APP 4: Dealing with Unsolicited Personal Information
Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team
Australian Privacy Principle 4 applies when your business receives personal information it did not request — a misdirected email, an unprompted résumé, a customer accidentally CC'd into a thread. You must first determine whether you could have lawfully collected that information under APP 3 had you sought it. If not, you must destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
| Governing provision | Privacy Act 1988 (Cth), Schedule 1, APP 4 |
| Trigger | Receiving personal information you did not solicit |
| Test | Could you have lawfully collected it under APP 3? |
| If no | Destroy or de-identify it as soon as practicable |
| If yes | It is then treated as if you had collected it — APPs 3, 5–13 apply |
What counts as unsolicited information
Unsolicited personal information is information you receive without having taken any active step to collect it. Common small-business examples include a stray résumé sent to a general inbox for a role that was never advertised, a customer's email that includes personal details about a third party, or a document mistakenly sent to the wrong recipient.
APP 4.1 requires a two-step test. First, if your business had actively solicited the information, would APP 3 have allowed you to collect it? If yes, the information is treated as though you had solicited it, and the rest of the APPs — notification, use limitation, security, and so on — apply as normal. If no, APP 4.3 requires you to destroy or de-identify it, but only if it is lawful and reasonable to do so — for example, you would not destroy a document you are separately required to retain by another law.
Who this applies to
Any business with a general inbox, a shared mailbox, or a contact form is at some risk of receiving unsolicited personal information. It is a low-frequency but easy-to-overlook obligation.
Common SME failure modes
- Retaining unsolicited résumés indefinitely "in case a role opens up," without applying the APP 3 lawfulness test or a defined retention period.
- No process to identify unsolicited information — most small businesses have never considered this a distinct category from information they actively collected.
- Forwarding or filing misdirected emails containing a third party's personal information without considering the destroy-or-de-identify obligation.
Practical compliance steps
- Set a simple internal rule: unsolicited personal information that you would not have been entitled to actively collect gets deleted promptly, not filed "just in case."
- For unsolicited job applications, decide upfront whether you will retain them for a defined period (e.g. genuinely under active consideration) or delete on receipt.
- Train staff who monitor general inboxes to recognise unsolicited personal information and apply the process consistently.
- Keep a short record of destruction for anything sensitive, in case you need to demonstrate compliance later.
Frequently asked questions
Someone emails our support inbox and mentions a friend's medical condition. What do we do?
That third party's health information is sensitive and you almost certainly could not have lawfully solicited it under APP 3 without their consent. Once you've dealt with the original enquiry, you should destroy or de-identify that detail as soon as practicable, unless retaining it is otherwise required by law.
Can we keep an unsolicited résumé for a role we might advertise in future?
If recruitment is a genuine function of your business, you may be able to justify retention under the APP 3 lawfulness test — but you should still notify the applicant under APP 5 and set a defined retention period rather than keeping it indefinitely.
What if deleting the information would breach another legal obligation?
APP 4.3 only requires destruction or de-identification where it is lawful and reasonable to do so. If another law requires you to retain the record — for example, certain financial or employment records — that obligation takes precedence, but you should still limit further use of the unsolicited information.
Use the free Unsolicited Information Check to see how APP 4 applies to the ways your business receives information it never asked for.
Check my APP 4 exposure →Explore more of the Privacy Act
- APP 1: Open and Transparent Management of Personal Information
- APP 2: Anonymity and Pseudonymity
- APP 3: Collection of Solicited Personal Information
- APP 5: Notification of the Collection of Personal Information
- Does the Privacy Act Apply to My Australian Small Business?
- What Is ADM Disclosure and Does My Australian Business Need One?