Pull up the privacy policy on your website and read it slowly. Somewhere in there is a line saying personal information is “stored securely”, probably another saying it is “destroyed when no longer required”, and possibly one stating that you don’t send information overseas. Now ask whoever manages your IT whether those statements are true.
For most Sydney businesses, the honest answer is “partly”. The policy was written from a template years ago, perhaps by a lawyer, perhaps by whoever built the website, and nobody has compared it against the systems since. Meanwhile the business moved to Microsoft 365, added a CRM, connected an e-signature platform, started using an AI note-taker in client meetings and kept every file server backup since 2017.
That mismatch is now one of the most practical issues in Privacy Act compliance for small business and mid-sized organisations alike, because the regulator has started reading privacy policies and asking whether they describe reality. This article covers where the gaps usually sit, why they matter more in 2026 than they did a year ago, and how to close them.
Your Privacy Policy Describes a Business That No Longer Exists
A privacy policy is a snapshot. It records how a business handled personal information on the day someone wrote it, while the systems underneath keep changing.
Under Australian Privacy Principle (APP) 1.4, a compliant policy has to set out the kinds of personal information you collect and hold, how you collect and hold it, why, how people can access and correct it, how they can complain, and whether you are likely to disclose it overseas (naming the countries where practicable). Every one of those items is a factual claim about your technology environment.
“How you hold it” means which platforms, which data centres and which backups. “Disclosure overseas” can include the US-hosted SaaS tool your sales team signed up to on a company credit card. The policy makes promises on behalf of systems that nobody has checked against it.
That is why we treat privacy policies as an IT question as much as a legal one. A lawyer can tell you what the policy must say. Only someone who can see your tenant, your endpoints, your backups and your third-party integrations can tell you whether it’s accurate.
Regulators Are Now Checking the Policy Against the Practice
For years, an outdated privacy policy carried little real-world risk. That changed with the Privacy and Other Legislation Amendment Act 2024, which gave the Office of the Australian Information Commissioner (OAIC) the ability to issue compliance and infringement notices for basic transparency failures without going to court.
The OAIC put those powers to work quickly. In January 2026 it began its first-ever privacy compliance sweep, reviewing the privacy policies of roughly 60 businesses across six sectors that collect personal information in person. As MinterEllison noted in its analysis of the OAIC sweep, penalties for failing to meet these transparency requirements can reach $66,000. Law firms advising on the sweep have been clear that having the right headings is not enough: the policy needs to reflect what the organisation actually does.
Public expectations are moving in the same direction. The OAIC received 1,205 data breach notifications in 2025, the most since mandatory reporting began in 2018, and its 2026 community attitudes research found 82% of Australians now regard data breaches as a major privacy risk. When a breach happens, one of the first documents a regulator, journalist or client’s lawyer reads is your privacy policy. If it claims something your systems never did, that becomes part of the story.
Being a “Small Business” Doesn’t Automatically Mean You’re Exempt
Many business owners assume the Privacy Act doesn’t apply to them because their annual turnover is under $3 million. The small business exemption is real, but it has always had exceptions, and more businesses are falling inside them.
You are generally covered regardless of turnover if you:
- provide a health service and hold health information, which captures allied health, dental and psychology practices
- trade in personal information, such as buying or selling customer lists
- are related to a larger business that is covered by the Act
- are a contracted service provider to a Commonwealth agency
- are a reporting entity under the AML/CTF Act
That last category matters more than it did a year ago. From 1 July 2026, the Tranche 2 anti-money laundering reforms brought accountants, lawyers, conveyancers and real estate professionals into the AML/CTF regime, and with it the Privacy Act for personal information handled in connection with those obligations. MinterEllison’s guidance on the change puts an APP-compliant privacy policy at the top of the to-do list for affected firms.
Plenty of businesses under the threshold also opt in voluntarily, or are contractually required to comply because larger clients write it into supplier agreements. If your website says you comply with the Australian Privacy Principles, customers and partners are entitled to rely on that statement whether or not the exemption technically applies to you.
Where the Gaps Between Policy and Systems Usually Hide
When we compare a client’s privacy policy against their actual environment, the same discrepancies come up repeatedly.
Overseas storage nobody declared. The policy says information is stored in Australia. Your Microsoft 365 tenant may well be, but the email marketing platform, online booking system, e-signature tool and support ticketing app may be hosted in the United States or Europe. Depending on how those services handle your data, each may count as an overseas disclosure that APP 1.4 expects you to mention.
Retention promises the systems can’t keep. “We destroy personal information when it is no longer needed” is standard wording, and it reflects APP 11.2. In practice, retention is rarely configured. Mailboxes belonging to staff who left years ago are still in the tenant. File shares hold scanned driver’s licences from old onboarding processes. Backup jobs keep everything indefinitely because nobody set a retention schedule.
