What is the Australian Privacy Act 1988, and how does it apply to you and your business?
The Australian Privacy Act 1988 is an act that helps protect individual privacy by regulating how personal data is collected, used, disclosed, processed, and stored. Personal data is defined as any information that can identify or be traced back to an individual, a full name, email address, or home address, for example.
It applies to most Australian, Australian Capital Territory, and Norfolk Island government agencies, as well as private or not-for-profit organisations with an annual turnover of $3 million or more, all private health service providers, and some small businesses.
Who It Applies To
Under the Privacy Act, an “organisation” is any of the following: an individual or sole trader, a corporate body, a partnership, any other unincorporated association, or a trust, unless they’re a small business operator, registered political party, state or territory authority, or a prescribed instrumentality of a state.
Small Businesses and the Privacy Act
Some small businesses with an annual turnover under $3 million are still covered, including:

- Health service providers (medical practitioners, pharmacists, private hospitals, naturopaths, chiropractors, gyms and weight loss centres, childcare centres, private schools and tertiary institutions)
- Any business that sells or purchases personal information
- Credit reporting bodies (organisations that report on an individual’s creditworthiness)
- Businesses that have opted in to the Privacy Act (which can help build customer trust)
- Businesses related to another business covered by the Act
- Businesses prescribed by the Privacy Regulation 2013
Some small businesses that don’t meet these requirements also choose to comply voluntarily, since it increases customer confidence and trust.
The Australian Privacy Principles (APPs)
There are 13 Australian Privacy Principles (APPs) under the Federal Privacy Act 1988, outlining how personal information must be handled in Australia. They’re legally binding and cover how and why a business collects data, how it’s used and disclosed, and how individuals can access and correct their information.
The 13 APPs are:
- APP 1: Open and transparent management of personal information
- APP 2: Anonymity and pseudonymity
- APP 3: Collection of solicited personal information
- APP 4: Dealing with unsolicited information
- APP 5: Notification of the collection of personal information
- APP 6: Use or disclosure of personal information
- APP 7: Direct marketing
- APP 8: Cross-border disclosure of personal information
- APP 9: Adoption, use, or disclosure of government-related identifiers
- APP 10: Quality of personal information
- APP 11: Security of personal information
- APP 12: Access to personal information
- APP 13: Correction of personal information
APP 1: Open and Transparent Management of Personal Information
Requires managing personal information in an “open and transparent” way, including having an up-to-date privacy policy written in plain language and readily available on your website. It must disclose what personal information you collect, how you collect it, your purposes for collecting/holding/using/disclosing it, how users can access and amend their information, how they can complain about a suspected privacy breach, and whether you disclose information overseas (and if so, where).
from iiNet’s privacy policy
APP 2: Anonymity and Pseudonymity
Individuals should generally have the option to use a pseudonym or not identify themselves, except where it’s impractical, or identity is required by law. In practice, this might mean allowing pseudonyms in comment sections or contact forms that don’t require a name or address.
APP 3: Collection of Solicited Personal Information
Personal information may only be collected where “reasonably necessary” for your business or website to function, and must relate to at least one business function. Sensitive information can only be collected with consent or where an exception applies, and must be collected lawfully, fairly, and directly from the individual unless collecting it from them isn’t practicable.
For example, it wouldn’t be reasonably necessary to request bank details to send a free sample, but it would be to process a purchase. Similarly, a date of birth isn’t necessary to process a payment, but would be if you offer a birthday bonus. Sensitive information (race, sexual orientation, criminal history, etc.) is treated differently from ordinary personal information.
APP 4: Dealing with Unsolicited Personal Information
Unsolicited personal information, anything received without your request, must be destroyed or de-identified as quickly as practicable, unless you could have collected it under APP 3 anyway.
