What a strata manager's privacy policy actually needs
A strata manager's privacy policy should describe the real data your office holds: the owners roll, tenants and occupiers, levy arrears and debt-recovery files, by-law-breach and dispute records, committee and proxy details, contractors, and CCTV footage and access logs. Whether Australian Privacy Principle 1 strictly requires you to have one depends on your turnover and structure. But a strata-written policy does real work a generic template cannot, and state strata and surveillance law apply regardless.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Do you legally need a privacy policy at all? The honest answer
This is the question most generic advice gets wrong for strata, so start here. A privacy policy is a strict legal requirement only if you are an APP entity bound by the Australian Privacy Principles, and in strata that is not automatic.
- If your managing-agent business is a covered APP entity, APP 1 requires one. Under Australian Privacy Principle 1.3, a covered entity must have a clearly expressed and up-to-date privacy policy about how it manages personal information. Your business is covered if either its annual turnover exceeds A$3 million (s 6D of the Privacy Act 1988 (Cth)) or it is a related body corporate of a larger group that is itself covered (s 6C). That related-body-corporate limb is why many branded and national strata managers are already caught even where a single office assumes it is exempt. Read: does the Privacy Act apply to strata managers?
- The owners corporation itself is usually exempt. An owners corporation or body corporate is almost always a small-business operator under A$3 million, so the APPs largely do not bind the scheme. The buyer of a privacy policy is the managing agent, not the scheme.
- If you are a small independent manager under A$3 million and not part of a larger group, you may genuinely have no APP 1 obligation at all. We will say so rather than sell you a duty you do not have. In that case a privacy policy is good practice and a trust signal, not a legal requirement under the Privacy Act.
Two honesty notes. First, the A$3 million small-business exemption is still in force as at July 2026. Its removal has been proposed as a future reform but is not law and has no legislated date, so we do not treat it as a deadline. Second, strata management is not an anti-money-laundering designated service, so there is no AUSTRAC trigger and no 1 July 2026 obligation pulling you into the Privacy Act by that route.
The point most templates miss: strata privacy is three laws, not one
Even where the Privacy Act does not reach you, a strata office is bound by two other layers regardless of turnover, and a good policy accounts for all three:
- The Privacy Act and the APPs, if you are a covered managing agent as above.
- Your state strata legislation, which requires the owners roll and records to be kept and made available for inspection. In NSW, the Strata Schemes Management Act 2015 sets the roll content (s 178: names and addresses), a record-retention floor (s 180: around seven years) and inspection access on request and payment of a prescribed fee (s 182). Victoria (Owners Corporations Act 2006) and Queensland (BCCM Act 1997) impose equivalent register and interested-person access duties, though the exact section numbers vary with amendments .
- Your state surveillance-devices law, which governs CCTV and audio on common property and binds you even if you sit inside the small-business exemption.
A policy that treats strata as "just another business website" describes none of this.
What a strata manager's privacy policy must cover
A policy that fits a strata or owners-corporation management business should address, at a minimum:
- What personal information you hold. Be specific to strata: the owners roll (names, lot numbers, addresses and contact details), tenants and occupiers whose details often arrive through the owner or letting agent without the person ever contacting you, levy arrears and debt-recovery files, by-law-breach and dispute records in a high-conflict context, committee, proxy and voting records that name individuals, contractor details, and CCTV footage and access or swipe logs.
- How and why you collect it. The purposes you collect for (administering the scheme, issuing levies, maintaining the roll, managing disputes, meeting your obligations to the owners corporation), and the fact that you routinely collect information about third parties, not just the person in front of you. A key strata point is the handover of an existing scheme, where you inherit a full data pool about people who never chose to deal with you.
- How you use and disclose it, including disclosures the law requires of you. This is the strata-specific heart of the document. State strata law compels you to make the roll and records available to owners, committee members, mortgagees and certain entitled persons, so "privacy" is generally not a lawful ground to refuse a proper inspection. Your policy should describe those lawful, statute-required disclosures honestly, alongside the routine ones (to the owners corporation, to your strata software provider, to insurers, to a debt collector for arrears recovery). Read: can a strata manager give out an owner's details?
- How you protect and confine it. If you are covered, APP 6 limits you to using or disclosing the data only for authorised purposes, and APP 11 requires reasonable steps to keep it secure. The honest tension a strata policy must hold: you must disclose the roll where the law requires it, and you must still not leak that same data to unauthorised third parties or use it for your own marketing. Read: who can access the strata roll, and what does it contain?
- CCTV and surveillance. How footage is captured, stored, accessed and retained, and a pointer to the standing surveillance policy and signage. Footage of identifiable people is personal information for a covered manager, and state surveillance-devices law applies to the cameras themselves independently of the Privacy Act. Read: CCTV and surveillance on strata common property
- How long you keep it, and how you destroy it. The retention and destruction approach, reconciling the state strata record-keeping floor (in NSW, around seven years) with the "destroy or de-identify when no longer needed" principle that APP 11.2 imposes on a covered manager. The honest answer is to keep records for the statutory period and then dispose of ex-owner and former-tenant data rather than hoard it indefinitely . Read: how long must a strata manager keep owner records?
