What a strata manager's privacy policy actually needs
A strata manager's privacy policy should describe the real data your office holds: the owners roll, tenants and occupiers, levy arrears and debt-recovery files, by-law-breach and dispute records, committee and proxy details, contractors, and CCTV footage and access logs. Whether Australian Privacy Principle 1 strictly requires you to have one depends on your turnover and structure. But a strata-written policy does real work a generic template cannot, and state strata and surveillance law apply regardless.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Do you legally need a privacy policy at all? The honest answer
This is the question most generic advice gets wrong for strata, so start here. A privacy policy is a strict legal requirement only if you are an APP entity bound by the Australian Privacy Principles, and in strata that is not automatic.
- If your managing-agent business is a covered APP entity, APP 1 requires one. Under Australian Privacy Principle 1.3, a covered entity must have a clearly expressed and up-to-date privacy policy about how it manages personal information. Your business is covered mainly where its annual turnover for the previous financial year was more than A$3 million (s 6D(1) of the Privacy Act 1988 (Cth)), or where it is a related body corporate of a larger group that is itself covered (s 6D(9)). That related-body-corporate limb is why many branded and national strata managers are already caught even where a single office assumes it is exempt. Section 6D(4) sets out further limbs that bite far less often in strata but are not nothing, including disclosing personal information about someone for a benefit (s 6D(4)(c), often carved out by consent under s 6D(7)) and holding a Commonwealth contract (s 6D(4)(e)). Treat the first two as the usual answers, not as a closed list. Read: does the Privacy Act apply to strata managers?
- The owners corporation itself is usually outside the APPs. An owners corporation's income is essentially the levies it raises to run one scheme, and for a typical residential scheme that sits well under the A$3 million small-business threshold in s 6D(1). A very large scheme, or one running a substantial commercial operation, could cross it. The buyer of a privacy policy is usually the managing agent, not the scheme.
- If you are a small independent manager under A$3 million, not part of a larger group, and none of the other section 6D(4) limbs apply to you, you may genuinely have no APP 1 obligation at all. The limb worth actually checking in strata is disclosing owner details to an insurer or broker for a commission (s 6D(4)(c)), which s 6D(7) will often carve out where the owners corporation authorised the placement. Two more things to know: the test looks at your previous financial year, and once a business has had turnover above A$3 million for a completed financial year, the exemption is not regained (s 6D(4)(a)). We will say all of this rather than sell you a duty you do not have. In that case a privacy policy is good practice and a trust signal, not a legal requirement under the Privacy Act.
Two honesty notes. First, the A$3 million small-business exemption is still in force as at July 2026. Its removal has been proposed as a future reform but is not law and has no legislated date, so we do not treat it as a deadline. Second, strata management is not named among the designated services in Tables 5 and 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), which cover brokering and assisting in the sale, purchase or transfer of real estate. The AML/CTF obligations that apply to real-estate agents and conveyancers from 1 July 2026 are not written at strata management, so we do not treat them as a deadline for a strata office.
The point most templates miss: strata privacy is three laws, not one
Even where the Privacy Act does not reach you, a strata office is bound by two other layers regardless of turnover, and a good policy accounts for all three:
- The Privacy Act and the APPs, if you are a covered managing agent as above.
- Your state strata legislation, which requires the owners roll and records to be kept and made available for inspection. In NSW, the Strata Schemes Management Act 2015 sets the roll content (s 178: names and addresses), a record-retention floor (s 180: around seven years) and inspection access on request and payment of a prescribed fee (s 182). Victoria's Owners Corporations Act 2006 requires the records to be kept (s 144), retained (s 145) and made available for inspection (s 146), with a separate owners corporation register at ss 147 and 148 that is inspected under s 150. Queensland's Body Corporate and Community Management Act 1997 gives an "interested person" a right to inspect and copy the body corporate records (s 205), while the roll contents sit in the applicable regulation module (for the Standard Module, BCCM (Standard Module) Regulation 2020 s 224), so confirm which module your scheme is under before relying on a section number.
- Your state's surveillance and listening-devices law, which applies to cameras and recording on common property independently of the Privacy Act and binds a strata office even if you sit inside the small-business exemption. Audio is the strict part and the rule is close to national: recording a private conversation without consent is an offence under the Surveillance Devices Act 2007 (NSW) s 7, the Surveillance Devices Act 1999 (Vic) s 6 and the Invasion of Privacy Act 1971 (Qld) s 43. Vision is not uniform: Victoria has an activity-based optical-surveillance offence (s 7), New South Wales a narrower one keyed to entry or interference (s 8), and Queensland has no general optical-surveillance offence at all. Do not carry one state's camera policy into another.
A policy that treats strata as "just another business website" describes none of this.
