If your organisation collects customer details, stores employee records, sends marketing messages, uses cloud software or responds to requests for personal information, privacy is already part of everyday business.
At the centre of Australia's federal privacy framework are the Australian Privacy Principles, usually called the APPs.
There are 13 APPs. They form part of the Privacy Act 1988 and set standards for how organisations and Australian Government agencies covered by the Act manage personal information. They address everything from collecting information and explaining why it is needed to using, disclosing, securing, accessing and correcting it.
The Australian Privacy Principles are administered by the Office of the Australian Information Commissioner, or OAIC. They are principles-based rather than a rigid set of one-size-fits-all procedures, which means their practical application depends on the circumstances.
This guide explains who the APPs apply to, what each of the 13 principles covers, and what they can mean in everyday Australian organisational practice.
What Are the Australian Privacy Principles?
The Australian Privacy Principles are 13 legally recognised privacy principles contained in Schedule 1 of the Privacy Act 1988.
Together, they regulate important stages in the handling of personal information, including:
-
privacy governance and transparency;
-
collection of personal information;
-
use and disclosure;
-
direct marketing;
-
overseas disclosure;
-
information quality and security; and
-
individual access and correction rights.
The OAIC describes the APPs as principles-based and technology-neutral. This is important.
They do not prescribe an identical privacy process for every business. Instead, organisations and agencies covered by the Act need to apply the principles to their own activities, systems, risks and information-handling practices. A retailer, health provider and technology company may therefore have very different operational controls while still working within the same APP framework.
The technology-neutral approach also means the principles are not restricted to paper records, traditional databases or any particular generation of technology. They can apply as information-handling practices evolve.
The OAIC's Australian Privacy Principles Guidelines provide detailed regulatory guidance on how each APP operates.
What is the difference between the Privacy Act and the APPs?
The terms are closely connected, but they do not mean exactly the same thing.
The Privacy Act 1988 is the broader Commonwealth legislation. It contains the Australian Privacy Principles as well as other privacy rules, powers, definitions and regulatory mechanisms.
The APPs are the 13 principles within that framework dealing specifically with how APP entities manage personal information.
In simple terms:
Privacy Act 1988 = the wider federal privacy framework
Australian Privacy Principles = 13 core personal-information handling principles within that framework
That distinction matters because complying with the APPs does not necessarily describe every privacy obligation an organisation may have. Other provisions of the Privacy Act, sector-specific requirements and state or territory laws may also be relevant.
Businesses following broader reform developments can read ACT's guide to Australia’s evolving privacy laws rather than treating this APP guide as a complete account of every privacy-law change.
Who Must Follow the Australian Privacy Principles?
The APPs apply to APP entities.
Broadly, this includes Australian Government agencies and organisations that are covered by the Privacy Act. Whether a particular private-sector organisation is covered depends on the Act's scope rules.
For many businesses, annual turnover is an important starting point. The OAIC states that most businesses with annual turnover of more than $3 million are covered by the Privacy Act.
But turnover is not the whole test.
Some businesses with annual turnover of $3 million or less are also covered. According to the OAIC guidance for small businesses, examples include certain businesses that:
-
provide health services;
-
trade in personal information;
-
provide services under a Commonwealth contract;
-
operate a residential tenancy database;
-
participate in credit reporting;
-
are reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 in relation to activities connected with their AML/CTF obligations;
-
are accredited under the Consumer Data Right system;
-
are related to a business already covered by the Privacy Act; or
-
have opted into Privacy Act coverage.
That makes the question “Does our turnover exceed $3 million?” useful, but not sufficient by itself.
An organisation also needs to consider what it does, the information it handles and whether any specific rule brings it within the Privacy Act.
Do the APPs apply to small businesses?
Not every Australian small business is automatically covered.
The OAIC defines a small business for these purposes as one with annual turnover of $3 million or less. Most small businesses are not covered by the Privacy Act, but important exceptions apply.

For example, a small private health service provider may be covered regardless of turnover. The same can apply to businesses that trade in personal information or undertake particular regulated activities.
Small businesses can also choose to opt into the Privacy Act.
The practical point is simple: do not decide privacy coverage from business size alone.
