← Blog

Guide

The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply

August 30, 2026 · 9 min read

The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.

Quick answer: the Australian Privacy Principles (APPs) are 13 principles in Schedule 1 of the Privacy Act 1988 that govern how organisations collect, use, disclose, secure and give access to personal information. They apply to Australian Government agencies and to private-sector organisations with an annual turnover above A$3 million — plus all health-service providers regardless of size. The Act also runs the Notifiable Data Breaches (NDB) scheme, which requires notifying the OAIC and affected individuals of eligible data breaches.

Who must comply?

The APPs bind “APP entities”: most Australian Government agencies, and private-sector organisations and not-for-profits with more than A$3 million annual turnover. Crucially, some organisations are covered regardless of turnover — including all health-service providers, businesses that trade in personal information, and credit-reporting bodies. If you handle the personal information of people in Australia, assume the APPs apply.

The 13 Australian Privacy Principles

  • APP 1 — Open and transparent management (an up-to-date APP Privacy Policy).
  • APP 2 — Anonymity and pseudonymity (give individuals the option where practicable).
  • APP 3 — Collection of solicited personal information (only what’s reasonably necessary).
  • APP 4 — Dealing with unsolicited personal information.
  • APP 5 — Notification of the collection of personal information.
  • APP 6 — Use or disclosure of personal information (limited to the purpose).
  • APP 7 — Direct marketing (restrictions and a simple opt-out).
  • APP 8 — Cross-border disclosure (accountability for overseas recipients).
  • APP 9 — Adoption, use or disclosure of government related identifiers.
  • APP 10 — Quality of personal information.
  • APP 11 — Security of personal information (and destruction/de-identification when no longer needed).
  • APP 12 — Access to personal information.
  • APP 13 — Correction of personal information.

The Notifiable Data Breaches (NDB) scheme

If you suspect an eligible data breach — unauthorised access, disclosure or loss of personal information likely to result in serious harm — you must carry out a reasonable and expeditious assessment (within 30 days) and, if confirmed, notify the OAIC and affected individuals as soon as practicable with a prescribed statement. A documented assessment-and-notification procedure is the control auditors and regulators look for.

APPs vs GDPR — how they compare

The APPs and GDPR share the same DNA: notice, purpose limitation, access and correction, security, cross-border rules and breach notification. There are differences — the APPs have no “legitimate interest” balancing test framed the GDPR way, and the NDB scheme differs from GDPR’s 72-hour rule — but if you’ve done GDPR (or DPDP), most of the work carries over.

Reuse your GDPR controls to get APP-ready

CATAAM ships the Australian Privacy Principles as a first-class framework and cross-maps them onto your existing GDPR/DPDP privacy controls — so a GDPR-ready organisation auto-satisfies most of the APPs and only builds the AU-specific pieces (APP 8 accountability, government identifiers, and the NDB duties). APP 11 (security) is validated with the same evidence-gated technical tests as SOC 2 and ISO 27001.

Automate the Australian Privacy Principles with CATAAM