The Australian Privacy Principles are 13 legally binding rules set out in the Privacy Act 1988 (Cth), and they apply to a wider slice of Australian business than most owners assume. If your business collects names, emails, health records, or payment details, the safest starting position is to treat the Australian Privacy Principles as relevant to you until you’ve confirmed otherwise, not the other way around.
Two things need to happen this week, not next quarter:
- Publish or update a Privacy Policy that explains what you collect, why, and who you share it with
- Start a basic data map: what personal information you hold, where it’s stored, and which third parties touch it
Many small businesses assume a turnover exemption may apply, but other exceptions can still bring them within scope, creating compliance risks.
Key Takeaways
Compliance with the Australian Privacy Principles depends on an accurate data map, an operational privacy policy, enforceable vendor contracts, and a tested breach response plan.
| Point | Details |
|---|---|
| Check exceptions, not just turnover | Health data, TFNs, and government contracts can pull small businesses into scope regardless of revenue. |
| Treat APP 11 as ongoing | Security and retention obligations require active de-identification and destruction, not indefinite storage. |
| Fix vendor contracts for APP 8 | Overseas cloud providers need enforceable data handling clauses before you sign, not after a breach. |
| Prepare for NDB notification | Know the serious harm threshold and who to notify before an incident forces you to work it out live. |
| Review the privacy program yearly | A Privacy Policy written once and never revisited is the most common compliance failure point. |
Table of Contents
- Does the Australian Privacy Principles law apply to my business?
- What do the 13 Australian Privacy Principles actually cover?
- How do you build a practical APP compliance program?
- What happens if personal information is exposed?
- Which compliance mistakes trip up small businesses most?
- How can Techbug help with Australian Privacy Principles compliance?
- Primary sources and further reading
- Why the conventional compliance advice undersells the vendor problem
- Sources
Does the Australian Privacy Principles law apply to my business?
The Privacy Act applies to “APP entities”, broadly Australian Government agencies and private sector organisations with an annual turnover above $3 million. On paper, that sounds like it excludes most small operators. In practice, exceptions swallow that exemption for a surprising number of businesses.
You’re likely covered regardless of turnover if you:
- Provide a health service, in any capacity, even part time
- Handle Tax File Numbers as part of payroll or contractor management
- Trade in personal information, such as selling or brokering customer lists
- Operate as a credit reporting body or handle credit-related personal information
- Deliver services under a Commonwealth government contract.
Business Queensland flags these exceptions specifically because so many small operators get caught out believing size alone protects them. If you’re unsure which category you fall into, the OAIC’s own guidance and Business Queensland’s checklists are the fastest way to confirm your status before you build a compliance program around the wrong assumption.
What do the 13 Australian Privacy Principles actually cover?
The Office of the Australian Information Commissioner groups the 13 APPs into five stages that roughly follow the life of a piece of personal information, from the moment you collect it to the day you delete it.
1. Open and accountable management (APP 1–2)
APP 1 requires an up to date Privacy Policy and a culture of managing information openly. APP 2 gives individuals the option to deal with you anonymously or under a pseudonym where that’s practical. Example: a retailer letting customers browse and ask questions without creating an account.

2. Collection (APP 3–5)
APP 3 limits collection to what’s reasonably necessary for your business. APP 4 governs unsolicited information you receive without asking. APP 5 requires a collection notice at the point of intake. Example: a signup form that tells the customer, in plain terms, why you’re asking for their date of birth.
3. Dealing, use and disclosure (APP 6–9)
APP 6 restricts using personal information for anything beyond its original purpose. APP 7 limits direct marketing use. APP 8 governs sending information overseas, and APP 9 restricts using government identifiers like Medicare numbers. Example: a business that collects an email for order updates can’t quietly add it to a marketing list without consent.
4. Data integrity (APP 10–11)
APP 10 requires accuracy. APP 11 requires reasonable security steps and destruction or de-identification once information is no longer needed. This is where most breaches originate.
5. Access and correction (APP 12–13)
APP 12 gives individuals a right to access their own information. APP 13 lets them request corrections.
APP 8 and APP 11 deserve the most attention from any business using cloud platforms or outsourced IT, because that’s where cross-border data flows and weak security controls tend to collide.
How do you build a practical APP compliance program?
Turning 13 principles into daily practice comes down to five concrete pieces of infrastructure, not a single policy document sitting unread on your website.
Data map first. List every category of personal information you hold, where it came from, where it’s stored, and which vendors or software touch it. You can’t secure or delete what you haven’t inventoried.