APP 5: Notification of Collection of Personal Information
Requires a policy, your privacy policy, that discloses your identity and contact details, how and why you collect personal information, what it’s used for, how it’s kept secure, any third-party disclosure, whether you disclose it overseas, and the consequences if it isn’t collected. You must take reasonable steps to make this policy easy to find, such as a prominent, clearly labelled link.
from Telstra’s privacy policy
APP 6: Use or Disclosure of Personal Information
Personal information may only be used for the purpose it was collected for, unless: the individual consents to a secondary purpose, they’d reasonably expect that use, it’s required by law, it relates to a permitted health situation, or the secondary use is necessary for the activities of your business.
third parties TPG may disclose personal information to, from their privacy policy
APP 7: Direct Marketing
Personal information can only be used for direct marketing if the individual consents, or would reasonably expect it; and you must provide a simple opt-out, and honour it once used. Sensitive information can only be used for direct marketing with explicit consent.
Telstra Direct Marketing clause from their privacy policy
APP 8: Cross-Border Disclosure of Personal Information
Before disclosing personal information to an overseas recipient, you must take steps to ensure they won’t breach the Australian Privacy Principles, and the information can only be used for the purpose it was originally collected for.
Vodafone’s International Data Transfer clause from their privacy policy
APP 9: Adoption, Use, or Disclosure of Government-Related Identifiers
You generally can’t adopt, use, or disclose a government-related identifier (any number, letter, or symbol used to verify identity) unless an exception applies, a person’s name and their ABN are excluded from this restriction.
APP 10: Quality of Personal Information
Requires reasonable steps to ensure personal information is correct, up to date, complete, and relevant: meaning accurate and not misleading, current, presenting a full picture, and connected to the purpose it was collected for. Regular reviews help ensure this stays true over time.
APP 11: Security of Personal Information
Requires reasonable steps to protect stored personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Depending on your business size, this could include locked storage for physical documents, access restrictions on systems, limiting portable storage devices, encryption (including for emails containing personal information), confidentiality clauses with third parties who access the data, and security measures like HTTPS on your website. You also can’t hold personal information longer than necessary; it must be destroyed or de-identified once no longer required.
How Vodafone keeps your personal information secure from their Vodafone Privacy Policy
APP 12: Access to Personal Information
Requires giving individuals access to their own personal information on request, within a reasonable timeframe, without disclosing third-party information in the process. You can refuse in certain circumstances (for example, where disclosure would be unlawful), but must give written notice of the refusal and the reason.
APP 13: Correction of Personal Information
If an individual shows that information you hold about them is inaccurate, outdated, incomplete, or irrelevant, you must take reasonable steps to correct it and notify any third parties you’ve shared it with. If you refuse to correct it, you must provide written reasons, an explanation of how to complain, and a note that the individual disputes the accuracy of the information. Make it clear how users can contact you to access or correct their data.
iiNet’s correction of personal information clause from their privacy policy
Best Compliance Practices
- Collection of personal information: only collect what’s necessary for your website or business to function. Obtain it lawfully and fairly, directly from the individual where practical, and be clear about how you’ll use it.
- Obtaining consent: good practice generally, and required for sensitive or health-related information. A checkbox is the simplest way to obtain consent online. Consent should be informed, voluntary, specific to current circumstances, and given by someone with the capacity to understand and communicate it.
- Disclosing personal information overseas: make your best effort to ensure an overseas recipient will comply with the Privacy Act. Recipients in the US, UK, Canada, and Europe are generally considered lower-risk, given their own strict privacy regimes.
- Contact information: make it easy for users to reach you with requests, complaints, or correction requests. Include contact details in your privacy policy, and ideally on a dedicated contact page too.
Contact information in Telstra’s privacy policy
Australian Privacy Act Compliant Privacy Policy
If your business meets the Privacy Act’s requirements, or you choose to comply anyway to build trust with your users, you’ll need a compliant privacy policy. It should be placed prominently on your website (your site’s main menu is a good option) and cover:
- Your business name and contact details
- What personal data you collect, and how
- Why you collect it and how you use it
- Whether you disclose it to third parties, and which ones
- Whether you disclose it outside Australia, and to which countries
- How users can access their personal data
- How users can complain if they believe their data has been mishandled
If you change your data handling practices, update your privacy policy and notify your users.
To ensure your privacy policy complies with the Australian Privacy Principles, use our privacy policy generator.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.