4.8

Google Reviews

Need Help? Contact An Australian Business Lawyer Today 1300 003 077
Search
Close this search box.

What Do I Need In A Privacy Policy?

Most Internet users have heard of a privacy policy. However, you may not know what it does or what it generally includes.

A Privacy Policy is important for every business. A privacy policy needs to include all the information set out in the Privacy Act 1988. We also recommend that a privacy policy includes information that is helpful and transparent for its readers.

If you have a website or app that collects personal data from its users, you need to establish a policy. Although it’s common for users not to read through this policy, it’s essential to have one for your business.

In this article, our privacy and data lawyer, explains why a privacy policy is important and what you should have in your businesses privacy policy.

Key takeaways

    • A privacy policy is a legal requirement if you collect and process personal data from customers or users of your website
    • Your privacy policy should be placed somewhere prominent on your website
    • Be transparent and disclose anything a user may want to know about how their personal information is going to be collected, used and disclosed
    • Businesses should not copy privacy policies from other websites

What is a Privacy Policy?

A privacy policy is a legal requirement if you collect and process personal data from customers or users of your website.

It discloses what kind of data you collect, how you collect it, what it is used for, where it is stored, and how you keep it secure. It also describes how you collect personal data, for example, using cookies, and how users can limit the data they share with you.

The definition of personal data varies depending on applicable law. However, personal data is any data that allows businesses to identify a person.

Examples of the types of personal information include:

  • Name
  • Email address
  • IP address
  • Passport Number

You may also collect sensitive data such as financial details, biodata, or data of minors. If you collect such data, you should highlight it in a Privacy Policy.

Why privacy policies are important

Reason One: It’s a Legal Requirement under Australian Privacy Laws

In Australia, collecting and storing personal information requires a privacy policy as a legal requirement. However, the law only requires businesses that meet certain criteria to have one. We will discuss those criteria below.

We are also aware that there are some significant changes coming to Australia’s privacy laws. You may need to revisit any privacy policy you include now once the new law comes into effect.

Reason Two: It builds trust and shows respect for your users’ privacy

A privacy policy shows that your company takes the data collected from its users seriously. A privacy policy assures website users and customers that you will keep their personal information safe and private. Additionally, they can trust that your business follows Australian laws.

Reason Three: It’s a requirement of a third-party service you use

Operating an online business or website often requires the use of third-party tools or services. For example, most websites use analytics tools to track the traffic coming to the website and traffic patterns. Websites and blogs often use advertising to generate revenue and affiliate links. All these services may require that your website, blog, or eCommerce store have a policy.

For example, companies like Google and Apple require your website to include a privacy policy.

Where to put a Privacy Policy?

Your policy must be easily accessible to your users or customers. Your privacy policy should be clearly displayed on your website and on every page where you gather personal information from users.

Here are some suggested locations for your businesses privacy policy:

Header Menu

The most obvious and prominent placement for the policy is in the website’s header menu. Business can out the privacy policy, terms and conditions, and feedback page on the header menu of your website.

The header menu can be accessible from any website page, and users can easily navigate to the privacy policy.

Make sure you have clearly marked your policy as “Privacy Policy” so that there is no confusion among users.

Footer

The website footer is another popular location for businesses to post their policy. It’s also accessible from any page on your website.

About us

Another place where your privacy policy could be housed is on the main menu under an “About Us” section. This is a convenient and easily accessible option, again, typically available on every page of your website.

Checkout Forms

An easy way to ensure your users can find your privacy policy is to add it to your checkout form (if suitable). This is typically done by adding a checkbox next to a statement such as “I have read and agree to the Privacy Policy.

The checkbox is near the “Pay” button, and you cannot process the transaction until you check the checkbox. A link to your privacy policy is provided. This means the customer must generally agree to, and read the privacy policy to purchase.

Do I need a privacy policy?

You need a privacy policy if:

  • your business has an annual turnover of more than $3 million
  • your business is a health service provider
  • your business engages in credit reporting activities
  • your business provides services to organisations covered by the Privacy Act
  • you collect personal information online
  • your business transfers personal information overseas

There are a variety of ways you can collect data from your users.

Some examples are:

  • Using cookies on your website;
  • Collecting email addresses for monthly newsletters;
  • Collecting email addresses to advise when you are running a sale or to publish your next blog post;
  • Collecting personal information to send goods to your customers.

What does a Privacy Policy need to include?

A policy should be a comprehensive handbook that leaves no stone unturned. It should encompass the following elements:

  1. The type of personal information you collect and store
  2. The purposes for which you collect, retain, use and disclose personal information
  3. How you collect and securely store personal information
  4. A promise not to “spam,” sell, or rent a visitor’s email address
  5. How an individual can get access to personal information and correct the information you hold, including unsubscribing from an email list
  6. How an individual can complain about a breach of the Australian Privacy Principles and how you’ll handle the complaint
  7. How you share personal information with others, and if they’re in other countries, the countries it will be shared with.
  8. Your contact details
 

The Australian Privacy Principles

The Australian Privacy Principles (APPs) strengthen Australia’s data protection by providing 13 fundamental rules for managing personal information. A robust policy must align with these principles, ensuring comprehensive adherence to the legal framework. These principles address matters such as lawful data collection, responsible use, and vigilant data security.

Tailor your Australian privacy policy to your business

We don’t recommend copying and pasting policies from other websites as they may not fully meet your needs.

A privacy policy is a legal document that informs and protects consumers. It should be well-written, readable, understandable, and accurate. Readers and customers won’t find a policy helpful if they cannot understand the meaning behind the legal jargon.

There are several ways to write a company’s privacy policy, and they’re:

  1. Hiring a law firm: reliable legal advice and the most expensive option available;
  2. Writing it yourself: The cheapest option, but also the most difficult and time-consuming. If you’re not familiar with the rules and regulations, you could miss important information and put your business at risk.

It’s best to hire a privacy lawyer to draft a privacy policy for your business website. If you want to write it yourself that is acceptable. However, we recommend hiring a privacy lawyer to review your privacy policy.

Privacy policy

Frequently asked questions

Where should I place my privacy policy on my website?

A privacy policy should be prominently placed where visitors can easily find it, such as in the website’s header, footer, or on a dedicated page linked from places where personal information is collected, like signup or checkout forms.

Yes, if your website uses cookies to collect data, such as tracking user behaviour or storing preferences. Businesses should include a section in your privacy policy that explains how cookies are used and what data they collect.

Not having a privacy policy when required can lead to legal penalties, including fines and regulatory actions.

It can also harm your business’s reputation and trustworthiness, as customers may be reluctant to share their personal information with you.

It’s essential to review and update your privacy policy regularly, especially when there are changes in your business practices, data collection methods, or applicable laws.

Keeping the policy up-to-date ensures ongoing compliance and transparency with your customers.

To ensure compliance, it’s advisable to consult with a privacy lawyer who can tailor your policy to meet the specific requirements of the Privacy Act 1988 and other relevant regulations, ensuring it covers all necessary aspects.

Use clear, straightforward language and organise the policy logically with headings and sections.

Avoid legal jargon to ensure that all users, regardless of their legal knowledge, can easily understand their rights and your practices.

About the Author

Farrah Motley
Director of Prosper Law. Farrah founded Prosper online law firm in 2021. She wanted to create a better way of doing legal work and a better experience for customers of legal services.

Contact an Australian Business Lawyer Today.

Contact us for a free consultation

Contact Us For A Free Legal Consultation
About Prosper Law

We provide legal advice to business and individuals across Australia, no matter which State or Territory you are located. Our easy-to-access, online legal services mean that you can talk to our lawyers wherever you are, at a time that suits you.

4.8

Google Reviews

Get Your Free Guide Now
Need Legal Assistance?

Don’t hesitate – reach out for your free legal assistance today. Your peace of mind is just a click or call away!

Check Out Our Latest Blog Posts

employer defending unfair dismissal
Business

Terms and conditions for your competition

Trade promotions and competitions have become a common tool for businesses to connect with their customers, create brand awareness and loyalty, and support sales and social media engagement. Whether it’s