APP 12 Privacy: Access to Personal Information
8 September 2026
APP 12 of the Privacy Act 1988 gives individuals the right to access personal information an organisation holds about them, on request. The obligation requires a response within a reasonable period (30 days is the general guide). A charge for giving access is permitted but not for the request itself, and refusal is limited to specific grounds - including where access would harm someone else's privacy.
Australian Privacy Principle 12 sits within the wider set of 13 Australian Privacy Principles - it's specifically the one covering access: an individual's right to see what personal information a business holds about them.
AI Framework's legislative register includes APP 12 as one of the 13 Australian Privacy Principles mapped against a business's actual profile, alongside other Commonwealth and state instruments - because the right exists whether or not a business has ever had to act on it.
The mechanics
APP 12 - organisations vs government agencies
- Response timeframe - Organisations: "reasonable period" - 30 days is the general guide, not a hard cap. Government agencies: 30 calendar days, statutory
- Can charge for the request? - Organisations: no. Government agencies: no
- Can charge for giving access? - Organisations: yes, if not excessive. Government agencies: no
- Refuses under - Organisations: 10 specific grounds (APP 12.3). Government agencies: FOI Act or equivalent access law
The 10 grounds an organisation can refuse access on
- 1 - Serious threat to life, health or safety
- 2 - Unreasonable impact on another person's privacy
- 3 - Request is frivolous or vexatious
- 4 - Relates to anticipated legal proceedings, not discoverable
- 5 - Would reveal negotiation intentions, prejudicing them
- 6 - Access would be unlawful (e.g. legal privilege, confidence)
- 7 - Refusal required or authorised by law or a court order
- 8 - Reasonable suspicion of unlawful activity or serious misconduct
- 9 - Would prejudice an enforcement body's activities
- 10 - Would reveal commercially sensitive evaluative information
What the right actually covers
Where an organisation holds personal information about someone and that person asks for it, APP 12 establishes a right of access - with only specific, limited exceptions. "Holds" means possession or control of a record containing the information, wherever it's physically or technically stored. It's a right to personal information specifically, not a general right to every document that happens to mention someone.
When can a business say no?
Ten specific grounds exist, and they fall into three broad categories: risk to someone's safety or privacy, legal or investigative sensitivity, and commercially sensitive internal evaluation. Inconvenience or embarrassment are not grounds for refusal - the ground has to fit one of the ten in the table above. Refusing access requires a written notice explaining why, except in specific circumstances.
How fast, and does it cost anything?
The obligation requires a response within a reasonable period - 30 days is the general guide, not a strict statutory deadline the way it is for government agencies. No charge applies for making the request. A charge for the work of giving access - retrieval, redaction, reproduction - is permitted, provided it isn't excessive and doesn't function as a barrier to the request itself.
Access also doesn't have to mean handing over a raw file. If giving it in the exact form requested isn't reasonable or practicable, a business can offer a redacted copy, a summary, an alternative format, or supervised viewing instead - whatever reasonably meets both sides' needs.
Access rights are one of 13 principles that apply to your business - see the full picture of which ones matter for your AI use, rather than working through all 13 from scratch.
Does APP 12 cover what an AI system holds - or made up - about someone?
In principle, yes. The OAIC's guidance on commercially available AI products is direct on this: personal information includes "inferred, incorrect or artificially generated information produced by AI models (such as hallucinations and deepfakes), where it is about an identified or reasonably identifiable individual," and that privacy obligations apply to AI-generated output the same way they apply to what was fed in. A chatbot transcript, an AI-generated risk score, an AI-written summary of a client - all of it can fall within the scope of APP 12's access right.
The OAIC's commercially available AI guidance covers APPs 1, 3, 5, 6, 8, 10 and 11 specifically. Neither document covers APP 12 in detail.
The 10 December 2026 disclosure requirement under APP 1.7 is a related but separate obligation - see the full explainer on what that requires - about telling people an automated system is involved in a decision, rather than giving them access to what it holds.
FAQ
Can a business refuse an APP 12 access request? Yes, but only on one of ten specific grounds - including serious safety risk, unreasonable impact on someone else's privacy, or the request being frivolous or vexatious. It can't be refused simply because it's inconvenient.
How long does a business have to respond to an access request? A reasonable period - 30 days is the general guide for organisations, though it's not a strict statutory deadline the way it is for government agencies.
Can a business charge a fee for an access request? Not for making the request. It can charge for the work of giving access, provided the charge isn't excessive.
Does APP 12 cover information an AI tool holds or generated about someone? In principle, yes - the OAIC's own guidance confirms AI-generated content about an identifiable person is personal information. The OAIC hasn't yet published detailed guidance working through APP 12 specifically, though.
What's the difference between APP 12 and APP 13? APP 12 is the right to access personal information. APP 13 is the separate right to have it corrected if it's inaccurate.
For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.
If your business handles personal information and uses AI, address it today with AI Framework.
This post is general information, not legal advice.
Current as at September 2026.