If there is uncertainty, organisations can use the OAIC's small-business privacy checklist and seek appropriate professional advice about their circumstances.
Employers also need to understand how privacy obligations interact with workplace information. ACT covers that implementation angle separately in its Privacy Act compliance checklist for Australian employers.
The 13 Australian Privacy Principles at a Glance
The 13 APPs follow the lifecycle of personal information, from privacy governance and collection through to use, security, access and correction.
Here is a practical overview.
|
APP |
What it covers |
Simple example |
|
APP 1 |
Open and transparent management of personal information |
Maintaining a clearly expressed, current privacy policy |
|
APP 2 |
Anonymity and pseudonymity |
Allowing a general enquiry without requiring identification where the principle permits |
|
APP 3 |
Collection of solicited personal information |
Collecting information that is reasonably necessary for the organisation's functions or activities |
|
APP 4 |
Unsolicited personal information |
Assessing information received unexpectedly and deciding whether it may be retained |
|
APP 5 |
Notification of collection |
Telling people relevant information when their personal information is collected |
|
APP 6 |
Use or disclosure |
Considering whether information may be used or disclosed for a particular purpose |
|
APP 7 |
Direct marketing |
Applying privacy requirements when personal information is used for direct marketing |
|
APP 8 |
Cross-border disclosure |
Addressing privacy responsibilities before disclosing personal information overseas |
|
APP 9 |
Government-related identifiers |
Restricting adoption, use and disclosure of government-related identifiers |
|
APP 10 |
Quality of personal information |
Taking reasonable steps to keep relevant information accurate and up to date |
|
APP 11 |
Security of personal information |
Protecting information and appropriately dealing with information that is no longer needed |
|
APP 12 |
Access to personal information |
Responding when an individual asks to access personal information held about them |
|
APP 13 |
Correction of personal information |
Correcting information that is inaccurate, out of date, incomplete, irrelevant or misleading where required |
The OAIC's Australian Privacy Principles quick reference provides an official summary of each principle.
The value of looking at the APPs together is that privacy compliance stops looking like 13 unrelated rules. Instead, the principles form a connected system for managing information throughout its lifecycle.
How the 13 APPs Work Across the Personal Information Lifecycle

The structure of the APPs follows five broad stages: privacy governance, collection, dealing with information, information integrity, and access and correction.
Understanding that structure makes the individual principles easier to apply.
Privacy Governance: APP 1 and APP 2
APP 1: Open and transparent management of personal information
APP 1 establishes the governance foundation for the rest of the APPs.
An APP entity must take reasonable steps to implement practices, procedures and systems that support compliance with the APPs and any registered APP code that binds it. It must also be able to deal with privacy-related enquiries and complaints.
APP 1 also requires an APP entity to maintain a clearly expressed and up-to-date APP privacy policy.
That policy needs to address matters specified by the principle, including the kinds of personal information the entity collects and holds, how it collects and holds that information, its purposes for doing so, and how individuals can seek access, correction or make a complaint.
The practical point is that privacy should be managed as an organisational process, not simply as a policy document published once and forgotten.
There is also an important upcoming change. From 10 December 2026, additional APP 1 transparency requirements apply where specified conditions involving certain computer-assisted decisions and personal information are met. The OAIC has published updated APP 1 guidance explaining those requirements.
APP 2: Anonymity and pseudonymity
APP 2 addresses a simple question: does the organisation actually need to know who the person is?
Where APP 2 applies, individuals must generally have the option of dealing with an APP entity anonymously or by using a pseudonym. Exceptions apply, including circumstances where identification is legally required or where it would be impracticable for the organisation to deal with an unidentified person.
A practical example might be a person making a general enquiry about a service. If no identification is necessary to answer the question, collecting a full name, date of birth and contact details may not be appropriate simply because an online form happens to ask for them.
The principle encourages organisations to think about identification as a business and privacy decision rather than an automatic default.
Collecting Personal Information: APP 3, APP 4 and APP 5
Collection is not just about where information comes from. The APPs also address whether information should be collected, what happens when it arrives unexpectedly, and what individuals should be told.
APP 3: Collection of solicited personal information
APP 3 deals with personal information that an APP entity actively solicits.
