Privacy Laws Are Changing: Does Your Business Need a Privacy Policy?

Privacy likely isn't the first thing you think about when it comes to your business website.

You're more likely to be worrying about whether the branding looks right, whether people can find your services, or why nobody seems to be filling out your contact form. But there's another question worth asking: what happens to all the personal information your business collects?

Names. Email addresses. Phone numbers. Enquiry details. Customer records. Newsletter subscriptions. Depending on what your business does, there could be quite a lot of it. With Australia's privacy laws continuing to evolve, having a Privacy Policy is becoming increasingly important.

Before we go any further, a disclaimer. We're website designers in Adelaide and digital marketers, not lawyers. This isn't legal advice, and privacy obligations vary depending on your business, what information you collect and how you use it. That being said, it is something Australian businesses should be paying attention to.

Australia's privacy laws are changing

Australia's Privacy Act 1988 isn't exactly new. The way businesses collect, store, and use information, however, has changed dramatically since its introduction.

For many years, most businesses with an annual turnover of $3 million or less have been exempt from the Privacy Act's 13 Australian Privacy Principles (APPs). As a result, many small businesses haven't had the same privacy obligations as larger organisations, though there are exceptions.

Private sector health service providers, businesses that trade in personal information, and certain businesses connected to larger organisations can already be covered regardless of turnover. There's also been another significant development.

Since 1 July 2026, certain lawyers, conveyancers, accountants, real estate professionals, dealers in precious metals, precious stones and products, and trust and company service providers have become subject to Privacy Act obligations for personal information they handle in connection with their AML/CTF obligations, under expanded Anti-Money Laundering and Counter-Terrorism Financing requirements.

So, yes, privacy rules are changing. But there's an important distinction: the $3 million small business exemption has not yet been removed.

Further reforms are underway, including proposals that could significantly expand the number of businesses covered by the Privacy Act. However, those changes have not yet been legislated. It would be misleading to tell every Australian small business that it is now legally required to have a full APP-compliant Privacy Policy. That doesn't mean the issue can be ignored.

"The way businesses collect, store, and use information, however, has changed dramatically."

Does your business need a Privacy Policy?

If your business is covered by the Privacy Act, the answer is essentially yes. Australian Privacy Principle 1 requires covered organisations to have a clearly expressed and up-to-date Privacy Policy explaining how they manage personal information. The policy must also be made available free of charge.

And here's an important point that is sometimes overlooked: Your Privacy Policy is about your business, not just your website.

Your website is simply one of the places where your business might collect personal information. Think about what happens away from the website. A customer might phone your office and provide their details. Someone might fill out a paper form. Your sales team could collect information during a meeting. An employee might enter customer details into your CRM. You could receive information by email, through social media, at an event or when someone makes a purchase in person.

All of that can be relevant.

Your Privacy Policy should therefore explain how your business generally handles personal information, rather than being written as though the website is the entire business. The website is just where most people will expect to find it.

Your website is still an important part of the picture

Of course, your website can be a significant source of personal information. Think about a basic contact form. Someone enters their name, email address, phone number and details about their enquiry. Where does that information go? Your email inbox? A CRM? A database?

Then there's Google Analytics, email marketing, online bookings, ecommerce, advertising platforms and customer accounts. Suddenly, that "simple" website design is handling quite a bit of information.

For businesses covered by the Privacy Act, the Privacy Policy needs to explain relevant practices across the organisation. Publishing it on your website is generally the easiest way to make it freely available and easy for customers to find. Usually, you'll see the link sitting quietly in the footer alongside the Terms and Conditions.

It doesn't need to take over your navigation or wave a giant privacy flag at every visitor. It just needs to be there, accessible and kept up to date.

Website designers in Adelaide can ensure your privacy policy is accessible.
Your Privacy Policy should be easy to find on your website.

A Privacy Policy shouldn't be written for robots

No doubt you have seen them. Huge blocks of legal-sounding text tucked away in the website footer. You click the link, read three sentences and decide you'll never understand it… not helpful. 

For businesses covered by the Privacy Act, the OAIC expects Privacy Policies to be clearly expressed and reasonably easy to understand.

In plain English, people want to know:

  • What information does your business collect? 
  • Why do you collect it? 
  • How do you use it? 
  • Who might you share it with? 
  • How is it stored and protected? 
  • How can someone access or correct their information?
  • Who can they contact with a privacy concern?

