Privacy Ready
← Learn

Australian Privacy Act: The 13 compliance obligations explained simply

Last updated 3 July 2026 · Reviewed by The PrivacyReady compliance team

The short answer

Australia's Privacy Act 1988 (Cth) requires businesses to collect only necessary personal information, be transparent about why it's collected, and use it only for that stated purpose unless an exception applies, while also keeping it secure and correcting or providing access when requested.

If a serious data breach is likely to cause harm, you must assess it and notify affected individuals and the Office of the Australian Information Commissioner.

Why now? Enforcement is increasing, data breaches are more frequent and costly, and regulators are tightening expectations as businesses rely more heavily on digital systems and AI-driven data use.

Explore the 13 Australian Privacy Principles

APP 1

Open and transparent management

Applies to you always — every APP entity needs one.

You must have a clearly written, publicly available privacy policy describing how you collect, hold, use, and disclose personal information — and actually follow it. From 10 December 2026, it must also disclose any automated decision-making process that significantly affects individuals.

Read the full APP 1 guide →
APP 2

Anonymity and pseudonymity

Applies if people can deal with you without giving their name — enquiries, walk-ins, phone calls.

Individuals must be able to deal with you anonymously or under a pseudonym where it's lawful and practicable — for most online enquiries, this means asking only for the minimum information needed.

Read the full APP 2 guide →
APP 3

Collection of solicited information

Applies to you always — any time you collect personal information from anyone.

Collection is limited to what's reasonably necessary for a legitimate business function, and must be by lawful and fair means. Sensitive information such as health data or biometrics needs the individual's explicit consent to collect.

Read the full APP 3 guide →
APP 4

Dealing with unsolicited information

Applies if you ever receive personal information you didn't ask for — a stray resume, a misdirected email.

If someone sends you personal information you didn't ask for and have no legitimate need to hold, you must destroy or de-identify it within a reasonable time.

Read the full APP 4 guide →
APP 5

Notification of collection

Applies to you always — at every point you collect data, from forms to contracts to sign-ups.

At or before collecting information, you must tell individuals who you are, why you're collecting it, who you might disclose it to, whether providing it is optional, and how they can access or correct it.

Read the full APP 5 guide →
APP 6

Use or disclosure

Applies to you always — any time you use or share data for something other than why it was collected.

Personal information can only be used or disclosed for the primary purpose it was collected for. Using a customer's email, collected to confirm an order, to add them to a marketing list without separate consent breaches this principle.

Read the full APP 6 guide →
APP 7

Direct marketing

Applies if you send marketing emails, SMS, or calls to customers or prospects.

Every marketing communication needs an easy, working opt-out, and sensitive information can't be used for direct marketing at all without the individual's explicit consent.

Read the full APP 7 guide →
APP 8

Cross-border disclosure

Applies if any personal information is stored or processed overseas — including via cloud or SaaS tools.

Before sending personal information to an overseas recipient — including via an offshore-hosted cloud service — you must take reasonable steps to ensure they handle it consistently with the APPs, or you're treated as having breached the APPs yourself.

Read the full APP 8 guide →
APP 9

Government-related identifiers

Applies if you collect Tax File Numbers, Medicare numbers, or other government identifiers.

You cannot adopt a government-assigned identifier — a Tax File Number, Medicare number, or driver licence number — as your own customer or account identifier.

Read the full APP 9 guide →
APP 10

Quality of personal information

Applies to you always — wherever you rely on the accuracy of data you hold.

You must take reasonable steps to keep personal information accurate, up to date, and complete before you use or disclose it.

Read the full APP 10 guide →
APP 11

Security of personal information

Applies to you always — this underpins your data breach obligations.

You must take reasonable steps to protect personal information from misuse, loss, and unauthorised access, and to destroy or de-identify it once it's no longer needed — this underpins the Notifiable Data Breaches scheme.

Read the full APP 11 guide →
APP 12

Access to personal information

Applies the moment someone asks what information you hold about them.

Individuals can request access to information you hold about them, and you must respond within 30 days. A reasonable fee can apply to providing access, but never to lodging the request.

Read the full APP 12 guide →
APP 13

Correction of personal information

Applies the moment someone asks you to correct their information.

Individuals can request correction of information that's inaccurate, out of date, incomplete, or misleading. You must either correct it or, if you disagree, add a notation of their claimed correction alongside the data.

Read the full APP 13 guide →

Is my business affected by this?

Free diagnostic tool

Business applicability check

Answer five questions about your business. Get an instant verdict on whether the 1 July 2026 threshold change affects you, plus the specific obligations that apply — at a permanent URL you can bookmark or share.

Question 1 of 5

What type of entity is your business?

Different structures have different Privacy Act obligations — some are covered automatically regardless of size.

Question 2 of 5

What's your approximate annual turnover?

Use your most recent completed financial year. The $3 million threshold was the key dividing line before 1 July 2026 — though industry and data types can override it.

Question 3 of 5

What's your primary industry?

Health and financial services are covered regardless of size. Others may have industry-specific obligations layered on top.

Question 4 of 5

What personal information does your business handle?

Select all that apply. Sensitive information types — health records, biometrics, government identifiers — carry additional obligations and can affect whether you're covered at all.

Select at least one to continue.

Question 5 of 5

Do you use AI or automated tools that make decisions affecting individuals?

This includes AI-assisted loan approvals, automated job screening, personalised pricing, AI chatbots handling complaints, or any system where software makes or assists a decision about a specific person. A new disclosure requirement applies to covered entities from 10 December 2026.

Frequently asked questions

Do all 13 APPs apply equally to every business?

Yes — all 13 apply to any APP entity. However, some only become relevant in specific circumstances: APP 4 if you receive unsolicited information; APP 9 if you handle government identifiers; APP 7 if you do direct marketing. In practice, APPs 1, 3, 5, 6, 11, and 12 are the ones most small businesses need to actively manage day-to-day.

What is "sensitive information" and why does it matter?

Sensitive information under s 6 of the Privacy Act includes health, genetic, biometric, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record information. It attracts higher protection: collection generally requires explicit consent (APP 3), and it cannot be used for direct marketing at all without consent (APP 7).

Is there a standard form privacy policy I can use?

The OAIC publishes guidance and templates at oaic.gov.au. Any template must be customised to your actual data practices — a generic document that does not reflect what you genuinely collect and do is non-compliant and can make things worse if the OAIC investigates.

What if a customer asks to access data I no longer hold?

You must still respond. Under APP 12, if you do not hold the information, you must inform the individual of that fact within 30 days. You have no obligation to recreate data you have legitimately destroyed — but the response to the access request is still required.

What happens if my business breaches an APP?

The OAIC can accept an enforceable undertaking, seek civil penalties, or investigate following a complaint. Serious or repeated breaches carry penalties of up to $50 million, 3 times the benefit obtained, or 30% of adjusted turnover — whichever is greatest. Less serious, per-contravention breaches carry penalties of up to $66,000.