1. The short answer: 13 principles in one schedule
  2. Who the APPs bind: APP entities and the small business exemption
  3. The exemption is not set and forget
  4. Scenario: you collect customer details on your website
  5. Scenario: your software and data live overseas
  6. Scenario: you market to your customers by email
  7. Scenario: you run a health, fitness or wellness business
  8. Scenario: something goes wrong and data is exposed
  9. Do you need a lawyer for any of this?
  10. The answer, and the question that matters

Almost every business in Australia handles personal information. It might be the names and email addresses people type into an enquiry form on your website, the delivery addresses sitting in your order system, the details in your staff files, the phone numbers on your marketing list, or the records your bookkeeper keeps about your customers and suppliers.

If you have ever stopped to wonder how many rules Australia actually has about all of this, the answer is a surprisingly neat one: there are 13 Australian Privacy Principles (the APPs), and they sit together in one schedule of the Privacy Act 1988 (Cth) (the Act).

As with most legal questions, though, the number is the easy part. The harder questions are whether the APPs apply to your business at all, and what they actually require you to do day to day. That is what this guide covers: what the 13 principles are, who they bind, and the everyday situations in which they matter to a small or growing business.

The short answer: 13 principles in one schedule

The Australian Privacy Principles are set out in Schedule 1 of the Act. Under s 14 of the Act, the APPs are the clauses of that schedule, and s 15 requires every APP entity to comply with each of them. An APP entity is, in simple terms, an Australian Government agency or a private sector organisation, and breach of a principle can lead to a complaint to the Office of the Australian Information Commissioner (the OAIC).

The 13 principles are:

  • APP 1 (open and transparent management): manage personal information openly and transparently, which in practice means having a clear privacy policy.
  • APP 2 (anonymity and pseudonymity): give people the option to deal with you anonymously or under a pseudonym where that is practicable.
  • APP 3 (collection of solicited personal information): only collect what is reasonably necessary for your functions or activities, and only collect sensitive information with consent.
  • APP 4 (dealing with unsolicited personal information): handle personal information you receive but did not ask for, including destroying or de-identifying it where you could not lawfully have collected it.
  • APP 5 (notification of collection): tell people, at or before the point of collection, who you are, what you are collecting, why, and who you might disclose it to.
  • APP 6 (use or disclosure): use or disclose personal information only for the purpose you collected it for, unless an exception such as consent or a reasonably expected related purpose applies.
  • APP 7 (direct marketing): only use personal information for direct marketing where the rules allow, and always provide a way to opt out.
  • APP 8 (cross-border disclosure): before sending personal information to an overseas recipient, take reasonable steps to ensure the recipient does not breach the APPs.
  • APP 9 (government related identifiers): do not adopt government identifiers such as Medicare numbers as your own identifier for individuals.
  • APP 10 (quality): take reasonable steps to keep personal information accurate, up to date and complete.
  • APP 11 (security): protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
  • APP 12 (access): give individuals access to the personal information you hold about them on request.
  • APP 13 (correction): correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.

Read as a list, they can look like administration. Read as a scheme, they trace the full lifecycle of personal information: collection, notice, use, disclosure, storage, security, access and correction. They are not merely paperwork rules. They affect the systems you choose, the software you use, the marketing you send and what you do when something goes wrong.

The Act defines personal information broadly as information or an opinion about an identified individual, or an individual who is reasonably identifiable. A customer's name and email address qualifies, and so does far more sensitive material such as health information.

Who the APPs bind: APP entities and the small business exemption

Because the APPs bind APP entities, the first question for any business is whether it is one. For most private sector businesses, that comes down to whether you count as a small business operator, because the Act carves small business operators out of the scheme.

The test in s 6D of the Act is turnover based. A business is a small business if its annual turnover for the previous financial year was $3 million or less. A new business that has not yet traded for a full financial year is tested against its current year turnover instead. Annual turnover is defined broadly, and includes the proceeds of sales of goods and services, commission income, rent, leasing and hiring income, interest and other operating income.

If your business is a small business operator, the APPs generally do not bind you. If your turnover exceeds $3 million, or you never qualified as a small business operator, you are an organisation and the APPs apply to you in full.

The exemption is not set and forget

The exemption depends on what you do, not just what you turn over. Under s 6D(4) of the Act, a business is not a small business operator, and so stays inside the privacy regime, if it:

  • Provides a health service and holds health information: this catches far more than doctors and dentists. Gyms, personal trainers, naturopaths, wellness coaches and some hospitality businesses can hold health information without thinking of themselves as health providers.
  • Discloses personal information for a benefit, service or advantage: for example, selling or sharing customer contact details with another business for a fee or other benefit.
  • Provides a benefit, service or advantage to collect personal information from someone else: for example, paying a third party for access to leads or contact lists.
  • Is a contracted service provider for a Commonwealth contract: if you deliver services under a Commonwealth government contract, the exemption does not apply to that work.
  • Is a credit reporting body: a narrow category, but credit reporting bodies are always covered.

There is also an opt-in route. Under s 6EA of the Act, a small business operator can choose to be treated as an organisation by giving the Commissioner a written choice that is registered. Businesses sometimes do this to win enterprise clients, who increasingly ask suppliers to confirm their privacy compliance.