What a strata manager's privacy policy must cover
For a covered manager, APP 1.4 sets the statutory minimum contents of the policy: the kinds of personal information you collect and hold, how you collect and hold it, the purposes, how someone gets access and correction, how they complain and how you will handle it, whether you are likely to disclose personal information overseas, and the countries those recipients are likely to be in where it is practicable to say. On top of that, a policy that fits a strata or owners-corporation management business should address:
- What personal information you hold. Be specific to strata: the owners roll (names, lot numbers, addresses and contact details), tenants and occupiers whose details often arrive through the owner or letting agent without the person ever contacting you, levy arrears and debt-recovery files, by-law-breach and dispute records in a high-conflict context, committee, proxy and voting records that name individuals, contractor details, and CCTV footage and access or swipe logs.
- How and why you collect it. The purposes you collect for (administering the scheme, issuing levies, maintaining the roll, managing disputes, meeting your obligations to the owners corporation), and the fact that you routinely collect information about third parties, not just the person in front of you. A key strata point is the handover of an existing scheme, where you inherit a full data pool about people who never chose to deal with you.
- How you use and disclose it, including disclosures the law requires of you. This is the strata-specific heart of the document. State strata law compels the roll and records to be made available to the class the Act entitles (in NSW, an owner, mortgagee or covenant chargee of a lot, or a person they authorise: s 182(1)), so "privacy" is generally not a lawful ground to refuse a proper inspection. Your policy should describe those lawful, statute-required disclosures honestly, alongside the routine ones (to the owners corporation, to your strata software provider, to insurers, to a debt collector for arrears recovery). Read: can a strata manager give out an owner's details?
- How you protect and confine it. If you are covered, APP 6.1 stops you using or disclosing the data for a purpose other than the one you collected it for, unless an exception applies, and APP 11.1 requires reasonable steps to keep it secure. The exception that resolves the strata tension is APP 6.2(b): a use or disclosure required or authorised by or under an Australian law. That is what makes a statutory roll inspection lawful for a covered manager. It is also why the same data still must not go to unauthorised third parties or into your own marketing, because neither is required or authorised by anything. The honest tension a strata policy must hold: you must disclose the roll where the law requires it, and you must still not leak that same data to unauthorised third parties or use it for your own marketing. Read: who can access the strata roll, and what does it contain?
- CCTV and surveillance. How footage is captured, stored, accessed and retained, and a pointer to the standing surveillance policy and signage. Footage of identifiable people is personal information for a covered manager, and state surveillance-devices law applies to the cameras themselves independently of the Privacy Act. Read: CCTV and surveillance on strata common property
- How long you keep it, and how you destroy it. The retention and destruction approach, reconciling the state strata record-keeping floor (in NSW, around seven years) with the "destroy or de-identify when no longer needed" principle that APP 11.2 imposes on a covered manager. The reconciliation is written into the principle itself: APP 11.2 only bites where you are not required by an Australian law to retain the information, so the state retention floor comes first and APP 11.2 governs what you do once it expires. Keep records for the statutory period, then dispose of ex-owner and former-tenant data rather than hoard it indefinitely. The floors differ: New South Wales is seven years (Strata Schemes Management Act 2015 (NSW) s 180); Victoria is seven years for general records, twelve months for voting papers, ballots and proxies, and life-of-building for foundational documents (Owners Corporations Act 2006 (Vic) s 145); Queensland is tiered rather than a single term, with some records disposable after six years and minor records after two, and nothing that is still current disposable at all (BCCM (Standard Module) Regulation 2020 s 231, and the tiers depend on which module your scheme is under). Read: how long must a strata manager keep owner records?
- How people can access, correct or complain. How an individual asks for the information you hold, seeks a correction, and raises a privacy concern, including that a covered entity's conduct can be complained about to the OAIC. A named privacy contact point makes this concrete.
A collection notice under APP 5 is a separate, shorter document you give people at the point their details are taken. The privacy policy is the standing public document; the collection notice is the point-of-collection heads-up. A covered strata office generally needs both. A written data-breach response plan is not itself named in the Act, but the OAIC has ordered entities to prepare one as a remedy (Datateks Pty Ltd (Privacy) [2023] AICmr 97 and Pacific Lutheran College (Privacy) [2023] AICmr 98, both 24 October 2023), and it is in practice how an entity meets the 30-day assessment duty in the notifiable data breaches scheme. Read: a data-breach response plan for strata managers
Where a generic template falls short
A free or off-the-shelf privacy policy is written for "a business", not a strata manager. In practice that means it usually:
- Names none of your real data. It will not mention the owners roll, tenants collected via the owner, arrears, by-law disputes, committee records or CCTV, so it describes a business that is not yours.
