Share this article

Australian Privacy Principles: A compliance guide for small businesses
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
Cyber threats have become more sophisticated, frequent, and harder to contain. Per Vanta’s 2025 State of Trust Report: Australia, 78% of organisations now experience cyber threats at least monthly, up from 68% in 2024. Organisations find themselves under growing pressure to strengthen how they protect personal information, and Australian Privacy Principles (APPs) provide the baseline requirements for doing so.
The APPs are set out in the Privacy Act 1988, which is now being reformed to expand their reach. As a result, businesses that didn’t previously have to comply with the principles may have to reassess applicability and prepare for new obligations. This guide outlines each of the APPs, explains what the reforms mean, and clarifies applicability criteria.
What are the Australian Privacy Principles?
The Australian Privacy Principles are the 13 privacy principles or rules of conduct set out in Schedule 1 of the Privacy Act 1988. APPs came into effect in March 2014 after an amendment to the Act. They define how organisations must handle personal information throughout its lifecycle, from collection and use to disclosure, security, access, and correction.
The APPs generally apply to:
- Australian Government organisations
- Private sector organisations with an annual turnover of AUD $3,000,000 or more
- Credit reporting bodies
- Private sector health service providers
- Organisations related to entities covered by the Privacy Act
- Businesses that trade in personal information
While not every organisation is currently covered by the Privacy Act, the scope can change with the upcoming updates. One reform has already expanded the Privacy Act’s reach. Since 1 July 2026, many small businesses in sectors such as real estate, legal, accounting, and conveyancing have become subject to the Act for personal information handled in connection with their AML/CTF obligations, regardless of turnover.
While further reforms are still expected, don’t wait until new requirements take effect to strengthen your alignment with APPs.
What does the reform mean for small businesses?
The proposed Privacy Act reforms are expected to remove the long-standing small business exception from the APPs. As a result, many organisations that were out of scope will now have to comply with the same privacy obligations as larger businesses once enacted.
The proposed changes acknowledge that small businesses routinely collect and process sensitive information, making robust privacy practices essential regardless of size.
While the broader reforms have not yet commenced, organisations that could be brought into scope should start reviewing their privacy practices now, since failing to meet APP criteria can result in substantial penalties.
Penalties for non-compliance with the APPs
Privacy Act penalties vary based on the nature and seriousness of the breach. For the most severe or repeated APP violations, the maximum penalties can be:
The maximum penalty applied is whichever of these three amounts is greatest. The Act also provides for lower-tier civil penalties and infringement notices for less serious contraventions.
When an organisation commits multiple breaches, the court may issue a combined penalty for each breach. However, the total fine can’t exceed what the maximum penalties could have imposed for each individual breach.
APP: The 13 principles explained
Instead of prescribing specific controls, the APPs allow organisations to determine and implement controls appropriate to their size, operations, and risk profile. Their 13 principles are interconnected and cover everything from collection to use, disclosure, storage, access, and correction. We can typically split them into five pillars:
APP 1: Open and transparent management of personal information
The goal of this principle is to ensure organisations handle data openly and transparently. It requires organisations to:
- Implement practices, procedures, and systems that set the foundation for other APPs
- Have a clearly defined and up-to-date APP policy for managing personal data
- Take reasonable steps to make the policy available free of charge
The reasonable steps that help align with this principle depend on the nature of your organisation, the type of data you’re processing, and the potential impact of an incident. Some common controls under APP 1 include:
- Procedures for identifying and responding to breaches
- Designating privacy officers
- Regular stakeholder training
APP 2: Anonymity and pseudonymity
This principle gives individuals the option to not identify themselves or use a pseudonym when working with an APP-covered entity. However, this rule doesn’t apply when the entity is required or authorised by Australian law to work with identified individuals, or when it’s impracticable for the entity to work with them.
This principle clarifies the difference between anonymity and pseudonymity. Anonymity means the individual doesn’t use any information that would support identification. Pseudonymity, on the other hand, means an individual can interact using a name other than their personal name, but it doesn’t necessarily mean that they can’t be identified.
