Privacy Ready
Privacy Policy Check · APP 1 open and transparent management

Does My Privacy Policy Meet APP 1?

Select what your current privacy policy covers. Get an instant APP 1 check across 11 required elements.

Under APP 1 of the Privacy Act 1988 (Cth), a business must manage personal information in an open and transparent way. This means having a clearly expressed, up-to-date APP privacy policy — available free of charge — that covers everything APP 1.4 requires. From 10 December 2026, entities using automated decision-making must also disclose this in their policy under APP 1.3. Select what your current policy covers to see where the gaps are.

Last updated: 2 July 2026

How each element is scored

Result Meaning
Compliant You've confirmed this element is covered in your current privacy policy
Gap This element applies to your business, and it isn't confirmed as covered yet

Why "we have a privacy policy" isn't the same as being APP 1 compliant

Most businesses that get asked about their privacy policy will say yes, they have one. Far fewer have checked it against what APP 1.4 actually requires it to say — the kinds of information collected, the purposes it's used for, how to access and correct it, how to complain, and whether it's disclosed overseas and to which countries. A generic template policy downloaded years ago frequently misses several of these, and almost never mentions automated decision-making.

APP 1.2 goes further than the document itself: it requires the internal practices, procedures and systems that make the policy true in practice, including a working process for handling privacy inquiries and complaints. And APP 1.3 requires the policy to stay current — a policy describing practices you changed two years ago is no longer "clearly expressed and up to date".

Free diagnostic tool

Privacy policy check

Select every element that applies to your business. For each one, tell us whether your current privacy policy already covers it. You'll get an instant APP 1 report at a permanent URL you can revisit or share.

Which elements apply to your business?

Select all that apply, then tell us whether your current policy already covers each one.

Core policy content (APP 1.4)

The kinds of personal information you collect and hold is currently covered
How you collect and hold personal information is currently covered
The purposes you collect, hold, use and disclose personal information for is currently covered
How an individual can access their information and seek its correction is currently covered
How an individual can complain about a breach of the APPs, and how you'll handle that complaint is currently covered

Conditional disclosures

Whether personal information is likely to be disclosed overseas, and to which countries is currently covered
Which decisions use automated decision-making (ADM), and what personal information they rely on is currently covered

Governance & accessibility (APP 1.2, 1.5)

A privacy policy is actually published and publicly available is currently covered
Internal practices, procedures and systems exist to comply with the APPs and handle privacy inquiries or complaints is currently covered
The policy is free to access, in an easily accessible form is currently covered
The policy is reviewed and updated whenever your data practices change is currently covered

When you need a privacy policy check

  • You've never checked your existing privacy policy against the APP 1.4 content requirements
  • You're newly covered by the Privacy Act following the 1 July 2026 threshold removal, and don't have a policy yet
  • Your policy doesn't mention automated decision-making, and your 10 December 2026 ADM disclosure deadline is approaching
  • You disclose personal information to overseas vendors — cloud storage, SaaS tools — but haven't stated this anywhere
  • You're preparing for an OAIC inquiry, a compliance audit, or a vendor due diligence questionnaire

Frequently asked questions

What does APP 1 of the Privacy Act require?

APP 1 requires a business to manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy that is free to access. From 10 December 2026, entities using automated decision-making must also disclose this in their policy under APP 1.3.

What must an APP privacy policy include?

Under APP 1.4, it must state the kinds of personal information collected and held, how it's collected and held, the purposes of collection, use and disclosure, how an individual can access and correct their information, how to complain about a breach, and whether information is likely disclosed overseas and to which countries.

Do I need a written privacy policy if I'm a small business?

If you're covered by the Privacy Act — including newly covered from 1 July 2026 — APP 1.3 requires a privacy policy regardless of business size. There's no small-business exemption from APP 1 once an entity is covered.

What does the free privacy policy check check?

It checks the elements you select as applicable against the content APP 1.4 requires, plus the governance and accessibility requirements in APP 1.2 and APP 1.5, flagging which are confirmed and which are gaps.

Select your policy elements above to get an instant APP 1 transparency report.

Get my privacy policy report →