Privacy Act Compliance for Your Enquiry Form: What Law, Accounting & Clinic Websites Are Legally Required to Tell Visitors
Every law firm, accounting practice and clinic website has one of these forms — name, email, a text box, "Submit" — and almost none of them say a single word about what happens to that information afterwards. Visitors notice the silence even when they can't name what's missing, and it's one of the quiet reasons a form that "should" convert doesn't. Here's how to fix it properly, without hiring a privacy lawyer for a five-minute job. 💖
What most law, accounting & clinic websites get wrong
- Saying nothing at all — the form just asks for details and submits, with no mention of what happens next.
- Burying it in a 3,000-word privacy policy nobody reads, with no signpost anywhere near the form itself.
- Not naming the third parties — the booking platform, practice management system or email tool the data actually flows into.
- Using a generic "Contact Us" template never written for a regulated profession collecting sensitive details.
- No visible way to ask "what do you have on me" or request a correction — or nobody who'd know how to answer if someone did.
The copy-paste collection notice formula
This isn't your full privacy policy — it's the short, honest version that sits at or near the form, doing the actual job the Privacy Act expects at the point of collection:
Five moves: what, why, who else sees it, marketing yes/no, and how to follow up. Sitting this directly above or below the submit button does more for trust than any testimonial slider.
Three worked examples
Same formula, adjusted for what each business actually collects and where it actually goes. 📈
Where this notice actually needs to live
Point of collection matters — a notice that only exists on a separate policy page three clicks away is doing a much weaker job than one visible right where someone is about to type in their details. In practice that means: a short version (two or three sentences, the formula above) sitting near the form itself, linking through to a fuller Privacy Policy page that covers your practice properly. List your real third parties by name or category — booking software, CRM, cloud file storage, email platform — rather than a vague "service providers." If any of those tools store data overseas, your policy should say so in general terms; that's a detail worth checking with each vendor rather than guessing.
Mistakes to avoid
- Treating the notice as set-and-forget — update it whenever you change booking platforms, CRMs or add a new tool.
- Assuming the small business exemption always applies — health providers and businesses that trade in personal information generally don't get it.
- Using an overseas-hosted tool without checking or disclosing where the data actually sits.
- No easy opt-out for follow-up marketing after someone's submitted a genuine enquiry.
- Writing it once and copying it to every page without checking it still matches what that specific form collects.
Frequently asked questions
Does the Privacy Act actually apply to my small firm or clinic?
Many small businesses under the $3 million turnover threshold are technically exempt — but there are well-known exceptions, and health service providers are generally not exempt regardless of size. If you're unsure where you sit, that's a five-minute question worth putting to a solicitor or the OAIC directly rather than guessing.
Does this short notice replace my full privacy policy?
No — and this is the honest trade-off. The short notice does one job (telling someone what's happening right as they hand over their details); your full Privacy Policy page does a different, more complete job. You need both, and the short version should link through to the long one.
What counts as "sharing" with a third party?
More than you'd think — your CRM, your booking platform, your cloud storage and your email marketing tool all technically receive and store the data your form collects, even if you're not deliberately handing it to a stranger. Naming those categories (or the actual products) in your notice is more honest than a vague "we may share your information."
How often should this be reviewed?
Any time your tools change — a new booking platform, a new CRM, a new email system — plus a general check-in every six to twelve months. A notice that still describes software you stopped using two years ago isn't doing its job. 🌴
Keep reading 🤍
I help Gold Coast and Brisbane businesses grow with branding, websites and marketing that actually works.
Work with me ✦