Organisations can use several methods to facilitate this principle, such as:
- Making personal information boxes on contact forms non-mandatory
- Allowing individuals to use pseudonyms on public comments or submissions
- Notifying individuals they can use a pseudonym before interactions
{{cta_simple19="/cta-blocks"}} | See how GDPR works
APP 3: Collection of solicited personal information
APP 3 outlines the requirements organisations must follow when they collect personal information. The principle differentiates between solicited personal information, which an organisation actively collects, and unsolicited personal information, which an organisation receives without requesting it.
The principle focuses on two aspects of information collection:
- When an APP entity can collect personal information: Personal information must generally be reasonably necessary for the organisation’s functions or activities. Sensitive information typically requires the individual’s consent, unless an exception applies.
- How an APP entity must collect personal information: Information must be collected by lawful and fair means, and in line with other APPs.
APP 3 is closely intertwined with APP 4, which guides organisations on handling personal information they did not request.
APP 4: Dealing with unsolicited personal information
According to the principle, entities must protect personal information even if they didn’t solicit it. Any information an organisation receives, but hasn’t requested, qualifies as unsolicited information. This includes:
- Misdirected mail
- A petition that contains names and addresses
- An employment application sent by the individual
When determining whether the information received is unsolicited, consider its nature and connection to any data requests. Treat any information you’re not sure about as unsolicited data, and either destroy or de-identify it.
APP 5: Notification of the collection of personal information
APP 5 mandates organisations to take reasonable steps to inform individuals of their personal information being collected, or ensure they’re aware of the process. This applies to both solicited and unsolicited data.
The principle lists several reasonable steps you can take to inform individuals:
- If the information is taken using websites or online forms, provide a clear APP 5 explanation on the form, or prominently show a link to the notice
- If the information is collected through telephone calls, inform the individual about the collection at the start of the call
- If the information is collected through another entity, conduct due diligence checks to verify the other entity has met the APP 5 criteria
Which steps your organisation should choose depend on the sensitivity of the information, the impact of collection on the individual, and any potential special needs.
APP 6: Use or disclosure of personal information
This APP outlines when organisations may use or disclose data. Like with the GDPR, APP 6 only allows data to be used for the purpose it was collected, with several exceptions:
- The individual consented to secondary use or disclosure
- Secondary use or disclosure is required by Australian law
- There’s a permitted general situation that would allow for secondary use or disclosure
Consent is only valid when it’s voluntary, informed, current, specific, and given by an individual who can understand and communicate their decision.
APP 7: Direct marketing
APP 7 regulates when organisations may use or disclose personal information for direct marketing to promote goods or services.
Not every marketing communication is direct marketing. For example, hand-delivering flyers to mailboxes or sending catalogues to all addresses at a specific location don’t count, since recipients aren’t selected using personal information.
Organisations must also give individuals a way to opt out. You must communicate an opt-out statement written in plain English, prominently positioned, and published in a font and size that’s easy to read.
APP 8: Cross-border disclosure of personal information
APP 8 sets the requirements for sending personal information to an overseas organisation. It generally makes the disclosing APP entity accountable for taking reasonable steps to ensure that the receiving organisation doesn’t breach the APPs, with some exceptions. Cross-border disclosures may also need to align with the consent criteria outlined in APP 6.
To enforce the principle, establish a contractual agreement with the recipient covering factors such as:
- Types of data being disclosed (with purpose)
- A requirement to align with the APPs
- The complaint handling process
Exceptions do apply, most notably when the recipient organisation is already aligned with another privacy regulation with similar protections.
{{cta_simple19="/cta-blocks"}} | See how GDPR works
APP 9: Adoption, use, or disclosure of government-related identifiers
APP 9 generally prohibits organisations from adopting, using, or disclosing government-related identifiers for their activities. These include:
- Medicare numbers
- Centrelink Reference numbers
- Driver licence numbers issued by State and Territory authorities
- Australian passport numbers
Other government identifiers are regulated by laws that restrict how entities may collect, use, and disclose such information.
