
Australian Privacy Principles: What Your Business Must Do
The Australian Privacy Principles are 13 legally binding principles in Schedule 1 of the Privacy Act 1988 that govern how you collect, use, store, disclose and correct personal information. They apply to Australian Government agencies and to businesses with annual turnover above the small business threshold, plus certain smaller businesses such as health service providers. For a typical Australian business, the practical work sits in four places: a privacy policy that matches reality, a collection notice, a retention schedule, and the security controls required by APP 11.

Most explanations of the Australian Privacy Principles list all 13 and stop. That is useful once. What a business owner actually needs is a shorter answer: which principles create ongoing work, which create a document, and which one an auditor or a regulator will test if something goes wrong.
What are the Australian Privacy Principles?
The Australian Privacy Principles are 13 principles set out in Schedule 1 of the Privacy Act 1988 (Cth) that govern the handling of personal information by APP entities. They are legally binding. Breaching one is an interference with the privacy of an individual, which the Office of the Australian Information Commissioner can investigate and enforce.
The 13 principles run in a deliberate order that follows the life of a piece of personal information: how you manage privacy openly, how you collect, how you use and disclose, how you keep it accurate and secure, and how a person gets access to it. The OAIC publishes the principles and its guidelines in full, and they are the authoritative source when a question is legal rather than operational.

Who do the Australian Privacy Principles apply to?
The Australian Privacy Principles apply to APP entities, which means Australian Government agencies and private sector organisations with an annual turnover above the small business threshold set in the Privacy Act. They also apply to a number of small businesses regardless of turnover, including private health service providers, businesses that trade in personal information, credit reporting bodies, and contracted service providers under Commonwealth contracts.
Two points catch Australian businesses out. First, a small business that is a related body corporate of a larger entity is covered. Second, a business under the threshold can opt in to being treated as an organisation, and many do because customers ask for it. If you sell to government, to health, or to any large enterprise, expect to be held to the principles by contract even where the Act does not reach you.
Growing past the threshold is the more common trigger. A business that crosses it mid financial year does not get a grace period to build a privacy programme, which is a good reason to build one slightly before you need it.
Which Australian Privacy Principle does a security review test?
APP 11 is the principle a security review tests. APP 11 requires an entity to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed. It is the only principle that turns directly into technical controls, and it is the one that is examined after a data breach.
The phrase that does the work is reasonable steps. The Privacy Act does not list controls. What counts as reasonable depends on the nature of the entity, the amount and sensitivity of the information, the consequences if it were compromised, and the practicality of the measures. A business holding health records is held to a higher standard than a business holding a mailing list, and both are held to a higher standard than they were ten years ago.
This is why a privacy programme built only on documents fails. A privacy policy is APP 1. A collection notice is APP 5. Neither protects anything. APP 11 is where multi factor authentication, access reviews, patching and tested backups belong, and it is where a regulator’s attention lands after an incident.
What does APP 11 expect from a business with 20 to 100 staff?
For an Australian business of 20 to 100 staff, reasonable steps under APP 11 generally means multi factor authentication on everything, unique accounts with least privilege, access reviews at least quarterly, patching within a defined window, endpoint protection, logging on systems that hold personal information, tested backups, and a retention schedule that is actually run. None of that is exotic, and all of it can be evidenced.

