Privacy Policies: Somebody Is Finally Reading the Fine Print

Published Category: Data Privacy 32 min read 6,336 words by James Nicholson

It is Saturday morning in Sandy Bay, and you are at an open home. You are not buying. You are looking, which in Hobart is a recognised leisure activity somewhere between a bushwalk and a crime. At the front door, a young agent in a very good jacket holds out a clipboard with a QR code on it. "Just pop your details in." Name, mobile, email. You pop them in. You admire a kitchen you will never cook in, and leave.

On the way home you stop at the chemist for cold and flu tablets. The pharmacist asks for your driver licence, types something, then offers a paperless receipt. You accept, so she gets your email too. Then it is the pub, where a scanner at the door reads your licence before you may buy a pint. That evening, a friend books a hire car for next week's trip up the East Coast and uploads a photo of your licence as the second driver. You find this out by text message.

By Saturday night, four businesses have your name, three have details from your licence, and one will ring you on Tuesday to ask how you felt about the kitchen.

You have read zero privacy policies. Of course you have not. Nobody reads privacy policies. A typical one, the ACCC found, runs to 6,876 words and takes about 29 minutes to read, and reading every one you meet would take nearly 46 hours a month. You would have to take out a second mortgage on the Sandy Bay house just to afford the time.

And for years, nobody else read them either. Certainly not the agent in the very good jacket, whose office policy was probably written by a lawyer in 2014 for a different office.

That has just changed. As of January 2026, somebody is reading them, line by line, with a checklist: the regulator.

On 9 December 2025, the Office of the Australian Information Commissioner (OAIC) announced its first-ever privacy compliance sweep. From the first week of January, it would review the privacy policies of about 60 businesses that collect information in person, including real estate agents at open homes, chemists, licensed venues, car rental companies, car dealerships and pawnbrokers. It would check each one against Australian Privacy Principle 1.4, the list of what a privacy policy must contain. And businesses with non-compliant policies "may face compliance and infringement notices and penalties of up to $66,000".

The privacy policy used to be a document that existed so that it could exist. Now it gets tested, and a missing line has a price.

Trust is thin. In the OAIC's own survey, 58% of Australians said they do not understand what organisations do with the information collected about them. A privacy policy is the one place where a business is required to tell them.

So here is the plan. First, what the sweep is and why the regulator chose Saturday-morning businesses. Then we will follow the money: how a missing paragraph turned into something that works like a parking ticket. Then we will read APP 1.4 item by item, the way the regulator will, and go looking for the places personal information comes in that a policy tends to forget. Finally, a (made-up) compliance manager will walk a car yard with a notebook, and you will get a checklist to run on your own business this week.

Let's get into it.

Part 1: What the Sweep Actually Is

Sixty businesses, six sectors, one list

The announcement is short, and every line of it tells you something. The OAIC will review the policies of "approximately 60 entities" from six sectors, and it names the exact kind of collection it has in mind for each:

  • Rental and property: personal information collected during property inspections.
  • Chemists and pharmacists: personal information for a paperless receipt, and identity information to provide medication.
  • Licensed venues: identity information to let people into a venue.
  • Car rental companies: identity and other personal information for a rental agreement.
  • Car dealerships: personal information to let someone take a test drive.
  • Pawnbrokers and second-hand dealers: identity information from people who want to sell or pawn goods.

If you just ticked off four of those from your own last weekend, congratulations: you are the target demographic of a regulatory initiative.

The OAIC says it chose these sectors because of "the particular privacy risks associated with collection of personal information, particularly personal identification documents, and the privacy breaches that have occurred within these sectors". It will pick businesses "having regard to their size and location", and it will include high-profile and high-risk ones, "including entities which may previously have been subject to a data breach". So if your business has already written a breach notification letter, assume the regulator has your name in a folder.

