Pillar · Privacy Act / APP / NDB

The 13 Australian Privacy Principles. From APP 1 to APP 13. Plain English.

The 13 APPs sit in Schedule 1 to the Privacy Act 1988. They cover the full lifecycle of personal information — from the moment you decide to collect it, to the day you delete it. Below is each APP, what it requires, when it applies, and how to actually implement it in a small business.

How XIntelliSync handles the 13 APPs structurally

Of the 13 Australian Privacy Principles, XIntelliSync's runtime structurally handles 7 — APP 1 (the platform privacy policy on /privacy-policy), APP 6 (Row-Level Security at the database layer makes cross-tenant reads impossible, not difficult), APP 8 (XGVS code-audit gates the cross-border flow class — see cross-border-app8), APP 10 (XGVS Stage 1 cross-file consistency catches data quality drift), APP 11 (multiple XGVS code-audit gates enforce reasonable security on every action — TFN validation, PII redaction, bank-field encryption, data classification, retention schedule), APP 12 + APP 13 (every customer-data table has full access and correction flows — customer-data-rights gate). The 6 that stay yours — APP 2 anonymity option (your business judgment), APP 3 collection rules, APP 4 unsolicited information, APP 5 collection notification copy, APP 7 direct marketing opt-in, APP 9 government identifier handling — require human judgment about your business. No software writes those for you, and we won't pretend otherwise.

XGVS — every action passes every APP gate that applies, or it halts and tells you why.

APP 1

Open and transparent management of personal information

Rule — Have a clearly-expressed and up-to-date privacy policy. Make it easily accessible. Link to it from every collection point.

In practice — Publish /privacy-policy on the public site. Reference it in every signup form, every contact form, every customer onboarding email.

APP 2

Anonymity and pseudonymity

Rule — Where lawful and practicable, give individuals the option to deal with you anonymously or under a pseudonym.

In practice — Support email signup without requiring legal name. Allow customer service contact without account creation. Document where APP 2 is unavailable and why.

APP 3

Collection of solicited personal information

Rule — Only collect what is reasonably necessary for your functions. Sensitive information requires consent under APP 3.3 (with limited exceptions).

In practice — No collecting fields you do not actually use. For health, biometric, or other sensitive information — capture explicit consent at the point of collection.

APP 4

Dealing with unsolicited personal information

Rule — If you receive personal information you did not solicit, decide whether you could have lawfully collected it. If not, destroy or de-identify it.

In practice — Resume sent to a job-board automation that scrapes wider than the role? Decide whether keeping it is APP 3-compliant. If no — destroy within reasonable time.

APP 5

Notification of the collection of personal information

Rule — At or before collection, tell the individual: who you are, why you are collecting, who you might disclose it to, and where they can read your privacy policy.

In practice — Every signup form, lead form, support form must show a collection notice with: name + ABN + reason + disclosure list + privacy policy link. Auto-rendered by XIntelliSync.

APP 6

Use or disclosure of personal information

Rule — Only use or disclose personal information for the primary purpose you collected it. Secondary uses require consent OR a related-purpose test.

In practice — Customer email collected for invoicing cannot be used for unrelated marketing without consent. Marketing-list use requires APP 5 collection notice that flagged it.

APP 7

Direct marketing

Rule — Direct marketing using personal information requires either explicit consent OR a reasonable-expectation test plus an opt-out mechanism on every message.

In practice — Every email campaign carries a one-click unsubscribe (also a Spam Act 2003 requirement). Every SMS campaign accepts STOP replies. Honour opt-outs within 2 business days.

APP 8

Cross-border disclosure of personal information

Rule — Before disclosing personal information overseas, ensure the foreign recipient is bound by substantially-similar privacy protection OR you have express consent.

In practice — When using overseas SaaS processors, contract them to APP-equivalent terms. Document the destination country. Disclose cross-border flows in the privacy policy.

APP 9

Adoption, use or disclosure of government related identifiers

Rule — Do not adopt a government identifier (TFN, Medicare number, driver licence) as your own customer ID. Restricted use and disclosure regime applies.

