Skip to content

What a strata manager's privacy policy actually needs

A strata manager's privacy policy should describe the real data your office holds: the owners roll, tenants and occupiers, levy arrears and debt-recovery files, by-law-breach and dispute records, committee and proxy details, contractors, and CCTV footage and access logs. Whether Australian Privacy Principle 1 strictly requires you to have one depends on your turnover and structure. But a strata-written policy does real work a generic template cannot, and state strata and surveillance law apply regardless.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Do you legally need a privacy policy at all? The honest answer

This is the question most generic advice gets wrong for strata, so start here. A privacy policy is a strict legal requirement only if you are an APP entity bound by the Australian Privacy Principles, and in strata that is not automatic.

Two honesty notes. First, the A$3 million small-business exemption is still in force as at July 2026. Its removal has been proposed as a future reform but is not law and has no legislated date, so we do not treat it as a deadline. Second, strata management is not named among the designated services in Tables 5 and 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), which cover brokering and assisting in the sale, purchase or transfer of real estate. The AML/CTF obligations that apply to real-estate agents and conveyancers from 1 July 2026 are not written at strata management, so we do not treat them as a deadline for a strata office.

The point most templates miss: strata privacy is three laws, not one

Even where the Privacy Act does not reach you, a strata office is bound by two other layers regardless of turnover, and a good policy accounts for all three:

A policy that treats strata as "just another business website" describes none of this.

What a strata manager's privacy policy must cover

For a covered manager, APP 1.4 sets the statutory minimum contents of the policy: the kinds of personal information you collect and hold, how you collect and hold it, the purposes, how someone gets access and correction, how they complain and how you will handle it, whether you are likely to disclose personal information overseas, and the countries those recipients are likely to be in where it is practicable to say. On top of that, a policy that fits a strata or owners-corporation management business should address:

A collection notice under APP 5 is a separate, shorter document you give people at the point their details are taken. The privacy policy is the standing public document; the collection notice is the point-of-collection heads-up. A covered strata office generally needs both. A written data-breach response plan is not itself named in the Act, but the OAIC has ordered entities to prepare one as a remedy (Datateks Pty Ltd (Privacy) [2023] AICmr 97 and Pacific Lutheran College (Privacy) [2023] AICmr 98, both 24 October 2023), and it is in practice how an entity meets the 30-day assessment duty in the notifiable data breaches scheme. Read: a data-breach response plan for strata managers

Where a generic template falls short

A free or off-the-shelf privacy policy is written for "a business", not a strata manager. In practice that means it usually:

One forward-looking layer, only if it applies to you

If you are a covered APP entity and your office has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, then from 10 December 2026 your privacy policy must set out the kinds of personal information those programs use and the kinds of decisions they make or help make (APP 1.7 and 1.8, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth)). Two things people get wrong: a part-automated process where a human still signs off is caught, and a tool that approves people is caught as much as one that refuses them. Whether a given tool crosses the threshold is fact-specific, so treat it as a "check this", not an automatic obligation, and only if your business is covered in the first place . Read: facial recognition, ANPR and smart surveillance in strata buildings

Separately, the OAIC ran a privacy-policy compliance sweep in the first half of 2026. It assessed the privacy policies of approximately 60 entities across six in-person-collection sectors against APP 1.4, and the Commissioner reported on 20 May 2026 that it found instances of non-compliance in a significant proportion. Strata was not one of the six sectors, so this is not a sweep aimed at strata offices. It is a useful signal of what the regulator opens first when it looks at a business, which for a covered manager is a reason to get the policy right. For a covered manager, that is a reason to get the policy right, not a manufactured deadline.

Common questions

Does a small strata manager under $3 million need a privacy policy?

Not necessarily as a legal requirement. If your managing-agent business turns over A$3 million or less and is not part of a larger covered group, the small-business exemption may mean the APPs do not bind you, so APP 1 does not compel a policy. It is still good practice and a trust signal. If your annual turnover for the previous financial year was more than A$3 million (s 6D(1)), or you are a related body corporate of a covered group (s 6D(9)), or another s 6D(4) limb applies to you, then APP 1.3 makes a clearly expressed, up-to-date privacy policy a strict requirement. Worth knowing if you are near the line: once a business has had turnover above A$3 million for a completed financial year, it does not get the exemption back (s 6D(4)(a)).

Is the owners corporation or the managing agent the one that needs the policy?

Usually the managing agent. An owners corporation's income is the levies for one scheme, which typically sits under the A$3 million threshold in s 6D(1), so the scheme itself is usually outside the APPs. The professional managing agent it hires is a separate entity with its own turnover and its own owners, and it is the one more often caught, most commonly by turnover over A$3 million (s 6D(1)) or by being a related body corporate of a larger covered group (s 6D(9)). The policy is a document for the management business. Read: strata manager vs owners corporation, who is actually covered?

Can I just use a free privacy policy template?

You can start from one, but a generic template rarely names a strata office's real data (the roll, tenants, arrears, disputes, CCTV) and often says "we never share your information", which is wrong for strata because state law compels you to disclose the roll on a proper request. Tailor it to the data you actually hold and the disclosures the law requires, or start from a document written for strata.

Should my policy say we never disclose the owners roll?

No. That would misstate your legal position. State strata law requires the roll and records to be made available to owners and other entitled persons on a proper request, so your policy should describe those statute-required disclosures honestly, while still confirming that a covered manager will not leak the same data to unauthorised third parties or misuse it.

Is a privacy policy the only document I need?

No. The policy is the standing public document. A strata office also needs collection notices (APP 5) for the points where details are taken, including scheme handovers, a CCTV and surveillance policy scoped to your state, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan.

Where Privaproof fits

Privaproof provides a dedicated, strata-specific privacy document set: a privacy policy, collection notices, a CCTV and surveillance policy with resident notice and signage guidance, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan. Written for owners-corporation and body-corporate management, scoped for New South Wales, Victoria and Queensland with clear prompts to confirm your own state, and kept current as the law changes. Not a one-off free download, and not a generic website policy.

→ Get the Strata Kit. Editable documents you tailor to your practice, with updates as the rules change.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and structure; many smaller managers and owners corporations fall outside it, while state strata legislation and state surveillance-devices law apply separately and vary by jurisdiction. The law changes over time, so check you are working from a current version and confirm your own state's requirements.