The test itself is narrow. Policies "will be assessed to ensure they meet the requirements of Australian Privacy Principle (APP) 1.4, which sets out what a privacy policy must include." That is the whole brief. The sweep does not ask whether your data practices are good. It asks whether your policy says the things the law says it must say.

Why the counter, and not the website

Most privacy commentary is about websites: cookies, pixels, consent banners. The sweep is about the counter. The Privacy Commissioner, Carly Kind, explained the choice:

"When confronted with in-person requests for their personal information from retailers, licenced venues, car hire companies or real estate agents, consumers often don't have access to all the information they might need to make an informed decision. This makes them vulnerable to overcollection of personal information and creates risks to their security and privacy."

The OAIC calls this "power and information asymmetries", which is regulator language for a simple scene. There is a queue behind you, the person asking for your licence is friendly and busy, and you want the pint. Nobody in that moment asks for the privacy policy. At a counter, the policy is effectively invisible.

The community already feels this. In the OAIC's 2023 survey of 1,916 Australians, real estate agencies and social media companies were the two least trusted sectors on the list. Almost half (46%) called real estate agencies "very" or "somewhat untrustworthy", against 66% for social media companies.

It also matters what gets collected. A phone number is one thing. A driver licence is an identity document, and when one leaks, you are the person who queues to replace it. In 2024, IT provider Outabox, whose sign-in systems were used by pubs and clubs, had a breach. A website that appeared to be run by someone with knowledge of its systems claimed that 1,050,169 records had been exposed worldwide, including driver licences, signatures and facial recognition data. ClubTIC listed 17 affected pubs and clubs. ID Support NSW confirmed the incident affected clubs in NSW and the ACT and that the OAIC had been notified. The venue scans your licence for a few seconds of checking. The copy can then live on in somebody's system for years.

A sweep is not an investigation

"Sweep" sounds like police in hi-vis walking a paddock. It is closer to a lecturer marking sixty essays against one rubric.

The Information Commissioner can assess an organisation's compliance with the APPs under section 33C of the Privacy Act. Document reviews like this are not new. In 2015, the OAIC reviewed 20 website privacy policies (more on that in Part 4). And in 2024, a sweep by the Global Privacy Enforcement Network (GPEN), which the OAIC reported on, looked at more than 1,000 websites and apps and found that more than 89% of privacy policies were long or used complex language suited to a university education.1

What is different this time is what can happen after the marking. Moores calls the January sweep "indicative of a move toward exercise stronger enforcement powers", and Clifford Chance says it is "unlikely to be the last". As of late January 2026, the sweep is under way and the OAIC has published no results. To see why the results could sting, we need to look at a change to the law that most small businesses missed.

Part 2: Why a Missing Line Can Now Cost Money

A Flemish-style street where a warden in a red cap pins wax-sealed tickets to market stalls that have no sign above them, while one stallholder hides behind a barrel and a modern ticket machine stands at the end of the row.
Fig. 1 — The warden only checks the sign, generated by OpenAI GPT Image.

Before: a rule with no ticket book

The current privacy policy rule, APP 1, dates from March 2014, when the Australian Privacy Principles began. But, as Meridian Lawyers puts it, after that the Commissioner "had limited ability to enforce the APPs". For a policy that was missing a paragraph, the realistic options were a conversation, an investigation, or a court case for a serious interference with privacy. A sloppy policy was almost never serious enough to be worth a court case. So the rule existed, and in practice it was checked mostly after something else had gone wrong.

That is how the one real policy finding most people know about happened. In November 2024, the Commissioner found that Bunnings had breached privacy law with its facial recognition system in 63 stores, and one of the findings was that it "did not include required information in its privacy policy". But that finding came at the end of a long investigation into something much bigger.2 The policy failure was found because somebody looked at the cameras first.

I wrote about the reforms that were coming back in 2023, when they were still a list of proposals. One of them has now arrived, quietly, and it changes the economics of a sloppy policy.

