Do you now need a Privacy Policy?
- Austin Jenish
- 1 day ago
- 3 min read
A summary of recent changes to Privacy Law and consequences for non-compliance.
There have been significant expansions of privacy law in Australia in 2026, and many organisations which have not previously been required to have privacy policies are now obliged to.
The Privacy Act 1988 (Cth) is the main legislation governing Australian Privacy Law. It is the source of the 13 Australian Privacy Principles (APPs) and defines the “APP organisations” and “APP agencies” which are bound by them.
All APP organisations and APP agencies must have a Privacy Policy. APP agencies generally refer to Federal government departments, bodies, ministers and other public entities, while APP organisations are private sector organisations that meet certain criteria.
From around mid-2026, changes to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the AML/CTF Act) have brought many businesses within the APP organisation criteria who didn’t previously need a privacy policy. These include real estate agents, lawyers and accountants, if they provide certain ‘designated services’ such as controlling or holding a person’s money, buying and selling companies or transactions involving the transfer of real estate.
Generally, if you have an obligation to report to the Australian Transaction Reports and Analysis Centre (AUSTRAC) under AML/CTF laws, you will now require a Privacy Policy.
Overview of Australian organisations that need a Privacy Policy
Any organisation that falls into any one or more of these categories is an APP organisation and is required by law to have a Privacy Policy:
You have at least one business with an annual turnover of more than $3,000,000; or
You disclose personal information from other people for your benefit or advantage (e.g. you sell personal information as part of your business); or
You provide personal information to other organisations for data analytics, marketing or other assessments to improve your business; or
You purchase client lists or procure clients from other organisations; or
You receive referral commissions; or
You provide a health service and hold any health information (other than employee records); or
You are a mortgage insurer or trade insurer; or
You are a contracted service provider for the Federal Government; or
You are a credit reporting body or a credit provider; or
You provide life insurance, pensions or superannuation; or
You provide certain legal, accounting, financial or real estate services; or
You otherwise have obligations to report to AUSTRAC based on AML/CTF regulations.
This list covers the common reasons for an organisation to be an APP organisation, but it is not comprehensive and there are other organisations which will require a privacy policy.
If you require a Privacy Policy, it must be tailored to your specific business practices and should be prepared with legal advice. A generic ‘industry template’ is very unlikely to accurately describe your business’ actual practices with accuracy, which can lead to penalties as described below.
Consequences for non-compliance
If you do not have a Privacy Policy and you are required to have one, you can face civil penalties under the Privacy Act. You can be issued an infringement notice by the Office of the Australian Information Commissioner (OAIC) for not having a Privacy Policy, or for failing to update your Privacy Policy or for serious breaches of your policy. Infringement notices are individually capped with maximum penalties, but where there are multiple breaches it is common for the OAIC to issue multiple notices, each with a separate cap.
Maximum civil penalty for an infringement notice
Breach | Fine for Individuals | Fine for Corporations |
Missing Policy | $72,800 | $364,000 |
Incorrect or out-of-date Policy | $72,800 | $364,000 |
Failure to deal with Privacy Requests | $72,800 | $364,000 |
Failure to provide the option of anonymity | $72,800 | $364,000 |
Breaches can also lead to a business facing other risks such as litigation from people or organisations harmed by the breach. There are also greater penalties for serious breaches such as interfering with the privacy of an individual.
Kyard Business Law can update your Privacy Policy or provide a new policy that is tailored to your circumstances and business. We also provide Credit Reporting Policies and other specialised Privacy Law products, as well as general commercial law services which reflect our extensive expertise.
Disclaimer: This is general information only and does not constitute legal advice. This information was last updated in August 2026, and has been written as a summary of key information and is not technically comprehensive.



Comments