Australian Privacy Principles explained for small business
A plain English rundown of all 13 Australian Privacy Principles, what each one means for your business, and where small businesses usually slip up.
The Australian Privacy Principles are the 13 rules in the Privacy Act 1988 (Cth) that set out how you collect, use, store and share people's personal information. They cover everything from your privacy policy to your marketing list. If your business is covered by the Act, all 13 apply to you.
They are written as principles rather than a checklist, which is deliberate. A café, a physio clinic and an online store all handle information differently, so the rules bend to fit. That flexibility is handy, but it does mean nobody hands you a tick list. This page is the plain English version.
Do the APPs apply to your business?
The Privacy Act covers Australian Government agencies and organisations with an annual turnover of more than $3 million, plus some other organisations regardless of size. Health service providers that hold health information are the most common example, and businesses that trade in personal information are another.
So if you turn over less than $3 million and you are not in one of those categories, the APPs may not apply to you yet. Two things worth knowing anyway:
The Spam Act 2003 (Cth) applies to your email and SMS marketing no matter what you turn over.
Plenty of small businesses opt in voluntarily, because customers and enterprise clients increasingly ask.
Whether you are caught depends on your specific situation, so if you are near the threshold or unsure about the exceptions, it is worth getting advice. Our guide on who the Privacy Act covers walks through it.
The 13 Australian Privacy Principles, in plain English
Before you collect anything
APP 1: Open and transparent management of personal information
You need a clearly expressed, up to date privacy policy, plus practical systems for handling privacy questions and complaints. Most policies are template text that does not match the tools actually running on the site.
APP 2: Anonymity and pseudonymity
Where it is practical, people should be able to deal with you without identifying themselves or by using a pseudonym. Limited exceptions apply, but a general enquiry form is a good example of where it should be an option.
When you collect it
APP 3: Collection of solicited personal information
Only collect what you reasonably need. Sensitive information (health, race, religion, sexual orientation, criminal record and similar) is held to a higher standard and usually needs consent. Asking for a date of birth you never use is over-collection.
APP 4: Dealing with unsolicited personal information
This covers information that arrives unasked, like a CV emailed out of the blue. If you could not have collected it under APP 3, you generally need to destroy or de-identify it, where that is lawful and reasonable.
APP 5: Notification of the collection of personal information
Tell people at or before collection who you are, why you are collecting, who you usually share with, and whether it goes overseas. Newsletter forms, account sign-up and checkout are the everyday risk points.
What you do with it
APP 6: Use or disclosure of personal information
Information collected for one purpose cannot be used for another without consent or an exception. Uploading a customer list to build a lookalike audience is the classic slip.
APP 7: Direct marketing
Personal information can only be used or disclosed for direct marketing if certain conditions are met, and people need a clear, working way to opt out. Abandoned cart emails to someone who never finished a purchase are worth a second look.
APP 8: Cross-border disclosure of personal information
Before customer data goes overseas, you need to take reasonable steps to make sure the recipient handles it in line with the APPs. Your email platform, ad networks and analytics tools all count.
APP 9: Government related identifiers
There are only limited circumstances where you can adopt, use or disclose a government identifier such as a tax file number or Medicare number. Do not use one as your own customer reference.
Keeping it accurate and safe
APP 10: Quality of personal information
Take reasonable steps to make sure the information you collect, use and disclose is accurate, up to date and complete. Stale records cause real harm when they drive billing or clinical decisions.
APP 11: Security of personal information
Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, and destroy or de-identify it once you no longer need it. That second half is where most businesses fall short, because old exports sit in inboxes and drives for years. It is also the principle behind most notifiable data breaches.
When someone asks about their information
APP 12: Access to personal information
If someone asks for the personal information you hold about them, you generally have to give it to them unless a specific exception applies. Know where it all lives before the request arrives.
APP 13: Correction of personal information
Correct information when someone asks, or when you work out it is wrong. If you have already shared the incorrect version, you may need to tell the recipient too.
What should you actually do about it?
You do not need a compliance team. You need a short, honest audit and a few habits.
1. Map what you collect
Every form, checkout field, booking system and spreadsheet. If you cannot name why you collect a field, stop collecting it.
2. List your tools
Email platform, analytics, ads, CRM, booking software. Note which ones sit overseas, because that is APP 8 territory.
3. Read your privacy policy properly
Check it names the tools you actually use and explains access, correction and complaints.
4. Fix your collection notices
A short line at the point of collection beats a long policy nobody opens.
5. Check your opt-outs work
Send yourself a test and click unsubscribe.
6. Set a deletion habit
Decide how long you keep customer records, then actually delete them.
7. Diarise a review
Twice a year, or whenever you add a new tool.
Common questions
Do the Australian Privacy Principles apply to small businesses?
Not automatically. The Act generally covers organisations turning over more than $3 million, with exceptions that catch smaller businesses such as health service providers. Check whether an exception applies to you.
What happens if you breach an APP?
A breach of an Australian Privacy Principle is treated as an interference with the privacy of an individual, and it can lead to regulatory action and penalties from the OAIC.
Do I need a privacy policy if I only collect email addresses?
If you are covered by the Act, you almost certainly do. An email address is personal information when it identifies someone, and APP 1 requires a policy regardless of how little you collect.
Are the APPs the same as the GDPR?
No. They overlap on ideas like transparency and access, but they are separate laws with different thresholds and obligations. If you sell into Europe, you may need to deal with both.
Want a simpler way to capture and record consent across your forms and website? Take a look at Savira's consent management tools.
Source: Australian Privacy Principles quick reference, OAIC, last updated 16 January 2025.
This is general information, not legal advice. Every business handles information a bit differently, so if you're not sure how this applies to yours, it's worth checking with a lawyer or privacy adviser.
Source: Office of the Australian Information Commissioner website – www.oaic.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. This summary is Savira's own and is not endorsed by the OAIC.