After: section 13K, the parking ticket

You already understand how this works, because you have had a parking ticket. Nobody takes you to court for parking in a loading zone. A warden walks past, sees a fact that is either true or false (car, loading zone, 10:42 am), and writes a ticket. You can pay it, and that is the end of it. Or you can refuse and argue it before a magistrate, at your own cost and risk. The system works because the rule is black and white and the fine is small enough to make arguing a bad deal.

The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and gave the OAIC a ticket book. Section 13K of the Privacy Act now lists a set of specific APP obligations. If an organisation breaches one of them, it contravenes a civil penalty provision, and the OAIC can issue a compliance notice or an infringement notice. Addisons sets out the list. It starts with:

  • APP 1.3: the requirement to have an APP privacy policy.
  • APP 1.4: the contents of the APP privacy policy.

It goes on to cover the right to deal with a business anonymously (APP 2.1), a written note of certain uses or disclosures (APP 6.5), direct marketing opt-outs (parts of APP 7) and response times for correction requests (APP 13.5). The regulations can add more.

None of these asks a hard question like "was this collection reasonably necessary?" Each is a fact you can check from a desk. Clyde & Co describes the privacy policy one neatly: "the organisation either has an APP 1.3 compliant privacy policy or it doesn't". That is the loading zone. The regulator needs only your policy, the text of APP 1.4 and an afternoon.

Two notices, in order

A compliance notice is a warning with a to-do list. It identifies the breach and tells you what to fix, by when. Clyde & Co notes three things about it. It is optional: the OAIC does not have to send one before it moves to a penalty. While it is in effect, or once you have complied, the OAIC cannot pursue a penalty for the same conduct. And ignoring it is a contravention in its own right.

An infringement notice is the ticket. It states the alleged breach and an amount. You can pay it and move on. If you want to contest it, Clyde & Co says, you have to go to court.

The OAIC says it "takes a risk based and proportionate approach", so many businesses caught by the sweep may only see a compliance notice. But the ticket book is in the warden's pocket, and this is the first time the warden has walked the street.

The arithmetic of "up to $66,000"

Now the number in the headline. Penalties in Commonwealth law are set in penalty units, a unit of money that the government indexes over time so that the Act does not need rewriting every time prices rise.3 The law firms that wrote about these notices before the sweep used $330 a unit.

On their reading, an infringement notice for one contravention is:

  • 12 penalty units ($3,960) for an individual;
  • 60 penalty units ($19,800) for a body corporate;
  • 200 penalty units ($66,000) for a listed corporation.

Clyde & Co and Clifford Chance give the same $19,800 and $66,000 figures. So the OAIC's "up to $66,000" is the top of the ticket range, for a company on the stock exchange. For the typical car yard or pharmacy company, the ticket is $19,800.

Two things push the number up. First, each breach is a separate contravention. Addisons points out that having no policy at all breaches both APP 1.3 and APP 1.4, so that is two contraventions. Second, if the matter becomes a civil penalty case in court instead of a ticket, the maximum is much larger: Addisons puts the maximum penalty for a breach of section 13K(1) at 1,000 penalty units ($330,000) for a corporation.

For a small business, $19,800 is a lot of money to pay because nobody updated a document. And as Meridian noted in December, there were "not yet any published examples of the OAIC applying these new powers". Somebody has to be first. The sweep is a very efficient way of finding them.

Part 3: What APP 1.4 Actually Asks For

A privacy policy is a food label

Pick up any packet in your pantry and turn it over. You will find an ingredients list, a nutrition panel, allergens, a use-by date and the name of whoever made it. Every packet has the same boxes because Food Standards Australia New Zealand sets standards for what information must be on food labels. A food inspector does not need to taste the biscuits to find a problem with the label. If the label has no allergen statement, the label is wrong, whatever is in the biscuits.

A privacy policy is a label for how a business handles information, and APP 1.4 is the list of boxes. The sweep is a label inspection. It will not open the packet.

