Privacy Ready
Compliance overview · Privacy Act 1988

What Do I Need to Do to Comply with the Australian Privacy Act?

The full compliance checklist across all 13 Australian Privacy Principles — track your progress step by step, plus the free tools that check each one for your business.

Compliance means meeting all 13 Australian Privacy Principles: a publicly accessible privacy policy (APP 1), collection notices at every data-capture point (APP 5), reasonable security safeguards (APP 11), and a documented process to respond to access and correction requests within 30 days (APPs 12–13). From 1 July 2026, this applies to almost every Australian business regardless of turnover. From 10 December 2026, businesses using automated decision-making must also disclose it under APP 1.3.

Last updated: 3 July 2026

Compliance at a glance

Governing law Privacy Act 1988 (Cth)
Number of principles 13 Australian Privacy Principles (APPs)
Who's covered from 1 July 2026 Virtually all Australian businesses, regardless of turnover
ADM disclosure deadline 10 December 2026 (APP 1.3)
Maximum penalty, serious breach $50 million, 3× the benefit obtained, or 30% of adjusted turnover — whichever is greatest

The compliance checklist, in order

Start with scope: confirm whether the Privacy Act covers your business and which data types trigger extra obligations. From 1 July 2026 almost every business is covered, so this step is now about identifying which APPs are most relevant to your operations, not whether you're covered at all.

Next, get the paperwork right: a privacy policy that meets all 11 required elements of APP 1, and collection notices at every point you gather personal information under APP 5. These are the two most commonly audited documents in an OAIC review.

Then close operational gaps: reasonable security safeguards under APP 11, a documented 30-day process for access and correction requests under APPs 12–13, and — if you use AI or automated tools to make or assist decisions about people — an ADM disclosure section ready before 10 December 2026.

Free interactive checklist

Track your progress

Tick items off as you complete them. Your progress is saved in this browser, so you can come back and pick up where you left off.

0 of 15 steps complete 0%

1. Scope

0/3

2. Policy & notices

0/3

3. Security & data quality

0/3

4. Rights & disclosure

0/3

5. Review cycle

0/3

Nothing here is sent anywhere — your progress is stored only in this browser's local storage.

Free diagnostic tools

Relevant free tools

When you need a full compliance review

  • You've never mapped your business against the 13 Australian Privacy Principles
  • You're newly covered by the 1 July 2026 removal of the small business exemption
  • Your privacy policy hasn't been reviewed since before the 2024 reform
  • You use AI or automated tools and haven't assessed the 10 December 2026 ADM disclosure deadline
  • A client, vendor, or the OAIC has asked you to demonstrate compliance

Frequently asked questions

What do I need to do to comply with the Australian Privacy Act?

Meet all 13 Australian Privacy Principles: publish a compliant privacy policy (APP 1), issue collection notices at every data-capture point (APP 5), apply reasonable security safeguards (APP 11), and respond to access and correction requests within 30 days (APPs 12–13). From 10 December 2026, businesses using automated decision-making must also disclose it under APP 1.3.

Does the Privacy Act apply to my business?

From 1 July 2026, yes for almost every Australian business, regardless of annual turnover — the $3 million small business exemption is removed by the Privacy and Other Legislation Amendment Act 2024. Health, financial services, credit and government entities were already covered before that date.

What happens if my business doesn't comply?

Serious or repeated breaches carry penalties of up to $50 million, 3 times the benefit obtained, or 30% of adjusted turnover — whichever is greatest. Non-serious contraventions carry penalties of up to $66,000 per contravention. A statutory tort for serious invasions of privacy also commenced in June 2025.

How long do I have to respond to a customer data request?

30 days from receiving the request, for both access requests (APP 12) and correction requests (APP 13). The period isn't extendable by choice — if more time is needed, respond with at least a partial answer within 30 days and explain the delay.

Do I need to disclose AI or automated decision-making?

Yes, from 10 December 2026, if you're a covered entity using a system that makes or substantially assists a decision affecting an individual. APP 1.3 requires a dedicated disclosure section in your privacy policy listing each system and how a person can seek human review.

Free tool · APP 1.3

Don't have a privacy policy yet?

Generate a custom, APP 1.3-compliant privacy policy draft — including the automated decision-making disclosure required from 10 December 2026 — in about 60 seconds. Free, no account required.

Generate my privacy policy →