Privacy Ready
← Learn

APP 3: Collection of Solicited Personal Information

Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team

The short answer

Australian Privacy Principle 3 restricts how much personal information you can collect: you may only collect information reasonably necessary for, or directly related to, one or more of your business functions or activities, and only by lawful and fair means. Collecting sensitive information — such as health data, biometric data, or information about sexual orientation or religious belief — requires the individual's explicit consent, subject to narrow exceptions.

Governing provision Privacy Act 1988 (Cth), Schedule 1, APP 3
Standard Reasonably necessary for your functions, collected lawfully and fairly
Sensitive information Requires explicit consent (APP 3.3), narrow exceptions apply
Applies to Every collection of personal information, regardless of channel
Related principle APP 5 requires you to notify at the point of collection

What "reasonably necessary" means

APP 3 does not permit collecting information "just in case" it might be useful later. The test is whether the specific item of information is reasonably necessary for, or directly related to, a function or activity your business actually carries out. A booking form that asks for a customer's date of birth when it has no bearing on the booking is a common example of over-collection.

Sensitive information — defined in s 6 of the Act to include health, genetic, and biometric information, and information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record — attracts a stricter standard. APP 3.3 generally requires the individual's explicit consent to collect it, with limited exceptions such as where collection is required by law or necessary to lessen a serious threat to health or safety.

Who this applies to

Every APP entity, on every occasion it collects personal information — through forms, contracts, phone calls, in-person interactions, or automated capture such as cookies and analytics tools that identify individuals.

Common SME failure modes

  • Over-collection on intake forms — asking for date of birth, gender, or occupation when none are relevant to the transaction.
  • Collecting sensitive information without explicit consent — for example, a health or allied-health intake form that does not clearly seek consent before capturing health details.
  • Unlawful or unfair collection methods — covert tracking, or collecting information through deception about the purpose.
  • Treating "nice to have" marketing data as necessary — collecting broad demographic data for future, unspecified marketing use.

Practical compliance steps

  1. Review every form field you collect and ask: is this genuinely necessary for the function it supports?
  2. Remove optional-looking fields that aren't actually used for anything.
  3. For any sensitive information field, add a clear, separate consent mechanism — not a pre-ticked box buried in general terms.
  4. Document the business reason for each category of information you collect, so you can justify it if asked.
  5. Review data collected via cookies, analytics, and tracking pixels for the same necessity test.

Frequently asked questions

Can I collect information for future, unspecified marketing purposes?

Generally no — collection needs to relate to a current, identifiable function. Broad, speculative collection "in case it's useful" is difficult to justify under APP 3 and separately raises APP 6 use-limitation issues if you later use it for an unrelated purpose.

What counts as "sensitive information" in practice?

Under s 6 of the Privacy Act: health information, genetic information, biometric information, and information about racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, trade union membership, and criminal record. Any of these generally needs explicit consent to collect.

Does APP 3 apply to information I collect about employees?

Employee records held in connection with an employment relationship are subject to a specific exemption in some circumstances under s 7B of the Act (unconfirmed scope — check current OAIC guidance) — but this exemption is narrower than commonly assumed and does not cover, for example, information collected before the employment relationship begins.

Do I need consent to collect ordinary contact details like name and email?

No — consent is not generally required for non-sensitive personal information under APP 3. What is required is that the collection is reasonably necessary for your functions and that you notify the individual under APP 5.

Use the free Collection Necessity Check to see which of your data fields go beyond what APP 3 allows.

Check my collection practices →