Australia
The 13 Australian Privacy Principles (APPs) Explained
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

The 13 Australian Privacy Principles (APPs) sit in Schedule 1 of the Privacy Act 1988 (Cth) and set the legal standards that bind APP entities when they handle personal information. They are principles-based, organised into five Parts, and enforced by the Office of the Australian Information Commissioner (OAIC).
For the wider framework, including penalties, the Notifiable Data Breaches scheme, the statutory tort, and pending reforms, see the Australia data privacy laws overview.
This reference page walks through the 13 APPs as they appear in Schedule 1, grouped the way the OAIC groups them. It covers who is bound, what each principle requires, and how the principles fit together, with a full table of all 13 at the end.
Where the APPs come from: Schedule 1 of the Privacy Act 1988
The 13 Australian Privacy Principles are contained in Schedule 1 of the Privacy Act 1988 (Cth). They were inserted by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth) and commenced on 12 March 2014, replacing the two earlier principle sets that had applied separately to the public and private sectors. Because the APPs sit in the Act itself, a breach of an APP is an interference with the privacy of an individual under the Privacy Act, which is what enlivens the OAIC's complaint, investigation, and enforcement powers.
The principles are deliberately drafted at a high level. The OAIC describes them as principles-based and technology-neutral, which means most obligations are framed around taking steps that are reasonable in the circumstances rather than prescribing exact procedures. The trade-off is flexibility for ongoing judgement: an entity must continually assess what is reasonable for its size, the sensitivity of the information, and the risk involved.
Who the APPs bind: APP entities
The APPs apply to APP entities. Under the Privacy Act 1988 (Cth), an APP entity is an agency or an organisation. An agency is broadly a Commonwealth (federal) government department or agency, or a body established under federal law for a public purpose. An organisation is an individual (such as a sole trader), body corporate, partnership, unincorporated association, or trust, that is not a small business operator, a registered political party, an agency, a state or territory authority, or a prescribed state or territory instrumentality.

The key threshold is the small business operator exemption. A small business operator generally has an annual turnover of A$3 million or less for a financial year and is therefore not an organisation and not bound by the APPs. The OAIC has long supported removing this exemption. On 31 August 2026 the Attorney-General's Department released the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 for consultation, with submissions closing on 18 September 2026. That is a proposal rather than law, and as drafted it keeps the small business exemption while rewriting APP 11 and APP 12 and proposing a new principle on destruction of personal information held by large digital platforms. The A$3 million threshold still applies at the federal level. Separately, the OAIC must register a Children's Online Privacy Code, a registered APP code covering online services likely to be accessed by children, by 10 December 2026 (Privacy Act s 26GC(10)).
Watch out: The small business exemption is riddled with exceptions, and several types of small business are bound by the APPs regardless of turnover. These include businesses that provide a health service and hold health information (other than in an employee record), businesses that trade in personal information (buy or sell it), credit reporting bodies, and contracted service providers under a Commonwealth contract. That list, in s 6D(4), is exhaustive. A clinic, allied health practice, or gym offering health services can be an APP entity even with turnover well below A$3 million.
Section 6E separately treats a small business operator as an organisation for particular activities: reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, protected action ballot agents, employee associations registered or recognised under the Fair Work (Registered Organisations) Act 2009, entities accredited under the Consumer Data Right, and residential tenancy database operators, who are prescribed for s 6E(2) by the Privacy Regulations 2025. Holding tax file number information does not make a small business an APP entity. It makes the business a file number recipient, bound by the rule the Commissioner issues under s 17, and a breach of that rule is an interference with privacy under s 13(4) rather than a breach of the APPs.
Part 1: Consideration of personal information privacy (APP 1-2)
The first Part is about governance and choice before any specific dealing with information. APP 1 (open and transparent management of personal information) requires an APP entity to manage personal information in an open and transparent way and to take reasonable steps to implement practices, procedures, and systems that ensure APP compliance and enable it to deal with related inquiries and complaints. APP 1 also requires a clearly expressed and up-to-date APP privacy policy describing how the entity handles personal information, and the entity must take reasonable steps to make that policy available free of charge and in a form that is appropriate (APP 1.5).
From 10 December 2026, APP 1.7 to 1.9 add an automated decision-making disclosure to that policy. They were inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1 Part 15, which commences on that date. Where an entity has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and personal information is used in the operation of that program, the policy must set out the kinds of personal information used, the kinds of such decisions made solely by the program, and the kinds of such decisions where the program does something substantially and directly related to the decision. Breaching APP 1.7 will be a civil penalty provision under s 13K(1)(b)(iia).
