A NSW Government website

Command Palette

Search for a command to run...

Email privacy guidance

Email communications from NSW Government agencies must embed privacy best practice in every campaign and service message. This ensures messages are lawful, respectful and trusted by the public.

Privacy obligations

When managing personal information in email communications, NSW Government agencies must comply with:

  • Privacy and Personal Information Protection Act 1998 (NSW) – governs the collection, use and disclosure of personal information.
  • Privacy Act 1988 (Cth) – applies when Commonwealth privacy laws are relevant.
  • State Records Act 1998 (NSW) – requires email records to be managed according to your agency's information governance frameworks.

Apply privacy best practice

  • Collect only the minimum personal information required.
  • Clearly explain how personal information will be used.
  • Include a privacy notice in every email or link to your agency's privacy policy.
  • Provide an opt-out option in all marketing or promotional emails.
  • Consent first – Only add people to mailing lists if they have opted in or where there is a lawful basis.
  • Agency identification – Clearly identify your agency in the ‘From' name, subject line and email footer.
  • Unsubscribe functionality – Every promotional email must include a working unsubscribe link that is easy to find and use. Action requests promptly.

Collection notices

Where email addresses or other personal information are collected (for example, through sign-ups or service forms), agencies must explain:

  • what information is collected
  • why it is collected
  • who it may be shared with, including third-party providers
  • how to access the agency's privacy policy.

Third-party services

When using an email service provider or other vendor:

  • Confirm where data is stored and processed (preferably within Australia).
  • Ensure contracts cover offshore disclosure, retention, deletion and breach management.

Avoid covert tracking

How the NSW email framework supports privacy

  • No built-in tracking – Templates are static HTML with no external calls. Analytics begin only after integration with your chosen provider.
  • Transparent code – Any added tracking must be explicit, allowing easy reviews and privacy checks.
  • Privacy-first by default – If you don't need behavioural data, use the default build and state: “No tracking technologies are included” in your privacy notice.

HTML build rules for privacy

  • Don't include personal data in code (such as names or email addresses in subject lines, filenames or URLs).
  • If unique links are needed, use short-lived tokens. Never expose raw personal information.
  • Host assets (like logos, images or fonts) on NSW Government infrastructure.
  • Link to authoritative NSW Government web pages instead of attaching documents that may contain personal data or metadata.

End-to-end handling

  • Retention and disposal – Keep personal information only as long as required under records law and agency policy.
  • Respect unsubscribe – Suppress unsubscribed addresses and don't re-add them.
  • Breach readiness – Prepare for misdirected campaigns or accidental disclosures. Notify the OAIC if serious harm is likely.

Privacy checklist

Before building

  • Confirm the purpose and only collect essential data.
  • Prepare a collection notice and check the privacy policy link.

During build

  • Avoid sensitive information in subject lines or preview text.
  • Don't include personal identifiers in URLs or filenames.
  • Don't embed hidden tracking scripts or pixels.
  • Insert an unsubscribe link and agency identification in the footer.

Before publishing

  • Test unsubscribe functionality.
  • Check that the privacy policy link works.
  • Confirm that third-party vendors meet privacy standards.

After publishing

  • Promptly action unsubscribe requests.
  • Monitor responses without asking for more personal information by email.
  • Apply retention and disposal rules to email data.

By aligning privacy practices with the NSW Email Toolkit, agencies can send emails that are clear, compliant and trusted by the people of NSW.

What this site collects

The guidance above is for the emails your agency sends. This section covers what the NSW Email Toolkit itself records, so the same standard is applied to us.

  • Subscription activity – We log each subscribe attempt, confirmation link visit and email send outcome so we can diagnose signups that fail. Each record also keeps the page the request came from and your browser user agent. Email addresses, confirmation tokens and IP addresses are hashed before they are stored, never recorded in readable form, and the address cannot be recovered from what is kept. These records are deleted daily once they are more than 90 days old.
  • Sign-in history – For accounts on this site we record the time, browser user agent and IP address of each sign-in, used for access monitoring and shown only to administrators.
  • Subscriber list – Your name and email address, kept until you unsubscribe. Unsubscribing moves your record to a suppression list so you are not re-added – see Subscribe.

Sources