ACXPA Glossary Term

Privacy Policy: What It Is & Why It Matters in CX

A privacy policy is a public statement explaining how an organisation collects, uses, stores, shares and protects people's personal information.

It's the document a customer can read to understand what happens to their data once they hand it over.

For years a privacy policy was treated as legal boilerplate. That's no longer safe.

Marketing, customer service and AI now run on customer data — and every one of them is a privacy risk.

A privacy policy is where a business shows whether it can be trusted with that data, which makes it a genuine customer experience issue, not just an IT or legal one.

ACXPA isn't a privacy regulator, and this isn't legal advice.

This guide explains, in plain English, what a generic privacy policy is, what it should cover, why it matters so much in CX today, and where to go for authoritative help.

What it is

A public, plain-language statement of how an organisation handles personal information — what it collects, why, how it's used and shared, and how it's kept safe.

Why it matters in CX

Trust is a CX currency. Most customers won't buy from a business they don't trust with their data — and marketing, service and AI all increase that risk.

What this guide covers

The definition, the CX trust case, the marketing/service/AI risk surface, what a policy covers, the rules in Australia and globally, and where to get help.

What is a Privacy Policy?

A privacy policy is a public-facing document that tells people how an organisation handles their personal information — that is, any information that identifies them or could reasonably be used to identify them.

It is how a business answers a simple customer question: "What are you going to do with my data?"

Almost any organisation that collects personal information should have one — a retailer taking orders, a contact centre recording calls, a SaaS product storing accounts, a charity managing donors.

If you collect names, emails, phone numbers, payment details, call recordings or behavioural data, a privacy policy is how you explain that collection openly.

A good privacy policy tells people, in plain language:

  • What personal information you collect
  • How and why you collect and use it
  • Who you share it with — including third parties and any overseas recipients
  • How it's stored, secured and how long it's kept
  • How people can access, correct or complain about their data

The key principle is honesty: a privacy policy is only worth anything if it describes what the business actually does. A polished policy that doesn't match real practice isn't protection — it's a liability.

Why a Privacy Policy Matters in CX

Privacy used to be filed under "legal" or "IT." Today it sits squarely inside customer experience, because how you handle data is part of the experience.

Customers increasingly judge brands on it — and they vote with their wallets.

95%

of consumers say they won't buy from a business if their data isn't properly protected.

75%

won't buy from a company they don't trust with their data, regardless of the offer.

1 in 2

privacy-active consumers have already switched companies over their data practices.

Source: Cisco Data Privacy Benchmark and Consumer Privacy research.

The CX position: privacy is a trust signal

A clear, honest privacy policy is one of the cheapest trust signals a business has. It tells customers you've thought about their data and you're willing to be held to it.

Treating privacy as a CX discipline — owned alongside marketing, service and product, not buried in legal — is increasingly what separates brands people stay with from brands they quietly leave.

The New Risk Surface: Marketing, Customer Service & AI

Most privacy risk doesn't come from a data breach in a server room.

It comes from the everyday ways businesses now collect and use customer data to compete — and three areas in particular have raced ahead of many privacy policies.

📣 Marketing & martech

Tracking pixels, cookies, list-building, lead capture, data enrichment and personalisation engines all collect and combine personal data — often more than customers realise, and sometimes without clear consent.

Your martech stack is frequently your biggest privacy exposure.

🎧 Customer service & contact centres

Call recordings, screen capture, chat transcripts, QA scoring, CRM notes and voice biometrics are all personal — sometimes sensitive — information.

Contact centres collect a lot of it, store it for a long time, and share it across systems and outsourcers.

🤖 AI & automation

Feeding customer data into AI tools, using transcripts to train or fine-tune models, letting AI agents access customer records, and making automated decisions about people all create new privacy risks — often before a privacy policy has caught up.

AI and automated decisions: the fast-moving frontier

AI raises specific questions a modern privacy policy needs to answer: Is customer data being sent to third-party AI services?

Are calls or chats used to train models? Are automated systems making decisions that affect people?

Regulators are moving on exactly this.

In Australia, from December 2026, organisations will have to disclose in their privacy policy where they use automated decision-making that uses personal information and could significantly affect a person's rights or interests (see the OAIC's APP 1 guidance).

A privacy policy that's silent on AI is increasingly a policy that's out of date.

💡 The CX takeaway

Before adopting a new martech, contact centre or AI tool, ask a simple question: "What personal data does this touch, and does our privacy policy honestly cover it?"

If the answer is no, the policy — or the practice — needs to change.

What a Privacy Policy Should Cover

There's no universal template, and the exact requirements depend on your jurisdiction. But a credible, modern privacy policy generally addresses these elements.

1

What you collect

The kinds of personal information you collect — including sensitive information, call recordings and any data gathered automatically through your website or apps.

2

Why and how you collect it

The purposes you collect it for, how you collect it, and the legal basis or consent you rely on where that applies.

3

How you use it

What you actually do with the data — service delivery, marketing, analytics, personalisation and any AI or automated processing.