For organisations, a central requirement is that collection must generally be reasonably necessary for one or more of the entity's functions or activities. Australian Government agencies operate under a related test based on whether information is reasonably necessary for, or directly related to, their functions or activities.
APP 3 also places higher requirements around the collection of sensitive information, including circumstances in which consent is required.
The OAIC's 2026 update to its APP 3 guidance places renewed attention on contemporary collection practices and the importance of considering whether information is genuinely necessary.
That makes data minimisation a useful practical discipline even though organisations still need to assess their exact legal obligations under the principle.
For example, a recruitment form should collect information genuinely relevant to the recruitment process rather than asking applicants for unrelated personal details simply because the system allows additional fields.
APP 4: Dealing with unsolicited personal information
Not all personal information arrives because an organisation asked for it.
A customer might send extra medical information in an email. A job applicant might attach records that were never requested. Someone may copy an organisation into correspondence containing another person's details.
APP 4 explains how APP entities should deal with unsolicited personal information.
Broadly, the organisation needs to assess whether it could have collected that information under APP 3 if it had solicited it. If the relevant requirements are not met, the entity may need to destroy or de-identify the information where it is lawful and reasonable to do so.
The operational lesson is useful: receiving information does not automatically mean an organisation should keep it indefinitely or add it to a permanent record.
APP 5: Notification of the collection of personal information
APP 5 focuses on transparency when personal information is collected.
An APP entity must take reasonable steps, either before or at the time of collection, or as soon as practicable afterwards, to notify the individual of specified matters or otherwise ensure the individual is aware of them.
Depending on the circumstances, those matters can include the entity's identity and contact details, the purposes of collection, usual disclosures and information about access, correction and complaints.
This is where a collection notice often becomes important.
A collection notice and a privacy policy are not the same thing.
APP 1 deals with the organisation's broader privacy policy. APP 5 deals with information that should be brought to someone's attention in connection with a particular collection.
For example, an online registration form may need an appropriate collection notice even though the organisation already has a comprehensive privacy policy elsewhere on its website.
Using and Sharing Personal Information: APP 6 to APP 9
Once personal information has been collected, the next question is what can be done with it.
APP 6: Use or disclosure of personal information
APP 6 regulates the use and disclosure of personal information.
A central concept is the primary purpose for which the information was collected. If an APP entity wants to use or disclose the information for a different, or secondary, purpose, it needs to consider whether the principle permits that use or disclosure.
Consent can be relevant, as can other circumstances recognised by the Privacy Act. The exact analysis depends on the situation.
A simple business example is customer contact information.
If details were collected to process and deliver a particular service, that does not mean they can automatically be used for every unrelated purpose the organisation later identifies.
For employees, managers and operational teams, this makes understanding the purpose of collection particularly important. People handling data should not assume that internal access automatically creates permission for any subsequent use.
APP 6 is one reason privacy needs to be considered throughout the information lifecycle, rather than only at the point where data enters the organisation.
APP 7: Direct marketing
APP 7 deals specifically with the use or disclosure of personal information for direct marketing.
Different requirements can apply depending on the type of information involved, how it was collected and whether the individual would reasonably expect it to be used for direct marketing.
The principle also contains opt-out requirements.
For businesses, this means marketing activity should not be treated as entirely separate from privacy governance. Customer lists, CRM records and other personal information used for promotional activity can trigger privacy considerations.
APP 7 also sits alongside other Australian laws that may regulate particular communication methods. Those separate requirements are beyond the scope of this APP guide.
The key point here is narrower: using personal information for direct marketing requires organisations to consider the conditions in APP 7 rather than assuming that possessing a person's contact details automatically makes every marketing use acceptable.
APP 8: Cross-border disclosure of personal information
Modern organisations frequently work with overseas providers, parent companies, contractors and technology platforms.
APP 8 deals with the cross-border disclosure of personal information.
Before an APP entity discloses personal information about an individual to an overseas recipient, the principle generally requires it to take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information, subject to specified exceptions.
The Privacy Act can also make the Australian entity accountable in certain circumstances for conduct by an overseas recipient.
This makes APP 8 relevant well beyond traditional international data transfers. An Australian organisation using an overseas provider may need to understand where personal information is being disclosed and how the arrangement is governed.