But a label also has to match the packet. A label that says "no nuts" on a packet of walnut biscuits passes a box check and is still wrong. Keep both tests in mind: every box present, and every box true.

The two rules above the list

Before the list, APP 1.3 sets the tone. An organisation must have a "clearly expressed and up-to-date" policy about how it manages personal information. The OAIC's guidelines, updated on 3 October 2025, two months before the sweep was announced, say that a clearly expressed policy should be "easy to understand (avoiding jargon, legalistic and in-house terms), easy to navigate", and should only include information relevant to how the entity manages personal information. It "should be tailored to the specific information handling practices of an entity". A large business whose units handle information differently may need a set of policies.

"Up to date" has a practical test too. The guidelines suggest an entity review its policy at least as part of annual planning, and include a note showing when it was last updated. If your policy's footer says "© 2017", the regulator will draw a conclusion before reading a word.

The seven boxes

The guidelines list the APP 1.4 content in paragraph 1.15. The list is "non-exhaustive", which means these are the minimum, not the whole job. Here is each item, and what the OAIC says it needs.

(a) The kinds of personal information you collect and hold. Describe them "in general terms", for example "contact details", "employment history" or "complaint details". Sensitive information, such as health information or criminal records, "could be separately listed". For a pharmacy, that means health information gets its own line. For a pawnbroker, it probably means identity documents do.

(b) How you collect and hold it. Explain your "usual approach to collecting personal information", for example directly from individuals, from list purchases, competitions or referrals. Then describe how you hold it, which "should include how the entity stores and secures personal information". The guidelines give the example of storage by a third-party provider. You do not need to publish your firewall rules: the description "should not provide details that jeopardise the effectiveness of those measures".

(c) The purposes. Why you collect, hold, use and disclose it. You do not need to list "normal internal business practices" like billing and auditing. The guidelines suggest the description could name the kinds of people or organisations you usually disclose to, and any functions you contract out.

(d) Access and correction. At a minimum, say that people can ask to access and correct their information, and give "the position title, telephone number, postal address and email address of a contact person". A generic privacy@ address is wise, because staff leave. You may publish a preferred process, but you "cannot require the individual to follow a particular procedure".

(e) Complaints. Explain how someone can complain about a breach of the APPs, and how you will handle it. If a registered APP code binds you, name it. The guidelines suggest you explain the stages: a complaint in writing to you first, a reasonable time to respond ("usually 30 days"), then any external dispute resolution scheme you belong to, then the OAIC.

(f) Whether you are likely to disclose information overseas. "Likely" has a specific meaning: you are likely to disclose overseas "if it is the entity's current practice or it has established plans to do so".

(g) And if so, which countries, if it is practicable to name them. This one has a firm edge. Impracticable means the burden is "excessively time-consuming, costly or inconvenient in all the circumstances", and an entity "is not excused from specifying the countries by reason only that it would be inconvenient". If the list is long, you can put it in an appendix, link to a list you keep updated, or, only where naming countries is not practicable, give regions such as "European Union countries".

That is the rubric: seven boxes, a plain-language rule and a date. A reviewer with a checklist can mark a policy against it in under an hour.

A Flemish-style market square where a robed inspector reads a very long scroll through a magnifying glass while nervous stallholders, a cart-hirer and a pawnbroker wait with their own scrolls, and a modern clipboard lies on the table beside him.
Fig. 2

The box that is not on the list: the notice at the counter

Here is the trap that catches good businesses. A privacy policy is not the only transparency document the law asks for, and at a counter it is not even the main one.

APP 5 requires a separate collection notice: the specific facts about this collection, given "at or before the time" you collect, or as soon as practicable afterwards. The APP 1 guidelines draw the line clearly: the policy describes your general practices, and a notice gives "specific information relevant to a particular collection". The APP 5 guidelines warn that a notice can point to the policy, but only after checking that the policy actually covers the notice matters, because the policy "may describe only the general information handling practices of the entity".