4

Who you share it with

Third parties, service providers, outsourcers and any overseas recipients — a critical and often-missed disclosure.

5

Storage, security & retention

How the information is protected, how long it's kept, and how it's disposed of when no longer needed.

6

Rights, contact & complaints

How people can access or correct their data, opt out, make a complaint, and who to contact — plus how you handle automated decisions.

💡 Match the policy to reality

The single most important test isn't length or legal polish — it's accuracy.

Walk through what your marketing, service and AI systems genuinely do with customer data, and make sure the policy reflects it. A privacy policy is a promise; keep it one you actually keep.

Privacy Policy vs Privacy Collection Notice

These two are often confused, but they do different jobs — and many organisations need both.

Privacy policy

The big-picture document. It describes your overall approach to personal information across the whole organisation — what you collect, how you use and share it, and how people exercise their rights.

It usually lives permanently on your website.

Privacy collection notice

A short, specific notice given at the moment you collect data — on a form, before a call recording, at sign-up. It tells the person, right then, why you're collecting this particular information and what will happen to it.

A real-world example

ACXPA maintains both, and they're a useful illustration of the difference: see our Privacy Policy (the overall statement) alongside our Privacy Collection Notice (the point-of-collection notice).

Looking at a real pair is often clearer than any definition.

The Rules: Australia & Globally

Privacy is regulated almost everywhere, and the rules are tightening.

Wherever you operate, the safest assumption is that you have obligations — and if you handle data about people overseas, you may be caught by their laws too. This is a high-level overview, not legal advice.

🇦🇺 Australia

The Privacy Act 1988 and the 13 Australian Privacy Principles (APPs) set the rules, regulated by the OAIC. APP 1 specifically requires covered entities to have a clear, up-to-date privacy policy.

Major 2024 reforms added a new statutory right to sue for serious invasions of privacy, stronger enforcement and penalties, and — from December 2026 — new transparency rules for automated decision-making.

🌏 Global

The EU/UK GDPR is the global benchmark, with strict consent, transparency and data-rights rules and large fines. California's CCPA/CPRA leads a wave of US state laws.

Both can reach beyond their borders: if you collect data about EU, UK or Californian residents, their rules may apply to you regardless of where your business sits.

💡 Know which rules apply to you

Your obligations depend on where you operate, your size and the data you handle.

Some small businesses are currently exempt from parts of Australia's Privacy Act, but that exemption is under review — and good privacy practice is worth adopting regardless.

For your specific situation, use the official regulator guidance below and seek qualified legal advice.

Common Privacy Policy Mistakes

Most privacy failures aren't dramatic breaches — they're everyday gaps between what the policy says and what the business does.

❌ Copy-pasting a generic template

A borrowed policy that doesn't describe how your business actually handles data is worse than useless — it's a documented promise you're not keeping.

❌ Saying nothing about AI

If you feed customer data into AI tools, train models on transcripts, or automate decisions about people, a policy that's silent on all of it no longer reflects reality.

❌ Hiding consent or using dark patterns

Burying consent in fine print, pre-ticking boxes or making opt-out hard erodes the exact trust a privacy policy is meant to build — and regulators are watching for it.

❌ Setting and forgetting it

Adding new martech, channels or AI without updating the policy lets it drift out of date. Privacy policies need reviewing whenever your data practices change.

The bottom line: a privacy policy is judged not by how it reads, but by whether it's true.

Keep it accurate, keep it current, and make sure marketing, service and AI all live up to it. This is general information, not legal advice.

Where to Get Help & Official Resources

ACXPA isn't the authority on privacy law — the regulators are. If you're writing or reviewing a privacy policy, start with the official guidance for your jurisdiction, and get qualified advice for anything specific.

Official regulator guidance

A real example to learn from

A note on this guide

This page is a plain-English overview to help you understand privacy policies and find the right help. It is not legal advice and is not a substitute for official regulator guidance or qualified professional advice.

If you have obligations under the Privacy Act, GDPR or another regime, start with the relevant regulator.

Frequently Asked Questions About Privacy Policies

What is a privacy policy?

A privacy policy is a public document that explains how an organisation collects, uses, stores, shares and protects people's personal information.

It tells customers what happens to their data — what's collected, why, who it's shared with, how it's secured, and how they can access, correct or complain about it.

Does my business need a privacy policy?

If you collect personal information — names, emails, phone numbers, payment details, call recordings or behavioural data — you almost certainly should have one, and you may be legally required to.

In Australia, APP 1 requires covered entities to have a clear, up-to-date privacy policy. Even where a small-business exemption applies, having one is good practice and builds customer trust.

What's the difference between a privacy policy and a privacy collection notice?

A privacy policy is the overall, permanent statement of how your organisation handles personal information.

A privacy collection notice is a short, specific notice given at the moment you collect data — on a form, at sign-up or before recording a call — explaining why you're collecting that particular information.

Many organisations need both.

How does AI affect a privacy policy?