Cloud services and AI platforms can make those questions more complex. ACT explores that intersection separately in privacy and AI governance in Australia rather than expanding it into a separate AI compliance guide here.
APP 9: Government-related identifiers
APP 9 restricts when organisations may adopt, use or disclose government-related identifiers.
These identifiers can include numbers or other identifiers assigned by government bodies for particular purposes.
The basic privacy concern is straightforward: a government identifier should not simply become a universal organisational identifier because it is convenient.
The principle contains circumstances in which adoption, use or disclosure may be permitted, so organisations should assess the specific legal position rather than applying a blanket rule.
For most businesses, APP 9 will arise less frequently than principles covering collection, disclosure or security. But where government identifiers are handled, staff and systems should recognise that these identifiers require particular care.
Keeping Personal Information Accurate and Secure: APP 10 and APP 11
Collecting information lawfully is only part of privacy management. Information also needs to remain fit for the purposes for which it is used and appropriately protected.
APP 10: Quality of personal information
APP 10 requires APP entities to take reasonable steps to ensure that personal information they collect is accurate, up to date and complete.
When information is used or disclosed, the organisation must take reasonable steps to ensure that it is accurate, up to date, complete and relevant, having regard to the purpose of that use or disclosure.
The practical significance is easy to see.
An outdated address might send confidential correspondence to the wrong place. An incorrect customer record might affect a decision. Old information copied across systems may continue influencing outcomes long after it stopped being accurate.
APP 10 therefore connects privacy with information quality.
Reasonable steps will vary with the circumstances. Information used for a significant decision may justify stronger quality controls than information with little potential impact.
Access and correction processes under APP 12 and APP 13 can also help organisations maintain information quality over time.
APP 11: Security of personal information
APP 11 is the main APP dealing with personal information security.
It requires APP entities to take reasonable steps to protect personal information they hold from misuse, interference and loss, and from unauthorised access, modification or disclosure.
The OAIC explains that reasonable steps include both technical and organisational measures. Security therefore goes beyond cybersecurity software. Governance, staff practices, access controls, third-party arrangements, physical security and information disposal can all matter.
APP 11 also addresses information an entity no longer needs.
Subject to the principle's conditions and exceptions, an APP entity must take reasonable steps to destroy or de-identify personal information that is no longer needed for a purpose for which it may be used or disclosed.
For example, a business may restrict access to customer records according to staff roles while also having processes for securely disposing of information it no longer needs and is not legally required to retain.
Financial-sector organisations dealing with overlapping regulatory obligations can explore ACT's discussion of privacy, security and CPS 234.
Individual Access and Correction: APP 12 and APP 13
The final two principles give individuals important mechanisms for understanding and correcting information held about them.
APP 12: Access to personal information
APP 12 deals with requests by individuals to access personal information held about them.
For organisations, the principle generally requires access to be given on request unless an exception applies. Australian Government agencies operate under related APP requirements alongside other access frameworks.
APP 12 also contains procedural requirements around responding to requests.
This means an access request should not be treated as an unusual administrative inconvenience. Organisations covered by the Privacy Act should have a way to recognise, direct and manage these requests appropriately.
Imagine a customer asking, “What personal information do you hold about me?”
The person receiving that enquiry does not need to improvise a privacy-law response on the spot. But they should know enough to recognise that the request may engage a formal privacy process and direct it correctly.
That is where clear procedures and staff awareness become important.
APP 13: Correction of personal information
APP 13 complements access rights by dealing with correction.
An APP entity must take reasonable steps to correct personal information where required under the principle, including where the entity is satisfied that information it holds is inaccurate, out of date, incomplete, irrelevant or misleading, having regard to the purpose for which it is held.
Individuals can also request correction.
For example, a customer might discover that an organisation holds an incorrect address, an outdated surname or another inaccurate detail. APP 13 provides a framework for dealing with that situation.
Correction is not simply an administrative courtesy. Accurate records support fairer decisions, better communication and stronger information governance.
The OAIC's APP 13 correction guidance explains the principle and its procedural requirements in greater detail.
What Do the APPs Look Like in Everyday Business Practice?