Privacy Policy and Collection Notices. Your Privacy Policy is the overarching document; your Collection Notices are the short, specific statements shown at the point of collection, on signup forms, at checkout, in job applications. Sprintlaw’s summary of the APPs sets out what each document needs to contain.
Vendor contracts under APP 8. If you use an overseas cloud provider, you need an enforceable contract obliging that recipient to handle data consistently with the APPs, plus documented evidence you assessed the risk before signing up. This matters for cloud hosting arrangements more than almost anything else in the Act.
Security controls under APP 11. Least-privilege access, encryption, ransomware-safe backups, and logging aligned to the ACSC Essential Eight give you a defensible position if the OAIC ever asks what “reasonable steps” you took.

Retention and de-identification. A working retention policy needs a deletion schedule tied to actual business events, not a vague “keep everything forever” default.
Pro Tip: Run a tabletop breach drill once a year with your actual staff, not just a written plan. Most Data Breach Response Plans fail on the first real incident because nobody has practised who calls whom, and in what order.
What happens if personal information is exposed?
The Notifiable Data Breaches scheme requires you to notify the OAIC and affected individuals when a breach is “likely to result in serious harm.” Assessing that threshold correctly, and moving fast, is the difference between a contained incident and a regulatory investigation.
- Contain the breach immediately. Isolate affected systems, revoke compromised credentials, and stop the data flow before you do anything else.
- Assess the harm. Work out what information was exposed and whether it meets the serious harm threshold; document your reasoning as you go.
- Notify. If the threshold is met, notify the OAIC and affected individuals, and give people practical steps to protect themselves, such as changing passwords or monitoring accounts.
- Keep a timeline. Record every decision and its timing. A well documented response is your strongest evidence of “reasonable steps” if the regulator follows up.
A breach of any APP counts as an interference with an individual’s privacy, and that gives the OAIC grounds to investigate regardless of whether the NDB threshold itself was reached.
Which compliance mistakes trip up small businesses most?
The same handful of errors show up across almost every enforcement case and audit finding, and all of them are avoidable with a bit of upfront discipline.
- Assuming the $3 million turnover threshold exempts you without checking the listed exceptions
- Holding onto customer data indefinitely instead of destroying or de-identifying it once its purpose has passed
- Signing up to an overseas cloud or SaaS vendor with no enforceable data handling clause in the contract
- Publishing a Privacy Policy once and never updating it as systems, vendors, or collection practices change
None of these are exotic failures. They’re the predictable result of treating privacy as a document you write once rather than a program you run continuously, which is exactly how the OAIC’s own guidance frames it: an ongoing governance exercise, not a project with an end date.
How can Techbug help with Australian Privacy Principles compliance?
Turning 13 principles into working IT controls is where most businesses get stuck, and it’s where Techbug spends most of its time with Australian clients. With over 30 years of combined experience, and working from the understanding that 42% of cyberattacks target small businesses, Techbug’s vendor-agnostic approach means you get controls that suit your actual systems, not a template built for someone else’s stack.
Support typically covers:
- Data mapping workshops to identify where personal information actually lives
- Privacy policy and collection notice drafting support
- Vendor contract reviews for APP 8 cross-border obligations
- ACSC Essential Eight alignment and ransomware-safe backup configuration
- Staff training so your team recognises the incidents that trigger NDB obligations
Three ways to engage: a DIY checklist and templates if you want to run it yourself, assisted implementation if you need hands-on help getting controls live, or a managed IT security subscription if you’d rather have proactive monitoring and emergency response covering you year round. Get in touch with Techbug for a compliance review before your next audit or vendor renewal forces the issue.
Primary sources and further reading
Start with the OAIC’s APP guidance, the Privacy Act 1988 Schedule 1 text, and practical summaries from Sprintlaw and Business Queensland.
Why the conventional compliance advice undersells the vendor problem
Most guides on the Australian Privacy Principles spend their energy on the Privacy Policy, because it’s visible and easy to tick off. The bigger risk usually sits somewhere less obvious: the overseas SaaS tool your bookkeeper signed up for on a free trial three years ago, with no enforceable data clause and nobody left who remembers approving it.
APP 8 doesn’t get the same airtime as APP 11, yet cross-border disclosure is where a lot of small businesses would fail an audit today. A polished privacy policy sitting next to an unreviewed vendor contract isn’t compliance. It’s a document that looks like compliance.
If you’re prioritising, start with the data map. You cannot secure, retain correctly, or contractually protect information you haven’t identified. Everything else, the policy wording, the security controls, the breach plan, only works once you know exactly what you’re protecting and where it sits.
— Ru
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Australian Privacy Principles | OAIC
- Legislation
- Sprintlaw: Australian Privacy Principles summary
- Business Queensland: protecting privacy information