AI introduces new data practices a policy should address: sending customer data to third-party AI services, training or fine-tuning models on transcripts and recordings, AI agents accessing customer records, and automated decision-making.

In Australia, from December 2026, organisations will need to disclose in their privacy policy where they use automated decision-making that uses personal information and could significantly affect people.

Why does a privacy policy matter for customer experience?

Because trust is part of the experience. Research consistently shows most customers won't buy from a business they don't trust with their data, and many have already switched providers over privacy concerns.

A clear, honest privacy policy is a low-cost trust signal — and marketing, service and AI all increase the data risk it needs to cover.

What laws govern privacy policies in Australia?

The Privacy Act 1988 and the 13 Australian Privacy Principles, regulated by the Office of the Australian Information Commissioner (OAIC).

Major reforms in 2024 added a new statutory right to sue for serious invasions of privacy, stronger enforcement and penalties, and new transparency requirements for automated decision-making that take effect from December 2026.

Do overseas privacy laws like GDPR apply to my business?

They can. The EU/UK GDPR and California's CCPA/CPRA can apply to organisations outside their borders if they handle personal data about people in those regions.

If you market to, sell to or collect data from EU, UK or Californian residents, you should check whether those rules apply to you, regardless of where your business is based.

How often should a privacy policy be updated?

Whenever your data practices change — for example, adopting new martech, adding channels, introducing AI tools, or changing who you share data with — and otherwise reviewed periodically.

A privacy policy that's never revisited tends to drift out of step with what the business actually does.

Where to Next

For authoritative guidance, start with the regulators above. To put privacy into practice across your CX — choosing trustworthy martech, AI and service suppliers — these may help.

🏛️

Official Privacy Guidance

The OAIC is the authoritative source for the Privacy Act, the APPs and what your privacy policy needs to include.

🧩

Martech & AI Suppliers

Choosing tools that touch customer data? Browse technology and martech providers in the CX Directory and ask how they handle privacy.

📄

See a Real Example

ACXPA's own Privacy Policy and Collection Notice show how the two documents work together in practice.

🎧

Call Centre Hub

ACXPA's library of resources for running contact centre operations — including the data and recording practices privacy touches.

Become an ACXPA Member

ACXPA membership gives you practitioner-led resources for running customer operations responsibly — including how data, technology and AI fit into a great customer experience.

, for authoritative guidance start with the regulators above. To put privacy into practice across your CX — choosing trustworthy martech, AI and service suppliers — these may help.

🏛️

Official Privacy Guidance

The OAIC is the authoritative source for the Privacy Act, the APPs and what your privacy policy needs to include.

🧩

Martech & AI Suppliers

Choosing tools that touch customer data? Browse technology and martech providers in the CX Directory and ask how they handle privacy.

📄

See a Real Example

ACXPA's own Privacy Policy and Collection Notice show how the two documents work together in practice.

🎧

Call Centre Hub

ACXPA's library of resources for running contact centre operations — including the data and recording practices privacy touches.

Upgrade your ACXPA Membership

, upgrading gives you the full Members Call Centre Hub and practitioner-led resources for running customer operations responsibly in the age of data and AI.

, the official regulators above are the place to start for guidance. Here are the member and supplier resources for putting privacy into practice across your CX.

🏛️

Official Privacy Guidance

The OAIC — the authoritative source for the Privacy Act, the APPs and privacy policy requirements.

🎧

Members Call Centre Hub

Resources for managing operations, recording, data and technology — useful context for your privacy obligations.

🧩

Martech & AI Suppliers

Browse technology, martech and AI providers in the CX Directory — and ask how they handle customer data.

📄

See a Real Example

ACXPA's own Privacy Policy and Collection Notice — a practical model of how the two documents pair up.

Summary: Privacy Policy

A privacy policy is a public statement of how an organisation collects, uses, stores, shares and protects people's personal information.

Almost any business that collects customer data should have one, and many are legally required to. Its value lies entirely in being accurate: a policy that doesn't match real practice is a liability, not protection.

In CX terms, privacy is a trust signal.

Most customers won't buy from — or stay with — a business they don't trust with their data, and the three areas driving the most data risk today are marketing and martech, customer service and contact centres, and AI and automation.

A modern privacy policy has to honestly cover all three, including automated decisions, which Australian rules will require organisations to disclose from December 2026.

ACXPA's role here is to explain and to point you in the right direction — not to give legal advice.

For authoritative guidance, start with the OAIC in Australia or the relevant regulator for your region, look at a real example like ACXPA's own Privacy Policy and Collection Notice, and seek qualified advice for your specific situation.

ACXPA PLATINUM SPONSORS

ACXPA Platinum SPONSORS
ACXPA SILVER SPONSORS
ACXPA Platinum SPONSORS
ACXPA BRONZE SPONSORS
ACXPA Platinum SPONSORS
ACXPA Platinum SPONSORS
Copyright © 2026 | Australian Customer Experience Professionals Association | Website Terms of Use | Privacy Policy

Log in with your email address

or Become an ACXPA Member

Forgot your details?

Create Account