1. Who the Australian Privacy Principles apply to
  2. What the 13 Australian Privacy Principles require
    1. Governance and transparency
    2. Collection
    3. Use and disclosure
    4. Data integrity and individual rights
  3. Where businesses most commonly get it wrong
  4. How Artificer Legal can assist with privacy compliance
  5. The single most important thing to understand about the APPs

If your business collects a name, email address, or phone number from a customer — even through a basic contact form — the Australian Privacy Principles (APPs) are almost certainly relevant to what you do. They are not obscure compliance jargon reserved for large corporations. They are practical rules embedded in the Privacy Act 1988 (Cth) that govern how personal information must be handled across most Australian organisations.

This article explains what the APPs are, which businesses they apply to, what each of the 13 principles requires in practice, and where the most common mistakes occur. By the end, you will have a clear picture of what "good privacy" looks like day to day and what documents underpin it.

Who the Australian Privacy Principles apply to

The APPs apply to "APP entities" — a category that covers most Australian Government agencies and many private sector businesses. For private sector organisations, the primary threshold is an annual turnover of more than $3 million. Businesses at or below that figure are generally exempt, but the exemption has important carve-outs.

Even a small business under the $3 million threshold must comply with the APPs if it:

  • provides a health service (including allied health, complementary therapists, and private hospitals)
  • trades in personal information for a benefit, service, or advantage
  • holds accreditation under the Consumer Data Right system
  • is an employee association registered under the Fair Work (Registered Organisations) Act 2009

If none of those categories applies and your turnover is $3 million or below, you are technically outside the Act's mandatory scope. Even so, APP-style practices are increasingly treated as a baseline expectation by customers, banks, and commercial counterparties — and if you publish a privacy policy, the statements in it can still create enforceable obligations under Australian Consumer Law if they are misleading.

What the 13 Australian Privacy Principles require

The 13 APPs are grouped around four broad themes: governance and transparency (APPs 1–2), collection (APPs 3–5), use and disclosure (APPs 6–9), and data integrity and rights (APPs 10–13). Here is what each one means for a practical business operator.

Governance and transparency

APP 1 — Open and transparent management. You must have a current, accessible privacy policy that explains what personal information you collect, why you collect it, how it is used and disclosed, whether it goes overseas, and how individuals can access, correct, or complain about their information. The policy must reflect your actual practices, not a generic template.

Note: from 10 December 2026, APP 1 will also require disclosure of how automated decision-making systems use personal information in ways that could significantly affect individuals' rights or interests.

APP 2 — Anonymity and pseudonymity. Where it is reasonably practicable and lawful to do so, you must give individuals the option to deal with you without identifying themselves. A general website enquiry rarely needs a full name. If you genuinely require identification to deliver a service, you can require it — but you should say so and explain why.

Collection

APP 3 — Collection of solicited personal information. Only collect personal information that is reasonably necessary for your functions or activities. For sensitive information — which includes health data, biometric data, racial or ethnic origin, sexual orientation, criminal record, religious beliefs, and political opinions — you need the individual's consent before collecting it, unless a specific legal exception applies. Collect directly from the individual where possible.

APP 4 — Unsolicited personal information. If you receive personal information you did not ask for (for example, someone forwards you a detailed email about a third party), you must decide whether you could have collected it lawfully under APP 3. If not, you must destroy or de-identify it as soon as practicable, provided doing so is lawful and reasonable.

APP 5 — Notification of collection. At or shortly before the point of collection, you must take reasonable steps to notify individuals of the key details: who you are, why you are collecting the information, whether it is required by law, how it will be used or disclosed, and how they can access or correct it. A short, plain-English collection notice embedded in your web forms or onboarding flow meets this obligation.

Use and disclosure

APP 6 — Use or disclosure. Personal information can only be used or disclosed for the primary purpose for which it was collected, or for a secondary purpose that the individual would reasonably expect and that falls within a permitted exception. For sensitive information, secondary use generally requires consent. If your business wants to use customer data in a new way — for example, sharing a customer list with a marketing partner — you need to revisit your notices and, in many cases, obtain fresh consent.

APP 7 — Direct marketing. You may only use personal information for direct marketing if you have the individual's consent or another permitted basis, and you must always provide a clear and functional opt-out mechanism. Additional restrictions apply when you are using sensitive information or information sourced from a third party. This principle works alongside the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth), which impose separate consent and identification obligations.

APP 8 — Cross-border disclosure. Before disclosing personal information to an overseas recipient — including by routing data through an offshore cloud service, helpdesk tool, or CRM — you must take reasonable steps to ensure the overseas recipient will handle the information in a way that is at least substantially similar to the APPs. If an overseas recipient mishandles the data, your organisation remains accountable. Contractual privacy and security obligations in your vendor agreements are the standard mechanism for meeting this requirement.

APP 9 — Government related identifiers. You generally cannot adopt, use, or disclose a government-issued identifier (such as a Medicare number or Tax File Number) as your own internal customer identifier, except in strictly limited circumstances. Use your own unique identifiers for your systems.