- How people can access, correct or complain. How an individual asks for the information you hold, seeks a correction, and raises a privacy concern, including that a covered entity's conduct can be complained about to the OAIC. A named privacy contact point makes this concrete.
A collection notice under APP 5 is a separate, shorter document you give people at the point their details are taken. The privacy policy is the standing public document; the collection notice is the point-of-collection heads-up. A covered strata office generally needs both, plus a data-breach response plan. Read: a data-breach response plan for strata managers
Where a generic template falls short
A free or off-the-shelf privacy policy is written for "a business", not a strata manager. In practice that means it usually:
- Names none of your real data. It will not mention the owners roll, tenants collected via the owner, arrears, by-law disputes, committee records or CCTV, so it describes a business that is not yours.
- Ignores the disclosure duty. A horizontal "we keep your information private and never share it" policy is actually wrong for strata, because state strata law compels you to disclose the roll on a proper request. A one-sided "lock it all down" message misstates your legal position. Read: is the Privacy Act a shield against strata record access?
- Misses CCTV and state surveillance law. Generic templates say nothing about common-property cameras, audio limits, signage or footage access, which are governed by state law that varies materially by jurisdiction.
- Carries the wrong coverage framing. Some assert a universal obligation you may not have; others assume you are exempt when the related-body-corporate limb has quietly caught you. Neither is honest for strata.
- Does not stay current. A one-off download does not update as the law moves.
One forward-looking layer, only if it applies to you
If you are a covered APP entity and your office uses software that makes, or substantially helps make, a decision that could significantly affect a person, then a new privacy-policy transparency requirement (commencing 10 December 2026) requires that automated decision-making to be disclosed in your policy. In strata this is most likely to bite around biometric or number-plate surveillance tools. Whether a given tool crosses the threshold is fact-specific, so treat it as a "check this", not an automatic obligation, and only if your business is covered in the first place . Read: facial recognition, ANPR and smart surveillance in strata buildings
Separately, the OAIC has signalled closer scrutiny of foundational failures such as lacking a compliant privacy policy, with penalty figures reported for non-compliant policies . For a covered manager, that is a reason to get the policy right, not a manufactured deadline.
Common questions
Does a small strata manager under $3 million need a privacy policy?
Not necessarily as a legal requirement. If your managing-agent business turns over A$3 million or less and is not part of a larger covered group, the small-business exemption may mean the APPs do not bind you, so APP 1 does not compel a policy. It is still good practice and a trust signal. If you are over A$3 million, or a related body corporate of a covered group, APP 1 makes a clearly expressed, up-to-date privacy policy a strict requirement.
Is the owners corporation or the managing agent the one that needs the policy?
Usually the managing agent. The owners corporation itself is almost always a small-business operator and exempt, whereas the professional managing agent it hires is frequently a covered APP entity, either by exceeding A$3 million turnover or through the related-body-corporate limb. The policy is a document for the management business. Read: strata manager vs owners corporation, who is actually covered?
Can I just use a free privacy policy template?
You can start from one, but a generic template rarely names a strata office's real data (the roll, tenants, arrears, disputes, CCTV) and often says "we never share your information", which is wrong for strata because state law compels you to disclose the roll on a proper request. Tailor it to the data you actually hold and the disclosures the law requires, or start from a document written for strata.
Should my policy say we never disclose the owners roll?
No. That would misstate your legal position. State strata law requires the roll and records to be made available to owners and other entitled persons on a proper request, so your policy should describe those statute-required disclosures honestly, while still confirming that a covered manager will not leak the same data to unauthorised third parties or misuse it.
Is a privacy policy the only document I need?
No. The policy is the standing public document. A strata office also needs collection notices (APP 5) for the points where details are taken, including scheme handovers, a CCTV and surveillance policy scoped to your state, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan.
Where Privaproof fits
Privaproof is building a dedicated, strata-specific privacy document set: a privacy policy, collection notices, a CCTV and surveillance policy with resident notice and signage guidance, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan. Written for owners-corporation and body-corporate management, scoped for New South Wales, Victoria and Queensland at launch with clear prompts to confirm your own state, and kept current as the law changes. Not a one-off free download, and not a generic website policy.
→ Join the founding list. Be first to know when the Strata Kit opens, and get the plain-English updates as the rules move. No cost, no obligation.
Keep reading
- Privacy compliance for Australian strata and owners-corporation managers
- Does the Privacy Act apply to strata managers?
- Strata manager vs owners corporation: who is actually covered?
- Can a strata manager give out an owner's details?
- CCTV and surveillance on strata common property
- A data-breach response plan for strata managers
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and structure; many smaller managers and owners corporations fall outside it, while state strata legislation and state surveillance-devices law apply separately and vary by jurisdiction. Privaproof's strata documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version and confirm your own state's requirements.