Privacy Policies & T&Cs: What Small Businesses Need

Privacy Policies & T&Cs: What Small Businesses Need

In Short

  • Australian Privacy Principles apply if your business has a turnover over $3 million, but many small businesses still need privacy policies due to third-party tools, cookies, and contact forms
  • Even "simple" websites typically collect data through analytics, embedded maps, social media plugins, and email subscriptions—making a privacy policy necessary
  • Terms and Conditions aren't legally mandated for all sites, but they're essential if you're selling products, offering services, or allowing user-generated content
  • AI-generated and template policies can work as starting points but carry real risks if they don't match your actual practices or comply with Australian law
  • Getting a lawyer involved depends on your risk profile—higher-value transactions, sensitive data, or complex business models warrant professional legal advice

The "We Don't Collect Data" Myth

Here's the thing most small business owners tell me: "Wade, my site's just a digital brochure. Contact details, maybe a form. I'm not storing anything." Wrong. Well, technically accurate but functionally wrong—which is worse. Your website is almost certainly collecting data even if you're not consciously doing it. That Google Analytics snippet your developer dropped in? Data collection. The Google Maps embed showing your location? Google's tracking users. The Facebook pixel you added because someone said it was important? Oh, that's definitely collecting data. Even that innocent "Subscribe to our newsletter" field is—you guessed it—data collection. So before we even get into whether you need a privacy policy, let's establish that you probably do need one, regardless of what you think your site does.

What Australian Law Actually Says

The Australian Privacy Principles (APPs) under the Privacy Act 1988 apply to businesses with an annual turnover exceeding $3 million. If you're under that threshold, you're technically exempt—unless you're a health service provider, deal with credit reporting, or you're a small business operator that has adopted the APPs voluntarily (and why would you do that to yourself?). But here's where it gets messy. Even if the Privacy Act doesn't directly apply to your business, other regulations might. State-based laws, industry-specific requirements, the Spam Act 2003 if you're doing email marketing—it's a patchwork. And if you're using third-party services (Mailchimp, Google, Facebook, literally any modern web tool), their terms often require you to have a privacy policy explaining how data flows through your site. Then there's the reputational angle. Consumers expect to see privacy policies. It's become a trust signal. A site without one looks either amateurish or dodgy—neither is a good look when you're trying to win business.

When You Absolutely Need a Privacy Policy

Let me be direct about this: if your website does any of the following, you need a privacy policy:
  • Collects email addresses (newsletter signups, contact forms)
  • Uses cookies or tracking scripts (Google Analytics, Facebook Pixel, heatmapping tools)
  • Embeds third-party content (YouTube videos, Google Maps, social media feeds)
  • Processes payments (even if it's through a third-party gateway like Stripe or PayPal)
  • Allows user accounts or logins
  • Stores any personal information whatsoever
That covers approximately 99.7% of modern websites. Even a basic WordPress site with a contact form and Google Analytics is collecting personal information and needs to disclose that. The policy doesn't need to be a 47-page legal thesis. It needs to clearly explain what data you collect, why you collect it, how you use it, who you share it with, and how people can access or delete their information. Transparency matters more than verbosity.

The Terms and Conditions Question

Terms and Conditions (T&Cs) are a different beast entirely. Unlike privacy policies—which are increasingly expected and sometimes legally required—T&Cs are more about managing your legal exposure and setting expectations. Do you need them? Not always. If your site is purely informational with no transactions, no user interactions beyond a contact form, and no downloadable resources, you can probably skip them. But the moment you introduce any of these elements, T&Cs become important:
  • E-commerce: Selling products or services online without T&Cs is asking for disputes about refunds, delivery, warranties, and liability
  • Service agreements: If you're booking appointments, consultations, or any service through your site, T&Cs define the relationship
  • User-generated content: Allowing reviews, comments, or uploads? You need terms governing acceptable use
  • Intellectual property: Protecting your content, images, and proprietary information
  • Limitation of liability: Defining what you're responsible for (and what you're not)
T&Cs are essentially a contract between you and your site users. They won't prevent all disputes, but they provide a framework for resolving them and can protect you if things go sideways.

The Template Temptation

Right. So you've accepted you need these documents. Now comes the question: can you just grab a template off the internet, run it through ChatGPT, and call it done? Technically? Yes. Advisably? That depends entirely on your risk tolerance and business complexity. Template privacy policies and T&Cs are everywhere—free generators, paid services, legal document libraries. Many are perfectly adequate for straightforward small business websites. The Office of the Australian Information Commissioner (OAIC) even provides guidance and resources for creating privacy policies. AI tools like ChatGPT can generate these documents quickly, and they're getting better at incorporating specific details. But—and this is crucial—they're only as good as the information you feed them and your ability to verify the output is actually correct and applicable to Australian law. The risks with templates and AI-generated documents:
  • Generic language that doesn't match your actual practices: If your privacy policy says you don't use cookies but you've got Google Analytics running, that's a problem
  • Jurisdiction mismatches: Many templates are written for US law, which differs significantly from Australian requirements
  • Outdated provisions: Privacy and digital law evolves; that template from 2015 probably doesn't address current practices
  • Missing clauses: Templates can't anticipate your specific business model or the particular tools you're using
  • False sense of security: Having a policy that's wrong or unenforceable might actually be worse than having none at all
I've seen AI-generated privacy policies that reference the GDPR (European law) but completely ignore the APPs. I've seen T&Cs that limit liability in ways that wouldn't hold up under Australian Consumer Law. These aren't just theoretical concerns—they're real gaps that could expose you legally.