- Ignores the disclosure duty. A horizontal "we keep your information private and never share it" policy is actually wrong for strata, because state strata law compels you to disclose the roll on a proper request. A one-sided "lock it all down" message misstates your legal position. Read: is the Privacy Act a shield against strata record access?
- Misses CCTV and state surveillance law. Generic templates say nothing about common-property cameras, audio limits, signage or footage access, which are governed by state law that varies materially by jurisdiction.
- Carries the wrong coverage framing. Some assert a universal obligation you may not have; others assume you are exempt when the related-body-corporate limb has quietly caught you. Neither is honest for strata.
- Does not stay current. A one-off download does not update as the law moves.
One forward-looking layer, only if it applies to you
If you are a covered APP entity and your office has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, then from 10 December 2026 your privacy policy must set out the kinds of personal information those programs use and the kinds of decisions they make or help make (APP 1.7 and 1.8, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth)). Two things people get wrong: a part-automated process where a human still signs off is caught, and a tool that approves people is caught as much as one that refuses them. Whether a given tool crosses the threshold is fact-specific, so treat it as a "check this", not an automatic obligation, and only if your business is covered in the first place . Read: facial recognition, ANPR and smart surveillance in strata buildings
Separately, the OAIC ran a privacy-policy compliance sweep in the first half of 2026. It assessed the privacy policies of approximately 60 entities across six in-person-collection sectors against APP 1.4, and the Commissioner reported on 20 May 2026 that it found instances of non-compliance in a significant proportion. Strata was not one of the six sectors, so this is not a sweep aimed at strata offices. It is a useful signal of what the regulator opens first when it looks at a business, which for a covered manager is a reason to get the policy right. For a covered manager, that is a reason to get the policy right, not a manufactured deadline.
Common questions
Does a small strata manager under $3 million need a privacy policy?
Not necessarily as a legal requirement. If your managing-agent business turns over A$3 million or less and is not part of a larger covered group, the small-business exemption may mean the APPs do not bind you, so APP 1 does not compel a policy. It is still good practice and a trust signal. If your annual turnover for the previous financial year was more than A$3 million (s 6D(1)), or you are a related body corporate of a covered group (s 6D(9)), or another s 6D(4) limb applies to you, then APP 1.3 makes a clearly expressed, up-to-date privacy policy a strict requirement. Worth knowing if you are near the line: once a business has had turnover above A$3 million for a completed financial year, it does not get the exemption back (s 6D(4)(a)).
Is the owners corporation or the managing agent the one that needs the policy?
Usually the managing agent. An owners corporation's income is the levies for one scheme, which typically sits under the A$3 million threshold in s 6D(1), so the scheme itself is usually outside the APPs. The professional managing agent it hires is a separate entity with its own turnover and its own owners, and it is the one more often caught, most commonly by turnover over A$3 million (s 6D(1)) or by being a related body corporate of a larger covered group (s 6D(9)). The policy is a document for the management business. Read: strata manager vs owners corporation, who is actually covered?
Can I just use a free privacy policy template?
You can start from one, but a generic template rarely names a strata office's real data (the roll, tenants, arrears, disputes, CCTV) and often says "we never share your information", which is wrong for strata because state law compels you to disclose the roll on a proper request. Tailor it to the data you actually hold and the disclosures the law requires, or start from a document written for strata.
Should my policy say we never disclose the owners roll?
No. That would misstate your legal position. State strata law requires the roll and records to be made available to owners and other entitled persons on a proper request, so your policy should describe those statute-required disclosures honestly, while still confirming that a covered manager will not leak the same data to unauthorised third parties or misuse it.
Is a privacy policy the only document I need?
No. The policy is the standing public document. A strata office also needs collection notices (APP 5) for the points where details are taken, including scheme handovers, a CCTV and surveillance policy scoped to your state, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan.
Where Privaproof fits
Privaproof provides a dedicated, strata-specific privacy document set: a privacy policy, collection notices, a CCTV and surveillance policy with resident notice and signage guidance, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan. Written for owners-corporation and body-corporate management, scoped for New South Wales, Victoria and Queensland with clear prompts to confirm your own state, and kept current as the law changes. Not a one-off free download, and not a generic website policy.
→ Get the Strata Kit. Editable documents you tailor to your practice, with updates as the rules change.
Keep reading
- Privacy compliance for Australian strata and owners-corporation managers
- Does the Privacy Act apply to strata managers?
- Strata manager vs owners corporation: who is actually covered?
- Can a strata manager give out an owner's details?
- CCTV and surveillance on strata common property
- A data-breach response plan for strata managers
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and structure; many smaller managers and owners corporations fall outside it, while state strata legislation and state surveillance-devices law apply separately and vary by jurisdiction. The law changes over time, so check you are working from a current version and confirm your own state's requirements.