Privacy Principles Australia: All 13 APPs Explained
15 September 2026
Australia's privacy principles are 13 rules under the Privacy Act 1988 that govern how organisations handle personal information. Most apply the same way regardless of technology. Four matter specifically when a business uses AI: collection (APP 3), use and disclosure (APP 6), quality (APP 10) and access (APP 12) - plus a new disclosure requirement landing 10 December 2026.
If you searched "privacy principles Australia" looking for a straight answer, here it is. The Australian Privacy Principles (APPs) are 13 legally binding rules under the Privacy Act 1988 that set out how organisations must collect, use, store and disclose personal information. They've applied since 12 March 2014, sit in Schedule 1 of the Act, and apply to most Australian Government agencies and to private-sector organisations with turnover above $3 million a year (some smaller businesses are covered too - health service providers, credit reporting bodies, and a few other categories, regardless of turnover).
The 13 principles, in order:
- APP 1 - Open and transparent management of personal information
- APP 2 - Anonymity and pseudonymity
- APP 3 - Collection of solicited personal information
- APP 4 - Dealing with unsolicited personal information
- APP 5 - Notification of the collection of personal information
- APP 6 - Use or disclosure of personal information
- APP 7 - Direct marketing
- APP 8 - Cross-border disclosure of personal information
- APP 9 - Adoption, use or disclosure of government related identifiers
- APP 10 - Quality of personal information
- APP 11 - Security of personal information
- APP 12 - Access to personal information
- APP 13 - Correction of personal information
The Australian Privacy Principles APPs apply to any business handling personal information, AI or not.
Which APPs matter most when your business uses AI
Most of the 13 APPs apply the same way whether or not AI is involved. Four are where AI use specifically changes what's expected of a business, based on the OAIC's own guidance on AI and privacy.
- APP 3 (collection) - Collection must be reasonably necessary and by fair means. An AI tool that retains or processes customer or applicant data can constitute a collection event under APP 3
- APP 5 (notification) - Tell people, at or before collection, how their information will be handled. Easy to miss when an AI tool gets bolted onto an existing form or intake process
- APP 6 (use/disclosure) - Use personal information only for the purpose it was collected for, unless the person consented. The OAIC's explicit position: don't put personal information - especially sensitive information - into public generative AI tools
- APP 11 (security) - Take reasonable steps to protect personal information. Extends to the security practices of third-party AI vendors and APIs handling personal information
APP 12: can someone see what an AI system holds about them?
APP 12 gives individuals a right to access personal information an organisation holds about them - and that includes information an AI system holds or has generated, not just what a person directly typed in. A chatbot transcript, a lead score, an AI-written summary of a client file: all of it can fall within the definition of "personal information" under the access right.
APP 10: what happens when AI gets something wrong?
APP 10 requires reasonable steps to keep personal information accurate - and the OAIC has specifically flagged that AI systems can produce inaccurate results. If an AI tool hallucinates a detail about a customer, or misclassifies something in a client record, that's a data-quality issue under APP 10 - the obligation sits with the organisation using the tool, not the AI vendor.
APP 1.7: the disclosure requirement landing 10 December 2026
From 10 December 2026, APP 1.7 requires any business using a computer program to make, or substantially support, a decision that could significantly affect someone's rights or interests to disclose that in its privacy policy. The definition is broad - it covers everyday business software and rule-based systems, not just generative AI, and a human "signing off" doesn't automatically exempt a business if the software was a key factor in the decision.
To be precise about what it does and doesn't require: it's a disclosure obligation, not a right for someone to challenge a decision or demand a human review it. The requirement is disclosure - saying what's being done. It doesn't extend to justifying the decision, offering an opt-out, or explaining the logic behind it.
The OAIC's consultation on compliance guidance closed in June 2026. The deadline is fixed. The final guidance on meeting it still hasn't been published.
What Australians actually think about this
Trust in how AI handles personal information is low, and the numbers are specific. In the OAIC's own 2026 community attitudes survey: 93% of Australians say it's unfair to use their personal information to train AI models, 91% see a significant AI-informed decision as unfair, and only 25% find AI acceptable for something like a loan approval. Separately, data breach notifications hit an all-time high in 2025 - 1,205 for the year, up 8% on 2024. Whatever a business's AI use looks like, it's landing on an audience that already doesn't fully trust the arrangement.
If you want the version specific to your own industry and turnover rather than the general guidance, AI Framework maps it against the Commonwealth and state instruments that apply to your business in one pass.
FAQ
What are the Australian Privacy Principles? 13 legally binding rules governing how organisations collect, use, store, disclose and secure personal information in Australia. They cover the full lifecycle - before collection, at collection, while the information is held, and when someone wants to access or correct it.
Who do the Australian Privacy Principles apply to? Most Australian Government agencies and private-sector organisations with turnover above $3 million a year - including real estate agencies, recruiters and professional services firms handling personal information as part of everyday business. Some organisations are covered regardless of turnover, including health service providers and credit reporting bodies.
Do the Australian Privacy Principles apply to AI specifically? There's no separate "AI law" in the Australian Privacy Principles APPs - the same 13 principles apply. What changes is how they apply in practice: collection, use, quality and access all work differently once an AI system is involved, and from 10 December 2026 a new disclosure requirement applies to automated decision-making specifically.
For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.
Reading Australia's privacy principles is step one. Knowing which ones apply to your specific business - and what else in Commonwealth and state law does too - is step two. Get your free preview covers the first two AI6 practices at no cost.
This post is general information, not legal advice.
Current as at September 2026.