Do I Have to Destroy Information I Never Asked For?
Select the ways your business receives personal information it didn't request. Get an instant APP 4 check across 17 common Australian scenarios.
Under APP 4 of the Privacy Act 1988 (Cth), if your business receives personal information it didn't solicit, you must determine whether APP 3 would have let you collect it. If not — and no Commonwealth record or other lawful/reasonable retention basis applies — you must destroy or de-identify it as soon as practicable. Select the scenarios below to see what's required.
Last updated: 2 July 2026
How each scenario is scored
| Result | Meaning |
|---|---|
| Compliant | APP 3 would have permitted collecting this information, a separate retention exception applies, or you already destroy/de-identify it as soon as practicable |
| Gap | APP 3 wouldn't have permitted collecting this information, no retention exception applies, and you don't currently destroy or de-identify it |
Why unsolicited information is easy to miss
APP 3 gets most of the attention because it governs what you actively ask for. APP 4 covers everything that lands in your business anyway — a misdirected email, a walk-in customer volunteering someone else's details, paperwork left in a returned product. None of it was solicited, but once you have it, the same obligations largely apply.
The default under APP 4.2 is destruction or de-identification as soon as practicable — not indefinite retention "just in case." The exceptions are narrow and specific: the information would have passed the APP 3 necessity test anyway, it's part of a Commonwealth record, or there's a genuine legal reason to keep it, such as an active investigation, a litigation hold, or a statutory recordkeeping obligation.
Unsolicited info check
Select every scenario where your business has received personal information it didn't ask for. For each one that isn't automatically exempt, tell us whether you currently destroy or de-identify it. You'll get an instant APP 4 report at a permanent URL you can revisit or share.
When you need an unsolicited info check
- — You've never reviewed what happens to misdirected emails, mail or documents your business receives
- — You're newly covered by the Privacy Act following the 1 July 2026 threshold removal
- — Recruitment routinely receives unsolicited resumes and references
- — You're drafting or updating your privacy policy and need to document your APP 4 handling process
- — You're preparing for an OAIC inquiry or a compliance audit
Frequently asked questions
What does APP 4 of the Privacy Act require?
APP 4 requires a business that receives unsolicited personal information to determine whether it could have collected it under APP 3. If not, and no Commonwealth record or other lawful/reasonable basis for retention applies, it must be destroyed or de-identified as soon as practicable.
When can a business keep unsolicited personal information?
When APP 3 would have permitted collecting it if solicited (APP 4.3 then applies as normal), or when a separate lawful or reasonable basis exists, such as an active legal hold, whistleblower protection, or statutory recordkeeping obligation.
Does a misdirected email need to be deleted straight away?
If it contains information you had no reason to collect and no legal basis to keep, yes — APP 4.2 requires destruction or de-identification as soon as practicable, not indefinite retention.
What does the free unsolicited info check check?
It checks the scenarios you select against a catalogue of 17 common Australian scenarios, flagging which ones must be destroyed or de-identified under APP 4, and which can be retained.
Select your scenarios above to get an instant APP 4 unsolicited info report.
Get my unsolicited info report →