Skip to main content

    AU Privacy Policy Generator

    Draft a Privacy Act 1988 compliant privacy policy for an AU SME, covering the 9 matters APP 1 requires, sector-specific overlays (health, NDIS, finance), cross-border disclosures (APP 8), and plain-English language accessible to non-lawyers. Produces ready-to-publish Markdown + a rollout checklist.

    intermediate
    Compliance & Legal
    Australian-Specific
    45–60 min first draft, 15 min per update
    1 uses
    Quick Start

    Australian Privacy Act compliant privacy policy templates

    Complete Guide

    When to use

    Triggers:

    • "Generate a privacy policy" / "Write our privacy policy"
    • "Draft a privacy policy" / "Update our privacy policy"
    • "Privacy policy template"
    • "We just launched a new [product/service] — does our privacy policy cover it?"
    • Any AU SME building or revising their website / app / CRM-related privacy policy

    Don't fire for:

    • The full privacy audit (use au-privacy-act-compliance-audit instead — this skill assumes you know your data flows)
    • Incident notification drafts (different workflow under the Notifiable Data Breaches scheme)
    • Non-Australian privacy frameworks (GDPR, CCPA — different skills)

    Prerequisites

    Before drafting, gather:

    1. Business details — legal name, ABN, trading name, primary jurisdiction (state)
    2. What personal information is collected — per source (website, app, phone, in-person, third-party sources)
    3. Why it's collected — the primary purpose (service delivery, support, marketing, compliance)
    4. Where it's stored — tools / SaaS / cloud locations (flag US / EU / Singapore vs AU)
    5. Who has access — your team, contractors, third-party services (MailChimp, Google Workspace, Claude, etc.)
    6. Direct-marketing practice — do you send marketing emails or SMS? Under what consent basis?
    7. Sector-specific overlays — are you a health service provider, NDIS registered, AFSL holder, credit provider?
    8. Complaints process — who handles privacy complaints internally, how do customers reach them?
    9. Last policy version and date (if updating an existing policy)

    If any of 1–7 are missing, stop and ask. Privacy policies built on guesses are the ones that end up non-compliant.

    The 9 matters APP 1 requires

    A compliant policy (APP 1.4) must cover:

    1. The kinds of personal information collected and held
    2. How personal information is collected
    3. The purposes for which personal information is held, used, and disclosed
    4. How individuals may access their personal information and seek correction (APPs 12 and 13)
    5. How individuals may complain about a breach of the APPs and how the business will handle it
    6. Whether personal information is likely to be disclosed to overseas recipients
    7. If likely to be disclosed overseas, the countries where recipients are likely to be located (if practicable to specify)
    8. Whether the business is likely to collect personal information from sources other than the individual (e.g. data brokers, publicly available sources)
    9. Any other information required by the APPs

    Plus (not strictly APP 1 but best practice):

    • How long the business retains personal information
    • Security measures in place (broad description, not a detailed security document)
    • Children's information handling (if the business serves under-18s)
    • Cookies / tracking technology on the website

    Standard policy structure

    Privacy Policy — [Business Legal Name]
    
    Effective date: [DD Month YYYY]
    Last reviewed: [DD Month YYYY]
    
    ## 1. About this policy
    Short paragraph — who the business is, what it does, why this policy exists.
    
    ## 2. The personal information we collect
    - Identifiers (name, date of birth, contact details)
    - Business identifiers (ABN, ACN, role, company name)
    - Transaction information (what you buy, when, how much)
    - Technical information (device, browser, IP — via cookies)
    - Communications (emails, phone calls, support tickets)
    - Sensitive information — [only if applicable; list specifically: health, financial, biometric, criminal history]
    
    ## 3. How we collect it
    - Directly from you (via forms, phone, in person)
    - Automatically (via our website analytics, app telemetry)
    - From third parties [specify: credit bureau, social login, referral partner]
    - Publicly available sources [specify, if applicable]
    
    ## 4. Why we collect it
    Plain-English list tied to specific purposes. Avoid "to improve our services" as a catch-all.
    
    ## 5. How we use it
    - To deliver the services you've asked for
    - To contact you about your account
    - To send you marketing [if applicable — and state consent mechanism]
    - To comply with legal obligations (tax, AML, industry regulation)
    
    ## 6. Who we share it with
    - Our team (access restricted to role-based need)
    - Our service providers [list categories: payment processor, email provider, cloud hosting, CRM — name the key ones where practical]
    - Regulators / courts [when legally required]
    - Business transfer recipients [if applicable — in M&A scenarios]
    
    ## 7. Overseas disclosure
    If your SaaS stack includes anything stored outside Australia:
    "We disclose personal information to recipients in the following countries: [list]. This typically occurs when using [named service]. We take reasonable steps under APP 8.1 to ensure overseas recipients handle personal information consistent with the APPs."
    
    If no overseas disclosure (rare for modern businesses):
    "We do not disclose your personal information to overseas recipients."
    
    ## 8. How we protect it
    High-level: access controls, encryption in transit and at rest, staff training, vendor due diligence. Don't publish security architecture details.
    
    ## 9. How long we keep it
    "We retain personal information for as long as necessary to deliver the services and to comply with legal retention obligations (generally 7 years for financial records under ATO requirements, or longer where specific laws apply — e.g. health records in some states require longer retention)."
    
    ## 10. Your rights
    - Access — how to request a copy
    - Correction — how to request corrections
    - Withdrawal of consent (for direct marketing) — unsubscribe link, SMS STOP, or contact details
    - Complaints — internal complaints contact, and then OAIC external recourse
    
    ## 11. Cookies and tracking
    If you use cookies (most businesses do):
    - What cookies you use (essential, analytics, marketing)
    - Consent mechanism (banner, toggle)
    - How to opt out
    
    ## 12. Changes to this policy
    "We may update this policy from time to time. Material changes will be communicated via [email to account holders / banner on our website / 30 days' notice]. The 'Last reviewed' date at the top indicates the latest update."
    
