Privacy Ready
Unsolicited Info Check · APP 4 dealing with unsolicited personal information

Do I Have to Destroy Information I Never Asked For?

Select the ways your business receives personal information it didn't request. Get an instant APP 4 check across 17 common Australian scenarios.

Under APP 4 of the Privacy Act 1988 (Cth), if your business receives personal information it didn't solicit, you must determine whether APP 3 would have let you collect it. If not — and no Commonwealth record or other lawful/reasonable retention basis applies — you must destroy or de-identify it as soon as practicable. Select the scenarios below to see what's required.

Last updated: 2 July 2026

How each scenario is scored

Result Meaning
Compliant APP 3 would have permitted collecting this information, a separate retention exception applies, or you already destroy/de-identify it as soon as practicable
Gap APP 3 wouldn't have permitted collecting this information, no retention exception applies, and you don't currently destroy or de-identify it

Why unsolicited information is easy to miss

APP 3 gets most of the attention because it governs what you actively ask for. APP 4 covers everything that lands in your business anyway — a misdirected email, a walk-in customer volunteering someone else's details, paperwork left in a returned product. None of it was solicited, but once you have it, the same obligations largely apply.

The default under APP 4.2 is destruction or de-identification as soon as practicable — not indefinite retention "just in case." The exceptions are narrow and specific: the information would have passed the APP 3 necessity test anyway, it's part of a Commonwealth record, or there's a genuine legal reason to keep it, such as an active investigation, a litigation hold, or a statutory recordkeeping obligation.

Free diagnostic tool

Unsolicited info check

Select every scenario where your business has received personal information it didn't ask for. For each one that isn't automatically exempt, tell us whether you currently destroy or de-identify it. You'll get an instant APP 4 report at a permanent URL you can revisit or share.

Which scenarios apply to your business?

Select all that apply. Where destruction or de-identification isn't automatically covered by an exception, tell us whether you currently do it.

Email & correspondence

Currently destroy or de-identify unsolicited information for Misdirected email naming an unrelated third party
Currently destroy or de-identify unsolicited information for Reply-all email disclosing a colleague's health information
Currently destroy or de-identify unsolicited information for Customer CCs an unrelated third party's contact details into a support thread

Customer service & returns

Currently destroy or de-identify unsolicited information for Paperwork left inside a returned product revealing the previous owner's details
Currently destroy or de-identify unsolicited information for Physical mail or a parcel misdelivered to your business address
Currently destroy or de-identify unsolicited information for Walk-in customer volunteers a neighbour or acquaintance's personal details unprompted

Recruitment

Currently destroy or de-identify unsolicited information for Unsolicited resume disclosing the applicant's medical condition
Currently destroy or de-identify unsolicited information for Referee unexpectedly emails a character reference containing criminal history details

Investigations & legal holds

Regulated retention

Currently destroy or de-identify unsolicited information for Supplier or invoice email mistakenly includes a third party's bank account details
Currently destroy or de-identify unsolicited information for Vendor document bundle mistakenly includes an individual's Tax File Number

When you need an unsolicited info check

  • You've never reviewed what happens to misdirected emails, mail or documents your business receives
  • You're newly covered by the Privacy Act following the 1 July 2026 threshold removal
  • Recruitment routinely receives unsolicited resumes and references
  • You're drafting or updating your privacy policy and need to document your APP 4 handling process
  • You're preparing for an OAIC inquiry or a compliance audit

Frequently asked questions

What does APP 4 of the Privacy Act require?

APP 4 requires a business that receives unsolicited personal information to determine whether it could have collected it under APP 3. If not, and no Commonwealth record or other lawful/reasonable basis for retention applies, it must be destroyed or de-identified as soon as practicable.

When can a business keep unsolicited personal information?

When APP 3 would have permitted collecting it if solicited (APP 4.3 then applies as normal), or when a separate lawful or reasonable basis exists, such as an active legal hold, whistleblower protection, or statutory recordkeeping obligation.

Does a misdirected email need to be deleted straight away?

If it contains information you had no reason to collect and no legal basis to keep, yes — APP 4.2 requires destruction or de-identification as soon as practicable, not indefinite retention.

What does the free unsolicited info check check?

It checks the scenarios you select against a catalogue of 17 common Australian scenarios, flagging which ones must be destroyed or de-identified under APP 4, and which can be retained.

Select your scenarios above to get an instant APP 4 unsolicited info report.

Get my unsolicited info report →