What Do I Need to Do to Comply with the Australian Privacy Act?
The full compliance checklist across all 13 Australian Privacy Principles — track your progress step by step, plus the free tools that check each one for your business.
Compliance means meeting all 13 Australian Privacy Principles: a publicly accessible privacy policy (APP 1), collection notices at every data-capture point (APP 5), reasonable security safeguards (APP 11), and a documented process to respond to access and correction requests within 30 days (APPs 12–13). From 1 July 2026, this applies to almost every Australian business regardless of turnover. From 10 December 2026, businesses using automated decision-making must also disclose it under APP 1.3.
Last updated: 3 July 2026
Compliance at a glance
| Governing law | Privacy Act 1988 (Cth) |
| Number of principles | 13 Australian Privacy Principles (APPs) |
| Who's covered from 1 July 2026 | Virtually all Australian businesses, regardless of turnover |
| ADM disclosure deadline | 10 December 2026 (APP 1.3) |
| Maximum penalty, serious breach | $50 million, 3× the benefit obtained, or 30% of adjusted turnover — whichever is greatest |
The compliance checklist, in order
Start with scope: confirm whether the Privacy Act covers your business and which data types trigger extra obligations. From 1 July 2026 almost every business is covered, so this step is now about identifying which APPs are most relevant to your operations, not whether you're covered at all.
Next, get the paperwork right: a privacy policy that meets all 11 required elements of APP 1, and collection notices at every point you gather personal information under APP 5. These are the two most commonly audited documents in an OAIC review.
Then close operational gaps: reasonable security safeguards under APP 11, a documented 30-day process for access and correction requests under APPs 12–13, and — if you use AI or automated tools to make or assist decisions about people — an ADM disclosure section ready before 10 December 2026.
Track your progress
Tick items off as you complete them. Your progress is saved in this browser, so you can come back and pick up where you left off.
1. Scope
0/32. Policy & notices
0/33. Security & data quality
0/34. Rights & disclosure
0/35. Review cycle
0/3Nothing here is sent anywhere — your progress is stored only in this browser's local storage.
Relevant free tools
Find out if the Privacy Act covers your business and which APPs apply.
Analyse your existing privacy policy against APP 1 requirements.
Check your collection notices cover everything APP 5 requires.
Check your data security safeguards against APP 11 requirements.
When you need a full compliance review
- — You've never mapped your business against the 13 Australian Privacy Principles
- — You're newly covered by the 1 July 2026 removal of the small business exemption
- — Your privacy policy hasn't been reviewed since before the 2024 reform
- — You use AI or automated tools and haven't assessed the 10 December 2026 ADM disclosure deadline
- — A client, vendor, or the OAIC has asked you to demonstrate compliance
Frequently asked questions
What do I need to do to comply with the Australian Privacy Act?
Meet all 13 Australian Privacy Principles: publish a compliant privacy policy (APP 1), issue collection notices at every data-capture point (APP 5), apply reasonable security safeguards (APP 11), and respond to access and correction requests within 30 days (APPs 12–13). From 10 December 2026, businesses using automated decision-making must also disclose it under APP 1.3.
Does the Privacy Act apply to my business?
From 1 July 2026, yes for almost every Australian business, regardless of annual turnover — the $3 million small business exemption is removed by the Privacy and Other Legislation Amendment Act 2024. Health, financial services, credit and government entities were already covered before that date.
What happens if my business doesn't comply?
Serious or repeated breaches carry penalties of up to $50 million, 3 times the benefit obtained, or 30% of adjusted turnover — whichever is greatest. Non-serious contraventions carry penalties of up to $66,000 per contravention. A statutory tort for serious invasions of privacy also commenced in June 2025.
How long do I have to respond to a customer data request?
30 days from receiving the request, for both access requests (APP 12) and correction requests (APP 13). The period isn't extendable by choice — if more time is needed, respond with at least a partial answer within 30 days and explain the delay.
Do I need to disclose AI or automated decision-making?
Yes, from 10 December 2026, if you're a covered entity using a system that makes or substantially assists a decision affecting an individual. APP 1.3 requires a dedicated disclosure section in your privacy policy listing each system and how a person can seek human review.
Don't have a privacy policy yet?
Generate a custom, APP 1.3-compliant privacy policy draft — including the automated decision-making disclosure required from 10 December 2026 — in about 60 seconds. Free, no account required.
Generate my privacy policy →