In practice — Never use TFN as a primary key in your database. Issue your own customer ID. TFN handler regime adds explicit-consent + secondary-use restrictions on top of APP 9.

APP 10

Quality of personal information

Rule — Take reasonable steps to ensure personal information is accurate, up-to-date, complete, and (for use or disclosure) relevant.

In practice — Self-service profile editing for customers. Periodic data-quality prompts. Mark records as stale after defined inactivity. Document the steps taken to maintain quality.

APP 11

Security of personal information

Rule — Take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure.

In practice — Encryption at rest + in transit. Multi-factor authentication on admin access. Audit logs on every sensitive query. Automated incident response. Quarterly penetration testing.

APP 12

Access to personal information

Rule — On request, give an individual access to the personal information you hold about them within 30 days (with limited exceptions for legal-privilege or third-party rights).

In practice — Self-service data download in the customer portal. For non-customer access requests — documented intake process, identity verification, response within 30 days.

APP 13

Correction of personal information

Rule — On request — or where you become aware of inaccuracy — correct personal information you hold. Notify any prior recipients of the correction where reasonable.

In practice — Self-service profile correction. Audit-log-backed correction trail. If a correction was disclosed to a third party — notify that third party of the corrected value.

All 22+ industries served

How the 13 APPs land in your industry.

Every industry XIntelliSync serves has at least one APP that sits at the centre of its day-to-day operations. Healthcare lives at APP 3.3 (sensitive information). E-commerce lives at APP 8 (cross-border). Recruitment lives at APP 11 (reasonable security). The matrix below is the per-industry shorthand.

Construction

APP focus — Subcontractor TFN + super-fund-membership data triggers TFN handler obligations (always-covered regardless of turnover). White card / induction database under APP 6 — secondary use limits.

Healthcare

APP focus — Health information requires explicit consent under APP 3.3 + APP 6.2(c). My Health Record interactions, AHPRA registration data, Medicare claims all carry overlapping consent regimes.

Hospitality

APP focus — Loyalty programme data + booking-system PII + employee TFNs all in scope when above threshold. POS data with card-on-file triggers PCI-DSS overlap (separate from Privacy Act but related).

Retail

APP focus — E-commerce capture of address + payment + browsing history all in scope above threshold. APP 5 collection notice required at point of capture; APP 1 privacy policy must be findable on the site.

Professional Services / Consulting

APP focus — Client-confidential information sits under both Privacy Act + common-law confidentiality. APP 11 reasonable-security standards extend to engagement files at rest + in transit.

Digital / Tech / SaaS

APP focus — Cookie / analytics / session data all PII in scope. APP 8 cross-border transfer requires either same-or-substantially-similar protection by the foreign recipient OR explicit consent.

Finance / Mortgage Brokers

APP focus — Credit information has stricter rules than general personal information — separate consent regime under Pt IIIA. APP 12 access requests carry credit-specific response time limits.

Legal

APP focus — Client legal-privilege information sits above Privacy Act protection but APP rules still apply to handling. Conflict-check databases under APP 11 reasonable-security standards.

Childcare / Early Learning

APP focus — Parent ID + child medical records + emergency contacts under APP 3.3 explicit-consent regime. Photo/video consent forms require granular specificity per APP 5 collection notices.

Education / RTOs

APP focus — Student record systems carry both APP and federal Education and Training Reform Act obligations. Disability-support records are sensitive information under APP 3.3.

Manufacturing

APP focus — Supplier portal capture + customer-relationship data + employee biometric (timeclock) data all in scope. APP 1 privacy policy + APP 5 collection notice required at customer onboarding.

Transport / Logistics

APP focus — Telematics / GPS / ELD data is personal information about the driver. APP 5 collection notice required at driver onboarding; secondary use restricted under APP 6.

Mining / Resources

APP focus — Biometric site-access data is sensitive information under APP 3.3 — explicit consent required. FIFO worker family-contact data carries higher-than-baseline privacy risk.

