APP 13: Correction of Personal Information
Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team
Australian Privacy Principle 13 gives individuals the right to request correction of personal information you hold about them that is inaccurate, out of date, incomplete, misleading, or irrelevant. If you agree, you must correct it within a reasonable period and, where you have disclosed the incorrect information to a third party, take reasonable steps to notify that third party of the correction if the individual asks. If you disagree, you must instead take reasonable steps to associate a statement with the information noting the individual's claimed correction.
| Governing provision | Privacy Act 1988 (Cth), Schedule 1, APP 13 |
| Grounds for correction | Inaccurate, out of date, incomplete, misleading, or irrelevant |
| If you agree | Correct within a reasonable period; notify prior recipients on request |
| If you disagree | Attach a statement noting the individual's claimed correction |
| Refusal notice | Must explain reasons and the individual's complaint options |
What APP 13 actually requires
Correction requests can arise on their own or alongside an APP 12 access request — someone reviews the information you hold and asks you to fix an error. APP 13.1 requires you to take reasonable steps to correct personal information to ensure it is accurate, up to date, complete, relevant, and not misleading, having regard to the purpose for which it is held.
If you correct the information and had previously disclosed the earlier, incorrect version to a third party, APP 13.2 requires you — on the individual's request — to take reasonable steps to notify that third party of the correction, unless it would be impracticable or unlawful to do so.
What happens if you disagree with the requested correction
You are not required to accept every claimed correction at face value. If you refuse, APP 13.4 requires you to give the individual a written notice setting out your reasons for refusal (subject to limited exceptions) and information about how they can complain. Separately, if the individual asks, you must take reasonable steps to associate a statement with the information noting that the individual claims it is inaccurate, out of date, incomplete, misleading, or irrelevant — even though you have not changed the underlying record.
Common SME failure modes
- No process to action correction requests — treated as an ad hoc customer service matter rather than a distinct legal obligation with its own requirements.
- Correcting the primary record but not flowing the change through to other systems where the same data is duplicated.
- Refusing a correction without a written notice explaining the reasons and complaint pathway.
- Not offering the statement-of-disagreement option when a correction is refused.
Frequently asked questions
Is there a fixed deadline to action a correction request, like the 30 days for access requests?
APP 13 requires correction within a "reasonable period" rather than a specific fixed number of days (unconfirmed whether OAIC guidance sets a benchmark). As a practical approach, many businesses align this with the 30-day APP 12 timeframe to avoid ambiguity.
Can I charge a fee for making a correction?
No. Unlike APP 12 access requests, which allow a reasonable fee for the cost of providing access, APP 13 does not provide for charging individuals to correct their own information.
What if the person wants the record deleted rather than corrected?
APP 13 covers correction, not deletion — there is no standalone right to erasure in Australian privacy law equivalent to GDPR's Article 17. If you no longer have a legitimate purpose to hold the information, APP 11.2 separately requires you to destroy or de-identify it.
Use the free Rights Request Response Letter Generator to build a ready-to-edit APP 13 correction response, including the statement-of-disagreement wording if you refuse.
Generate my response letter →Explore more of the Privacy Act
- APP 1: Open and Transparent Management of Personal Information
- APP 2: Anonymity and Pseudonymity
- APP 3: Collection of Solicited Personal Information
- APP 4: Dealing with Unsolicited Personal Information
- Does the Privacy Act Apply to My Australian Small Business?
- What Is ADM Disclosure and Does My Australian Business Need One?