Because the policy relates to your business as a whole, it should cover the different ways your organisation handles personal information, not just the information captured through the website. That might mean considering customers, prospective customers, suppliers, employees and other people your business interacts with. 

A generic Privacy Policy copied from another website isn't necessarily going to cover any of that particularly well.
 

Your business collects more than you might realise

Your website design may collect information directly through forms, registrations, purchases and bookings. But there can also be plenty happening behind the scenes and outside the website.

Google Analytics can collect information about website use. Advertising platforms can track interactions and build audiences. Email marketing software stores subscriber details. Your CRM may contain customer information. Your hosting provider stores website data. And your staff may be collecting and handling personal information every day as part of their normal work. Some third-party services may also process or store information overseas.

For businesses covered by the Privacy Act, these arrangements can be relevant to their privacy obligations, including requirements around overseas recipients of personal information.

Which brings us to a simple point: Your Privacy Policy shouldn't be a set-and-forget website page.

If your business changes, your Privacy Policy may need to change too. Added online bookings? Started using a new CRM? Introduced email marketing? Changed how customer information is collected or stored? It's worth reviewing the policy.

website designers in Adelaide reviewing Privacy policy
Update your Privacy Policy as your business evolves.

Privacy is also about trust

Privacy isn't only a legal issue. It's a trust issue. When someone gives your business their personal information, they're trusting you to look after it.

From the business side, a contact form might just be another enquiry coming through. From the customer's perspective, it's their name, phone number, email address or other information being handed over to a business they may have never dealt with before. A clear Privacy Policy helps demonstrate that you've thought about what happens next.

It doesn't guarantee compliance. It doesn't replace good data security. And it certainly isn't a magic legal shield. But it does show that privacy isn't an afterthought, and for businesses dealing with sensitive or valuable information, that can be particularly important.

There's more coming

One confirmed change, effective 10 December 2026, concerns automated decision-making. For organisations covered by the Privacy Act, additional information will need to be included in their Privacy Policy where computer systems use personal information to make, or substantially influence, decisions that could significantly affect an individual.

There's also a Children's Online Privacy Code being developed for online services likely to be accessed by children.

And then there are the broader proposed Privacy Act reforms, including the potential removal of the small-business exemption. What those reforms will ultimately look like isn't settled yet, but the direction is clear: Privacy is becoming a bigger issue for Australian businesses.

What should your business do?

You probably don't need a new website design because privacy legislation is changing. But it is worth taking a closer look at how your business collects and handles personal information.

If your business is already covered by the Privacy Act, make sure your Privacy Policy is current, accessible, and reflects your actual business practices. Remember, that means looking beyond the website. Consider how your staff collect information, including via email, over the phone, in-store, through forms, via your CRM, and through the various digital services your business uses.

If you're currently exempt, having a Privacy Policy can still be a sensible move. It provides transparency, gives customers a place to find information, and gets your business thinking about privacy before your obligations potentially change.

And if your existing policy was written several years ago? It might be time to dust it off.

Your business probably isn't the same business it was back then. You've likely added new systems, software, marketing tools or ways for customers to interact with you. Your Privacy Policy should keep up.

Privacy policy review on your website design
Businesses evolve over time. Make sure your privacy policy is current.

Your website design should reflect the business behind it

At Quisk, we spend a lot of time thinking about how a website design represents a business. That's the obvious stuff: branding, design, content and functionality. 

However, a professional website design is about more than its appearance. It's about creating confidence. Making important information easy to find. Being transparent about what happens when someone gets in touch.
Privacy is increasingly part of that picture.

We're not lawyers, just humble website designers in Adelaide, so we'll leave the interpretation of legislation to the people who are. But from a website design perspective, making your Privacy Policy easy to find, easy to understand, and consistent with how your whole business actually handles personal information is a pretty good place to start.

Because your website shouldn't just tell people what your business does. It should show them that you've thought about how you do it, too.

This article provides general information only and does not constitute legal advice. Privacy obligations vary across businesses and can depend on factors such as business activities, the information collected, and how that information is handled. If you're unsure about your obligations, speak with a suitably qualified legal or privacy professional.


References:

SEE ALL BLOG POSTS

Like Coffee? Us too! We prefer Gin, but can definitely do coffee. 

Let's chat

Quisk SEO adelaide branding graphic design website