APP 10: Quality of personal information
APP 10 requires organisations to keep personal data accurate, complete, relevant, and up to date. Reasonable steps include:
- Reminding data subjects to update their personal data during engagement points
- Providing individuals with a way to review and update their personal data ongoingly
- Implementing protocols that help collect data in a consistent format
- Implementing internal systems to audit, monitor, identify, and correct low-quality personal information
APP 11: Security of personal information
APP 11 requires organisations to take reasonable steps to protect personal information from misuse, interference, and loss, as well as unauthorised disclosure, modification, and access.
The principle also provides guidelines for destroying and de-identifying personal information, which include removing or altering personal identifiers so they can’t be linked to an individual, or destroying information until it is irretrievable or unusable.
Tip: Use leading compliance solutions to implement and maintain the reasonable security expectations under APP 11, including encryption, access management, and multi-factor authentication. If you're already managing multiple compliance frameworks, platforms like Vanta can help centralise security controls, automate evidence collection, and maintain the security practices that support APPs.
APP 12: Access to personal information
APP 12 requires organisations to disclose personal information to data subjects upon request, unless an exception within the Privacy Act applies. Organisations must meet the principle’s minimum access criteria and respond within a reasonable period. General processing requirements for disclosing information include:
- Providing access to the information in the requested format
- Providing the information in an alternative format for a justifiable reason
- Redacting information that the organisation is permitted to withhold before providing access
APP 13: Correction of personal information
APP 13 requires organisations to correct personal information that’s inaccurate, out of date, misleading, or irrelevant. It applies in two situations:
- When the organisation identifies that the personal information is inaccurate or outdated
- When an individual requests that their personal information be updated
The principle outlines minimal requirements for correcting personal information. These include taking reasonable steps to correct it, responding to correction requests within the Act timelines, and notifying other organisations of the change if it's appropriate and requested by the individual.
Putting APPs into practice
Organisations with mature compliance programs often have a strong foundation for APP compliance. For example, being GDPR compliant as a SaaS provider means you’re likely aligned with APPs 1, 6, and 11. With the overlaps for transparency, purpose limitation controls, and security measures, APP compliance largely becomes a localisation and documentation exercise.
A common mistake organisations make is treating APPs as a policy exercise and assuming all it takes is a privacy notice update, when the principles are quite operationally demanding on their own.
For example, APP 8 often requires fresh effort since it requires you to closely track where your data goes once it leaves Australia. Even mature privacy programs tend to have blind spots around third-party data flows that were never mapped properly, although the disclosing entity remains accountable.
As you expand operations in the ANZ landscape, relying on a leading privacy or GDPR compliance platform like Vanta can help you build a strong foundation for security controls and governance.
Build a strong compliance infrastructure with Vanta
Vanta is the leading agentic trust platform that helps organisations build and modernise their GRC and privacy infrastructure. It supports you with a combination of tools and resources, including agentic workflows, continuous monitoring, automated evidence collection, and streamlined dashboards, to keep your data management practices consistent and defensible.
Vanta supports 35+ leading security frameworks and regulations across the globe. Its automated compliance solution comes with features such as:
- A centralised data inventory for easier management
- Policy management with templates and a step-by-step builder
- Continuous monitoring
- 1,400+ automated, hourly tests powered by 400+ integrations
- Pre-built and custom security controls
- Vanta AI Agent to fast-track everyday tasks
Vanta offers a dedicated privacy module to manage your data privacy obligations across jurisdictions alongside security and risk. Use it to maintain a live data inventory, run RoPAs and DPIAs, and map privacy obligations to specific frameworks.
Schedule a custom demo to explore how Vanta can support your compliance program.
{{cta_withimage12="/cta-blocks"}} | Global compliance
Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.














.png)








