Australia · Office of the Australian Information Commissioner (OAIC) · Privacy Act / APPs

Privacy Act & Australian Privacy Principles

The 13 Australian Privacy Principles (APPs) govern how APP entities handle personal information under the Privacy Act.

What it is

The Privacy Act 1988 sets out how APP entities - most Commonwealth agencies and private-sector organisations with turnover above $3M, plus specific exceptions below that threshold - must handle personal information. The 13 Australian Privacy Principles cover collection, use and disclosure, data quality, security (APP 11), access and correction, and cross-border transfers. APP 11 is the requirement that matters most for cybersecurity programs: entities must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

Who it applies to

Australian Government agencies, private-sector organisations over $3M turnover, and specific classes of entity regardless of turnover (health service providers, credit reporters, residential tenancy databases, businesses trading in personal information).

Requirements

APP 1 – Open and transparent management

Have a clearly expressed, up-to-date privacy policy.

APP 3 – Collection of personal information

Collect only personal information reasonably necessary for functions or activities.

APP 6 – Use or disclosure

Use personal information only for the primary purpose, or a related secondary purpose the individual would reasonably expect.

APP 8 – Cross-border disclosure

Take reasonable steps to ensure overseas recipients meet APP standards.

APP 11 – Security of personal information

Reasonable steps to protect personal information and to destroy or de-identify it when no longer needed.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.