Privacy Ready
Collection · APPs 3, 4 & 5

How Do I Collect Customer Data Legally in Australia?

The three APPs that govern collection, where "just in case" fields go wrong, and the free tools to check your intake forms.

Only collect personal information that's reasonably necessary for your business functions (APP 3), and tell people what you're collecting, why, and how at the point of collection (APP 5). Sensitive information — health, biometric, or genetic data — generally needs explicit consent. Information you receive but didn't request has separate handling rules under APP 4.

Last updated: 2 July 2026

The three collection principles

APP Governs
APP 3 Whether you're permitted to collect it at all — must be reasonably necessary
APP 4 What to do with information received but never solicited
APP 5 Telling the individual you're collecting it, and why

Where intake forms go wrong

"Just in case" fields are the most common APP 3 breach — collecting date of birth, gender, or full residential address when the service doesn't actually need them. Every field on a form should trace back to a specific, reasonably necessary function.

A second common gap is silence: collecting data through a form, phone call or in-person intake without telling the person what it's for. APP 5 requires a notice — even a short one — at or before collection, not buried three clicks deep in a general privacy policy.

Free diagnostic tools

Relevant free tools

Related Privacy Act questions

When to check your collection practices

  • Your intake forms collect fields you're not sure are actually necessary
  • You don't have a collection notice at every point you gather data
  • You've received information you never asked for, like a resume sent to the wrong inbox
  • You collect health, biometric or other sensitive information without explicit consent
  • You've added a new form or intake channel since your last review

Frequently asked questions

How do I collect customer data legally under the Privacy Act?

Only collect personal information that's reasonably necessary for your business functions (APP 3), and tell people what you're collecting, why, and how at the point of collection (APP 5). Sensitive information — health, biometric, or genetic data — generally needs explicit consent. Information you receive but didn't request has separate handling rules under APP 4.

Can I collect any personal information I want?

No. APP 3 restricts collection to personal information that's reasonably necessary for your functions or activities. Collecting extra fields "just in case" — like date of birth for a service that doesn't need it — is a common APP 3 breach.

Do I need a collection notice on every form?

Yes. APP 5 requires notification at or before the time of collection, or as soon as practicable after, covering what's collected, why, and how the person can access or complain about it. This applies to every collection point — website forms, phone intake, and paper forms alike.

What do I do with data I receive but didn't ask for?

Under APP 4, if the information could have been lawfully collected under APP 3, you may keep it and apply the usual APPs. If it couldn't have been lawfully collected, you must destroy or de-identify it as soon as practicable, unless doing so is unlawful.

Run the free collection necessity checker to see which fields on your forms go beyond what APP 3 allows.

Check my collection practices →