The Australian Privacy Principles, Explained One by One

The Privacy Act 1988 is built around the 13 Australian Privacy Principles (APPs), which govern how organisations handle personal information. This breakdown explains each principle in plain English and the risk of getting it wrong, then covers the Notifiable Data Breaches scheme. For a shorter overview, see our Privacy Act & NDB guide.

The Act applies to Australian Government agencies, businesses with annual turnover over $3 million, and some smaller organisations regardless of size — including health service providers and businesses that trade in personal information. Even where it doesn’t strictly apply, following the APPs is increasingly expected by customers and partners.

How to read this breakdown:
In black — what the principle requires, in plain summary.
In blue — what it actually means for your business.
In red — the risk if you leave it unaddressed.

APP 1 — Open and transparent management

The principle: Manage personal information openly, with a clear, up-to-date and freely available privacy policy.

What it means: People should be able to see what you collect, why, and how to contact you about it.

Risk if ignored: No (or a vague) privacy policy is a breach in itself, erodes trust, and is one of the first things a regulator looks at after an incident.

APP 2 — Anonymity and pseudonymity

The principle: Where practical, give individuals the option to deal with you anonymously or using a pseudonym.

What it means: Don’t demand someone’s identity when you don’t genuinely need it to provide the service.

Risk if ignored: Collecting identity you don’t need adds data you must protect — and can itself breach the principle.

APP 3 — Collection of solicited personal information

The principle: Only collect personal information you reasonably need for your functions, by lawful and fair means.

What it means: Practise data minimisation — collect less, by the book.

Risk if ignored: Over-collection means more to protect and more to lose in a breach; unlawful or unfair collection attracts penalties.

APP 4 — Dealing with unsolicited personal information

The principle: If you receive personal information you didn’t ask for, decide whether you could lawfully have collected it — if not, destroy or de-identify it.

What it means: Don’t quietly keep data that turns up unexpectedly.

Risk if ignored: Hanging on to unsolicited (often sensitive) data you shouldn’t hold multiplies both your breach exposure and your compliance risk.

APP 5 — Notification of collection

The principle: Tell people what you’re collecting, why, and who you may share it with — at or before the time of collection.

What it means: Provide a clear collection notice, not just a buried policy.

Risk if ignored: Silent collection breaches the principle and looks far worse when it surfaces during a breach investigation.

APP 6 — Use or disclosure

The principle: Only use or disclose personal information for the purpose you collected it (or a directly related purpose the person would expect), unless an exception applies.

What it means: Don’t repurpose data people gave you for one reason to do something else.

Risk if ignored: Using data for unexpected purposes — like on-selling a customer list — is a serious breach and a trust catastrophe.

APP 7 — Direct marketing

The principle: Use personal information for direct marketing only within strict limits, and always provide a simple way to opt out.

What it means: Respect consent and make unsubscribing easy.

Risk if ignored: Non-compliant marketing draws complaints, Spam Act exposure and regulatory penalties.

APP 8 — Cross-border disclosure

The principle: Before sending personal information overseas, take reasonable steps to ensure the overseas recipient handles it consistently with the APPs.

What it means: Vet your overseas providers and cloud services — where your data physically lives matters.

Risk if ignored: You generally remain accountable for the data — an overseas provider’s breach can become your liability.

APP 9 — Government related identifiers

The principle: Don’t adopt, use or disclose government identifiers (such as a Tax File Number or Medicare number) as your own identifier, except in limited circumstances.

What it means: Don’t use government ID numbers as your internal customer keys.

Risk if ignored: Misusing these identifiers breaches the principle and dramatically increases identity-theft harm if the data leaks.

APP 10 — Quality of personal information

The principle: Take reasonable steps to ensure the personal information you hold is accurate, up to date and complete.

What it means: Keep records correct — bad data leads to bad decisions and harm.

Risk if ignored: Acting on inaccurate personal data can harm individuals, damage your decisions, and breach the principle.

APP 11 — Security of personal information

The principle: Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access — and destroy or de-identify it when no longer needed.

What it means: This is the core security obligation: encryption, access control, patching, and not keeping data forever.

Risk if ignored: Weak security here is exactly what becomes a notifiable data breach — bringing penalties, mandatory notifications and lasting reputational damage.

APP 12 — Access to personal information

The principle: Give individuals access to the personal information you hold about them when they request it, subject to limited exceptions.

What it means: You must be able to find and provide a person’s data on request.

Risk if ignored: Being unable or unwilling to respond breaches the principle and signals weak underlying data governance.

APP 13 — Correction of personal information

The principle: Correct personal information when it is inaccurate, or when an individual asks and correction is justified.

What it means: Fix wrong records promptly when they’re identified.

Risk if ignored: Knowingly leaving incorrect data in place harms the individual and breaches the principle.

The Notifiable Data Breaches (NDB) scheme

Notifiable data breaches

The principle: If an eligible data breach occurs — unauthorised access to, or loss of, personal information that is likely to result in serious harm — you must notify both the OAIC and the affected individuals as soon as practicable.

What it means: You need a process to detect a suspected breach, assess it quickly, and notify on the clock.

Risk if ignored: Failing to notify compounds the breach with regulatory penalties and destroyed trust — and having no plan means you’re improvising during the worst possible moment.

Penalties for serious or repeated privacy breaches have increased substantially, so readiness matters more than ever.

Find out where your privacy and security gaps are — free, in about five minutes.