The destruction limb of APP 11 is the one almost everyone ignores. If you no longer need personal information for any purpose permitted under the principles, and you are not required by law to keep it, you must destroy it or de-identify it. In practice this means a retention schedule with dates against each data set, and someone whose job it is to run the deletions. Old customer records you kept just in case are a liability, not an asset.
If you already run an information security management system, most of this is done. Our guide to running an ISO 27001 risk assessment covers how to decide which controls are proportionate, and ISO 27001 for small business in Australia covers the lighter path to the same outcome.
What happens if you breach the Australian Privacy Principles?
A breach of the Australian Privacy Principles is an interference with the privacy of an individual, which the Office of the Australian Information Commissioner can investigate following a complaint or on its own initiative. The Commissioner can make determinations requiring an entity to change its practices and to pay compensation, accept enforceable undertakings, and apply to the Federal Court for civil penalties in serious cases.
Separately, the Notifiable Data Breaches scheme requires you to notify the Commissioner and affected individuals when there is an eligible data breach, meaning unauthorised access to or disclosure of personal information that is likely to result in serious harm and that you cannot remediate in time. The OAIC publishes guidance and statistics on notifiable data breaches, and reading a recent report is the fastest way to understand what actually goes wrong.
For most small and medium Australian businesses, the realistic consequence is not a penalty. It is the notification itself: telling your customers that their information was exposed, and then answering their security questionnaires for the next two years. Our guide to building an incident response plan covers preparing for that conversation before you need to have it.
How do you turn 13 principles into a plan?
Turn the 13 Australian Privacy Principles into a plan by grouping them into six pieces of work, assigning each to a person, and giving each a finishing condition. Trying to work through 13 principles in order produces a long document and very little change. Grouping them by the artefact they produce gets the work finished.
| Workstream | Principles | What finished looks like |
|---|---|---|
| Be open | APP 1, APP 2 | A current privacy policy that matches what you actually do, and an anonymity option where practical |
| Collect less | APP 3, APP 4, APP 5 | A data inventory, a collection notice at every collection point, and a process for unsolicited information |
| Use it properly | APP 6, APP 7, APP 9 | Documented purposes, a working marketing opt out, and no use of government identifiers as your own keys |
| Send it safely | APP 8 | A sub-processor list, contract terms with each one, and named countries in your privacy policy |
| Secure it | APP 10, APP 11 | Controls in place with evidence, plus a retention schedule that is actually run |
| Let people in | APP 12, APP 13 | A documented process for access and correction requests, with a response time you can meet |
Start with Secure it and Be open. Those two carry the most regulatory risk and produce the artefacts your customers ask for in vendor security questionnaires anyway. If your business also handles critical infrastructure or government data, our guides to the SOCI Act and recent cyber security and privacy reforms cover the obligations that sit alongside the Privacy Act.
Common questions
How many Australian Privacy Principles are there?
There are 13 Australian Privacy Principles. They are set out in Schedule 1 of the Privacy Act 1988 (Cth) and cover open and transparent management of personal information, anonymity, collection, use and disclosure, direct marketing, cross border disclosure, government related identifiers, data quality, security, and an individual’s rights to access and correct their own information.
Do the Australian Privacy Principles apply to private companies?
Yes, for private sector organisations above the small business turnover threshold in the Privacy Act. They also apply to certain small businesses regardless of turnover, including private health service providers, businesses that trade in personal information, credit reporting bodies, and contracted service providers under Commonwealth contracts. A small business that is a related body corporate of a covered entity is also caught.
Are the Australian Privacy Principles legally binding?
Yes. The Australian Privacy Principles are set out in the Privacy Act 1988 and a breach by an APP entity is an interference with the privacy of an individual. They are not voluntary guidance. The Office of the Australian Information Commissioner can investigate, make determinations, accept enforceable undertakings, and seek civil penalties through the Federal Court in serious cases.
Who enforces the Australian Privacy Principles?
The Office of the Australian Information Commissioner enforces the Australian Privacy Principles. The Commissioner can investigate complaints from individuals, open investigations without a complaint, require changes to an entity’s practices, accept enforceable undertakings, and apply to the Federal Court for civil penalty orders. The OAIC also administers the Notifiable Data Breaches scheme.
What do the Australian Privacy Principles cover?
The Australian Privacy Principles cover the full life of personal information: how an entity manages privacy openly, whether people can deal with it anonymously, what it may collect and how, what it must tell people at collection, how it may use and disclose information including for direct marketing and overseas, the accuracy and security of what it holds, and how an individual accesses and corrects their own information.
Which Australian Privacy Principle deals with security?
APP 11 deals with security of personal information. It requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. It also requires destruction or de-identification once the information is no longer needed for a permitted purpose and is not required to be retained by law.
Where to start
If you do not have a data inventory, build that first. You cannot protect, retain or delete information you have not listed, and every other workstream depends on knowing what you hold and where it sits. A half day workshop with the people who actually run your systems will get you most of the way there.
Siege Cyber helps Australian businesses turn privacy obligations into controls that can be evidenced, rather than documents that sit unread. You can see how that works on our cyber security advisory page, or through ongoing support from our virtual CISO service. If you would like to talk it through, get in touch. For the law itself, the OAIC remains the authoritative source, and our guide to security awareness training covers the human side of APP 11.