1. Who must comply with the APPs
  2. The employee records exemption is narrower than it sounds
  3. Duty 1: maintain a compliant privacy policy (APP 1)
  4. Duty 2: collect only what you need, and handle unsolicited applications (APPs 3 and 4)
  5. Duty 3: use and disclose information only for the right purposes (APP 6)
  6. Duty 4: check before sending information overseas (APP 8)
  7. Duty 5: keep the information secure (APP 11)
  8. What happens if you get it wrong
  9. A practical compliance checklist
  10. When a lawyer can help
  11. The gap that costs employers most

If your business is covered by the Privacy Act 1988 (Cth) (the Act), its Australian Privacy Principles (APPs) govern how you handle the personal information of everyone you deal with. That includes people who do not work for you: job applicants, independent contractors, volunteers, referees and the employees of your suppliers. Many employers assume their privacy duties stop at their own staff. They do not.

The Act's "employee records" exemption only covers current and former employees. Everyone else you collect information about is protected by the APPs to the same standard as your customers, and a breach involving their information carries the same penalties. This article explains who must comply, where the exemption trap sits, the five duties that matter most when you handle non-employee information, and what happens if you get it wrong.

Who must comply with the APPs

The APPs bind APP entities. Those are government agencies and private sector organisations, and an organisation can be an individual, a body corporate, a partnership, an unincorporated association or a trust.

Most small businesses sit outside the Act. Under section 6D of the Act, a business is a small business if its annual turnover for the previous financial year was $3 million or less. For a business that is new, the test uses the current year instead. Annual turnover is broadly defined and includes the proceeds of sales, commission income, rent, leasing and hiring income, interest, royalties, dividends and other operating income, so a business can cross the threshold without realising it.

However, some businesses are caught regardless of turnover. Section 6D(4) provides that the following are not small business operators:

  • Health services: a business that provides a health service to someone and holds their health information.
  • Trading in personal information: a business that discloses personal information for a benefit, service or advantage, or provides a benefit to collect personal information about someone else.
  • Commonwealth contracts: a contracted service provider under a Commonwealth contract.
  • Credit reporting: a credit reporting body.
  • Related companies: a body corporate related to a company that is not a small business.

Separately, a small business operator that is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) is treated as an organisation for its AML/CTF activities. A small business can also choose to opt in to the Act voluntarily, which some businesses do to reassure customers and business partners.

The employee records exemption is narrower than it sounds

The main reason employers think they owe nothing to non-employees is the employee records exemption in section 7B(3) of the Act. It exempts an employer's acts and practices that are directly related to a current or former employment relationship and to an employee record held by the employer. In practice, the exemption covers things like payroll, leave, performance and disciplinary records for people on the books.

The Office of the Australian Information Commissioner (OAIC) makes the limits clear:

  • Unsuccessful applicants are covered: The exemption does not cover prospective employees. From the moment someone applies until the moment they are hired, their information is fully protected by the APPs. Once an employment relationship forms, the pre-employment records become exempt, but an unsuccessful applicant's data never does.
  • Contractors are covered: The exemption does not cover contractors and subcontractors who handle the personal information of another organisation's employees. If your recruitment agency or HR provider holds applicant or employee data, it must comply with the APPs itself.
  • Volunteers are covered: An organisation and a volunteer are not in an employment relationship, so the exemption does not apply.

The practical result is that for every non-employee, you owe the same duties you owe customers.

Duty 1: maintain a compliant privacy policy (APP 1)

APP 1 requires your organisation to have a clearly expressed and up-to-date privacy policy. The policy must cover the kinds of personal information you collect and hold, how you collect and hold it, the purposes for which you collect, hold, use and disclose it, how an individual can access and correct their information, and how they can complain about a breach and how you will handle the complaint.

APP 1 also requires you to take reasonable steps to implement practices, procedures and systems that ensure compliance with the APPs and any registered APP code that binds you, and that let you deal with inquiries and complaints.

Make sure the policy addresses applicants, contractors and volunteers, not just employees. A policy that only speaks about "employees" is incomplete, because it describes only the slice of your data handling that the APPs do not regulate.

Duty 2: collect only what you need, and handle unsolicited applications (APPs 3 and 4)

APP 3 says an organisation must not collect personal information unless it is reasonably necessary for its functions or activities. For a job application, collect what you need to assess the application and no more. Sensitive information such as health information from a pre-employment medical requires the applicant's consent, and the collection must still be reasonably necessary.

APP 4 deals with information you did not solicit. If a speculative application arrives, or a CV is emailed to you without being invited, you must determine within a reasonable period whether you could have collected the information under APP 3. If you could not have collected it, you must destroy it or de-identify it as soon as practicable, where it is lawful and reasonable to do so. If you keep it, every other APP applies as if you had collected it.

A candidate may apply for a role you never advertised, or a third party may forward a CV without the person's knowledge. If that information is not reasonably necessary for your business functions, delete it or de-identify it rather than filing it "just in case". If you want to hold it for future roles, you need the person's consent and a collection notice that says so.

