A Queensland law firm’s website almost certainly collects personal information through a contact form, an intake form, or a chatbot. That collection point is exactly what Australia’s privacy regulator has spent 2026 paying closer attention to — and a second, more specific obligation arrives in December that firms using any form of automated enquiry handling need to plan for now, not in November.
The sweep that started the year
In January 2026, the Office of the Australian Information Commissioner ran its first-ever compliance sweep, reviewing the privacy policies of around 60 businesses across six sectors that collect personal information in person — real estate agents, pharmacies, licensed venues, car rental and dealership businesses, and pawnbrokers among them. Law firms weren’t a named sector. The mechanism the OAIC used to assess compliance is the relevant part for every business with a website, not just the ones reviewed.
The sweep checked privacy policies against Australian Privacy Principle 1.4, which sets out what a privacy policy must contain at minimum: the kinds of personal information collected, how it’s used and disclosed, how someone can access or correct their own information, how a complaint is handled, and whether information is disclosed overseas. Non-compliant policies can attract infringement notices and penalties of up to $66,000 — a consequence of 2024 amendments to the Privacy Act that expanded the OAIC’s enforcement powers specifically for this kind of foundational failure.
The regulator has been explicit that this sweep signals a broader shift from guidance to enforcement. A privacy policy that hasn’t been reviewed since the site was built carries real exposure right now.
The December deadline that matters more for legal practices
From 10 December 2026, new requirements under APP 1.7–1.9 take effect. Any entity using automated decision-making that involves personal information must disclose that specifically in its privacy policy — what kind of decision is being made, and what role automation plays in it.
This is the part that connects directly to how law firms are increasingly handling enquiries. A chatbot that triages a new enquiry, an automated intake form that routes a matter by practice area, or any tool that uses personal information to make a decision about how an enquiry is handled — all of it falls inside this disclosure requirement once December arrives. A privacy policy written before these tools existed has no reason to cover them.
This isn’t a reason to avoid AI-assisted intake tools. It’s a reason to make sure the privacy policy describes what the tool actually does, in plain terms, before the deadline rather than after a complaint.
Why this sits slightly outside the general advice
General commentary on this sweep — and there’s been a reasonable amount of it since January — is written for businesses broadly. Two things make a law firm’s situation more specific.
First, the small-business exemption that some firms might assume protects them doesn’t apply cleanly. Entities that collect health information don’t get the general turnover-based exemption regardless of size, and health information is a routine part of personal injury and family law matters. A firm well under the usual turnover threshold can still be a full APP entity because of what it collects, not how big it is.
Second, a privacy policy isn’t just a compliance document for a law firm — it sits next to QLS advertising obligations as part of the same broader expectation: that what a firm represents to the public about how it operates is accurate and current. A stale privacy policy is the same category of problem as a stale “About” page making claims that no longer hold.
What this looks like in practice
A privacy policy that’s actually current for 2026 covers:
- What’s collected through every form on the site, including any chatbot or intake tool
- Whether any tool makes an automated decision using that information, and what that decision is
- How a person can ask what’s held about them, or have it corrected
- How a complaint is handled, and the timeframe for response
This is also the same standard we hold ourselves to. How AI tools are used in producing content on this site — and the verification process every published claim goes through — is set out in our AI Use Policy.
A privacy policy that accurately reflects what a site actually does rarely happens by accident — it gets built deliberately, alongside the rest of the site. If your firm’s website hasn’t had this kind of review, request a confidential discussion — or read how legal SEO works for Queensland law firms.
Frequently asked
Does a small Queensland law firm need to worry about this if it’s under the $3 million turnover threshold?
The general small-business exemption doesn’t apply to entities that collect health information, regardless of turnover. Personal injury and family law practices routinely collect health information as part of a matter, which means many small firms are full APP entities even though their turnover sits well under the usual threshold.
Does a contact form on a law firm’s website count as the kind of personal information collection this applies to?
Yes. Any form collecting a name, contact details, or matter information is collecting personal information under the Privacy Act, and the firm’s privacy policy needs to accurately describe that collection — what’s gathered, why, and how it’s used.
What happens if a firm’s privacy policy doesn’t mention an AI chatbot or automated intake tool it’s using?
From 10 December 2026, that’s a compliance gap. The new APP 1.7–1.9 requirements specifically require disclosure of automated decision-making involving personal information. A privacy policy that predates the tool won’t cover it, and needs to be updated before the deadline.
Is updating a privacy policy something a law firm needs a privacy lawyer for, or can it be handled as part of a website rebuild?
Both have a role. The specific legal wording and risk assessment is appropriately a job for a privacy lawyer, particularly given the firm’s own professional obligations. The practical side — making sure every form, tool, and data-collection point on the site is actually accounted for in that policy — is the kind of work that belongs inside a proper law firm website design process, and it’s the kind of gap that gets missed when a site has grown informally over several years without anyone auditing what it actually collects.
References
1. Office of the Australian Information Commissioner, Privacy compliance sweep to put privacy policies under the spotlight, December 2025.
2. MinterEllison, OAIC Targets Privacy Policies in High Risk Sectors, February 2026.
3. Russell Kennedy, OAIC’s 2026 Privacy Policy Sweep: Is Your Organisation Ready?, January 2026.
Jane Cluff