    ## 13. Contact us
    Privacy Officer: [name or role]
    Email: privacy@[business].com.au
    Post: [business address]
    Phone: [number]
    
    To complain externally:
    Office of the Australian Information Commissioner (OAIC)
    Website: oaic.gov.au
    Phone: 1300 363 992
    

    Sector-specific overlays

    Health service providers

    Additional sections required:

    • Health information as a sensitive information category with specific consent handling
    • My Health Record (if you're a registered provider) — separate policy section
    • Referrals to other providers — consent mechanism for sharing clinical information

    NDIS registered providers

    Additional requirements from the NDIS Practice Standards:

    • Participant rights around information about themselves
    • Family / guardian / nominee consent mechanisms
    • Sharing information with the NDIA for compliance / audit
    • Secondary use (research, quality improvement) consent

    Cross-reference your internal service agreement (see ndis-progress-notes-assistant).

    AFSL (financial services)

    • Credit reporting information handling (if applicable, per Privacy Act Part IIIA)
    • Client identification obligations under AML/CTF Act
    • Professional services privilege interaction

    Education

    • Child-student information under state legislation (Victorian VIT, NSW TRB, etc.)
    • Parental access rights for minors

    Cross-border disclosure detail

    If your SaaS stack includes services hosted outside Australia — and most do — you MUST disclose this. Be specific where practical.

    Common AU SME SaaS and where they store data (verify with your vendor):

    | Service | Primary storage | What to say | |---|---|---| | Google Workspace | US (with AU option available) | "We use Google Workspace which may store your information in the United States. We have a data processing agreement with Google." | | Microsoft 365 | AU (for most AU tenants) | "We use Microsoft 365 which stores your information in Australian data centres." | | Xero | AU | "We use Xero which stores your financial information in Australia." | | MYOB | AU | Similar. | | MailChimp | US | "We use MailChimp for email campaigns, which stores contact data in the United States." | | HubSpot | US (with EU option) | "We use HubSpot CRM which stores information in the United States." | | Stripe | US + regional | "Payment processing is handled by Stripe, which processes data in the United States and other regions." | | Claude | US (with enterprise zero-retention option) | "We use Anthropic's Claude AI. If you submit personal information through our Claude-assisted workflows, it is processed in the United States subject to Anthropic's enterprise terms (including zero-retention where applicable)." |

    Be precise. A vague "we may share information with third parties" is not APP 8-compliant.

    Consent mechanisms

    For marketing (email, SMS, push), the policy must describe:

    • Express consent — opt-in checkbox, tick-box, acknowledgement at signup. The form itself must be present and dated.
    • Inferred consent (for B2B only, per Spam Act 2003) — existing business relationship or publicly published business email
    • Withdrawal — unsubscribe link working for at least 30 days, honoured within 5 business days (see au-cold-outreach-spam-compliant)

    Notifiable Data Breach (NDB) preparation

    The policy doesn't list your NDB plan — that's internal. But the policy should say:

    "In the event of a data breach that is likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme."

    Your internal NDB response plan is covered separately (see au-privacy-act-compliance-audit).

    Rollout checklist

    After drafting:

    □ Draft reviewed by owner / Privacy Officer
    □ Draft reviewed by privacy counsel (strongly recommended for compliance-sensitive sectors)
    □ Policy published on website at /privacy (or /privacy-policy)
    □ Policy linked from every form that collects personal information
    □ Policy linked from website footer
    □ Mobile app privacy policy link (if applicable) updates pushed
    □ Email marketing footer links updated
    □ Internal team trained on the policy
    □ Previous policy version archived with date
    □ Review cadence scheduled (12 months, or on material change)
    

    Output format

    Per request:

    1. Full privacy policy draft — Markdown, ready to publish (or hand to web designer)
    2. Gap list — fields the operator needs to fill in before publishing
    3. Sector-specific overlay — additional sections if relevant
    4. Rollout checklist — as above

    What this skill does NOT do

    • Replace legal counsel. For health, financial services, NDIS, government contractors, novel tech (biometric, AI, IoT), get legal review.
    • Cover GDPR / CCPA / UK DPA. Different frameworks. If you serve customers in those jurisdictions, you need additional policy sections.
    • Lodge with any authority. Privacy policies don't need lodgement — they need publication.
    • Handle your actual NDB response. That's operational, not policy.

    Tier access

    Base. Universal need. Pro-tier members get a privacy counsel review cycle via THL's referral network.

    Related skills

    • au-privacy-act-compliance-audit — upstream audit; the policy implements what the audit surfaces
    • au-cold-outreach-spam-compliant — consent and withdrawal mechanisms tie back to the policy
    • ndis-progress-notes-assistant — NDIS privacy overlay detail

    References

    Usage Examples
    • →Privacy policy for e-commerce website
    • →Privacy policy for service business with contact forms
    • →Mobile app privacy policy
    Skill Details

    Source

    community

    Author

    Tech Horizon Academy

    Version

    2.0

    Complexity

    Compatible With

    Claude web
    Claude api

    Prerequisites

    • Business description
    • Data collection practices
    • Third-party services list

    Best For

    retail
    professional services
    trades

    Tags

    app-1
    compliance
    oaic
    privacy
    privacy-act
    privacy-app-8
    privacy-policy
    Need Help?
    Learn more about using Claude Skills effectively