Does a small business website need a privacy policy in Australia?
Most small businesses are not covered by the Privacy Act, but some are regardless of size. How to find out which side you are on, and what a short privacy page should say either way.
Most small businesses in Australia are not covered by the Privacy Act 1988, so most are not legally required to publish a privacy policy under it. Some businesses are covered whatever their size, and a contact form means your site collects personal information whichever group you are in, so a short privacy page is still sensible. This is general information, not legal advice.
Is my small business covered by the Privacy Act?
The Office of the Australian Information Commissioner (OAIC) states that most small businesses are not covered, and that a small business is one under a turnover threshold set in the Act. Turnover for this purpose includes all income from all sources and does not include assets held, capital gains or proceeds of capital sales. The OAIC's small business guidance gives the current figure and a privacy checklist, so check it there rather than relying on a number copied into a blog post.
The OAIC's checklist starts with one question: does your business handle personal information? If it does not, you do not need to comply with the Australian Privacy Principles. A business with a contact form, a booking system or a mailing list handles personal information.
Which businesses are covered whatever their turnover?
Regardless of turnover, the OAIC lists these as covered:
- Health service providers trading in personal information.
- Contractors providing services under a Commonwealth contract.
- Operators of a residential tenancy database.
- Credit reporting bodies.
- Reporting entities under the anti-money laundering and counter-terrorism financing law.
- Businesses accredited under the Consumer Data Right system.
- Businesses related to a covered business, and businesses that have opted in to the Act.
If your business is in one of those groups, or you are not sure, use the OAIC's checklist or ask your industry association or a lawyer, as the OAIC itself suggests.
What does the Privacy Act require of a covered business?
A covered business has to comply with the Australian Privacy Principles. The first of them, APP 1, requires open and transparent management of personal information, which includes having a clearly expressed and up-to-date APP privacy policy, according to the OAIC's quick reference. The website is the usual place to publish it, linked from the footer so it can be found from every page.
What should a short privacy page cover if you are not covered?
Even where the law does not require one, a short page tells people what happens to what they type into your site. Keep it to facts about your own setup:
- What you collect: the fields on your forms, plus anything your analytics or booking tool records.
- Why you collect it: to reply to an enquiry, to book an appointment, to send a newsletter they asked for.
- Who else receives it: your email provider, booking tool, CRM or analytics provider. Every integration is another copy of that data, so the list should match what is connected.
- How long you keep it and how someone asks you to delete or correct it, with a contact address that is monitored.
Write the page from your real setup rather than from a template, and update it when you add a tool. A policy that describes systems you no longer use, or misses ones you do, is worse than a short accurate one.
Who should check your forms and tools?
Whoever controls your accounts should be able to list every place a form submission ends up. That is the same list as the accounts covered in our post on who owns your website, and it is the list the privacy page is written from. If nobody can produce it, that is the first job.
If you want a person to go through your forms, analytics and connected tools and tell you what the page needs to say, request a free website audit.