Privacy Ready
← Learn

APP 1: Open and Transparent Management of Personal Information

Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team

The short answer

Australian Privacy Principle 1 requires every APP entity to manage personal information openly and transparently: implement practices, procedures, and systems that actually give effect to the APPs (APP 1.2), and maintain a clearly expressed, up-to-date privacy policy that is free for anyone to access without registering or paying (APP 1.3). From 10 December 2026, that policy must also disclose any automated decision-making process that substantially affects individuals.

Governing provision Privacy Act 1988 (Cth), Schedule 1, APP 1
Who it applies to Every APP entity — no exceptions
Core requirement Practices, procedures and systems (APP 1.2) + a free, public policy (APP 1.3)
Minimum policy content 6 elements under APP 1.4
New from 10 Dec 2026 ADM disclosure (APP 1 amendment)
Maximum penalty Up to $50M, 3× benefit, or 30% adjusted turnover for serious breaches

What APP 1 actually requires

APP 1 has two distinct limbs, and businesses often only address the second one. APP 1.2 requires you to take reasonable steps to implement practices, procedures, and systems that ensure you comply with the APPs and can deal with related inquiries and complaints. Having a policy document is not enough on its own — the OAIC expects evidence that you actually follow it: staff training, a designated privacy contact, a documented process for handling access requests, and so on.

APP 1.3 and APP 1.4 govern the privacy policy itself. It must be free to access — no login wall, no fee, no requirement to hand over personal information to read it — and it must cover, at minimum: the kinds of personal information you collect and hold; how you collect and hold it; the purposes for collection, use, and disclosure; how individuals can access and correct their information; how they can complain; and whether you disclose information to overseas recipients and to which countries.

Who this applies to

APP 1 applies to every APP entity with no size or sector carve-out. From 1 July 2026, that includes an estimated 100,000+ Australian small businesses that previously relied on the small business exemption. If your business collects any personal information — a customer list, a booking form, employee records — you need a compliant, publicly available privacy policy from the date you become regulated.

Common SME failure modes

  • No policy at all — the single most common gap for newly regulated businesses ahead of 1 July 2026.
  • A copied US or UK template — GDPR and CCPA language does not satisfy APP 1.4; it typically omits the OAIC complaint pathway and Australian-specific overseas disclosure wording.
  • Policy exists but is stale — describes tools or data flows the business stopped using years ago, or omits ones added since.
  • Buried or gated access — a policy only available on request, or behind a customer login, fails APP 1.3's "freely available" requirement.
  • Missing the complaints process — APP 1.4(h) specifically requires this, and it is one of the most frequently omitted elements in self-drafted policies.

Practical compliance steps

  1. Audit what you actually collect — do not draft from a template; list every category of personal information your business genuinely holds.
  2. Map your data flows — which systems store it, which third parties receive it, and whether any of those are overseas.
  3. Draft in plain language — short sentences, active voice, no undefined jargon.
  4. Publish it prominently — a footer link on every page is the standard, low-friction approach.
  5. Review at least annually, and immediately after adopting any new tool that touches personal information.
  6. From 10 December 2026, add a section describing any automated decision-making process and whether a human reviews its output.

Frequently asked questions

Does a privacy policy need its own page, or can it live inside Terms & Conditions?

A standalone page is strongly recommended. Burying privacy content inside dense terms and conditions is likely to fail the plain-language expectation in APP 1.4 and makes it harder for individuals to find their rights.

Do I need a lawyer to write my privacy policy?

Not necessarily. APP 1.4's content requirements are specific and manageable, and what matters most is that the policy accurately describes your actual practices. Legal review adds value for larger organisations or those handling sensitive information, but many small businesses can draft a compliant policy themselves using OAIC guidance as a framework.

How often do I need to update my privacy policy?

Whenever your data practices materially change — a new tool that processes personal information, a new category of data collected, or a new type of recipient. A formal annual review plus an update on adopting new technology is a practical baseline.

What happens if someone complains that my privacy policy is inadequate?

They can lodge a complaint with the OAIC, which will typically contact you and give you an opportunity to respond before attempting conciliation. Most first-instance complaints of this kind are resolved by updating the policy; formal enforcement is more likely where there is a pattern of non-compliance.

Use the free Privacy Policy Analyser to check your existing policy against every element of APP 1.4 — including the ADM disclosure required from 10 December 2026.

Analyse my privacy policy →