Australia flag

Australia

The 13 Australian Privacy Principles (APPs) Explained

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

The 13 Australian Privacy Principles (APPs) Explained

Frequently Asked Questions

Where are the 13 Australian Privacy Principles found in law?

The 13 APPs are set out in Schedule 1 of the Privacy Act 1988 (Cth). They were inserted by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth) and commenced on 12 March 2014, replacing the earlier National Privacy Principles and Information Privacy Principles. Because they sit in the Act, breaching an APP is an interference with the privacy of an individual under the Privacy Act.

Who has to comply with the Australian Privacy Principles?

The APPs bind 'APP entities', which means Australian Government agencies and 'organisations'. An organisation is generally a business that is not a small business operator. Agencies are broadly Commonwealth government departments and bodies established under federal law for a public purpose. The principles do not, on their own, bind state and territory government agencies, which are covered by separate state and territory privacy regimes. Those regimes vary. Most states and territories have privacy legislation, but South Australia's public sector is governed only by an administrative Cabinet instruction, Premier and Cabinet Circular PC012 (the Information Privacy Principles Instruction), rather than by statute.

Are small businesses bound by the APPs?

Generally no. A small business operator with annual turnover of A$3 million or less is usually exempt at the federal level. However, s 6D(4) sets out the categories bound regardless of turnover: businesses that provide a health service and hold health information other than in an employee record, businesses that disclose personal information for a benefit or provide a benefit to collect it, contracted service providers under a Commonwealth contract, and credit reporting bodies. Section 6E separately treats some small business operators as organisations for particular activities, including AML/CTF reporting entities, Consumer Data Right accredited entities and residential tenancy database operators. Holding tax file number information does not make a small business an APP entity; it makes the business a file number recipient bound by the Commissioner's rule under s 17. The OAIC supports removing the small business exemption. The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, released for consultation on 31 August 2026 with submissions closing 18 September 2026, is a proposal and would keep the exemption.

How are the 13 APPs grouped?

The OAIC groups the APPs into five Parts. Part 1 (APP 1-2) covers consideration of personal information privacy. Part 2 (APP 3-5) covers collection. Part 3 (APP 6-9) covers dealing with personal information, including use, disclosure, direct marketing, cross-border disclosure, and government related identifiers. Part 4 (APP 10-11) covers integrity, meaning quality and security. Part 5 (APP 12-13) covers access and correction.

What is the difference between APP 1 and an APP privacy policy?

APP 1 is the broader governance obligation to manage personal information openly and transparently and to maintain practices, procedures, and systems that ensure APP compliance. Having a clearly expressed and up-to-date APP privacy policy is one specific requirement within APP 1. The policy must describe matters such as the kinds of information collected, how it is collected and held, the purposes of use and disclosure, and how individuals can access, correct, or complain about their information. From 10 December 2026, APP 1.7 to 1.9 also require the policy to disclose significant automated decision-making that uses personal information, and a breach of APP 1.7 will be a civil penalty provision under s 13K(1)(b)(iia).

Which APP deals with data security and breaches?

APP 11 (security of personal information) requires an APP entity to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, and to destroy or de-identify it when it is no longer needed. Since 11 December 2024, APP 11.3 confirms that those reasonable steps include technical and organisational measures. APP 11 is the principle most frequently engaged in data breach enforcement, and it operates alongside the separate Notifiable Data Breaches scheme in the Privacy Act.

Do individuals have a right to access their information under the APPs?

Yes. APP 12 requires an APP entity to give an individual access to the personal information it holds about them on request, unless a specific exception applies, such as where access would pose a serious threat to life or health or unreasonably affect another person's privacy. APP 13 separately requires the entity to take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.

Who enforces the Australian Privacy Principles?

The Office of the Australian Information Commissioner (OAIC) administers and enforces the APPs. It handles complaints, can conduct investigations on its own initiative, and publishes the APP Guidelines explaining how it interprets each principle. The OAIC is the starting point for any individual who believes an APP entity has mishandled their personal information.

Updates

Corrected the APP 3 collection test to show that an agency may collect information reasonably necessary for, or directly related to, its functions while an organisation is limited to what is reasonably necessary; added APP 11.3 and APP 8.2(aa) and 8.3, all in force since 11 December 2024, and the APP 1.7 to 1.9 automated decision-making policy requirement commencing 10 December 2026; corrected the small business exception list to the exhaustive s 6D(4) categories, removed tax file number recipients from it and added the s 6E categories; and tightened the descriptions of APP 7, APP 9, APP 12 and APP 13 and the statutory definition of sensitive information.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Independently fact-checked against the cited primary sources

Sources and References

  1. Privacy Act 1988 (Cth), Schedule 1 (Australian Privacy Principles)(legislation.gov.au).gov
  2. OAIC, Australian Privacy Principles overview(oaic.gov.au).gov
  3. OAIC, APP Guidelines Chapter B: Key concepts (APP entity, agency, organisation, small business operator), version 1.4, 21 December 2022(oaic.gov.au).gov
  4. OAIC, Australian Privacy Principles quick reference(oaic.gov.au).gov
  5. OAIC, Australian Privacy Principles guidelines(oaic.gov.au).gov
  6. Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128, 2024, as made (APP 8.2(aa) and 8.3 and APP 11.3 in force 11 December 2024; APP 1.7-1.9 commencing 10 December 2026)(legislation.gov.au).gov
  7. Privacy Regulations 2025 (Cth), s 7 (residential tenancy database operators prescribed under s 6E(2) of the Privacy Act 1988)(legislation.gov.au).gov
  8. Attorney-General's Department, Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 (released 31 August 2026, submissions close 18 September 2026)(consultations.ag.gov.au).gov
Share: