Does My Privacy Policy Meet APP 1?
Select what your current privacy policy covers. Get an instant APP 1 check across 11 required elements.
Under APP 1 of the Privacy Act 1988 (Cth), a business must manage personal information in an open and transparent way. This means having a clearly expressed, up-to-date APP privacy policy — available free of charge — that covers everything APP 1.4 requires. From 10 December 2026, entities using automated decision-making must also disclose this in their policy under APP 1.3. Select what your current policy covers to see where the gaps are.
Last updated: 2 July 2026
How each element is scored
| Result | Meaning |
|---|---|
| Compliant | You've confirmed this element is covered in your current privacy policy |
| Gap | This element applies to your business, and it isn't confirmed as covered yet |
Why "we have a privacy policy" isn't the same as being APP 1 compliant
Most businesses that get asked about their privacy policy will say yes, they have one. Far fewer have checked it against what APP 1.4 actually requires it to say — the kinds of information collected, the purposes it's used for, how to access and correct it, how to complain, and whether it's disclosed overseas and to which countries. A generic template policy downloaded years ago frequently misses several of these, and almost never mentions automated decision-making.
APP 1.2 goes further than the document itself: it requires the internal practices, procedures and systems that make the policy true in practice, including a working process for handling privacy inquiries and complaints. And APP 1.3 requires the policy to stay current — a policy describing practices you changed two years ago is no longer "clearly expressed and up to date".
Privacy policy check
Select every element that applies to your business. For each one, tell us whether your current privacy policy already covers it. You'll get an instant APP 1 report at a permanent URL you can revisit or share.
When you need a privacy policy check
- — You've never checked your existing privacy policy against the APP 1.4 content requirements
- — You're newly covered by the Privacy Act following the 1 July 2026 threshold removal, and don't have a policy yet
- — Your policy doesn't mention automated decision-making, and your 10 December 2026 ADM disclosure deadline is approaching
- — You disclose personal information to overseas vendors — cloud storage, SaaS tools — but haven't stated this anywhere
- — You're preparing for an OAIC inquiry, a compliance audit, or a vendor due diligence questionnaire
Frequently asked questions
What does APP 1 of the Privacy Act require?
APP 1 requires a business to manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy that is free to access. From 10 December 2026, entities using automated decision-making must also disclose this in their policy under APP 1.3.
What must an APP privacy policy include?
Under APP 1.4, it must state the kinds of personal information collected and held, how it's collected and held, the purposes of collection, use and disclosure, how an individual can access and correct their information, how to complain about a breach, and whether information is likely disclosed overseas and to which countries.
Do I need a written privacy policy if I'm a small business?
If you're covered by the Privacy Act — including newly covered from 1 July 2026 — APP 1.3 requires a privacy policy regardless of business size. There's no small-business exemption from APP 1 once an entity is covered.
What does the free privacy policy check check?
It checks the elements you select as applicable against the content APP 1.4 requires, plus the governance and accessibility requirements in APP 1.2 and APP 1.5, flagging which are confirmed and which are gaps.
Select your policy elements above to get an instant APP 1 transparency report.
Get my privacy policy report →