APP 2 (anonymity and pseudonymity) gives individuals the option of not identifying themselves, or of using a pseudonym, when dealing with an APP entity. The option does not apply where the entity is required or authorised by law (or a court or tribunal order) to deal with identified individuals, or where it is impracticable for the entity to deal with an unidentified or pseudonymous individual.
Part 2: Collection of personal information (APP 3-5)
Part 2 governs the front door, that is, how and when information may be collected. APP 3 (collection of solicited personal information) splits the collection test by entity type. If the entity is an agency, it must not collect personal information (other than sensitive information) unless the information is reasonably necessary for, or directly related to, one or more of its functions or activities (APP 3.1). If the entity is an organisation, the test is narrower: the information must be reasonably necessary for one or more of its functions or activities, with no 'directly related to' limb (APP 3.2). Most private-sector readers are organisations, so the narrower test is the one that applies to them.
Sensitive information needs the individual's consent as well as that necessity test, and the same agency and organisation split applies to it (APP 3.3(a)), unless one of the grounds in APP 3.4 applies. Section 6(1) defines sensitive information to include health information, genetic information, biometric information that is to be used for automated biometric verification or biometric identification, biometric templates, and information or opinions about racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, and criminal record. Biometric information collected for some other purpose is not sensitive information.
APP 4 (dealing with unsolicited personal information) applies when an entity receives personal information it did not ask for. The entity must decide whether it could have collected that information under APP 3. If it could not, and the information is not in a Commonwealth record, the entity must destroy or de-identify it as soon as practicable if lawful and reasonable to do so. APP 5 (notification of the collection of personal information) requires the entity, at or before collection (or as soon as practicable after), to take reasonable steps to notify the individual of specified matters, including the entity's identity and contact details, the purposes of collection, the consequences of not providing the information, any usual disclosures, and how the individual can access and correct their information or complain.
Part 3: Dealing with personal information (APP 6-9)
Part 3 is the largest grouping and covers what an entity may do with information once it holds it. APP 6 (use or disclosure of personal information) is the core limit: information collected for a primary purpose may generally only be used or disclosed for that purpose, unless the individual consents, or a secondary purpose applies that the individual would reasonably expect and that is related (or directly related, for sensitive information) to the primary purpose, or another exception applies.

APP 7 (direct marketing) provides that an organisation must not use or disclose personal information for direct marketing unless one of the exceptions in APP 7.2 to 7.5 applies. The two main exceptions, APP 7.2 and APP 7.3, require the organisation to provide a simple means of opting out. The exceptions for sensitive information used with the individual's consent (APP 7.4) and for a contracted service provider meeting an obligation under a Commonwealth contract (APP 7.5) carry no such condition. Separately, under APP 7.6 and 7.7 an individual may at any time ask not to receive direct marketing, or ask for the source of the information, free of charge, and the organisation must give effect to that request within a reasonable period. APP 8 (cross-border disclosure of personal information) requires an entity, before disclosing personal information to an overseas recipient, to take reasonable steps to ensure the recipient does not breach the APPs. Critically, an accountability rule in s 16C means the disclosing entity can be treated as responsible for the overseas recipient's acts. APP 8.1 does not apply where one of the grounds in APP 8.2 is met, most often where the entity reasonably believes the recipient is subject to a law or binding scheme that protects the information in a way that overall is at least substantially similar to the APPs and that the individual can enforce (APP 8.2(a)), or where the individual consents after being expressly told APP 8.1 will not apply (APP 8.2(b)). Since 11 December 2024, APP 8.2(aa) and APP 8.3 also switch APP 8.1 off where the recipient is subject to the laws of a country, or participates in a binding scheme, prescribed by regulations made under s 100(1A). The Privacy Regulations 2025 prescribe no country or scheme, so that mechanism is not yet available in practice. APP 9 (adoption, use or disclosure of government related identifiers) stops an organisation adopting a government related identifier (such as a tax file number or Medicare number) as its own identifier of the individual (APP 9.1). It separately restricts using or disclosing such an identifier at all, unless one of the exceptions in APP 9.2 applies, for example where the use or disclosure is reasonably necessary to verify the individual's identity or to meet an obligation to an agency or a State or Territory authority.
