Australian Privacy Act: The 13 compliance obligations explained simply
Last updated 3 July 2026 · Reviewed by The PrivacyReady compliance team
Australia's Privacy Act 1988 (Cth) requires businesses to collect only necessary personal information, be transparent about why it's collected, and use it only for that stated purpose unless an exception applies, while also keeping it secure and correcting or providing access when requested.
If a serious data breach is likely to cause harm, you must assess it and notify affected individuals and the Office of the Australian Information Commissioner.
Why now? Enforcement is increasing, data breaches are more frequent and costly, and regulators are tightening expectations as businesses rely more heavily on digital systems and AI-driven data use.
Explore the 13 Australian Privacy Principles
Tap to expand
APP 1
Open and transparent management
Applies to you always — every APP entity needs one.
Open and transparent management
Applies to you always — every APP entity needs one.
You must have a clearly written, publicly available privacy policy describing how you collect, hold, use, and disclose personal information — and actually follow it. From 10 December 2026, it must also disclose any automated decision-making process that significantly affects individuals.
Read the full APP 1 guide →
APP 2
Anonymity and pseudonymity
Applies if people can deal with you without giving their name — enquiries, walk-ins, phone calls.
Anonymity and pseudonymity
Applies if people can deal with you without giving their name — enquiries, walk-ins, phone calls.
Individuals must be able to deal with you anonymously or under a pseudonym where it's lawful and practicable — for most online enquiries, this means asking only for the minimum information needed.
Read the full APP 2 guide →
APP 3
Collection of solicited information
Applies to you always — any time you collect personal information from anyone.
Collection of solicited information
Applies to you always — any time you collect personal information from anyone.
Collection is limited to what's reasonably necessary for a legitimate business function, and must be by lawful and fair means. Sensitive information such as health data or biometrics needs the individual's explicit consent to collect.
Read the full APP 3 guide →
APP 4
Dealing with unsolicited information
Applies if you ever receive personal information you didn't ask for — a stray resume, a misdirected email.
Dealing with unsolicited information
Applies if you ever receive personal information you didn't ask for — a stray resume, a misdirected email.
If someone sends you personal information you didn't ask for and have no legitimate need to hold, you must destroy or de-identify it within a reasonable time.
Read the full APP 4 guide →
APP 5
Notification of collection
Applies to you always — at every point you collect data, from forms to contracts to sign-ups.
Notification of collection
Applies to you always — at every point you collect data, from forms to contracts to sign-ups.
At or before collecting information, you must tell individuals who you are, why you're collecting it, who you might disclose it to, whether providing it is optional, and how they can access or correct it.
Read the full APP 5 guide →
APP 6
Use or disclosure
Applies to you always — any time you use or share data for something other than why it was collected.
Use or disclosure
Applies to you always — any time you use or share data for something other than why it was collected.
Personal information can only be used or disclosed for the primary purpose it was collected for. Using a customer's email, collected to confirm an order, to add them to a marketing list without separate consent breaches this principle.
Read the full APP 6 guide →
APP 7
Direct marketing
Applies if you send marketing emails, SMS, or calls to customers or prospects.
Direct marketing
Applies if you send marketing emails, SMS, or calls to customers or prospects.
Every marketing communication needs an easy, working opt-out, and sensitive information can't be used for direct marketing at all without the individual's explicit consent.
Read the full APP 7 guide →
APP 8
Cross-border disclosure
Applies if any personal information is stored or processed overseas — including via cloud or SaaS tools.
Cross-border disclosure
Applies if any personal information is stored or processed overseas — including via cloud or SaaS tools.
Before sending personal information to an overseas recipient — including via an offshore-hosted cloud service — you must take reasonable steps to ensure they handle it consistently with the APPs, or you're treated as having breached the APPs yourself.
Read the full APP 8 guide →
APP 9
Government-related identifiers
Applies if you collect Tax File Numbers, Medicare numbers, or other government identifiers.
Government-related identifiers
Applies if you collect Tax File Numbers, Medicare numbers, or other government identifiers.
You cannot adopt a government-assigned identifier — a Tax File Number, Medicare number, or driver licence number — as your own customer or account identifier.
Read the full APP 9 guide →
APP 10
Quality of personal information
Applies to you always — wherever you rely on the accuracy of data you hold.
Quality of personal information
Applies to you always — wherever you rely on the accuracy of data you hold.
You must take reasonable steps to keep personal information accurate, up to date, and complete before you use or disclose it.
Read the full APP 10 guide →
APP 11
Security of personal information
Applies to you always — this underpins your data breach obligations.
Security of personal information
Applies to you always — this underpins your data breach obligations.
You must take reasonable steps to protect personal information from misuse, loss, and unauthorised access, and to destroy or de-identify it once it's no longer needed — this underpins the Notifiable Data Breaches scheme.
Read the full APP 11 guide →
APP 12
Access to personal information
Applies the moment someone asks what information you hold about them.
Access to personal information
Applies the moment someone asks what information you hold about them.
Individuals can request access to information you hold about them, and you must respond within 30 days. A reasonable fee can apply to providing access, but never to lodging the request.
Read the full APP 12 guide →
APP 13
Correction of personal information
Applies the moment someone asks you to correct their information.
Correction of personal information
Applies the moment someone asks you to correct their information.
Individuals can request correction of information that's inaccurate, out of date, incomplete, or misleading. You must either correct it or, if you disagree, add a notation of their claimed correction alongside the data.
Read the full APP 13 guide →Is my business affected by this?
Business applicability check
Answer five questions about your business. Get an instant verdict on whether the 1 July 2026 threshold change affects you, plus the specific obligations that apply — at a permanent URL you can bookmark or share.
Frequently asked questions
Do all 13 APPs apply equally to every business?
Yes — all 13 apply to any APP entity. However, some only become relevant in specific circumstances: APP 4 if you receive unsolicited information; APP 9 if you handle government identifiers; APP 7 if you do direct marketing. In practice, APPs 1, 3, 5, 6, 11, and 12 are the ones most small businesses need to actively manage day-to-day.
What is "sensitive information" and why does it matter?
Sensitive information under s 6 of the Privacy Act includes health, genetic, biometric, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record information. It attracts higher protection: collection generally requires explicit consent (APP 3), and it cannot be used for direct marketing at all without consent (APP 7).
Is there a standard form privacy policy I can use?
The OAIC publishes guidance and templates at oaic.gov.au. Any template must be customised to your actual data practices — a generic document that does not reflect what you genuinely collect and do is non-compliant and can make things worse if the OAIC investigates.
What if a customer asks to access data I no longer hold?
You must still respond. Under APP 12, if you do not hold the information, you must inform the individual of that fact within 30 days. You have no obligation to recreate data you have legitimately destroyed — but the response to the access request is still required.
What happens if my business breaches an APP?
The OAIC can accept an enforceable undertaking, seek civil penalties, or investigate following a complaint. Serious or repeated breaches carry penalties of up to $50 million, 3 times the benefit obtained, or 30% of adjusted turnover — whichever is greatest. Less serious, per-contravention breaches carry penalties of up to $66,000.
Explore more of the Privacy Act
- Does the Privacy Act Apply to My Australian Small Business?
- What Is ADM Disclosure and Does My Australian Business Need One?
- What Counts as a Notifiable Data Breach in Australia?
- What Must an Australian Privacy Policy Include Under the Privacy Act?
- How to Respond to a Customer's Privacy Access Request in Australia
- What Is the OAIC and What Enforcement Powers Does It Have Over Australian Businesses?