← Blog

Guide

The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply

August 30, 2026 · 9 min read

The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.

Quick answer: the Australian Privacy Principles (APPs) are 13 principles in Schedule 1 of the Privacy Act 1988 that govern how organisations collect, use, disclose, secure and give access to personal information. They apply to Australian Government agencies and to private-sector organisations with an annual turnover above A$3 million — plus all health-service providers regardless of size. The Act also runs the Notifiable Data Breaches (NDB) scheme, which requires notifying the OAIC and affected individuals of eligible data breaches.

Watch (2:05): what the 13 APPs are, who must comply, the 30-day Notifiable Data Breaches clock, how they map to GDPR, and how CATAAM automates the Privacy Act.

Who must comply?

The APPs bind “APP entities”: most Australian Government agencies, and private-sector organisations and not-for-profits with more than A$3 million annual turnover. Crucially, some organisations are covered regardless of turnover — including all health-service providers, businesses that trade in personal information, and credit-reporting bodies. If you handle the personal information of people in Australia, assume the APPs apply.

The 13 Australian Privacy Principles

  • APP 1 — Open and transparent management (an up-to-date APP Privacy Policy).
  • APP 2 — Anonymity and pseudonymity (give individuals the option where practicable).
  • APP 3 — Collection of solicited personal information (only what’s reasonably necessary).
  • APP 4 — Dealing with unsolicited personal information.
  • APP 5 — Notification of the collection of personal information.
  • APP 6 — Use or disclosure of personal information (limited to the purpose).
  • APP 7 — Direct marketing (restrictions and a simple opt-out).
  • APP 8 — Cross-border disclosure (accountability for overseas recipients).
  • APP 9 — Adoption, use or disclosure of government related identifiers.
  • APP 10 — Quality of personal information.
  • APP 11 — Security of personal information (and destruction/de-identification when no longer needed).
  • APP 12 — Access to personal information.
  • APP 13 — Correction of personal information.

The Notifiable Data Breaches (NDB) scheme

If you suspect an eligible data breach — unauthorised access, disclosure or loss of personal information likely to result in serious harm — you must carry out a reasonable and expeditious assessment (within 30 days) and, if confirmed, notify the OAIC and affected individuals as soon as practicable with a prescribed statement. A documented assessment-and-notification procedure is the control auditors and regulators look for.

APPs vs GDPR — how they compare

The APPs and GDPR share the same DNA: notice, purpose limitation, access and correction, security, cross-border rules and breach notification. There are differences — the APPs have no “legitimate interest” balancing test framed the GDPR way, and the NDB scheme differs from GDPR’s 72-hour rule — but if you’ve done GDPR (or DPDP), most of the work carries over.

Reuse your GDPR controls to get APP-ready

CATAAM ships the Australian Privacy Principles as a first-class framework and cross-maps them onto your existing GDPR/DPDP privacy controls — so a GDPR-ready organisation auto-satisfies most of the APPs and only builds the AU-specific pieces (APP 8 accountability, government identifiers, and the NDB duties). APP 11 (security) is validated with the same evidence-gated technical tests as SOC 2 and ISO 27001.

Automate the Australian Privacy Principles with CATAAM