For in-person collection, the guidelines expect you to plan this in advance. "Brief privacy notices on forms or signs may be supplemented by longer notices made available online or in brochures", and "staff should be trained". For a business without a website, the APP 1 guidelines even suggest displaying the policy "on a stand at the entity's premises".4

The sweep tests the policy, not the notice. But the two documents have to agree. If the sign on the open-home clipboard says one thing and the office policy says another, a reviewer who reads both will notice. And the policy only passes box (a) and box (b) if it knows about the clipboard at all.

Part 4: Where Collection Points Hide

This is the part of the job that no template can do for you. A policy can have all seven headings and still be wrong, because it describes the business the lawyer imagined, not the one that exists.

What counts as a collection point

A collection point is any place where personal information enters something you keep: a form, a system, a spreadsheet, a phone, a vendor's database.

Try it on the open home from the intro. The QR code opens a form on a property platform, which stores them in the platform's database, which syncs to the agency's customer relationship manager (CRM), which feeds an SMS tool for the Tuesday follow-up call, which may send messages through a gateway in another country. That is one QR code and five systems. Each is a place where box (b) "how collected and held", box (c) "purposes" and maybe box (f) "overseas" need a sentence.

Most policies describe the front door. Your job is to walk behind it.

Vendors hold what you hold

The most common missed collection point is somebody else's software. You run a sign-in kiosk, a booking platform, a licence scanner or a test-drive app. The vendor's servers hold the data. It is tempting to think that is the vendor's problem.

It is not. Box (b) asks how you hold the information, and the guidelines' own example is storage "by a third party data storage provider".

The Outabox breach shows why. The website behind the leak claimed that Outabox had contracted a team of developers in the Philippines, with access to the personal data, and backed up all data to the cloud.5 Whether or not that claim is accurate, the question it raises is exactly the one box (f) asks: does your information go overseas, and where? At Privacy Awareness Week that year, Kind said, "We're absolutely seeing a rise in third party suppliers being the source of data breaches", and stressed that larger organisations such as clubs must pass their privacy obligations on to their suppliers.

Overseas: a use or a disclosure?

Box (f) is where most businesses guess, and the guidelines are more precise than the guesses. The key idea is a distinction between a use and a disclosure.

  • A use is handling information inside your own effective control.
  • A disclosure is making it accessible to someone outside your organisation and releasing the handling of it from your control.

Box (f) is only about disclosures. So the guidelines say that routing information, in transit, through a server located outside Australia would usually be a "use", not a disclosure. Your email passing through a data centre in Singapore on its way to a customer in Launceston is not an overseas disclosure.

Cloud storage is the tricky middle. The APP 8 guidelines say that giving information to an overseas cloud provider only to store it may be a use, but only if the contract gives you effective control: you can access, change and retrieve it, you know who else can see it, and you can delete it at the end. If the vendor can use the data for its own purposes, or you cannot get it back, you are closer to a disclosure, and box (f) and box (g) apply.

So the question for each vendor is not "is the server overseas?" It is "who controls the data once it is there?" You answer that from the contract, which is why almost nobody answers it.

What failed last time

We have a useful guide to where policies go wrong, and it is old but specific. In 2015, the OAIC reviewed the policies behind 20 of the most visited, and most complained-about, websites in Australia, from banks to news sites. As iTnews reported, the then Commissioner, Timothy Pilgrim, said more than half were deficient on some basic level. Twenty per cent did not properly disclose whether information was likely to go overseas and where. Forty per cent did not say how the organisation would deal with privacy complaints. Twenty-five per cent did not explain how they would protect the security of customer data. The median policy was 3,413 words long, and one ran to 18,000.