The APPs become easier to understand when they are connected to routine business activity.
A customer-service employee collecting contact details, a marketing team preparing a campaign, an HR team receiving an unexpected document and an IT team managing access to a database may all encounter different parts of the same privacy framework.
Here are some common situations.
|
Business situation |
Relevant APPs |
Useful privacy question |
|
Collecting customer details |
APP 3 and APP 5 |
Do we need this information, and have we properly explained the collection? |
|
Receiving unexpected personal information |
APP 4 |
Should we keep this information, and are we permitted to do so? |
|
Using information for a new purpose |
APP 6 |
Is this use consistent with the original purpose or otherwise permitted? |
|
Direct marketing |
APP 7 |
Are the relevant privacy conditions and opt-out requirements being followed? |
|
Using an overseas service provider |
APP 8 |
Have we considered our cross-border privacy responsibilities? |
|
Maintaining customer records |
APP 10 and APP 11 |
Is the information accurate, appropriately protected and retained only as required? |
|
Receiving an access or correction request |
APP 12 and APP 13 |
Do staff know how to recognise and direct the request? |
This is why privacy compliance rarely belongs to one person alone.
Legal and compliance teams may oversee the framework, but information is handled by people across marketing, HR, customer service, IT, operations and management. Their day-to-day decisions can affect how APP obligations are met.
Employers looking specifically at workplace implementation can use ACT's Privacy Act compliance checklist for Australian employers rather than relying on this general APP overview.
Training can also help teams understand how the principles connect to their roles. ACT's Privacy & AI Governance: Complying with the Privacy Act course covers APP governance and wider privacy considerations for professionals who need a more structured understanding of the framework.
The goal is not for every employee to become a privacy lawyer. It is for people handling personal information to recognise where privacy questions arise and know how the organisation expects them to respond.
Do the Australian Privacy Principles Apply to AI and Automated Decisions?
Yes, the APP framework can apply when an APP entity uses AI or automated systems to handle personal information.

Using AI does not create a separate zone outside ordinary privacy obligations.
Depending on how a system works, principles relating to privacy governance, collection, use and disclosure, overseas disclosure, information quality and security may all become relevant.
For example, an organisation may need to consider:
-
what personal information is being collected or entered into an AI system;
-
whether that information is reasonably necessary;
-
whether a proposed use is consistent with the purpose for which the information was collected;
-
whether information is disclosed to an overseas recipient;
-
whether information used in decision-making is sufficiently accurate; and
-
whether appropriate security measures protect the information.
There is also a specific upcoming transparency change.
The OAIC states that from 10 December 2026, APP entities must include prescribed information in their privacy policy where they have arranged for a computer program to make, or substantially and directly assist in making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and personal information about the individual is used in operating that program.
The OAIC guidance on automated decision-making transparency explains the change.
AI privacy involves much more than that one amendment. Rather than duplicating the wider subject here, ACT's Privacy & AI Governance in Australia: Complying with the Privacy Act examines the intersection in greater depth.
Understanding the APPs Is Only the First Step
The Australian Privacy Principles provide a framework for managing personal information from the moment an organisation considers collecting it through to its eventual use, disclosure, protection, access, correction and, where appropriate, disposal.
Knowing the names of the 13 APPs is useful. Applying them consistently is the harder part.
That depends on translating legal obligations into practical systems: sensible collection practices, clear notices, privacy policies, access controls, escalation processes, staff awareness and decisions about when information should or should not be used.
The details will differ between organisations. That is one reason the APP framework is principles-based rather than a single procedural checklist.
Businesses should continue to use current OAIC guidance and obtain appropriate advice where the application of the Privacy Act to a particular situation is uncertain.
Professionals who need a more structured introduction to APP governance, privacy controls and emerging AI-related issues can explore ACT's Privacy & AI Governance: Complying with the Privacy Act course.
For readers interested in building privacy responsibility into a specialist role, ACT also has a separate guide on how to become a Data Privacy Officer in Australia.
The main point is straightforward: the APPs are not simply privacy-policy wording. They shape decisions about why personal information is collected, what happens to it afterwards, how it is protected, and how individuals can exercise rights over information held about them.
