How Do I Respond to a Customer Data Request?
The 30-day deadline, when refusal is allowed, and the free tools to generate a compliant response.
Respond within 30 days of receiving it. Access requests fall under APP 12, correction requests under APP 13. If you need more time, provide at least a partial answer within 30 days and explain the delay — silence is what generates OAIC complaints, not a late or partial response.
Last updated: 2 July 2026
Quick reference
| Access request | APP 12, respond within 30 days |
| Correction request | APP 13, respond within 30 days, no fee |
| ADM explanation request | APP 1.3, available from 10 December 2026 |
| Refusal grounds | Specific, narrow exceptions only — with a stated reason and complaint rights |
Where the 30-day clock trips businesses up
The most common mistake is treating "we're still gathering the records" as a valid reason to miss the 30-day deadline. It isn't. The correct response is to answer within 30 days with whatever can be confirmed — even a partial answer — rather than staying silent until the file is complete.
A second gap: businesses that can locate the data but have no template for the response letter itself, which wastes days of the 30-day window on drafting rather than substance. From 10 December 2026, requests can also ask for an explanation of a specific automated decision under APP 1.3 — a request type most businesses have never had to answer before.
Relevant free tools
Generate a compliant response letter for an access, correction or ADM explanation request.
Check whether the personal information you hold is accurate and up to date.
Check whether you need to offer an anonymous or pseudonymous option at any touchpoint.
Related Privacy Act questions
When to prepare your response process
- — You've received an access or correction request and don't have a template ready
- — You're not confident where all of a customer's personal information is stored
- — You don't have a documented process for the 30-day deadline
- — You use automated decision-making and haven't prepared for an APP 1.3 explanation request
- — You've considered refusing a request without checking whether a valid ground applies
Frequently asked questions
How do I respond to a customer data request?
Respond within 30 days of receiving it. Access requests fall under APP 12, correction requests under APP 13. If you need more time, provide at least a partial answer within 30 days and explain the delay — silence is what generates OAIC complaints, not a late or partial response.
Can I charge a fee for responding?
Generally no meaningful fee — access requests under APP 12 must not be charged an excessive fee, and the same 30-day response expectation applies regardless of whether a fee applies. Correction requests under APP 13 must not be charged at all.
Can I refuse a request?
Only on specific, narrow grounds set out in the Privacy Act 1988 (Cth) — not for convenience or time pressure. Where a request is refused, the entity must still explain the reason and the individual's right to complain to the OAIC.
What do I need to track to respond on time?
A record of what personal information you hold, where it's stored, and — if you use automated decision-making — a disclosure log to answer an APP 1.3 explanation request. Without this, most of the 30-day period gets consumed just locating the data.
Generate a compliant response letter in under a minute with the free rights request generator.
Generate my response letter →