Chartered Accountants

Latest News

What Are the Privacy Policy Requirements for Australian E-Commerce Businesses?

An online store collects personal information constantly, and most of it arrives without anyone deciding to collect it.

 

An online store collects personal information constantly, and most of it arrives without anyone deciding to collect it. A visitor loads a page, and an analytics tag records an address. A customer abandons a cart and an advertising pixel follows them. Australian privacy law asks you to be transparent about all of it, in two documents: a short notice wherever you collect, and a policy that explains the whole picture. The hard part is not writing them. It is keeping them true, because every new tool changes what you collect, and most businesses write the policy once and leave it. A new obligation lands in December that makes accuracy harder to fake. This article explains which privacy obligations apply to an Australian e-commerce business, the two documents you need, what each must contain, and when to update them.

Who Needs to Comply

The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to your business if you have an annual turnover above $3 million. You may also need to comply if your business trades in personal information or provides a health service and holds health information.

If your turnover is below $3 million, the APPs may not legally apply to you. However, following them is best practice. Building compliant privacy practices early means you are ready as your business scales, and many payment processors and business partners will expect compliance.

Documents You Need

You will need two key documents:

  • a privacy collection notice: a short notice that appears at every point where you collect personal information; and
  • a privacy policy: a publicly available document on your website that explains how your business collects, uses, stores, and shares personal information.

Where You Must Display Collection Notices

You must display a collection notice at every point where you collect personal information, including:

  • newsletter or mailing list subscription forms;
  • account sign-up forms; and
  • contact and enquiry forms.

Each notice will briefly explain:

  • what information you are collecting;
  • why you are collecting it;
  • who you may share it with; and
  • where you store it.

Each notice must also link to your full privacy policy.

What Your Privacy Policy Needs To Cover

Your privacy policy must be written in plain language and easy to find on your website. For an ecommerce business, it will cover:

  • what you collect: such as contact details, payment information, IP addresses, and cookies;
  • how you collect it: such as directly from customers or through third-party payment processors;
  • why you collect it: such as to process orders, send marketing emails, or meet legal obligations;
  • who you share it with: including any third-party service providers that may store personal information outside of Australia;
  • cookies and tracking technologies: what you use, why you use them, and how customers can manage their preferences; you must specifically disclose tools such as Google Analytics or Meta Pixel;
  • AI tools: whether you use any AI tools to process personal information and how you maintain human oversight;
  • customer rights: including the right to access their personal information, request corrections, and opt out of marketing; and
  • your complaints process: including how customers can escalate a complaint to the Office of the Australian Information Commissioner (OAIC).

“Most of the businesses I speak to think their privacy policy is fine because nobody has complained about it, but that only tells you nobody has read it closely yet. The December changes are less about writing new paragraphs and more about actually knowing what your own tools do, which is often the harder question for a business to answer. I would rather spend an hour auditing your tools with you now than explain to the regulator later why the policy did not mention one of them.”

Danielle Henry

Lawyer, LegalVision

Keeping Your Documents Current

Review your privacy documents at least once a year. You should also update them whenever you:

  • add a new tool or technology that affects how you collect or use personal information;
  • change service providers; and
  • expand into new markets.

If you sell to customers in the EU or UK, additional obligations apply under the GDPR. These include identifying legal bases for processing personal information, setting data retention periods, and providing additional individual rights beyond those required under Australian law.

Key Takeaways

E-commerce businesses must understand their privacy obligations and keep their documents accurate as their data practices change. The key points are:

  • the APPs apply to businesses with an annual turnover above $3 million, but all e-commerce businesses should follow them as best practice;
  • you need both a privacy collection notice and a privacy policy;
  • collection notices must appear on subscription forms, account sign-up forms, and enquiry forms, and should link to your full privacy policy;
  • your privacy policy will cover what you collect, why, and who you share it with;
  • review and update your privacy documents annually and whenever your business practices change; and
  • selling to EU or UK customers triggers additional obligations under the GDPR.

 

 

 

By: Danielle Henry | 21 September 2026 | legalvision.com.au

Hot Issues

Latest Accounting News