Three horizontal bars and a zero marker. In the OAIC's 2015 review of 20 major Australian website privacy policies, 40% did not explain how complaints are handled, 25% did not explain how data is kept secure, and 20% did not properly disclose overseas sharing and locations. All 20 adequately described what they collect and how. The failures were in the lower items of the list, not the top.
Fig. 3 — The bottom of the list is where policies fail. Drawn from iTnews, "Top Aussie websites need to improve privacy policies: Pilgrim", 4 May 2015, reporting the OAIC's review.

The part I find most useful is the good news. All 20 policies "adequately" described what information they collected and how. The top of the list was fine. The failures were at the bottom: complaints, security, overseas. Those are the boxes about what happens after collection, which is where the vendors and the back-office systems live. The lawyers wrote the front of the label well. Nobody walked into the kitchen.

Those were large organisations with legal teams. The January sweep includes pawnbrokers.

Who is actually covered

Before you panic, check that the Act covers you. Most small businesses, those with an annual turnover of $3 million or less, are exempt. Turnover here means all income from all sources.

Two of the sweep sectors sit on the exceptions. A business is covered, whatever its turnover, if it is a health service provider, and the OAIC's list of health service providers includes pharmacists. Real estate agents are covered if they are over the threshold, and any organisation that runs a residential tenancy database is covered regardless of turnover. There are other exceptions, such as trading in personal information without consent, so do not assume that small means exempt.

The six sectors are also only a starting point. DW Fox Tucker suggests that organisations outside those sectors should also review their policies, because complaints can prompt similar scrutiny.

Part 5: Marguerite Walks the Car Yard

A Flemish-style horse yard where a woman with a ledger walks past hitching posts, a clerk copying papers and a messenger leaving by the gate, marking each in her book, while a laptop sits on a hay bale and a cup of tea steams on the fence.
Fig. 4 — Every gate in the yard gets a line in the book, generated by OpenAI GPT Image.

Meet Marguerite. Marguerite is the operations manager for a family-owned car dealership on Main Road in Glenorchy, with a service centre and about forty staff. (She is made up. Main Road is real, and it does have a remarkable number of car yards.) Turnover is well over $3 million, so the Privacy Act covers the business. On the second Monday of January, the owner forwards her a law firm newsletter about the sweep with a one-line note: "Are we OK?"

Marguerite does not know, so she spends a week finding out.

Monday: read the label

She opens the privacy policy on the website. It is 4,100 words long, dated 2019, and refers to a finance partner the dealership stopped using three years ago. It has headings for most of the APP 1.4 items. It has no heading for complaints, which it mentions once, in a sentence that ends "please contact us". The contact is an email address for a sales manager who left in 2022.

She makes a table with seven rows, (a) to (g), and marks each one present, missing or wrong. Already, (e) is missing a real process, (d) has a dead contact, and the date fails the "up-to-date" test. She has not left her desk.

Tuesday: walk the yard

This is the important day. Marguerite takes a notebook and a cup of tea and follows a customer's details from the first "hello" to wherever they end up. She stands at each desk and asks one question: "When someone gives you their details, where do they go next?"

By lunchtime she has six collection points:

  1. The test-drive form. A tablet at the front desk takes name, address, phone and email. Sales staff also photograph the customer's licence, because the insurer requires it.
  2. The licence photo. It goes into the dealer management system, where it sits against the customer record indefinitely.
  3. The dealer management system itself, which is a cloud product. The vendor's support page says it is hosted overseas.
  4. The SMS follow-up tool. Sales staff send "how did you find the drive?" messages through a third-party SMS service.
  5. The finance referral. When a customer asks about finance, their details go to a finance broker.
  6. The customer who asks. A man once rang to ask what information the dealership held on him. Reception did not know who to transfer him to, so the call went to the owner's voicemail.
Six stacked boxes for a hypothetical car yard. The test-drive form maps to APP 1.4(a) kinds, (b) how and (c) purposes. The licence photo in the dealer system maps to (a) and (b). The overseas-hosted dealer system maps to (b), and to (f) and (g) only if the host gets control, which makes it a disclosure. The SMS follow-up service maps to (c), and to (f) and (g) if messages are sent offshore. The finance referral maps to (c), who it goes to. A customer asking what you hold maps to (d) access and correction and (e) complaints. A point with no item beside it is a gap in the policy.
Fig. 5 — One car yard, six collection points. A hypothetical example, mapped to the items in APP 1.4 as the OAIC's APP 1 guidelines (updated 3 October 2025) describe them.

