles here are general information only and may not fit your circumstances or reflect the most recent changes in the law. Review anything you publish, and get advice from a qualified lawyer in your jurisdiction if your business handles sensitive data or operates in a regulated industry. See our full disclaimer.

Advertisement

Generate your policy now

Free • PDF & DOCX • No signup

Start the generator

Frequently asked questions

Everything you need to know before publishing your policy.