Duty 3: use and disclose information only for the right purposes (APP 6)

APP 6 allows you to use or disclose personal information for the purpose it was collected, the primary purpose. A secondary purpose is only allowed if the individual consents, or if they would reasonably expect the use or disclosure and it is related to the primary purpose (and directly related, for sensitive information).

Reference checks are a good example. Disclosing an applicant's details to a referee to verify their history is part of assessing the application. Telling the referee more than necessary, or later using the applicant's details to send them marketing, is not.

Building a talent pool is another common slip. Holding a rejected applicant's CV for future roles is a secondary purpose, so it needs consent. The same logic applies when you share information between related companies or with a recruitment agency: each transfer is a disclosure under the APPs and needs a purpose that fits.

Duty 4: check before sending information overseas (APP 8)

If you disclose personal information to someone outside Australia, APP 8 requires you to take such steps as are reasonable in the circumstances to ensure the overseas recipient does not breach the APPs. That matters if you use an overseas recruitment platform, an offshore HR provider, or a referee who is based overseas.

The Act makes you accountable for what the recipient does. Under section 16C, the acts of the overseas recipient are taken to be your own, so you can be liable for a breach committed by a contractor on the other side of the world.

The main exceptions are where you reasonably believe the recipient is subject to a law or binding scheme that protects the information to a standard at least substantially similar to the APPs, where the individual has given informed consent, or where the disclosure is required or authorised by law. In practice, review the contracts with your overseas providers, check their jurisdiction and security, and disclose in your privacy policy the countries you are likely to send information to.

Duty 5: keep the information secure (APP 11)

APP 11 requires you to take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. That includes technical and organisational measures: access controls, secure storage for CVs and applications, and training for whoever handles recruitment data. When you no longer need the information, you must take reasonable steps to destroy it or de-identify it.

Security breaches involving non-employee data are treated like any other breach. If a breach of applicant or contractor information is likely to result in serious harm, the Notifiable Data Breaches scheme requires you to notify the affected individuals and the OAIC. An unencrypted laptop with a spreadsheet of applicant CVs is a classic eligible data breach.

What happens if you get it wrong

The OAIC can investigate complaints about APP breaches, make determinations, accept enforceable undertakings and, where the law allows, seek civil penalties in the courts. A determination can require you to pay compensation to the affected individual.

For serious or repeated interferences with privacy, the penalties are substantial. Under section 13G of the Act, the maximum civil penalty is $2.5 million for an individual and, for a body corporate, the greater of $50 million, three times the benefit obtained from the conduct, or 30% of adjusted turnover during the breach period.

Individuals also have more direct routes. Since 10 June 2025 the Act has included a statutory tort for serious invasions of privacy, which means an applicant or contractor can sue your business directly in court, subject to exemptions that a lawyer would need to check against the particular facts.

Finally, keep an eye on reform. The removal of the small business exemption has been flagged as part of successive privacy law reform packages. The exemption remains in force at the time of writing, but an exempt business should treat it as a reprieve rather than a permanent fixture, because that position has been repeatedly identified for change.

A practical compliance checklist

Work through the following steps to check where you stand:

  • Confirm whether the APPs apply to you: turnover above $3 million, or one of the exceptions in section 6D(4).
  • Review your privacy policy so it covers applicants, contractors and volunteers, and make it freely available on your website.
  • Collect only what is reasonably necessary for the role or engagement, and get consent before collecting sensitive information.
  • Put a process in place for unsolicited applications: assess them promptly, then destroy or de-identify anything you could not have collected.
  • Use applicant information only for recruitment; get consent before keeping CVs for future roles.
  • Audit every overseas recipient of personal information and update your contracts with them.
  • Secure applicant and contractor data, and train the people who handle it.
  • If a breach occurs, assess whether it is an eligible data breach and notify the OAIC and affected individuals where serious harm is likely.

When a lawyer can help

The exemption questions are fiddly, and the section 6D(4) exceptions catch businesses that do not expect to be caught. A privacy lawyer can confirm whether the APPs apply to you, review and update your privacy policy and collection notices, audit your overseas data flows and contracts, and help you respond if the OAIC receives a complaint or a data breach needs notification. If reform removes the small business exemption, a lawyer can also help you build the practices now so the change does not catch you mid-recruitment.

The gap that costs employers most

The most-missed point in this area is the employee records exemption itself. Employers routinely treat applicant and contractor data as if the privacy rules did not apply, because the words "employee records" sound like they cover everyone connected with the workforce. They do not. An unsuccessful applicant, an independent contractor and a volunteer are all protected by the APPs, and a serious interference with their privacy can expose a company to a penalty of up to $50 million.

The first action to take this week is to check whether the APPs apply to you, and if they do, look at where applications and CVs are stored. That inbox and that shared drive are where most of this exposure sits, and they are cheap to fix before a complaint, a breach or a reform cycle forces the issue.