- Who must comply with the APPs
- APP 1: open and transparent management of personal information
- APP 2: anonymity and pseudonymity
- APP 3: collection of solicited personal information
- APP 4: dealing with unsolicited personal information
- APP 5: notification of the collection of personal information
- APP 6: use or disclosure of personal information
- APP 7: direct marketing
- APP 8: cross-border disclosure of personal information
- APP 9: government related identifiers
- APP 10: quality of personal information
- APP 11: security of personal information
- APP 12: access to personal information
- APP 13: correction of personal information
- What happens if you don't comply
- A practical compliance checklist
- When you need a lawyer
- The $3 million threshold is narrower than it looks
Every business in Australia that holds customer details, staff records or marketing lists is handling personal information (information that can identify an individual, such as names, emails, phone numbers and addresses). The Privacy Act 1988 (Cth) sets out how that information must be handled through the Australian Privacy Principles (APPs), the 13 obligations contained in Schedule 1 of the Act.
The APPs apply to more businesses than most owners assume, and the penalties for getting them wrong now run into the tens of millions of dollars. This guide sets out who must comply, what each of the 13 principles requires in practice, what happens if you breach them, and the steps to take to get compliant.
Who must comply with the APPs
The APPs bind APP entities: Australian Government agencies and private sector organisations (companies, partnerships, trusts, unincorporated associations and individuals carrying on business). For most businesses, the question is whether the small business exemption in s 6D of the Act applies.
Under s 6D, a business is a small business (and generally exempt from the APPs) if its annual turnover for the previous financial year was $3,000,000 or less. A new business is tested against its current-year turnover instead.
That threshold is narrower than it sounds. Section 6D(4) removes the exemption for a business that:
- provides a health service and holds health information (including many allied health, wellness and fitness businesses)
- discloses personal information about another individual to anyone else for a benefit, service or advantage (in short, trading in personal information)
- provides a benefit, service or advantage to collect personal information from anyone else
- is a contracted service provider for a Commonwealth contract
- is a credit reporting body
A body corporate that is related to a larger entity is also not a small business operator, so a group structure can defeat the exemption even where one entity sits under the $3 million line.
The exemption does not cover everything either. Under s 7B(3), an act is exempt only where it is directly related to a current or former employment relationship and to an employee record, so customer, supplier and prospect data held by a small business is outside that carve-out. Even where the Act does not apply, banks, payment platforms, app stores and customers increasingly require APP-standard practices as a condition of doing business, so aligning with the APPs is usually sensible regardless of turnover.
APP 1: open and transparent management of personal information
You must manage personal information openly and transparently, with practices, procedures and systems in place to comply with the APPs. In practical terms this means publishing a clear, up-to-date APP privacy policy (APP 1.3 and 1.4 set out what it must contain) and making sure your team actually follows it. The privacy policy is the document customers, partners and the regulator will look for first.
APP 2: anonymity and pseudonymity
Where it is lawful and practicable, give individuals the option of dealing with you anonymously or under a pseudonym. A website enquiry form that works without a name is a common example. You can still require identification where it is needed to provide the service, such as opening an account or running a credit check.
APP 3: collection of solicited personal information
Collect only personal information that is reasonably necessary for your functions or activities, and collect it only by lawful and fair means. Sensitive information such as health details generally requires consent. Where it is reasonable and practicable, collect directly from the individual rather than from third parties or data brokers.
APP 4: dealing with unsolicited personal information
If personal information arrives without you having asked for it, work out quickly whether you could have collected it under APP 3. If you could not have, and it is lawful and reasonable to do so, destroy or de-identify it.
APP 5: notification of the collection of personal information
At or before collection (or as soon as practicable afterwards), notify the individual of the essentials: what you are collecting and why, whether you are likely to disclose it and to whom, whether it may be sent overseas, how they can access and correct it, how they can complain, and your contact details. A short collection notice on every form, checkout and booking page is the standard way to meet this principle.
APP 6: use or disclosure of personal information
Use and disclose personal information only for the purpose you collected it, or for a secondary purpose that fits one of the exceptions, such as consent or a related purpose the individual would reasonably expect. If you hand information to a third-party service provider, such as a customer relationship platform or payment processor, a data processing agreement makes the permitted uses and safeguards explicit.
APP 7: direct marketing
The APPs prohibit using or disclosing personal information for direct marketing unless an exception applies. You can market to someone you collected information from if they would reasonably expect it and you provide a simple, easy opt-out; otherwise you need consent. Sensitive information can only be used for direct marketing with consent. You must honour opt-out requests promptly and draw attention to the right to opt out in every message. Direct marketing email is also regulated separately under Australia's anti-spam laws, so marketing programs need to be checked against both regimes.