Agriculture / Primary Production

APP focus — Seasonal worker data + WHM (working holiday maker) records carry overlap with immigration data-handling regime. Drone footage capturing neighbouring properties may breach others’ privacy.

Fitness / Health Clubs

APP focus — Member health screening + biometric access (gym entry fingerprints) + personal training records all sensitive information under APP 3.3 explicit-consent regime.

Not-for-Profit

APP focus — Donor data + beneficiary case files + volunteer working-with-children-check records all sensitive. APP 1 privacy policy must address donor + beneficiary + volunteer separately.

Events / Conferences

APP focus — Attendee dietary + accessibility data is sensitive information under APP 3.3. Photo / video capture at events requires APP 5 collection notice + opt-out signage.

Creative / Photography / Production

APP focus — Model release + image rights consent under APP 5 + APP 6 secondary-use rules. Capture of minors requires parental consent + sensitive-information regime under APP 3.3.

Marketing / Advertising Agencies

APP focus — Email-marketing under Spam Act 2003 + APP 7 (direct marketing) overlap. Lead-generation forms must satisfy APP 5 collection notice + APP 1 privacy policy linkage.

HR / Recruitment

APP focus — Resume + background-check + reference data all PII. Background checks involving police records are sensitive information under APP 3.3 — explicit consent required.

Insurance Brokers / Underwriters

APP focus — Medical reports + claim histories + financial-position data all sensitive information. APP 8 cross-border data flow common in re-insurance — disclosure regime applies.

Real Estate / Property Management

APP focus — Tenancy applications carry the heaviest collection notice requirements per APP 5 + tenancy-database-specific rules. Bond data + utility account references all in scope.

FAQs

The 13 APPs — answered.

Where do the 13 APPs come from?

The 13 Australian Privacy Principles are set out in Schedule 1 to the Privacy Act 1988 (Cth). They replaced the prior 10 National Privacy Principles + 11 Information Privacy Principles structure on 12 March 2014. The full text is available on AustLII at austlii.edu.au and explained on oaic.gov.au.

What counts as "sensitive information" under APP 3.3?

Sensitive information is a defined category in s 6 of the Privacy Act: information about racial or ethnic origin, political opinions, membership of political associations, religious beliefs, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, biometric information, and biometric templates. Sensitive information requires explicit consent under APP 3.3 with limited exceptions.

Does APP 5 require a collection notice on every form?

Yes — at or before the time of collection. The notice must include: your identity + contact details, the fact and circumstances of collection, whether the collection is required or authorised by law, the purposes of collection, the consequences of not providing the information, the entities to which information is usually disclosed, that the privacy policy contains information about access + correction + complaints, and any cross-border disclosures (incl. country names). XIntelliSync auto-renders APP 5 collection notices on every customer-facing form.

Is one-click unsubscribe required under APP 7?

Yes — for direct marketing using personal information, every electronic commercial message must offer a simple opt-out mechanism (APP 7 + Spam Act 2003 s 18). The opt-out must be honoured within a reasonable time (industry practice: 2 business days). For non-electronic marketing, individuals must still be told they can request to stop receiving direct marketing.

How does APP 8 affect using overseas SaaS providers?

When you disclose personal information to an overseas recipient — typically through a SaaS provider hosted outside Australia — APP 8 makes you accountable for any breach of the APPs by that overseas recipient unless: (a) the recipient is bound by laws or a binding scheme that provide substantially-similar protection AND a complaint mechanism is available, OR (b) the individual gave express consent after being told that consent removes the substantially-similar safeguard. Disclose cross-border flows in your privacy policy with destination countries listed.

How long do I have to respond to an APP 12 access request?

Within a reasonable period — practice is 30 days. You may charge for access (must not be excessive). You may refuse access in limited circumstances (e.g. if access would have an unreasonable impact on the privacy of others, would reveal evaluative information by you in connection with a commercially-sensitive decision, or would prejudice law-enforcement). If you refuse, give written reasons + the OAIC complaint mechanism.