She writes the matching boxes next to each point. The licence photo gets its own line under (a), because it is an identity document, much as the guidelines suggest listing sensitive information separately.

Then she reads the 2019 policy against the list. It does not mention licences at all. It does not mention the dealer system, the SMS tool or the current finance broker. It says, "We do not disclose your information overseas."

Wednesday: ask the vendors

That last sentence might be true. Marguerite does not know yet, so she writes to three vendors with the same three questions. Where is the data stored? Who can access it, and for what purposes? Can we retrieve and delete it at the end of the contract?

The dealer system vendor replies that data sits in Australian and US regions, that its support team in another country can access records, and that the customer can export and delete. This is the use-or-disclosure question from Part 4, so Marguerite asks the dealership's lawyer. The lawyer's view is that it is safest to treat it as a likely disclosure and name the countries in box (g). That is a careful choice, not a ruling, and it removes a sentence that might have been untrue.

The SMS vendor does not reply. A collection point with an unanswered question is still a collection point.

Thursday: fix the counter, then the label

She starts with the counter, because that is where the customer is. She adds a short collection notice to the test-drive form: what is collected, why, that the licence photo is for insurance, who it is shared with, and a link to the full policy. She writes a two-sentence script for sales staff for when someone asks why a photo is needed. She sets up privacy@ and a position title, "Privacy Officer", so the contact does not leave when a person does.

Then she rewrites the policy. It goes from 4,100 words to about 1,600, with a short summary at the top (the guidelines call this a "layered" approach) and the full detail below.6 Each of the seven boxes now has a heading. Box (a) lists licences separately. Box (b) names the kinds of vendors that store data. Box (c) names finance brokers and insurers. Box (e) sets out the steps: write to us, we respond within 30 days, then the OAIC. Box (f) says yes, and box (g) names the countries. The footer says "Last updated: January 2026".

Friday: the report

Marguerite's note to the owner is one paragraph. "We were not OK. Our policy was out of date, had no complaints process, did not mention licence photos and said we do not send data overseas, which is probably not true. It is fixed now. The SMS vendor has not answered, so I will check again next month. I have put a reminder in the calendar to walk the yard again every January."

The owner replies with a thumbs-up emoji, which in car-yard management is the highest form of praise.

The rewrite took an afternoon. Finding out what to write took three days. The label is easy. The walk is the work.

What to Do This Week

You do not need to be one of the 60 to do this. The rubric is public, and the checks cost mostly time.

  1. Check that the Act covers you. Turnover over $3 million, or a health service provider (including a pharmacy), or a residential tenancy database, or one of the other exceptions. If you are not sure, ask a lawyer before you assume you are exempt.
  2. Find your policy and read the date. If there is no "last updated" note, add one. If it is more than a year old, assume it is wrong somewhere.
  3. Mark it against the seven boxes. Make a table: APP 1.4(a) to (g). For each, write "present", "missing" or "wrong". Use the OAIC's APP 1 guidelines, paragraphs 1.15 to 1.32, as your rubric.
  4. Pay special attention to (d) and (e). Is there a position title, phone number, postal address and email for access and correction requests? Is there a real complaints process with stages? These are where policies failed most in 2015.
  5. Walk the business. Follow a customer's details from the first contact to wherever they end up. At each desk, ask, "Where does this go next?" List every form, scanner, QR code, spreadsheet, app, vendor and phone.
  6. Map each collection point to a box. Anything with no box beside it is a gap in your policy.
  7. Treat identity documents as their own line. If you copy, scan or photograph licences or passports, say so under (a), and say why under (c).
  8. Ask every vendor three questions. Where is the data? Who can access it, and for what? Can we get it back and delete it? Then decide, with advice if you need it, whether each one is a use or an overseas disclosure.
  9. Name the countries. If you are likely to disclose overseas, list the countries. "Inconvenient" is not an excuse. If the list is long, use an appendix or a linked list you keep up to date.
  10. Check the counter. Is there a collection notice at each in-person collection point, on the form, a sign or in a staff script? Does it agree with the policy? If you have no website, keep a printed copy of the policy at the counter.
  11. Cut the length. Plain English, with a short summary at the top.
  12. Put the next review in the calendar. Every year, and every time you add a system, a vendor or a new way of collecting.
  13. Look ahead to December. From 10 December 2026, if a computer program uses personal information to make decisions that could significantly affect people, the policy must say so.7 If you use automated scoring or approvals, start listing them now.

