Privacy Act 1988 · Schedule 1
The 13 Australian Privacy Principles, in plain English.
The APPs govern how you collect, use, secure, disclose and dispose of personal information. Three of them do most of the work in a security conversation: APP 1 governance, APP 8 overseas disclosure and APP 11 security. Here is all thirteen, and what reasonable steps actually means.
General guidance for Australian businesses, current as at August 2026. It is not legal advice; the law changes and your circumstances matter, so take your own advice before acting.
All thirteen
What each principle asks of a business.
Highlighted principles are the ones a security program directly owns; the rest are mostly governance, marketing and records questions, though APP 3 has a security effect people miss: information you never collected cannot be breached.
- APP 1Open and transparent management of personal informationHave a clear, current privacy policy and the practices, procedures and systems to back it. This is the governance principle: it is the one the OAIC reaches for when nothing was written down.
- APP 2Anonymity and pseudonymityWhere lawful and practicable, people must have the option of dealing with you without identifying themselves.
- APP 3Collection of solicited personal informationOnly collect what you reasonably need for your functions. Sensitive information generally needs consent. The cheapest security control is not collecting it.
- APP 4Dealing with unsolicited personal informationIf information arrives that you could not have collected, destroy or de-identify it if it is lawful and reasonable to do so.
- APP 5Notification of the collection of personal informationTell people what you collected, why, who you might disclose it to and how to complain, at or before collection.
- APP 6Use or disclosure of personal informationUse it for the purpose you collected it for. Secondary uses need consent or an exception, which is where marketing and AI training questions land.
- APP 7Direct marketingRules on using personal information for direct marketing, including an easy opt-out. Sits alongside the Spam Act, which has its own requirements.
- APP 8Cross-border disclosure of personal informationBefore you send personal information overseas, take reasonable steps to ensure the recipient handles it consistently with the APPs, and understand that you can remain accountable for what they do with it. Every offshore SaaS decision touches this.
- APP 9Adoption, use or disclosure of government related identifiersYou generally cannot adopt a government identifier (such as a Medicare or driver licence number) as your own customer identifier.
- APP 10Quality of personal informationTake reasonable steps to ensure what you hold is accurate, up to date and complete.
- APP 11Security of personal informationTake reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure, and to destroy or de-identify it when it is no longer needed. This is the principle a breach is measured against, and the retention half is the one most businesses fail.
- APP 12Access to personal informationGive people access to the personal information you hold about them on request, subject to exceptions, generally within 30 days.
- APP 13Correction of personal informationCorrect information that is inaccurate, out of date, incomplete, irrelevant or misleading, on request or on your own initiative.
APP 11 in practice
“Reasonable steps” is deliberately relative. Here is the current baseline.
The Act does not list controls. The OAIC weighs the nature of your business, how much and how sensitive the information is, what harm a breach would cause, and how practicable and costly the measures are. A ten-person practice holding health records is held to a different standard from a ten-person business holding contact details.
Certifying against a framework does not automatically satisfy APP 11, but it gives you a documented, defensible answer to what you did and why. An Essential Eight assessment or SMB1001 certification are the two most common ways Australian SMBs evidence it.
What reasonable steps usually includes
- Access control: individual accounts, MFA, least privilege, and access removed when people leave.
- Protective technology proportionate to the risk: endpoint detection, patching, email authentication, network controls.
- Encryption of sensitive information in transit and, where it matters, at rest.
- Backups you have actually restored from, held where an attacker cannot reach them.
- Retention and destruction: deleting what you no longer need is the single most effective way to shrink a breach.
- People and process: training, a breach response plan, and third-party assurance over the providers holding your data.
The retention line does the most work. Most large Australian breaches were made worse by data the organisation no longer needed but had never deleted.
Common questions
Asked and answered.
What are the Australian Privacy Principles?
Thirteen principles in Schedule 1 of the Privacy Act 1988 that govern how APP entities handle personal information across its whole life: collection, notice, use and disclosure, quality, security, access and correction. They are outcome-based rather than prescriptive, so what compliance looks like depends on your size, the sensitivity of the information and the risk.
Which APP covers data security?
APP 11. It requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and to destroy or de-identify it once it is no longer needed for any permitted purpose. Both halves matter: holding data you no longer need is an APP 11 problem as well as a bigger breach when one happens.
What counts as reasonable steps under APP 11?
It scales with risk. The OAIC looks at the nature of the entity, the amount and sensitivity of the information, the possible consequences of a breach, and the practicability and cost of the measures. For most businesses the baseline now looks like MFA everywhere, patched and monitored endpoints, least-privilege access, tested backups, encryption of sensitive data, staff training and a breach response plan. A framework such as the Essential Eight or SMB1001 is a defensible way to evidence it.
Do the APPs apply to my small business?
If your annual turnover is over $3 million, yes. Under that, the general exemption applies unless you fall into an exception: private-sector health service providers, businesses that trade in personal information, credit providers and credit reporting bodies, TFN recipients, and Commonwealth contracted service providers. Removing the exemption is proposed but not law.
How do the APPs relate to the Notifiable Data Breaches scheme?
The APPs set the standard of handling; the NDB scheme is what happens when that handling fails and someone could be seriously harmed. In practice a notification invites the question of whether APP 11 reasonable steps were in place, which is why the security work and the breach work belong together.
Does using overseas cloud services breach APP 8?
No, but it engages it. You must take reasonable steps to ensure the overseas recipient handles the information consistently with the APPs, usually through contractual terms and diligence, and in many cases you remain accountable for their acts. Know where your data physically sits, what the contract says, and whether the provider would tell you about their own breach.
The obligations guide
Incident now, or preparing for one?
Could you evidence “reasonable steps” if you had to?
An audit against the Essential Eight, ISO 27001 or SMB1001 turns APP 11 from an argument into a document, with the gaps prioritised and costed.