Skip to content

What a strata manager's privacy policy actually needs

A strata manager's privacy policy should describe the real data your office holds: the owners roll, tenants and occupiers, levy arrears and debt-recovery files, by-law-breach and dispute records, committee and proxy details, contractors, and CCTV footage and access logs. Whether Australian Privacy Principle 1 strictly requires you to have one depends on your turnover and structure. But a strata-written policy does real work a generic template cannot, and state strata and surveillance law apply regardless.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Do you legally need a privacy policy at all? The honest answer

This is the question most generic advice gets wrong for strata, so start here. A privacy policy is a strict legal requirement only if you are an APP entity bound by the Australian Privacy Principles, and in strata that is not automatic.

Two honesty notes. First, the A$3 million small-business exemption is still in force as at July 2026. Its removal has been proposed as a future reform but is not law and has no legislated date, so we do not treat it as a deadline. Second, strata management is not an anti-money-laundering designated service, so there is no AUSTRAC trigger and no 1 July 2026 obligation pulling you into the Privacy Act by that route.

The point most templates miss: strata privacy is three laws, not one

Even where the Privacy Act does not reach you, a strata office is bound by two other layers regardless of turnover, and a good policy accounts for all three:

A policy that treats strata as "just another business website" describes none of this.

What a strata manager's privacy policy must cover

A policy that fits a strata or owners-corporation management business should address, at a minimum:

A collection notice under APP 5 is a separate, shorter document you give people at the point their details are taken. The privacy policy is the standing public document; the collection notice is the point-of-collection heads-up. A covered strata office generally needs both, plus a data-breach response plan. Read: a data-breach response plan for strata managers

Where a generic template falls short

A free or off-the-shelf privacy policy is written for "a business", not a strata manager. In practice that means it usually:

One forward-looking layer, only if it applies to you

If you are a covered APP entity and your office uses software that makes, or substantially helps make, a decision that could significantly affect a person, then a new privacy-policy transparency requirement (commencing 10 December 2026) requires that automated decision-making to be disclosed in your policy. In strata this is most likely to bite around biometric or number-plate surveillance tools. Whether a given tool crosses the threshold is fact-specific, so treat it as a "check this", not an automatic obligation, and only if your business is covered in the first place . Read: facial recognition, ANPR and smart surveillance in strata buildings

Separately, the OAIC has signalled closer scrutiny of foundational failures such as lacking a compliant privacy policy, with penalty figures reported for non-compliant policies . For a covered manager, that is a reason to get the policy right, not a manufactured deadline.

Common questions

Does a small strata manager under $3 million need a privacy policy?

Not necessarily as a legal requirement. If your managing-agent business turns over A$3 million or less and is not part of a larger covered group, the small-business exemption may mean the APPs do not bind you, so APP 1 does not compel a policy. It is still good practice and a trust signal. If you are over A$3 million, or a related body corporate of a covered group, APP 1 makes a clearly expressed, up-to-date privacy policy a strict requirement.

Is the owners corporation or the managing agent the one that needs the policy?

Usually the managing agent. The owners corporation itself is almost always a small-business operator and exempt, whereas the professional managing agent it hires is frequently a covered APP entity, either by exceeding A$3 million turnover or through the related-body-corporate limb. The policy is a document for the management business. Read: strata manager vs owners corporation, who is actually covered?

Can I just use a free privacy policy template?

You can start from one, but a generic template rarely names a strata office's real data (the roll, tenants, arrears, disputes, CCTV) and often says "we never share your information", which is wrong for strata because state law compels you to disclose the roll on a proper request. Tailor it to the data you actually hold and the disclosures the law requires, or start from a document written for strata.

Should my policy say we never disclose the owners roll?

No. That would misstate your legal position. State strata law requires the roll and records to be made available to owners and other entitled persons on a proper request, so your policy should describe those statute-required disclosures honestly, while still confirming that a covered manager will not leak the same data to unauthorised third parties or misuse it.

Is a privacy policy the only document I need?

No. The policy is the standing public document. A strata office also needs collection notices (APP 5) for the points where details are taken, including scheme handovers, a CCTV and surveillance policy scoped to your state, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan.

Where Privaproof fits

Privaproof is building a dedicated, strata-specific privacy document set: a privacy policy, collection notices, a CCTV and surveillance policy with resident notice and signage guidance, a strata-roll disclosure and access procedure, a retention and destruction schedule, and a data-breach response plan. Written for owners-corporation and body-corporate management, scoped for New South Wales, Victoria and Queensland at launch with clear prompts to confirm your own state, and kept current as the law changes. Not a one-off free download, and not a generic website policy.

→ Join the founding list. Be first to know when the Strata Kit opens, and get the plain-English updates as the rules move. No cost, no obligation.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and structure; many smaller managers and owners corporations fall outside it, while state strata legislation and state surveillance-devices law apply separately and vary by jurisdiction. Privaproof's strata documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version and confirm your own state's requirements.