Security claims without the controls behind them. Policies often describe “industry-standard security” or “encryption”. If multi-factor authentication isn’t enforced on every account, laptops aren’t encrypted or admin credentials are shared, that description doesn’t hold up under scrutiny.
Shadow IT and forgotten integrations. Staff can connect apps to Microsoft 365 or Google Workspace in a couple of clicks, granting access to mailboxes, calendars and files. Each of those apps is now holding or processing personal information the policy never mentions.
Third parties with more access than anyone realises. Bookkeepers, marketing agencies, developers and software vendors often hold logins or data exports. The policy may say information is shared with service providers only “as necessary”, while the access logs tell a broader story.
AI tools fed with client data. Meeting transcription, AI writing assistants and chatbot plug-ins are being adopted faster than policies are updated. If client conversations are being recorded, transcribed and stored by a third-party AI service, your policy should say so.
None of these gaps are exotic. They are the ordinary result of a business adopting cloud tools over several years without anyone owning the link between the systems and the policy.
10 December 2026 Adds a New Disclosure Your Systems Have to Support
The next fixed deadline is close. From 10 December 2026, new requirements in APP 1.7 to 1.9 commence. If your business uses a computer program that relies on personal information to make decisions that could reasonably be expected to significantly affect someone’s rights or interests, or to do something substantially and directly related to making such a decision, your privacy policy must describe the kinds of personal information used and the kinds of decisions involved.
Business owners tend to hear “automated decision-making” and assume it applies to banks and insurers. Then you look at the actual software stack: automated credit checks before extending payment terms, applicant screening in recruitment software, booking or tenancy approvals driven by a scoring tool, eligibility rules built into a client portal. The obligation applies to decisions made from 10 December onward, even if the system was set up years earlier.
Writing that disclosure accurately requires knowing which systems are making or shaping those decisions. That is an inventory exercise first and a drafting exercise second.
The Next Round of Reform Rewards Businesses That Already Know Where Their Data Lives
On 31 August 2026, the Attorney-General’s Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the long-awaited second tranche of reform. Consultation closed on 18 September, so the detail may still change, but the direction is clear. The draft proposes that collection, use and disclosure of personal information must be fair and reasonable, broadens what counts as personal information, and introduces a 72-hour window to notify the OAIC of eligible data breaches.
Seventy-two hours is very little time to work out what was in a compromised mailbox or which system a leaked file came from. Businesses with a current data map can meet that timeframe. Businesses discovering their data holdings in the middle of an incident will struggle.
According to Colin Biggers & Paisley’s summary of the draft, the small business exemption survives this round, so the $3 million threshold stays for now. For every organisation already inside the Act, though, the gap between what the policy says and what the systems do is about to become much harder to defend.
What a Policy-to-Systems Audit Actually Involves
Closing the gap is mostly a matter of putting the policy beside the technology environment and checking each claim, rather than launching a large compliance program. A practical audit runs like this:
- Inventory where personal information lives. Cover Microsoft 365 or Google Workspace, line-of-business applications, file servers, endpoints, backups, SaaS subscriptions and data held by third parties, including apps staff have connected themselves.
- Map how it moves. Record which systems collect it, which integrations copy it, which vendors receive it and in which countries those vendors store it.
- Test the policy clause by clause. For every statement about storage, security, disclosure, overseas transfer and retention, note whether the systems support it, contradict it or can’t be verified.
- Decide what to change: the system or the wording. Some gaps are fixed by configuring retention policies, enforcing MFA, removing unused integrations or moving data to Australian hosting. Others are fixed by updating the policy to describe what you genuinely do and why.
- Flag automated decision-making ahead of 10 December. Identify any system that makes or substantially informs decisions about people so the new disclosure can be drafted accurately.
- Set a review trigger. Repeat the comparison whenever you adopt a significant new system or change a key vendor, and at least once a year.
The output should be a short gap register your legal adviser can use to update the policy, and a remediation list your IT team can work through. Legal advice and technical evidence need to meet in the middle, and in most businesses nobody is assigned to that middle ground.
Rewriting the Policy Is the Easy Part
Many businesses respond to privacy pressure by having a lawyer refresh the policy wording. That’s worth doing, but a well-drafted policy describing systems that don’t exist only shifts the risk somewhere else. The harder and more valuable work is making the technology and the document agree, then keeping them in step as the business changes.
Sydney Technology Solutions has supported Sydney businesses since 1999, and this is the kind of review we are well placed to run. We can see the tenant configuration, backup jobs, endpoint controls and third-party connections that determine whether your privacy policy is accurate, and we work alongside your legal adviser so the final policy is both compliant and true.
If you’re not sure your privacy policy reflects what your systems actually do, talk to us about a privacy policy and systems review before 10 December, or call (02) 8212 4722. For more on how we protect client data, see our approach to cyber security for Sydney businesses.
55 Park Road,