APP 8: cross-border disclosure of personal information
Before disclosing personal information to a recipient outside Australia, including through an offshore cloud provider, help desk or customer platform, you must take reasonable steps to ensure the recipient will not breach the APPs. Contractual protections and vendor due diligence are the usual measures. If the overseas recipient mishandles the information, s 16C of the Act treats the disclosure as your own act, so responsibility does not end at the border.
APP 9: government related identifiers
You must not adopt a government related identifier, such as a tax file number, Medicare number or driver licence number, as your own identifier for individuals, and you can only use or disclose such identifiers in limited circumstances. Building a customer database keyed to a TFN, for example, would breach this principle.
APP 10: quality of personal information
Take reasonable steps to make sure the personal information you collect, use and disclose is accurate, up-to-date, complete and relevant. Practical measures include letting customers update their own details, confirming details before significant actions and cleaning mailing lists before campaigns.
APP 11: security of personal information
Protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, and destroy or de-identify information once it is no longer needed. Access controls, encryption, staff training and a written security policy are the basics. The security obligation connects to the Notifiable Data Breaches scheme in Part IIIC of the Act: if a data breach is likely to result in serious harm to any individual, you must notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals.
APP 12: access to personal information
On request, give individuals access to the personal information you hold about them within a reasonable period, unless an exception applies (for example, where access would pose a serious threat to health or safety, or would unreasonably impact another person). Make the request channel obvious and keep a record of requests and responses.
APP 13: correction of personal information
Correct personal information on request when it is inaccurate, out-of-date, incomplete, irrelevant or misleading. If you have disclosed incorrect information to others, take reasonable steps to notify those recipients of the correction. The same reasonable-period requirement applies as for access requests.
What happens if you don't comply
The OAIC investigates complaints and can also act on its own initiative. It can make determinations (including awards of compensation), accept enforceable undertakings under s 80V, issue infringement notices for specific breaches under s 13K, and seek civil penalties in court.
The penalty exposure is the sharp end. For a serious interference with privacy under s 13G, a body corporate faces a maximum penalty equal to the greatest of $50,000,000, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover during the breach period. Individuals face up to $2,500,000. Other interferences with privacy carry penalties of up to 2,000 penalty units under s 13H. Failing to notify an eligible data breach under the Notifiable Data Breaches scheme is itself a contravention that can attract penalties.
Beyond fines, a breach can mean a published enforceable undertaking, an OAIC investigation that consumes management time, and reputational damage that customers and partners remember.
A practical compliance checklist
A defensible baseline is achievable by working through these steps in order:
- Publish your privacy policy: A customer-facing statement of how you collect, use, disclose, store and secure personal information, kept current with what you actually do.
- Map your data: List what you collect, from whom, where it is stored and who it is shared with. Everything else flows from this.
- Cut collection: Remove form fields you do not genuinely need. Less data means less risk and an easier APP 3 assessment.
- Standardise collection notices: Embed an APP 5 notice in every web form, paper form, email sign-up and booking flow, in consistent language.
- Review offshore vendors: Check where your cloud tools store data and put contractual protections in place before relying on them under APP 8.
- Fix direct marketing: Confirm consent or reasonable expectation for every list, put a working opt-out in every message and honour requests promptly.
- Set up access and correction: Give customers an obvious channel to request access and correction under APPs 12 and 13, and log the outcomes.
- Plan for breaches: Know your notifiable data breach trigger, prepare a response plan and test it before an incident, not after.
When you need a lawyer
Most APP compliance is straightforward process work, but a privacy lawyer is worth engaging where the stakes or complexity are higher: working out whether the small business exemption actually applies to your structure (the turnover tests, related entities and s 6D(4) exceptions are easy to misread), drafting a privacy policy and collection notices that match how you actually handle data, reviewing cross-border and vendor arrangements, and responding to an OAIC complaint, investigation or data breach. A practitioner will also test your processes against the APPs before a regulator does.
The $3 million threshold is narrower than it looks
The small business exemption is the provision that catches most owners by surprise. If you provide a health service, sell or share personal information for a benefit, work under a Commonwealth contract or sit within a larger group, the $3 million test does not protect you. And even where the Act does not apply, banks, platforms and customers increasingly demand APP-standard practices as a condition of doing business. The first step this week is to decide which side of the line you sit on, then publish a privacy policy that reflects what you actually collect and why.