Part 4: Integrity of personal information (APP 10-11)
Part 4 is about keeping information accurate and secure. APP 10 (quality of personal information) requires an APP entity to take reasonable steps to ensure the personal information it collects is accurate, up to date, and complete, and that information it uses or discloses is, having regard to the purpose, accurate, up to date, complete, and relevant.
APP 11 (security of personal information) requires an entity to take reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. APP 11 also requires the entity to take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed under the APPs, and the information is not in a Commonwealth record or required to be retained by law. Since 11 December 2024, APP 11.3 states expressly that the reasonable steps required by APP 11.1 and 11.2 include technical and organisational measures. It was inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1 Part 5. APP 11 is the principle most often at the centre of data breach enforcement.
Part 5: Access to, and correction of, personal information (APP 12-13)
The final Part confers the two main individual rights inside the APPs. APP 12 (access to personal information) requires an APP entity to give an individual access to the personal information it holds about them on request, unless a specific exception applies (for example, where access would pose a serious threat to life, health, or safety, or unreasonably affect another person's privacy). An agency that refuses generally relies on Freedom of Information grounds (APP 12.2). On timing, an agency must respond to an access request within 30 days and an organisation within a reasonable period (APP 12.4(a)). On charges, an agency cannot charge at all (APP 12.7), while an organisation cannot charge for the making of the request and any charge for giving access must not be excessive (APP 12.8).
APP 13 (correction of personal information) requires an entity to take reasonable steps to correct personal information to ensure it is accurate, up to date, complete, relevant, and not misleading, either where the entity is satisfied it is inaccurate or where the individual requests correction. If the entity refuses, it must give written reasons and notify the individual of available complaint mechanisms, and, on request, take reasonable steps to associate a statement with the information that the individual believes it is inaccurate. The same response deadlines apply as for access: an agency must respond within 30 days and an organisation within a reasonable period, and neither may charge for the request (APP 13.5).
All 13 Australian Privacy Principles at a glance
| APP | Title | Part |
|---|---|---|
| APP 1 | Open and transparent management of personal information | 1: Consideration of privacy |
| APP 2 | Anonymity and pseudonymity | 1: Consideration of privacy |
| APP 3 | Collection of solicited personal information | 2: Collection |
| APP 4 | Dealing with unsolicited personal information | 2: Collection |
| APP 5 | Notification of the collection of personal information | 2: Collection |
| APP 6 | Use or disclosure of personal information | 3: Dealing with information |
| APP 7 | Direct marketing | 3: Dealing with information |
| APP 8 | Cross-border disclosure of personal information | 3: Dealing with information |
| APP 9 | Adoption, use or disclosure of government related identifiers | 3: Dealing with information |
| APP 10 | Quality of personal information | 4: Integrity |
| APP 11 | Security of personal information | 4: Integrity |
| APP 12 | Access to personal information | 5: Access and correction |
| APP 13 | Correction of personal information | 5: Access and correction |

The OAIC publishes detailed APP Guidelines that explain how each principle is interpreted in practice, and these are the starting point for any entity working out what reasonable steps look like for its own circumstances.
This page presents general legal information about the Australian Privacy Principles as set out in the Privacy Act 1988 (Cth). It is not legal advice. The law continues to evolve through reform and OAIC guidance, so consult a lawyer admitted in the relevant Australian jurisdiction for advice on your specific situation.
Frequently Asked Questions
Where are the 13 Australian Privacy Principles found in law?
The 13 APPs are set out in Schedule 1 of the Privacy Act 1988 (Cth). They were inserted by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth) and commenced on 12 March 2014, replacing the earlier National Privacy Principles and Information Privacy Principles. Because they sit in the Act, breaching an APP is an interference with the privacy of an individual under the Privacy Act.
Who has to comply with the Australian Privacy Principles?
The APPs bind 'APP entities', which means Australian Government agencies and 'organisations'. An organisation is generally a business that is not a small business operator. Agencies are broadly Commonwealth government departments and bodies established under federal law for a public purpose. The principles do not, on their own, bind state and territory government agencies, which are covered by separate state and territory privacy regimes. Those regimes vary. Most states and territories have privacy legislation, but South Australia's public sector is governed only by an administrative Cabinet instruction, Premier and Cabinet Circular PC012 (the Information Privacy Principles Instruction), rather than by statute.
Are small businesses bound by the APPs?
