If your website collects enquiries, tracks visitors, sells products, takes bookings or connects with third-party tools, your legal pages are worth reviewing.
A lot has changed since the days when a basic website could get by with a short privacy statement and a simple disclaimer in the footer. Today, even a fairly straightforward business website may use contact forms, analytics, email marketing platforms, chat tools, AI-powered features, payment gateways, booking systems, CRM integrations and cloud services behind the scenes. In many cases, that means the website is collecting, using or disclosing personal information in ways that are not always obvious at first glance.
This guide explains, in general terms:
- what a Privacy Policy does
- what Website Terms of Use do
- when you may also need Terms and Conditions of Sale or Service
- why older template wording is often no longer enough
- some common website compliance issues business owners should be aware of
Important disclaimer
This article is provided as general information only. It is not legal advice, and it should not be relied on as a substitute for advice from a suitably qualified legal professional.
Redback is not a law firm. Website privacy, e-commerce and online terms requirements depend on your business, your website functionality, the tools and providers you use, the information you collect, and how that information is stored, used and disclosed. Before publishing or relying on a Privacy Policy, Website Terms of Use, Terms and Conditions of Sale or similar document, you should obtain advice appropriate to your circumstances.
Why this matters more now
For many businesses, website legal documents are no longer just “nice to have” pages sitting quietly in the footer.
Australia’s privacy landscape has become more serious from both a legal and commercial point of view. Maximum penalties for serious or repeated interferences with privacy were significantly increased by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth), which amended the Privacy Act 1988 (Cth). The Office of the Australian Information Commissioner also has broader powers in relation to investigations, information gathering and data breaches.
That does not mean every business website has exactly the same obligations in exactly the same way. It does mean older templates, copied wording and “set and forget” legal pages are more likely to create problems.
A good rule of thumb is this: your website documents should describe what your website actually does today, not what a template assumed it did a few years ago.
If your site now uses tools like Google Analytics, Meta Pixel, Mailchimp, HubSpot, Stripe, Shopify, chat widgets or AI-assisted tools, it is worth checking whether your legal pages still reflect the reality.
Who is responsible for my website Privacy Policy and Terms?
Ultimately, responsibility sits with the website owner; the business or organisation whose website it is and on whose behalf it is run. This is not the web developer, hosting provider, agency or other supplier engaged to help build, host or maintain the site.
Even if you engage a web developer, hosting provider, digital agency, staff member, contractor, template provider or lawyer to help prepare or publish website documents, you remain responsible for ensuring those documents are legally appropriate for your business or organisation, accurate, and kept up to date as your website, systems and practices change.
The three website documents people often mix up
These documents are related, but they do different jobs.
Document: Privacy Policy
- What it generally covers: How personal information is collected, used, stored and disclosed
- When it is commonly needed: Where a website collects personal information
Document: Website Terms of Use
- What it generally covers: The rules for using the website, including content, disclaimers, acceptable use and liability points
- When it is commonly needed: Where the business wants to manage risk around use of the site itself
Document: Terms and Conditions of Sale or Service
- What it generally covers: The legal terms of a transaction, booking, subscription or service engagement
- When it is commonly needed: Where customers can buy, book, register or subscribe online
One common mistake is trying to use one short legal page to cover all three. In practice, that often leaves important gaps.
What is a Privacy Policy?
A Privacy Policy explains how a business handles personal information.
Depending on the website, that can include information collected through:
- contact and enquiry forms
- quote request forms
- ecommerce checkout
- booking tools
- account registration
- newsletter signups
- support forms
- chat tools
- customer portals
- analytics and tracking technologies
For businesses covered by the Australian Privacy Principles, there is generally an obligation to have a clearly expressed and up-to-date privacy policy about the management of personal information under Privacy Act 1988 (Cth) sch 1 cl 1.3.
What counts as personal information?
Whether particular data points amount to personal information depends on context, but it can include much more than a name and email address.
Examples may include:
- name
- phone number
- postal address
- account details
- order history
- support enquiries
- IP address or device-related data in some contexts
- website usage data linked to an identifiable person
If a website collects sensitive information, the compliance risk is usually higher again. Under the Privacy Act, organisations must not collect sensitive information unless an exception applies, commonly including consent: Privacy Act 1988 (Cth) sch 1 cl 3.3.
Do you need a Privacy Policy?
There is no one-size-fits-all answer, because privacy obligations depend on the legal status of the business, the nature of the information collected, and the circumstances in which it is handled.
That said, as a practical matter, a Privacy Policy is commonly appropriate where a website includes:
- enquiry forms
- email signup forms
- booking systems
- ecommerce checkout
- member or client logins
- customer accounts
- support forms
- lead-generation tools
- analytics or marketing technologies tied to user activity
Even where a business believes it may fall outside parts of the Privacy Act framework, a Privacy Policy may still be commercially important. Customers, software providers, payment platforms, marketplaces and business partners often expect one as part of ordinary website governance.
What should a Privacy Policy usually cover?
The precise content depends on the website and business, but a modern Privacy Policy will often need to explain:
- what information is collected
- how it is collected
- the purposes for which it is collected
- whether collection is required or optional in particular cases
- the consequences, if any, of not providing the information
- who the information is disclosed to
- whether information is likely to be disclosed overseas
- how an individual can request access to or correction of their information
- how privacy complaints can be made
- how the business can be contacted about privacy matters
These kinds of matters broadly align with APP 1 and APP 5 transparency and collection notice expectations: Privacy Act 1988 (Cth) sch 1 cl 1.4, Privacy Act 1988 (Cth) sch 1 cl 5.2.
If your Privacy Policy says one thing, but your website tools, forms, integrations or workflows do something else, that mismatch can create both legal and reputational risk.
Consent: broad wording is not always enough
One of the most common website privacy issues is assuming that a broad statement somewhere on the site automatically amounts to valid consent for everything the business does with personal information.
That is not a safe assumption.
The OAIC’s guidance indicates that consent should generally be informed, voluntary, current and specific, and organisations should be cautious about relying on implied consent where individuals have not clearly agreed to the particular handling of their information. The OAIC has also cautioned against bundled consent, where multiple purposes are combined in a way that does not allow meaningful choice.
For example, wording such as:
“By using this website, you consent to all collection, use and disclosure of your information for any purpose connected with our business.”
may be too broad to be particularly useful, especially where the website also uses analytics, advertising technologies, marketing automation, remarketing tools or multiple third-party platforms.
A more careful approach is to make sure your Privacy Policy and any collection notices explain, in plain English:
- what is being collected
- why it is being collected
- which kinds of third parties are involved
- whether overseas disclosure may occur
- what choices users have, where relevant
Cookies, analytics and tracking tools
This is one of the areas where older website articles are most likely to be out of date.
Many websites now use cookies or similar technologies for:
- essential website functionality
- security
- analytics
- conversion measurement
- customer support tools
- embedded content
- advertising or remarketing
Not every website using cookies will face the same legal analysis, and the appropriate compliance approach can depend on the purpose of the technology and what data is being collected or combined. However, from a practical risk perspective, a generic sentence like “we use cookies” is often not enough on its own to accurately describe what a modern business website is doing.
A sensible starting point is to distinguish between:
- essential technologies used to operate the website
- analytics tools used to measure traffic and performance
- advertising or behavioural tracking tools used for marketing, profiling or remarketing
If your site uses tools such as Google Analytics, Meta Pixel, Google Ads tags, session replay technologies, marketing automation platforms or other tracking features, it is worth checking whether your public-facing disclosures actually describe that use in a meaningful way.
Using AI tools on your website
Many websites now use AI-assisted tools in one form or another, including:
- chatbots
- enquiry-routing tools
- support assistants
- transcription or summarisation tools
- automated marketing tools
- personalisation or recommendation features
If those tools collect, analyse, store or disclose personal information, the usual privacy issues still apply. Using an AI feature does not remove the need to think carefully about transparency, consent, offshore disclosure, data security and accuracy.
As a practical starting point, businesses using AI-enabled website tools may wish to consider:
- whether users are entering personal information into an AI-powered tool
- whether website enquiries are being analysed by a third-party provider
- whether data is being sent offshore
- whether outputs are reviewed before they are relied on or sent to customers
- whether the Privacy Policy accurately describes those data flows
Where AI or automated systems are used in ways that may materially affect individuals, the legal position may become more complex again. That is an area where tailored legal advice is often worth obtaining.
Offshore disclosure and overseas service providers
A typical website today may rely on multiple offshore providers, sometimes without the business fully appreciating how many are involved.
Examples include:
- Meta
- Shopify
- Stripe
- Mailchimp
- HubSpot
- cloud hosting providers
- CRM platforms
- form tools
- customer support platforms
If personal information is disclosed overseas, APP 8 may be relevant: Privacy Act 1988 (Cth) sch 1 cl 8.1. In general terms, entities subject to the Privacy Act should take reasonable steps to ensure that overseas recipients do not breach the Australian Privacy Principles in relation to the information, unless an exception applies.
For website owners, the practical point is simple: your Privacy Policy should be reviewed with your actual technology stack in mind. If your website relies on offshore platforms, your policy should say so in a clear and accurate way.
Security and “reasonable steps”
Privacy compliance is not only about what your website says. It is also about what your business actually does.
Under APP 11, entities subject to the Privacy Act must take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure: Privacy Act 1988 (Cth) sch 1 cl 11.1.
In website terms, that may involve questions such as:
- where form submissions are stored
- who can access enquiry and customer data
- whether plugins, CMS software and integrations are maintained
- whether backups are protected
- whether data is retained longer than necessary
- whether payment details are handled by the business or by a payment gateway
- whether access permissions are properly controlled internally
A common drafting mistake is overpromising. If a policy says, for example, that a business uses “industry best practice security” or “state of the art protection”, those statements should be supportable in practice.
Data breaches: website policies are only part of the picture
A Privacy Policy is useful, but it is not a complete privacy compliance plan.
Australia’s Notifiable Data Breaches scheme may require notification to affected individuals and to the OAIC where an eligible data breach occurs and is likely to result in serious harm: Privacy Act 1988 (Cth) pt IIIC.
