Our website uses cookies to give you the best experience and for us to analyse our site usage. If you continue to use our site, we will take it you are OK about this. Click on More for information about the cookies on our site and what you can do to opt out.

We respect your Do Not Track preference.

How to comply

If you're collecting personal information about someone - for example a customer - and you're getting the information from that person, principle 3 of the Privacy Act says that you need to let them know what you're doing.

Sometimes, of course, it's obvious that you are collecting the information and what you're going to use it for. You may not intend to disclose it to anyone. But people are still understandably cautious about giving out their personal information. They need to know they can trust you. They are more likely to do so if you tell them, up front, what you're doing with their information and why. People are particularly concerned that their information may be passed on to other agencies without them knowing.

Occasionally, it may not be obvious that you are collecting information at all unless you say so. For example, you may have a CCTV system, or your website may place a cookie on visitors' computers.

A privacy notice ensures that people are aware:

  • that you're collecting information about them (if it's not obvious)
  • why you're collecting the information;
  • what you're going to use it for;
  • who you're going to give it to (if anyone);
  • whether the person has to give you the information and what will happen if they don't;
  • that they can access the information you hold about them, and they can correct it if it's wrong.

Also, be prepared to answer people's questions about how you will handle their personal information. They're entitled to ask.

There are times when you don't have to provide a privacy notice - check principle 3 for a list of these exceptions.


Giving notice to website visitors about how your agency collects and uses personal information is good practice. An effective approach to this task is to use a layered privacy notice, and we have recommended '10 Steps to develop a multilayered privacy notice' as a source of detailed information.

Click the link to see 'Questions and Answers about Layered Privacy Notices'.

Additional Resources

Center for information policy leadership
Ten steps to develop a multilayered privacy notice

OECD (Organisation for Economic Cooperation and Development)
Making Privacy Notices Simple: An OECD Report and Recommendations
Report annexes
OECD Privacy Statement Generator

APEC (Asia-Pacific Economic Cooperation)

Multi-Layered Notices - A Developing Standard
Multi-Layered Notices Explained