APP 3: Collection of Solicited Personal Information
Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team
Australian Privacy Principle 3 restricts how much personal information you can collect: you may only collect information reasonably necessary for, or directly related to, one or more of your business functions or activities, and only by lawful and fair means. Collecting sensitive information — such as health data, biometric data, or information about sexual orientation or religious belief — requires the individual's explicit consent, subject to narrow exceptions.
| Governing provision | Privacy Act 1988 (Cth), Schedule 1, APP 3 |
| Standard | Reasonably necessary for your functions, collected lawfully and fairly |
| Sensitive information | Requires explicit consent (APP 3.3), narrow exceptions apply |
| Applies to | Every collection of personal information, regardless of channel |
| Related principle | APP 5 requires you to notify at the point of collection |
What "reasonably necessary" means
APP 3 does not permit collecting information "just in case" it might be useful later. The test is whether the specific item of information is reasonably necessary for, or directly related to, a function or activity your business actually carries out. A booking form that asks for a customer's date of birth when it has no bearing on the booking is a common example of over-collection.
Sensitive information — defined in s 6 of the Act to include health, genetic, and biometric information, and information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record — attracts a stricter standard. APP 3.3 generally requires the individual's explicit consent to collect it, with limited exceptions such as where collection is required by law or necessary to lessen a serious threat to health or safety.
Who this applies to
Every APP entity, on every occasion it collects personal information — through forms, contracts, phone calls, in-person interactions, or automated capture such as cookies and analytics tools that identify individuals.
Common SME failure modes
- Over-collection on intake forms — asking for date of birth, gender, or occupation when none are relevant to the transaction.
- Collecting sensitive information without explicit consent — for example, a health or allied-health intake form that does not clearly seek consent before capturing health details.
- Unlawful or unfair collection methods — covert tracking, or collecting information through deception about the purpose.
- Treating "nice to have" marketing data as necessary — collecting broad demographic data for future, unspecified marketing use.
Practical compliance steps
- Review every form field you collect and ask: is this genuinely necessary for the function it supports?
- Remove optional-looking fields that aren't actually used for anything.
- For any sensitive information field, add a clear, separate consent mechanism — not a pre-ticked box buried in general terms.
- Document the business reason for each category of information you collect, so you can justify it if asked.
- Review data collected via cookies, analytics, and tracking pixels for the same necessity test.
Frequently asked questions
Can I collect information for future, unspecified marketing purposes?
Generally no — collection needs to relate to a current, identifiable function. Broad, speculative collection "in case it's useful" is difficult to justify under APP 3 and separately raises APP 6 use-limitation issues if you later use it for an unrelated purpose.
What counts as "sensitive information" in practice?
Under s 6 of the Privacy Act: health information, genetic information, biometric information, and information about racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, trade union membership, and criminal record. Any of these generally needs explicit consent to collect.
Does APP 3 apply to information I collect about employees?
Employee records held in connection with an employment relationship are subject to a specific exemption in some circumstances under s 7B of the Act (unconfirmed scope — check current OAIC guidance) — but this exemption is narrower than commonly assumed and does not cover, for example, information collected before the employment relationship begins.
Do I need consent to collect ordinary contact details like name and email?
No — consent is not generally required for non-sensitive personal information under APP 3. What is required is that the collection is reasonably necessary for your functions and that you notify the individual under APP 5.
Use the free Collection Necessity Check to see which of your data fields go beyond what APP 3 allows.
Check my collection practices →Explore more of the Privacy Act
- APP 1: Open and Transparent Management of Personal Information
- APP 2: Anonymity and Pseudonymity
- APP 4: Dealing with Unsolicited Personal Information
- APP 5: Notification of the Collection of Personal Information
- Does the Privacy Act Apply to My Australian Small Business?
- What Is ADM Disclosure and Does My Australian Business Need One?