How to Respond to a Customer's Privacy Access Request in Australia
Under APP 12 of the Privacy Act 1988 (Cth), individuals have the right to request access to personal information your business holds about them. You must respond within 30 days of receiving the request. A reasonable fee may be charged for providing access — but not for lodging the request. Access can only be refused on the specific grounds listed in APP 12.3, such as where providing access would unreasonably impact another individual's privacy.
| Relevant law | APP 12, Privacy Act 1988 (Cth) |
| Response deadline | 30 days from receiving the request |
| Fees | Reasonable cost of providing access only — not for lodging |
| Format | Preferred format of the individual must be considered |
| Grounds for refusal | Limited — specifically listed in APP 12.3 |
| Failure to respond | May constitute interference with privacy |
| Complaint pathway | OAIC at oaic.gov.au |
What triggers an access request?
Any communication from an individual asking what personal information your business holds about them activates an APP 12 obligation. It does not need to use formal language. An email saying "can you tell me what information you have on me?" or "can I see my customer file?" is an access request.
You should have a clear privacy contact point as required by APP 1 — but access requests sent to generic inboxes like info@ or hello@ still count as received once your team reads them.
What must you do within 30 days?
The 30-day clock starts when you receive the request. Within that window:
- Verify identity — take reasonable steps to confirm the person is who they claim to be before disclosing any data. For a known customer, confirming their account email and a security question is often sufficient.
- Locate the information — search all systems where you hold data about that individual: CRM, email history, accounting software, paper files, cloud storage, backups.
- Assess whether any exceptions apply — review the specific grounds for refusal in APP 12.3.
- Provide access in the preferred format — if the individual asks for a PDF or data export and it is reasonably practicable, provide it in that form.
- Respond in writing — even if declining access, you must respond in writing explaining which APP 12.3 exception applies.
When can you refuse to provide access?
APP 12.3 lists specific grounds for refusal. These are narrow:
- Providing access would pose a serious threat to life, health, or safety
- It would have an unreasonable impact on another individual's privacy
- The request is frivolous or vexatious
- The information relates to existing or anticipated legal proceedings and would not be discoverable in those proceedings
- Providing access would reveal a commercially sensitive decision-making process
- Access would be unlawful under another law
- Access would prejudice enforcement-related activities
"It would take too long" and "it's inconvenient" are not grounds for refusal. If you decline, you must tell the individual in writing which specific exception applies and advise them they can complain to the OAIC.
Can you charge a fee, and what format is required?
Yes, but only for the cost of providing access — not for receiving or processing the request. Reasonable fees reflect actual cost: time spent compiling records, photocopying, a nominal administration charge. Fees must not be set at a level that deters people from exercising their right. If you intend to charge, tell the individual the estimated fee upfront.
APP 12.5 requires you to provide access in the manner requested if it is reasonable and practicable. Common formats: a structured PDF summary of the records, a data export from your CRM, a printed letter. You are not required to build a custom report — providing accessible records in a usable form is sufficient.
Frequently asked questions
On what grounds can I refuse an access request (denial of access)?
Only the specific grounds listed in APP 12.3: a serious threat to life, health, or safety; an unreasonable impact on another individual's privacy; a frivolous or vexatious request; information relating to existing or anticipated legal proceedings that wouldn't be discoverable in those proceedings; revealing a commercially sensitive decision-making process; access being unlawful; or prejudice to enforcement-related activities. "It would take too long" or "it's inconvenient" are not valid grounds. If you refuse, you must tell the individual in writing which specific ground applies and that they can complain to the OAIC.
What is the response deadline for a privacy access request?
30 days from the date you receive the request. The 30-day limit is not extendable by choice — if you genuinely need more time, communicate with the individual promptly, explain why, and aim to provide at least a partial response within the 30 days. Silence generates more OAIC complaints than a late, communicated response.
Can I charge a fee to respond to an access request?
Yes, but only the reasonable cost of providing access — not for lodging or processing the request itself. Fees must reflect actual cost (time compiling records, photocopying, a nominal admin charge) and must not be set at a level that deters someone from exercising their rights. Tell the individual the estimated fee upfront if you intend to charge one.
What if the person asking has never been a customer — just someone who contacted us once?
The right applies to all personal information you hold about an individual, regardless of whether they are a current, former, or prospective customer. If you collected their name and email through a contact form and still hold it, they can request access. If you no longer hold the information, tell them that.
Can I ignore a request sent via social media or by phone?
No. The channel of communication does not change your obligation. A message received through Instagram or by telephone is still an access request. Acknowledge it and continue through a more secure channel for identity verification and data transfer if needed.
A customer wants their data deleted — does APP 12 cover that?
No. There is currently no standalone right to erasure in Australian privacy law equivalent to GDPR's Article 17. However, APP 11 requires you to destroy or de-identify information you no longer need for a permitted purpose. If you have no ongoing reason to retain the data, you should destroy it.
I genuinely cannot compile the data within 30 days. What do I do?
The 30-day limit is not extendable by choice. If you need more time, communicate with the individual immediately, explain the circumstances, and aim to provide at least a partial response within 30 days. Silence is the worst response — it is the basis of most access-related OAIC complaints.
Do we need to search archived emails and backups?
The APP 12 obligation applies to all personal information you "hold," which technically includes backups and archives. In practice, the OAIC's guidance on "reasonable steps" acknowledges that searching every backup may be disproportionate. Document the systems you searched and why, and be transparent with the requester about the scope.
Use the free Rights Request Response Letter Generator to build a ready-to-edit response letter with the correct APP 12 grounds already filled in.
Generate my response letter →