The exemption is also a moving target in two practical ways. First, turnover can grow: once a financial year closes with turnover above $3 million, the exemption is gone. Second, your activities can change: take on a Commonwealth contract, start sharing customer data with other businesses, or add a health-related service, and you can move inside the regime without realising it. Even while you are exempt, treating the APPs as a baseline of good practice is usually sensible, because customers, enterprise clients and investors increasingly expect it, and because other laws, such as spam and marketing rules, still apply to what you send and how you collect consent.

Scenario: you collect customer details on your website

If you run an online store, take bookings, or capture leads through forms on your website, several principles shape how you operate if you are an APP entity.

Under APP 3, you may only collect personal information that is reasonably necessary for your functions or activities. A newsletter sign-up form does not need a date of birth, and a contact form does not need a customer's occupation. Under APP 3.3, collecting sensitive information, such as health details, requires consent. Under APP 5, you must notify people at or before the point of collection, which is what a privacy collection notice on a checkout page or lead form does. And under APP 1, you need a privacy policy that explains your practices in plain terms.

For a covered business, the trap is usually a mismatch: a privacy policy that says one thing while forms, tools and staff habits do another. The goal is an accurate policy, not a strict one.

Scenario: your software and data live overseas

Most small businesses run on tools built outside Australia: customer relationship software, email marketing platforms, analytics, cloud storage and payment processors. Under APP 8, before you disclose personal information to an overseas recipient, you must take such steps as are reasonable in the circumstances to ensure the recipient does not breach the APPs. The Act backs this up: under s 16C, if an overseas recipient breaches the APPs in handling information you disclosed, the breach is treated as your own.

Whether a particular arrangement involves a disclosure to an overseas recipient can depend on the details, such as where the data is stored, whether the provider's staff can access it, and the terms of your contract. The point is not that overseas tools are off limits. It is that you should know which of your tools involve cross-border handling, check whether the provider offers protections substantially similar to the APPs, and reflect the reality in your privacy policy and vendor checks. Working through a short list of your main software tools with a lawyer is often the quickest way to see where APP 8 bites.

Scenario: you market to your customers by email

APP 7 is the direct marketing principle. It does not ban marketing to existing customers. It sets the conditions: you may generally use personal information for direct marketing where the individual would reasonably expect you to, or where they have consented, and you must give them a simple way to opt out of further messages, which you then honour.

For a business building an email list, this mostly means thinking about marketing at the point of collection, being upfront in your collection notice about how the information may be used, and keeping the unsubscribe path working. Where privacy law does not apply because of an exemption, marketing rules under other legislation can still impose their own requirements on what you send.

Scenario: you run a health, fitness or wellness business

If your business provides a health service and holds health information, the small business exemption does not apply, whatever your turnover. Under s 6D(4)(b) of the Act, providing a health service and holding health information takes you outside the definition of a small business operator.

The consequence is that the APPs apply in full, and health information is sensitive information, which attracts higher standards. Under APP 3.3 you need consent to collect it, and the other principles, from notification to security to access and correction, apply with that sensitivity in mind. Businesses in this category are often surprised to find themselves covered. If there is any doubt about whether what you do counts as a health service, it is worth checking with a lawyer rather than assuming the exemption protects you.

Scenario: something goes wrong and data is exposed

The Notifiable Data Breaches scheme sits in Part IIIC of the Act, and it applies to APP entities. Under s 26WE, an eligible data breach happens when there is unauthorised access to, unauthorised disclosure of, or loss of, personal information that is likely to result in serious harm to any of the individuals concerned.

The scheme has a simple logic. If you have reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment, and the Act requires you to take all reasonable steps to complete it within 30 days. If you then have reasonable grounds to believe an eligible data breach has happened, you must prepare a statement and give it to the OAIC as soon as practicable, and take reasonable steps to notify the affected individuals. The Commissioner can also direct you to notify.

The practical point is that a covered business needs to know what to do before an incident happens: who assesses it, what evidence to gather, and how quickly notification duties crystallise. The 30-day assessment clock and the serious harm threshold are the parts that matter, and a data breach response plan that a lawyer has helped you build is far cheaper than working it out under pressure.

Do you need a lawyer for any of this?

For many small businesses, the honest answer is: not yet. If you are genuinely exempt, collect minimal information and keep it only as long as you need it, the APPs may never bite. But the situations above show how quickly the position can change. A business that takes on a Commonwealth contract, moves into health-adjacent services, starts using a stack of overseas tools, or grows past $3 million in turnover can cross into the regime almost without noticing.

That is why a quick check is usually worth it. A privacy lawyer can confirm whether the Act applies to you, identify which of the 13 principles actually bind your operations, review whether your privacy policy and collection notices match what your business really does, and help you build a simple process for access, correction and breach requests. You do not need a compliance department to do any of this, and finding out where you stand does not have to cost anything: most firms, including Artificer Legal, offer an initial consultation, and a five-minute enquiry will normally give you an excellent steer on whether you have a real issue or can safely leave it for now.

The answer, and the question that matters

The answer to the question in the title is easy to remember: there are 13 Australian Privacy Principles, set out in Schedule 1 of the Privacy Act 1988 (Cth), and they bind APP entities, which in practice means most businesses that are not small business operators. The number only gets you so far. The question that actually matters is whether the principles apply to you, and if they do, whether your collection, storage, marketing and disclosure practices line up with what you tell your customers. If you can answer that second question, the 13 principles largely take care of themselves. If you are not sure, a short conversation with a privacy lawyer will tell you which side of the line you are on.