If you want the bigger picture on where Australia's privacy law is going next, I covered the overhaul for marketers in 2023, and in August I looked at the Productivity Commission's proposal to replace some of these rules with outcomes. Whichever way that goes, a policy that tells the truth about your collection points is useful under both.

Final Thoughts

Think back to the Saturday in Sandy Bay. The clipboard, the chemist, the pub, the hire car. Four businesses, three copies of your licence details and zero privacy policies read.

You still will not read them, and that is fine. Somebody who can act on them is reading a sample, so every business now has a reason to make its policy tell the truth. A privacy policy has always been a label on a packet. For the first time, there is an inspector at the shelf with a ticket book in the pocket.

The fix is not glamorous. Read your own policy against seven boxes. Then walk your own business and find every place a customer's details go. The second step is the one that matters, because the regulator can read your label from Sydney, but only you can walk into the kitchen.

So pick a day this week, take a notebook, and follow one customer's details from the front door to the last system that holds them. For a small business, by my count, that is about four cups of tea of work.8 Now, if you'll excuse me, I have a policy to reread, and the kettle is already on.

Notes

  1. GPEN, the Global Privacy Enforcement Network, is a group of privacy regulators that run coordinated "sweeps" on a theme each year. The 2024 sweep looked at deceptive design, such as making the least private option the easiest to click. ↩

  2. The Bunnings determination covered facial recognition in 63 stores in Victoria and New South Wales between 2018 and 2021. Bunnings had the right to seek review of the decision. ↩

  3. The value of a Commonwealth penalty unit is set in the Crimes Act and indexed every few years. The law firms quoted here used $330 a unit, so check the current value before converting any unit figure into dollars. ↩

  4. The same guidance suggests printing the policy on request, putting details of how to get it at the bottom of correspondence, and telling phone callers how they can access it. ↩

  5. These details come from a website that, ClubTIC reported in May 2024, was set up "seemingly by someone with knowledge of the Outabox systems". They are claims, not findings, and Outabox said at the time that it could not provide more information because of the police investigation. ↩

  6. The OAIC describes a layered policy as a condensed version that outlines the key information, with direct links to the detail in the full policy. The guidelines point to the OAIC's own policy summary as an example. ↩

  7. These are the new APP 1.7 to 1.9, added by the same 2024 Act. The OAIC has said it will publish detailed guidance on them during 2026. ↩

  8. I drink about 1,820 cups a year, so I measure most tasks in cups. Four cups is a morning. A full audit of a big business is closer to a fortnight of tea, and a policy nobody has touched since 2019 may need a new packet. ↩

end of article · 6,336 words · 27 January 2026

James Nicholson, smiling, in round tortoiseshell glasses and a white T-shirt.

James Nicholson

James is a technology consultant in Hobart, Tasmania, and runs NEOBADGER. He works where technology, regulation and the people organisations serve meet: AI harnesses, development, data and compliance.

The story

Further reading

3 more articles on Data Privacy.