Skip to content

Privacy Policy: How do I draft the ‘storage and security’ clause?

Summarise with:
ChatGPT logo ChatGPT Perplexity logo Perplexity

On this page

A Privacy Policy states how your business will deal with personal information. It is important for businesses that collect personal information to have a detailed Privacy Policy. An experienced contract lawyer typically drafts this document. Your Privacy Policy explains to customers how your business will store their personal information, and your customer’s rights. A Privacy Policy can be used for any business that collects personal information, whether online or in person. It might be a good idea for you to contain a ‘storage and security’ clause in your Privacy Policy.

What should the ‘storage and security’ clause contain?

It is important that the ‘storage and security’ clause of your Privacy Policy explains to customers your policies in relation to how you store and secure customers’ information. It should also explain the risks associated with providing a website with personal information that could be unintentionally disclosed.

The ‘storage and security’ clause in your Privacy Policy should reflect your business’ commitment to ensuring that there are suitable procedures to safeguard and secure the information that has been collected from your customers.

You should clearly set out what procedures have been put in place to safeguard and secure the personal information. This could be any physical, electronic or managerial procedures which prevent personal information from misuse, interference, loss and unauthorised access, modification and disclosure.

However, to protect your business, your lawyer should set out that, if information is transmitted over the Internet, this transmission cannot be guaranteed to be secure and that the transmission and exchange of information is carried out at the visitor’s own risk.

Conclusion

If the Privacy Act applies to your business, you must have a Privacy Policy.

Failing to comply with the Privacy Act may result in fines of up to $1.7 million for companies, or $340,000 for entities that are not companies (including individuals) for serious or repeated breaches of the Privacy Act.

If you are unsure of whether or not your business requires a Privacy Policy, or a ‘storage and security’ clause, and if you would like assistance in drafting one, contact one of our contract lawyers today.

Register for our free webinars

You’ve Been Hacked! Legal Steps and Duties After a Data Breach

Online
Learn breach reporting requirements, act within 30 days, notify correctly, and establish a clear response plan. Register now.
Register Now

Buying a Business: The Roadmap From Offer to Settlement

Online
Learn the roadmap to buying a business, from due diligence and deal structure to risk management and settlement. Register today.
Register Now

Ask an Employment Expert: Anti-Discrimination in the Workplace in 2026

Online
Ask an employment law expert your workplace discrimination and AI questions in our free live webinar. Register today.
Register Now

ESG Failures Are Costing Boards: The Risks You Cannot Ignore

Online
Understand ESG obligations and reduce legal risks. Register for our free webinar.
Register Now
See more webinars >
Avatar photo

Priscilla Ng

Read all articles by Priscilla

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

LegalVision is an award-winning business law firm

  • Award

    2025 Future of Legal Services Innovation Finalist - Legal Innovation Awards

  • Award

    2025 Employer of Choice - Australasian Lawyer

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2022 Law Firm of the Year - Australasian Law Awards