Data integrity and individual rights

APP 10 — Quality of personal information. Take reasonable steps to ensure the personal information you collect, use, or disclose is accurate, up-to-date, and complete. This means building basic data quality checks into your processes — for example, prompting customers to confirm their contact details during annual renewals.

APP 11 — Security of personal information. Protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Technical measures (encryption, access controls, multi-factor authentication, regular patching) must be matched by administrative measures (staff training, need-to-know access policies, secure deletion procedures). When you no longer need information for any lawful purpose, you must take reasonable steps to destroy or de-identify it.

APP 12 — Access to personal information. Individuals have a right to request access to personal information you hold about them. You must have a process to verify identity, respond within a reasonable time, and provide the information in the format requested where practicable. If you refuse, you must explain the lawful basis for refusal and how the individual can complain.

APP 13 — Correction of personal information. If an individual tells you their personal information is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you must take reasonable steps to correct it. If you are not satisfied that correction is warranted, you must explain your reasons and tell the individual how they can complain.

Where businesses most commonly get it wrong

The APPs are principles-based, which gives businesses flexibility — but that same flexibility means mistakes often come from inattention rather than wilful non-compliance. The following patterns appear repeatedly in OAIC investigations and complaints.

Collecting more than you need. Forms tend to accumulate fields over time. Every field that captures personal information is a field that must be secured, maintained, and disclosed in your privacy policy. Challenge each one: if it is not genuinely necessary to deliver the service or meet a legal obligation, remove it.

Marketing without a proper basis. Many businesses assume that because a customer provided their email address at checkout, they have consented to receiving marketing. This is not necessarily the case. Consent for marketing needs to be informed and voluntary, distinct from the terms of the transaction. Sourcing a contact list from a third party does not transfer the original consent, and a blanket "by providing your details you agree to receive marketing" buried in terms and conditions is unlikely to satisfy the requirement.

Overlooking overseas disclosures. Using a US-based CRM, a Philippine-based customer support team, or a cloud storage provider with servers in Ireland is a cross-border disclosure for APP 8 purposes. Many businesses are unaware of where their data actually travels. Mapping your software stack and putting contractual safeguards in place with each vendor is not optional if you are an APP entity.

Weak security fundamentals. The OAIC consistently identifies shared passwords, unpatched software, absent multi-factor authentication, and inadequate staff training as factors in data breaches. APP 11 is not satisfied by purchasing security software — it requires documented procedures and trained people following them.

No plan for a data breach. Under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988, an APP entity that has reasonable grounds to believe an eligible data breach has occurred must notify the OAIC and affected individuals as soon as practicable. An eligible data breach is one that involves unauthorised access to or disclosure of personal information (or its likely loss) that is likely to result in serious harm. The entity generally has 30 days to complete its assessment. Businesses that discover a breach and do not have a response plan invariably take longer than they should, increasing both harm and regulatory exposure.

Applying the APPs to a real business involves judgement calls the article cannot make for you. Working out whether your collection practices satisfy APP 3, whether a particular overseas arrangement meets the APP 8 threshold, or whether a historical marketing list was lawfully obtained requires someone who understands the detail of your operations as well as the legal standard.

At Artificer Legal, we assist clients with:

  • Privacy policy drafting and review — ensuring your published policy accurately reflects your data practices and satisfies APP 1, rather than creating a misleading representation that could attract Australian Consumer Law liability alongside a privacy complaint
  • Collection notice design — drafting concise, timely notices that meet APP 5 at each collection point in your business (web forms, onboarding, intake, payments)
  • Vendor contract review — reviewing and negotiating data processing terms with offshore and domestic vendors to address APP 8 accountability
  • Data breach response planning — preparing a step-by-step internal playbook so that if an eligible data breach occurs, your team can contain, assess, and notify within the scheme's timeframes
  • Privacy program health checks — mapping what data you collect, where it flows, who has access, and whether your current practices align with the APPs

If you are unsure whether the Act applies to your business, or if you are an APP entity that has not yet reviewed your compliance position, an initial consultation is the right starting point.

The single most important thing to understand about the APPs

The Australian Privacy Principles are not a checklist you complete once. They are an ongoing obligation to handle personal information honestly, securely, and with respect for the individuals whose information you hold. Most compliance failures do not begin with a dramatic breach — they begin with a privacy policy that was never updated, a form that collects more than it needs, a vendor that was never asked how it handles your data, or a staff member who did not know what to do when something went wrong.

Key points to take away:

  • The $3 million annual turnover threshold exempts most small businesses from the Act, but health service providers, businesses that trade in personal information, and Consumer Data Right accredited entities are covered regardless of size
  • Sensitive information (health data, biometric data, racial origin, sexual orientation, religious beliefs, criminal record) requires consent to collect and attracts higher protection throughout the APPs
  • APP 8 accountability means overseas data flows through cloud tools and offshore vendors are your responsibility — document where data goes and put contractual protections in place
  • APP 11 requires both technical and administrative security measures; writing them down and training your team is part of compliance, not a bonus
  • Under the NDB scheme, an eligible data breach triggering likely serious harm must be assessed within 30 days and, if confirmed, notified to the OAIC and affected individuals promptly
  • A current, accurate privacy policy and timely collection notices at each data-gathering point are the foundation on which everything else rests