What your privacy policy might reveal about your massage practice
Introducing AMT’s Sole Trader Privacy Policy template
Did you know that, as a massage therapist collecting personal and health information, you’re required by law to have a clear, up-to-date privacy policy?
Under the Privacy Act 1988 (Cth), any business covered by the Australian Privacy Principles (APPs) needs a privacy policy that meets the requirements of APP 1.4. According to the Office of the Australian Information Commissioner’s (OAIC) guide to developing an APP privacy policy, that policy has to cover specific ground: what personal information you collect, how you collect it, how you store and secure it, why you use and disclose it, how people can access or correct their information, how they can complain, and whether any of their information goes overseas.
The OAIC is also clear that a good privacy policy shouldn’t just recycle the wording of the Privacy Act. Their guidance advises entities to make the privacy policy specific to their own business rather than simply repeating the wording of the APPs, and to write it in plain language a reader can understand rather than treating it as a dense legal document.
And that’s the philosophy behind the template that AMT has created to help members meet their obligations under the Privacy Act to manage personal information in an open and transparent way. It is written in first person, plain English, and structured around the real activities of a massage therapy practice rather than abstract legal categories.
What’s in AMT’s privacy policy template
We have formulated a template that is based on the OAIC’s guidance and checklist. The template walks through:
- Who the policy applies to (clients, prospective clients, and website visitors)
- What information is collected (everyday contact and billing details, and sensitive health information that is central to safe treatment)
- How information is collected (through bookings, intake forms, and consultations, and indirectly through referring practitioners or booking platforms)
- How information is stored/security of personal information (cloud systems or paper files, password protection, multi-factor authentication, and retention periods aligned with health record-keeping requirements)
- Use and disclosure of information (treatment planning, invoicing, and the limited third parties information might be shared with)
- Overseas disclosure (a section for naming any software or services that store data outside Australia)
- Access, correction, and complaints (how clients can see or fix their information, and what happens if something goes wrong).
AI scribes
The AMT template also directly addresses AI transcription tools used during consultations. If you use an AI scribe to record or summarise sessions, that’s a form of sensitive information collection and overseas disclosure that needs to be transparently disclosed, along with any other third-party software. The template includes prompts to name the provider, explain how long recordings are kept, and note where the data is stored and processed.
Health information requires stronger security
Because massage therapists collect health information, a category of sensitive information under the Australian Privacy Principles, the OAIC’s guidance on reasonable security steps expects more than a business just collecting basic details like names and emails. The AMT template reflects this by including multi-factor authentication and access limitation as baseline security measures, not optional extras.
How to use the AMT template
The template is a starting point, not a finished document. Every bracketed placeholder needs to be filled in with what actually happens in your practice. The OAIC’s guidance is worth reading alongside the template: it recommends testing your finished policy on someone outside your business to make sure it reads clearly. The OAIC also recommends reviewing your privacy policy regularly so it keeps matching your real practices as they change (a new booking platform, a new AI tool, an updated retention period).
A privacy policy is also not just a compliance box to tick. If it is done well, it’s one of the ways you build trust with clients who are handing over sensitive health information: not a shield against legal risk but a document that helps people feel confident in how you are looking after their information.
You’ll find the privacy policy template in the “Resources” section of your AMT membership portal. It is also available for purchase by non-members. Please contact AMT Head Office for more information.
Discover more from AMT's blog
Subscribe to get the latest posts sent to your email.

