Privacy Act & APPs
Privacy Act 1988 (Cth) and the Australian Privacy Principles
- Regulator
- Office of the Australian Information Commissioner (OAIC)
- Who it applies to
- Australian Government agencies and organisations with an annual turnover above AUD 3 million — and smaller businesses that, among others, provide health services, trade in personal information or contract to the Commonwealth.
- If you fall short
- For serious or repeated interferences with privacy, the greater of AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover.
- What it asks of you
- Manage personal information openly under the 13 APPs, with a clear and current privacy policy (APP 1)
- Collect only what you need, and use and disclose it only for the purpose you collected it (APPs 3 to 6)
- Take reasonable steps to protect it and destroy or de-identify it when no longer needed (APP 11)
- Take reasonable steps before disclosing it overseas (APP 8), and give people access and correction (APPs 12 and 13)
- Assess a suspected data breach within 30 days, and notify the OAIC and affected people of an eligible data breach likely to cause serious harm
The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy, a Children's Online Privacy Code and transparency about automated decisions, phased in from 2025. The small business exemption is under review.