Privacy Ready
← Learn

APP 4: Dealing with Unsolicited Personal Information

Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team

The short answer

Australian Privacy Principle 4 applies when your business receives personal information it did not request — a misdirected email, an unprompted résumé, a customer accidentally CC'd into a thread. You must first determine whether you could have lawfully collected that information under APP 3 had you sought it. If not, you must destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Governing provision Privacy Act 1988 (Cth), Schedule 1, APP 4
Trigger Receiving personal information you did not solicit
Test Could you have lawfully collected it under APP 3?
If no Destroy or de-identify it as soon as practicable
If yes It is then treated as if you had collected it — APPs 3, 5–13 apply

What counts as unsolicited information

Unsolicited personal information is information you receive without having taken any active step to collect it. Common small-business examples include a stray résumé sent to a general inbox for a role that was never advertised, a customer's email that includes personal details about a third party, or a document mistakenly sent to the wrong recipient.

APP 4.1 requires a two-step test. First, if your business had actively solicited the information, would APP 3 have allowed you to collect it? If yes, the information is treated as though you had solicited it, and the rest of the APPs — notification, use limitation, security, and so on — apply as normal. If no, APP 4.3 requires you to destroy or de-identify it, but only if it is lawful and reasonable to do so — for example, you would not destroy a document you are separately required to retain by another law.

Who this applies to

Any business with a general inbox, a shared mailbox, or a contact form is at some risk of receiving unsolicited personal information. It is a low-frequency but easy-to-overlook obligation.

Common SME failure modes

  • Retaining unsolicited résumés indefinitely "in case a role opens up," without applying the APP 3 lawfulness test or a defined retention period.
  • No process to identify unsolicited information — most small businesses have never considered this a distinct category from information they actively collected.
  • Forwarding or filing misdirected emails containing a third party's personal information without considering the destroy-or-de-identify obligation.

Practical compliance steps

  1. Set a simple internal rule: unsolicited personal information that you would not have been entitled to actively collect gets deleted promptly, not filed "just in case."
  2. For unsolicited job applications, decide upfront whether you will retain them for a defined period (e.g. genuinely under active consideration) or delete on receipt.
  3. Train staff who monitor general inboxes to recognise unsolicited personal information and apply the process consistently.
  4. Keep a short record of destruction for anything sensitive, in case you need to demonstrate compliance later.

Frequently asked questions

Someone emails our support inbox and mentions a friend's medical condition. What do we do?

That third party's health information is sensitive and you almost certainly could not have lawfully solicited it under APP 3 without their consent. Once you've dealt with the original enquiry, you should destroy or de-identify that detail as soon as practicable, unless retaining it is otherwise required by law.

Can we keep an unsolicited résumé for a role we might advertise in future?

If recruitment is a genuine function of your business, you may be able to justify retention under the APP 3 lawfulness test — but you should still notify the applicant under APP 5 and set a defined retention period rather than keeping it indefinitely.

What if deleting the information would breach another legal obligation?

APP 4.3 only requires destruction or de-identification where it is lawful and reasonable to do so. If another law requires you to retain the record — for example, certain financial or employment records — that obligation takes precedence, but you should still limit further use of the unsolicited information.

Use the free Unsolicited Information Check to see how APP 4 applies to the ways your business receives information it never asked for.

Check my APP 4 exposure →