AI Framework

Privacy Principles Australia: All 13 APPs Explained

Australia's privacy principles are 13 rules under the Privacy Act 1988 that govern how organisations handle personal information. Most apply the same way regardless of technology. Four matter specifically when a business uses AI: collection (APP 3), use and disclosure (APP 6), quality (APP 10) and access (APP 12) - plus a new disclosure requirement landing 10 December 2026.

If you searched "privacy principles Australia" looking for a straight answer, here it is. The Australian Privacy Principles (APPs) are 13 legally binding rules under the Privacy Act 1988 that set out how organisations must collect, use, store and disclose personal information. They've applied since 12 March 2014, sit in Schedule 1 of the Act, and apply to most Australian Government agencies and to private-sector organisations with turnover above $3 million a year (some smaller businesses are covered too - health service providers, credit reporting bodies, and a few other categories, regardless of turnover).

The 13 principles, in order:

The Australian Privacy Principles APPs apply to any business handling personal information, AI or not.

Which APPs matter most when your business uses AI

Most of the 13 APPs apply the same way whether or not AI is involved. Four are where AI use specifically changes what's expected of a business, based on the OAIC's own guidance on AI and privacy.

APP 12: can someone see what an AI system holds about them?

APP 12 gives individuals a right to access personal information an organisation holds about them - and that includes information an AI system holds or has generated, not just what a person directly typed in. A chatbot transcript, a lead score, an AI-written summary of a client file: all of it can fall within the definition of "personal information" under the access right.

APP 10: what happens when AI gets something wrong?

APP 10 requires reasonable steps to keep personal information accurate - and the OAIC has specifically flagged that AI systems can produce inaccurate results. If an AI tool hallucinates a detail about a customer, or misclassifies something in a client record, that's a data-quality issue under APP 10 - the obligation sits with the organisation using the tool, not the AI vendor.

APP 1.7: the disclosure requirement landing 10 December 2026

From 10 December 2026, APP 1.7 requires any business using a computer program to make, or substantially support, a decision that could significantly affect someone's rights or interests to disclose that in its privacy policy. The definition is broad - it covers everyday business software and rule-based systems, not just generative AI, and a human "signing off" doesn't automatically exempt a business if the software was a key factor in the decision.

To be precise about what it does and doesn't require: it's a disclosure obligation, not a right for someone to challenge a decision or demand a human review it. The requirement is disclosure - saying what's being done. It doesn't extend to justifying the decision, offering an opt-out, or explaining the logic behind it.

The OAIC's consultation on compliance guidance closed in June 2026. The deadline is fixed. The final guidance on meeting it still hasn't been published.

What Australians actually think about this

Trust in how AI handles personal information is low, and the numbers are specific. In the OAIC's own 2026 community attitudes survey: 93% of Australians say it's unfair to use their personal information to train AI models, 91% see a significant AI-informed decision as unfair, and only 25% find AI acceptable for something like a loan approval. Separately, data breach notifications hit an all-time high in 2025 - 1,205 for the year, up 8% on 2024. Whatever a business's AI use looks like, it's landing on an audience that already doesn't fully trust the arrangement.

If you want the version specific to your own industry and turnover rather than the general guidance, AI Framework maps it against the Commonwealth and state instruments that apply to your business in one pass.

FAQ

What are the Australian Privacy Principles? 13 legally binding rules governing how organisations collect, use, store, disclose and secure personal information in Australia. They cover the full lifecycle - before collection, at collection, while the information is held, and when someone wants to access or correct it.

Who do the Australian Privacy Principles apply to? Most Australian Government agencies and private-sector organisations with turnover above $3 million a year - including real estate agencies, recruiters and professional services firms handling personal information as part of everyday business. Some organisations are covered regardless of turnover, including health service providers and credit reporting bodies.

Do the Australian Privacy Principles apply to AI specifically? There's no separate "AI law" in the Australian Privacy Principles APPs - the same 13 principles apply. What changes is how they apply in practice: collection, use, quality and access all work differently once an AI system is involved, and from 10 December 2026 a new disclosure requirement applies to automated decision-making specifically.

For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.

Reading Australia's privacy principles is step one. Knowing which ones apply to your specific business - and what else in Commonwealth and state law does too - is step two. Get your free preview covers the first two AI6 practices at no cost.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights