Level 4, 20 Grenfell Street,
Adelaide SA  5000

Phone: 08 8231 1888
Fax: 08 8231 3888

Email: admin@crase.com.au


Liability limited by a scheme approved under Professional Standards Legislation

 
Latest News
Hot Issues
Write a business plan
Two Cautionary Tales About Resources Important to Anyone Using a Domain Name or Website
What Are the Privacy Policy Requirements for Australian E-Commerce Businesses?
Privacy Compliance Sweep 2026: Is Your Business Ready?
Foreign investor fined $370k as ATO cracks whip on land banking
The AI moment in accounting will follow a familiar pattern
Latest Intergenerational Report points to stubborn productivity issues that AI cannot fix
Check out the smartest species on earth: Data from 200M BC to 2026
Steps to close a business
Paid parental leave super contributions have started
How Do I Write Legally Compliant Terms and Conditions for My Business?
Don’t get caught out at tax time with your multiple jobs
Division 296 tax on large super balances
More of the same with latest missive from Treasury
'No place to hide': ATO puts contractors on notice over $1bn in missing TPAR payments
Check out the largest castles by country
ATO no longer treating debt the same as during COVID
Warning for early lodger this tax time!
Global companies turn to cost-cutting amid ongoing inflation
Don’t get caught out at tax time with your multiples jobs
Does Your Small Business Need to Follow AML Privacy Rules?
SMEs warned as ATO ramps up tax debt collection
Taxpayer given 35% penalty for BAS recklessness
How Our Diets have Changed.
Tips to help you this tax time
Tax Time Checklists Individuals; Company; Trust; Partnership; and Super Funds
ATO warns millions of Australian chasing tax deductions to stop making 'unusual' claims
Impersonation scams are on the rise
Components of a cyber security plan
Social Security Payments and Their Effect on Discretionary Trusts
LRBA ban no better for housing supply or retirement, accountants clap back
The evolution of the world's languages
Articles archive
Quarter 2 April - June 2026
Quarter 1 January - March 2026
Quarter 4 October - December 2025
Quarter 3 July - September 2025
Quarter 2 April - June 2025
Quarter 1 January - March 2025
Quarter 4 October - December 2024
Quarter 3 July - September 2024
Quarter 2 April - June 2024
Quarter 1 January - March 2024
Quarter 4 October - December 2023
Quarter 3 July - September 2023
Quarter 2 April - June 2023
Quarter 1 January - March 2023
Quarter 4 October - December 2022
Quarter 3 July - September 2022
Quarter 2 April - June 2022
Quarter 1 January - March 2022
Quarter 4 October - December 2021
Quarter 3 July - September 2021
Quarter 2 April - June 2021
Quarter 1 January - March 2021
Quarter 4 October - December 2020
Quarter 3 July - September 2020
Quarter 2 April - June 2020
Quarter 1 January - March 2020
Quarter 4 October - December 2019
Quarter 3 July - September 2019
Quarter 2 April - June 2019
Quarter 1 January - March 2019
Quarter 4 October - December 2018
Quarter 3 July - September 2018
Quarter 2 April - June 2018
Quarter 1 January - March 2018
Quarter 4 October - December 2017
Quarter 3 July - September 2017
Quarter 2 April - June 2017
Quarter 1 January - March 2017
Quarter 4 October - December 2016
Quarter 3 July - September 2016
Quarter 2 April - June 2016
Quarter 1 January - March 2016
Quarter 4 October - December 2015
Quarter 3 July - September 2015
Quarter 2 April - June 2015
Quarter 1 January - March 2015
Quarter 4 October - December 2014
What Are the Privacy Policy Requirements for Australian E-Commerce Businesses?

An online store collects personal information constantly, and most of it arrives without anyone deciding to collect it.



 


An online store collects personal information constantly, and most of it arrives without anyone deciding to collect it. A visitor loads a page, and an analytics tag records an address. A customer abandons a cart and an advertising pixel follows them. Australian privacy law asks you to be transparent about all of it, in two documents: a short notice wherever you collect, and a policy that explains the whole picture. The hard part is not writing them. It is keeping them true, because every new tool changes what you collect, and most businesses write the policy once and leave it. A new obligation lands in December that makes accuracy harder to fake. This article explains which privacy obligations apply to an Australian e-commerce business, the two documents you need, what each must contain, and when to update them.


Who Needs to Comply


The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to your business if you have an annual turnover above $3 million. You may also need to comply if your business trades in personal information or provides a health service and holds health information.


If your turnover is below $3 million, the APPs may not legally apply to you. However, following them is best practice. Building compliant privacy practices early means you are ready as your business scales, and many payment processors and business partners will expect compliance.


Documents You Need


You will need two key documents:


  • a privacy collection notice: a short notice that appears at every point where you collect personal information; and
  • a privacy policy: a publicly available document on your website that explains how your business collects, uses, stores, and shares personal information.

Where You Must Display Collection Notices


You must display a collection notice at every point where you collect personal information, including:


  • newsletter or mailing list subscription forms;
  • account sign-up forms; and
  • contact and enquiry forms.

Each notice will briefly explain:


  • what information you are collecting;
  • why you are collecting it;
  • who you may share it with; and
  • where you store it.

Each notice must also link to your full privacy policy.


What Your Privacy Policy Needs To Cover


Your privacy policy must be written in plain language and easy to find on your website. For an ecommerce business, it will cover:


  • what you collect: such as contact details, payment information, IP addresses, and cookies;
  • how you collect it: such as directly from customers or through third-party payment processors;
  • why you collect it: such as to process orders, send marketing emails, or meet legal obligations;
  • who you share it with: including any third-party service providers that may store personal information outside of Australia;
  • cookies and tracking technologies: what you use, why you use them, and how customers can manage their preferences; you must specifically disclose tools such as Google Analytics or Meta Pixel;
  • AI tools: whether you use any AI tools to process personal information and how you maintain human oversight;
  • customer rights: including the right to access their personal information, request corrections, and opt out of marketing; and
  • your complaints process: including how customers can escalate a complaint to the Office of the Australian Information Commissioner (OAIC).

“Most of the businesses I speak to think their privacy policy is fine because nobody has complained about it, but that only tells you nobody has read it closely yet. The December changes are less about writing new paragraphs and more about actually knowing what your own tools do, which is often the harder question for a business to answer. I would rather spend an hour auditing your tools with you now than explain to the regulator later why the policy did not mention one of them.”


Danielle Henry


Lawyer, LegalVision


Keeping Your Documents Current


Review your privacy documents at least once a year. You should also update them whenever you:


  • add a new tool or technology that affects how you collect or use personal information;
  • change service providers; and
  • expand into new markets.

If you sell to customers in the EU or UK, additional obligations apply under the GDPR. These include identifying legal bases for processing personal information, setting data retention periods, and providing additional individual rights beyond those required under Australian law.


Key Takeaways


E-commerce businesses must understand their privacy obligations and keep their documents accurate as their data practices change. The key points are:


  • the APPs apply to businesses with an annual turnover above $3 million, but all e-commerce businesses should follow them as best practice;
  • you need both a privacy collection notice and a privacy policy;
  • collection notices must appear on subscription forms, account sign-up forms, and enquiry forms, and should link to your full privacy policy;
  • your privacy policy will cover what you collect, why, and who you share it with;
  • review and update your privacy documents annually and whenever your business practices change; and
  • selling to EU or UK customers triggers additional obligations under the GDPR.

 


 


 


By: Danielle Henry | 21 September 2026 | legalvision.com.au




22nd-October-2026
      Site By AcctWeb