When to Actually Get a Lawyer

Here's my honest assessment of when you should invest in proper legal advice: You probably don't need a lawyer if:
  • Your site is purely informational with basic contact forms
  • You're using well-known, simple tools (standard WordPress plugins, basic analytics)
  • You're not handling sensitive personal information
  • Your business turnover is modest and transactions are straightforward
  • You're comfortable reviewing and customising a quality template
In these cases, a well-chosen template or AI-generated document that you've carefully reviewed and customised can work. The OAIC resources are genuinely helpful. Just make sure whatever you use actually reflects your practices and is written for Australian jurisdiction. You should seriously consider a lawyer if:
  • You're handling health information, financial data, or children's data
  • Your business model is complex or unusual
  • You're processing significant volumes of personal information
  • You're approaching or exceeding the $3 million turnover threshold
  • You're operating in a regulated industry
  • You're selling high-value products or services with complex terms
  • You've got subscription models, recurring billing, or complex refund scenarios
  • You're allowing user-generated content or building a platform
Legal fees for privacy policies and T&Cs typically range from around $1,500 to $5,000+ depending on complexity. Yes, that's significant for a small business. But it's also insurance against regulatory action, customer disputes, and the reputational damage that comes with getting it wrong. Think of it this way: if a privacy breach or contractual dispute could cost you more than the legal fees, get the lawyer. If the worst-case scenario is a customer complaint you can resolve with a refund and an apology, maybe the template is fine.

The Hybrid Approach That Actually Works

For many small businesses, there's a middle path that balances cost and protection: Start with a quality template or AI generation, but be selective. Use Australian-specific resources. The OAIC has a privacy policy guide that's actually useful. Some legal firms offer reasonably priced template packages designed for Australian small businesses. Customise thoroughly. Don't just fill in your business name and call it done. Actually read the document. Remove sections that don't apply. Add specifics about the tools you use—name Google Analytics, Mailchimp, whatever you've got running. Be honest about what data you collect and why. Audit your actual practices. Before you finalise any policy, do a proper audit of your website. What cookies are being set? What forms collect data? Where does that data go? What third-party services are embedded? Your privacy policy needs to reflect reality, not an idealised version of your site. Get a legal review for the high-risk bits. Some lawyers will review and refine existing documents for less than creating them from scratch. If you're uncertain about specific clauses—particularly around liability, refunds, or data handling—a targeted consultation can be worthwhile. Keep them updated. This isn't a set-and-forget exercise. When you add new tools, change your data practices, or modify your business model, your policies need to be updated. Set a calendar reminder to review them annually at minimum.

What Actually Goes in These Documents

Since we're being practical here, let's talk about what these documents should actually contain. Privacy Policy essentials:
  • What personal information you collect (be specific: names, emails, IP addresses, browsing behaviour)
  • How you collect it (forms, cookies, third-party tools)
  • Why you collect it (to respond to enquiries, improve the site, send newsletters)
  • How you use and store it (your email system, your CRM, your hosting environment)
  • Who you share it with (email providers, analytics services, payment processors)
  • How people can access, correct, or delete their information
  • Your cookie policy (what cookies you use and why)
  • How you handle security
  • How you'll notify people of policy changes
  • Contact information for privacy enquiries
Terms and Conditions essentials:
  • Who can use your site and services (age restrictions, geographic limitations)
  • What users can and can't do (acceptable use policy)
  • Your intellectual property rights
  • Payment terms and conditions (if applicable)
  • Refund and cancellation policies
  • Disclaimers and limitations of liability
  • How disputes will be resolved
  • Which jurisdiction's laws apply
  • How you can modify the terms
Neither document needs to be intimidating or written in impenetrable legalese. Clear, plain English is actually better—it's more likely to be read and understood, which is kind of the point.

The Practical Reality

Look, I'm not a lawyer—I'm a creative director who's built hundreds of websites for Australian small businesses. What I've observed over 15 years is this: most small businesses operate in a grey zone where they're probably not going to face regulatory action over an imperfect privacy policy, but they absolutely could face customer trust issues or disputes over unclear terms. The businesses that handle this well treat these documents as communication tools, not just legal obligations. They use their privacy policy to explain their data practices transparently, building trust. They use their T&Cs to set clear expectations, reducing disputes before they start. The businesses that struggle either ignore these documents entirely (risky and increasingly untenable) or slap up generic templates that bear no relationship to their actual practices (arguably worse, because it's dishonest and potentially misleading). For most small business websites I work with, here's what I recommend: invest the time to understand what your site actually does, use quality Australian templates as a starting point, customise them honestly to reflect your practices, and get legal advice if you're handling anything sensitive or complex. It's not sexy, it's not fun, but it's part of running a responsible digital presence. And if you're genuinely not collecting any data—no analytics, no forms, no cookies, no third-party embeds—then congratulations, you've built one of the approximately 0.3% of websites that might not need a privacy policy. But you should probably still have one anyway, because someone's going to look for it and wonder why it's missing. The digital world demands a certain baseline of transparency and accountability. These documents are how you demonstrate that. Do them properly, keep them current, and treat them as part of your relationship with customers rather than a bureaucratic burden. That's the approach that actually works.
Wade Ashley

Wade Ashley

Creative Director, Dygiphy

Wade has been designing user interfaces for 30+ years — from mainframe terminals to modern responsive websites. He founded Dygiphy in 2009 to bring enterprise-level UX expertise to Australian small businesses.

More about Wade

More articles

Need help with your website?

Whether you need a new website, want to improve an existing one, or just have a question — we're here to help.

Get in Touch