Skip to content

Australia · In force since 1988; Notifiable Data Breaches scheme since 2018

Australia — Privacy Act 1988 and the Australian Privacy Principles

Australia's federal privacy regime, structured around thirteen Australian Privacy Principles, applying to agencies and to organisations above a small-business threshold, with a mandatory notifiable data breach scheme.

Regulator: Office of the Australian Information Commissioner (OAIC)Last reviewed August 2026

The Privacy Act 1988 regulates how APP entities — Australian Government agencies and most private-sector organisations — handle personal information. Its operative obligations are the thirteen Australian Privacy Principles set out in Schedule 1.

The Act uses a small-business exemption: many organisations with an annual turnover of AUD 3 million or less are outside its scope, though important exceptions bring in health service providers, businesses that trade in personal information, credit reporting bodies and contracted service providers to government.

Sensitive information — including health, biometric, racial or ethnic origin, political and religious information — attracts higher requirements, generally including consent for collection.

The Notifiable Data Breaches scheme requires assessment and notification of eligible data breaches, and the OAIC publishes periodic statistics that are a useful benchmark for incident planning.

Who and what it applies to

APP entities
Australian Government agencies and private-sector organisations that are not exempt, including all health service providers regardless of turnover.
Small business exemption
Organisations at or below AUD 3 million annual turnover are often exempt, subject to significant carve-outs that reinstate coverage.
Extraterritorial reach
Organisations with an Australian link can be covered even where personal information is collected or held outside Australia.

Core principles

  • APP 1 — open and transparent management of personal information, including a clearly expressed privacy policy.
  • APP 2 — the option of anonymity or pseudonymity where lawful and practicable.
  • APP 3 — collection of solicited personal information only where reasonably necessary, with consent for sensitive information.
  • APP 4 — dealing with unsolicited personal information, including destruction where it could not have been collected.
  • APP 5 — notification of collection at or before the time, or as soon as practicable after.
  • APP 6 — use or disclosure only for the primary purpose or a permitted related purpose.
  • APP 7 — restrictions on direct marketing and a right to opt out.
  • APP 8 — accountability for cross-border disclosure.
  • APP 9 — restrictions on adopting or using government-related identifiers.
  • APP 10 — quality of personal information.
  • APP 11 — security of personal information, including destruction or de-identification when no longer needed.
  • APP 12 — access to personal information on request.
  • APP 13 — correction of personal information.

Individual rights

Access

Request access to the personal information an entity holds, with limited grounds for refusal that must be explained.

Correction

Request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading information.

Opt out of direct marketing

Request not to receive direct marketing and to know the source of the information used.

Anonymity

Deal with an entity anonymously or under a pseudonym where lawful and practicable.

Complain

Complain to the entity and then to the OAIC.

Organisational obligations

Privacy policy

Maintain a clearly expressed and up-to-date policy covering collection, purposes, disclosure, overseas recipients, access and complaints.

Collection notice

Tell individuals the APP 5 matters at or before collection, including likely overseas recipients.

Sensitive information consent

Obtain consent before collecting sensitive information unless a specific exception applies.

Security and destruction

Take reasonable steps to protect information and to destroy or de-identify it when no longer needed for a permitted purpose.

Notifiable data breaches

Assess a suspected eligible data breach expeditiously — the scheme contemplates assessment within 30 days — and notify the OAIC and affected individuals where serious harm is likely.

Cross-border accountability

Take reasonable steps to ensure an overseas recipient does not breach the APPs, and remain accountable for acts that would breach them.

Cross-border considerations

  • APP 8 requires reasonable steps before disclosing personal information overseas to ensure the recipient does not breach the APPs.
  • The disclosing entity generally remains accountable for the overseas recipient's handling, which makes contractual controls and due diligence the practical mechanism.
  • Exceptions exist, including where the individual gives informed consent after being told accountability will not apply, or where the recipient is subject to a substantially similar law with enforceable rights.
  • Overseas recipients must be identified in the privacy policy and, where practicable, in the collection notice.

Enforcement overview

  • The OAIC investigates complaints, conducts assessments, accepts enforceable undertakings and can seek civil penalty orders through the Federal Court.
  • Serious or repeated interferences with privacy attract substantially increased maximum civil penalties following reforms to the Act.
  • The OAIC publishes notifiable data breach statistics and determinations, which set practical expectations for incident handling.
  • Reform of the Privacy Act has been proceeding in stages, so entities should track amendments rather than assume the position is static.

Implementation checklist

  1. 1Confirm whether the small-business exemption genuinely applies, including the carve-outs.
  2. 2Refresh the APP 1 privacy policy and APP 5 collection notices, including overseas recipients.
  3. 3Identify sensitive information flows and confirm a consent or exception applies.
  4. 4Document reasonable steps taken for each overseas disclosure under APP 8.
  5. 5Operate an eligible data breach assessment process with a documented 30-day assessment clock.
  6. 6Implement destruction and de-identification triggers, not just retention statements.
  7. 7Provide an accessible access and correction process with reasons for any refusal.

Frequently asked questions

Are all small businesses exempt from the Privacy Act?

No. The exemption has significant carve-outs — health service providers, businesses trading in personal information and government contractors are covered regardless of turnover.

How quickly must an eligible data breach be notified?

An entity must assess a suspected breach expeditiously, with the scheme contemplating assessment within 30 days, and notify the OAIC and individuals as soon as practicable once it is an eligible breach.

Official sources

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.