
An online store collects personal information constantly, and most of it arrives without anyone deciding to collect it. A visitor loads a page, and an analytics tag records an address. A customer abandons a cart and an advertising pixel follows them. Australian privacy law asks you to be transparent about all of it, in two documents: a short notice wherever you collect, and a policy that explains the whole picture. The hard part is not writing them. It is keeping them true, because every new tool changes what you collect, and most businesses write the policy once and leave it. A new obligation lands in December that makes accuracy harder to fake. This article explains which privacy obligations apply to an Australian e-commerce business, the two documents you need, what each must contain, and when to update them.
Who Needs to Comply
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to your business if you have an annual turnover above $3 million. You may also need to comply if your business trades in personal information or provides a health service and holds health information.
If your turnover is below $3 million, the APPs may not legally apply to you. However, following them is best practice. Building compliant privacy practices early means you are ready as your business scales, and many payment processors and business partners will expect compliance.
Documents You Need
You will need two key documents:
Where You Must Display Collection Notices
You must display a collection notice at every point where you collect personal information, including:
Each notice will briefly explain:
Each notice must also link to your full privacy policy.
What Your Privacy Policy Needs To Cover
Your privacy policy must be written in plain language and easy to find on your website. For an ecommerce business, it will cover:
“Most of the businesses I speak to think their privacy policy is fine because nobody has complained about it, but that only tells you nobody has read it closely yet. The December changes are less about writing new paragraphs and more about actually knowing what your own tools do, which is often the harder question for a business to answer. I would rather spend an hour auditing your tools with you now than explain to the regulator later why the policy did not mention one of them.”
Danielle Henry
Lawyer, LegalVision
Keeping Your Documents Current
Review your privacy documents at least once a year. You should also update them whenever you:
If you sell to customers in the EU or UK, additional obligations apply under the GDPR. These include identifying legal bases for processing personal information, setting data retention periods, and providing additional individual rights beyond those required under Australian law.
Key Takeaways
E-commerce businesses must understand their privacy obligations and keep their documents accurate as their data practices change. The key points are:
By: Danielle Henry | 21 September 2026 | legalvision.com.au