Generally no. A small business operator with annual turnover of A$3 million or less is usually exempt at the federal level. However, s 6D(4) sets out the categories bound regardless of turnover: businesses that provide a health service and hold health information other than in an employee record, businesses that disclose personal information for a benefit or provide a benefit to collect it, contracted service providers under a Commonwealth contract, and credit reporting bodies. Section 6E separately treats some small business operators as organisations for particular activities, including AML/CTF reporting entities, Consumer Data Right accredited entities and residential tenancy database operators. Holding tax file number information does not make a small business an APP entity; it makes the business a file number recipient bound by the Commissioner's rule under s 17. The OAIC supports removing the small business exemption. The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, released for consultation on 31 August 2026 with submissions closing 18 September 2026, is a proposal and would keep the exemption.
How are the 13 APPs grouped?
The OAIC groups the APPs into five Parts. Part 1 (APP 1-2) covers consideration of personal information privacy. Part 2 (APP 3-5) covers collection. Part 3 (APP 6-9) covers dealing with personal information, including use, disclosure, direct marketing, cross-border disclosure, and government related identifiers. Part 4 (APP 10-11) covers integrity, meaning quality and security. Part 5 (APP 12-13) covers access and correction.
What is the difference between APP 1 and an APP privacy policy?
APP 1 is the broader governance obligation to manage personal information openly and transparently and to maintain practices, procedures, and systems that ensure APP compliance. Having a clearly expressed and up-to-date APP privacy policy is one specific requirement within APP 1. The policy must describe matters such as the kinds of information collected, how it is collected and held, the purposes of use and disclosure, and how individuals can access, correct, or complain about their information. From 10 December 2026, APP 1.7 to 1.9 also require the policy to disclose significant automated decision-making that uses personal information, and a breach of APP 1.7 will be a civil penalty provision under s 13K(1)(b)(iia).
Which APP deals with data security and breaches?
APP 11 (security of personal information) requires an APP entity to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, and to destroy or de-identify it when it is no longer needed. Since 11 December 2024, APP 11.3 confirms that those reasonable steps include technical and organisational measures. APP 11 is the principle most frequently engaged in data breach enforcement, and it operates alongside the separate Notifiable Data Breaches scheme in the Privacy Act.
Do individuals have a right to access their information under the APPs?
Yes. APP 12 requires an APP entity to give an individual access to the personal information it holds about them on request, unless a specific exception applies, such as where access would pose a serious threat to life or health or unreasonably affect another person's privacy. APP 13 separately requires the entity to take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
Who enforces the Australian Privacy Principles?
The Office of the Australian Information Commissioner (OAIC) administers and enforces the APPs. It handles complaints, can conduct investigations on its own initiative, and publishes the APP Guidelines explaining how it interprets each principle. The OAIC is the starting point for any individual who believes an APP entity has mishandled their personal information.
Updates
Corrected the APP 3 collection test to show that an agency may collect information reasonably necessary for, or directly related to, its functions while an organisation is limited to what is reasonably necessary; added APP 11.3 and APP 8.2(aa) and 8.3, all in force since 11 December 2024, and the APP 1.7 to 1.9 automated decision-making policy requirement commencing 10 December 2026; corrected the small business exception list to the exhaustive s 6D(4) categories, removed tax file number recipients from it and added the s 6E categories; and tightened the descriptions of APP 7, APP 9, APP 12 and APP 13 and the statutory definition of sensitive information.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Independently fact-checked against the cited primary sources
Sources and References
- Privacy Act 1988 (Cth), Schedule 1 (Australian Privacy Principles)(legislation.gov.au).gov
- OAIC, Australian Privacy Principles overview(oaic.gov.au).gov
- OAIC, APP Guidelines Chapter B: Key concepts (APP entity, agency, organisation, small business operator), version 1.4, 21 December 2022(oaic.gov.au).gov
- OAIC, Australian Privacy Principles quick reference(oaic.gov.au).gov
- OAIC, Australian Privacy Principles guidelines(oaic.gov.au).gov
- Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128, 2024, as made (APP 8.2(aa) and 8.3 and APP 11.3 in force 11 December 2024; APP 1.7-1.9 commencing 10 December 2026)(legislation.gov.au).gov
- Privacy Regulations 2025 (Cth), s 7 (residential tenancy database operators prescribed under s 6E(2) of the Privacy Act 1988)(legislation.gov.au).gov
- Attorney-General's Department, Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 (released 31 August 2026, submissions close 18 September 2026)(consultations.ag.gov.au).gov