For website owners, this is a reminder that it is not enough just to publish legal wording. It is also important to know:
- what information the website collects
- where it is stored
- which providers receive it
- who within the business needs to respond if something goes wrong
If your website processes sensitive, financial, customer account or other higher-risk data, breach response planning becomes even more important.
What is a Website Terms of Use document?
A Website Terms of Use document sets the rules for using your website.
Depending on the site, it may deal with issues such as:
- ownership of website content
- intellectual property
- permitted and prohibited use
- website availability
- disclaimers about general information
- third-party links
- misuse of forms or interactive tools
- limitations or exclusions of liability, where appropriate
- governing law and jurisdiction
This document is different from a Privacy Policy. It is concerned with the use of the site itself, not the handling of personal information.
Why Terms of Use still matter
Even a fairly straightforward website can create legal risk.
For example, your site may contain:
- blog articles
- case studies
- service descriptions
- pricing guidance
- downloadable resources
- testimonials
- technical or professional information
- links to third-party websites or platforms
Terms of Use can help manage expectations around how website content is used and reduce arguments about misuse, unauthorised copying or reliance on general website information.
That said, Terms of Use are not “magic words”. Their effectiveness can depend in part on how they are presented to users and whether users are given a proper opportunity to review them.
Browsewrap vs clickwrap
A browsewrap model usually means the terms are linked in the footer and said to apply simply because a person uses the site.
A clickwrap model usually requires a positive action, such as ticking a box or clicking “I agree”.
For a purely informational website, footer-linked terms are still common. However, where a website allows users to:
- place orders
- make bookings
- create accounts
- upload or submit material
- access gated resources
- subscribe to services
- use a portal or member area
an active acceptance method is generally much stronger than relying only on passive footer links.
The right approach depends on the website’s functionality and the legal significance of the interaction, but businesses should be cautious about assuming that a passive link alone will always provide strong contractual protection.
If you sell online, you usually need more than one document
If your website sells products, accepts bookings, offers subscriptions or allows customers to engage services online, you will often need more than just a Privacy Policy and a short Terms of Use page.
In many cases, businesses should consider a document suite, which may include:
- a Privacy Policy
- Website Terms of Use
- Terms and Conditions of Sale or Service
- refund or cancellation terms
- shipping and delivery terms
- subscription or renewal terms, where relevant
If your site uses a payment provider such as Stripe, PayPal, Square or Shopify Payments, it is also worth checking that your customer-facing wording accurately reflects how payments are processed and what role third-party providers play.
Common website legal mistakes
Some of the more common issues for business websites include:
- Using a generic template that does not match the site
- Copying another business’s Privacy Policy
- Failing to account for analytics, marketing tools, AI tools or offshore providers
- Using broad, all-purpose consent wording
- Assuming Terms of Use are enough for ecommerce or online bookings
- Overstating security practices
- Adding new plugins, forms or integrations without updating legal pages
- Treating privacy compliance as a once-only task
A quick way to work out what your website may need
A Privacy Policy is commonly relevant if your site:
- has a contact or enquiry form
- collects email signups
- accepts bookings
- allows account creation
- tracks visitor activity
- processes customer details during checkout
- integrates with third-party marketing or support tools
Website Terms of Use are commonly relevant if your site:
- publishes original content
- contains technical or professional information
- links to third-party services
- offers interactive tools
- includes downloadable resources
Terms and Conditions of Sale or Service are commonly relevant if your site:
- sells products
- takes bookings
- offers subscriptions
- has recurring billing
- provides online services
- needs refund, cancellation, shipping or delivery rules
Practical steps
For many business websites, a sensible starting point is to start by consulting a qualified legal professional to work through practical steps such as:
- map what the website actually collects
- identify which tools and providers sit behind it
- review whether the current Privacy Policy matches those real data flows
- review whether the site also needs Terms of Use
- add sale or service terms if customers can buy, book or subscribe
- consult your qualified legal professional and update those documents when the website changes
Final thoughts
Website legal documents should not be there simply to fill the footer.
When they are done properly, they can help improve transparency, manage risk, support customer trust and make it easier for your website content, forms and transactions to operate in a more predictable way.
If your website has grown over time, added new forms, adopted marketing tools, integrated third-party software or started taking online payments, there is a fair chance your legal pages should be reviewed by a qualified legal professional as well.
And if your site collects personal information or supports online transactions, it is worth making sure your documents reflect the website you actually have today, not the one you launched years ago.
Want a winning website with those policies?
Whether you’re after a new custom build, an SEO action plan or anything in between, we’ve got you covered. To get your digital project with Redback up and running, contact our team of website and marketing specialists today.
- Important disclaimer
- Who is responsible for my website Privacy Policy and Terms?
- The three website documents people often mix up
- What is a Privacy Policy?
- Cookies, analytics and tracking tools
- Using AI tools on your website
- Offshore disclosure and overseas service providers
- Security and “reasonable steps”
- What is a Website Terms of Use document?
- If you sell online, you usually need more than one document
- Common website legal mistakes
- A quick way to work out what your website may need
- Final thoughts