Australia · Privacy Act 1988 · 13 APPs + NDB

Australian Privacy Principles Compliance

Automate the Australian Privacy Principles inside CATAAM — the 13 APPs plus the Notifiable Data Breaches scheme. Cross-mapped to GDPR so a GDPR-ready program auto-satisfies most of the APPs — and the only platform that also proves your APP 11 safeguards work.

Where the APPs stand today

The Australian Privacy Principles are the operative core of the Privacy Act 1988, enforced by the OAIC, and they bind most organisations with turnover above AUD $3 million plus all health providers. Because the APPs cover the same ground as the GDPR, CATAAM lets you reuse the privacy and security evidence you already have and build only the genuinely Australia-specific controls — the APP Privacy Policy, government identifiers, cross-border accountability and the Notifiable Data Breaches scheme.

Every APP, covered

CATAAM ships the Australian Privacy Principles as a first-class framework across all 13 APPs and the NDB scheme — with APP 11 security validated by native tests and policy/process controls tracked with managed evidence.

APP 1 — Open & Transparent Management

Maintain a clearly expressed, up-to-date APP Privacy Policy and the practices, procedures and systems that ensure compliance and let you handle privacy inquiries and complaints.

APP 2 — Anonymity & Pseudonymity

Give individuals the option of dealing with you anonymously or under a pseudonym, unless it is impracticable or a lawful exception applies.

APP 3-4 — Collection & Unsolicited Information

Collect only the personal information reasonably necessary, by lawful and fair means (sensitive information with consent), and destroy or de-identify unsolicited information you could not have collected under APP 3.

APP 5 — Notification of Collection

Provide a collection notice covering the APP 5 matters — your identity and contact details, the purposes, usual disclosures, your Privacy Policy and any overseas disclosure — at or before the time of collection.

APP 6 — Use or Disclosure

Use or disclose personal information only for the primary purpose, a reasonably-expected related secondary purpose, with consent, or under a permitted exception.

APP 7 — Direct Marketing

Use personal information for direct marketing only where permitted, always offer a simple opt-out and honour it, and comply with the Spam Act and Do Not Call Register where they apply.

APP 8 — Cross-border Disclosure

Before disclosing to an overseas recipient, take reasonable steps to ensure they do not breach the APPs — and remain accountable under APP 8.1 for their handling unless an exception applies.

APP 9-10 — Identifiers & Data Quality

Do not adopt, use or disclose government related identifiers (TFN, Medicare, licence numbers) except as permitted, and take reasonable steps to keep personal information accurate, up-to-date and complete.

APP 11 — Security of Personal Information

Protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure — and destroy or de-identify it when no longer needed. This is where CATAAM validates your safeguards with live tests.

APP 12-13 — Access & Correction

Give individuals access to their personal information on request within the required timeframe, and correct it (and notify third parties) where it is inaccurate, out-of-date, incomplete, irrelevant or misleading.

Notifiable Data Breaches (NDB) Scheme

Assess a suspected eligible data breach expeditiously (within 30 days), and where serious harm is likely, notify the OAIC and affected individuals as soon as practicable with the required statement.

Prove your safeguards — don’t just claim them

APP 11 requires “reasonable steps” to secure personal information but prescribes no checklist — so most platforms have you tick a box. CATAAM validates each safeguard with an evidence-gated test: a control passes only on confirmed technical proof pulled from your live environment. And because CATAAM is also an attack-surface and breach-simulation platform, it goes one step further than any pure GRC tool — it attacks your own environment to prove the safeguards actually work, feeding those findings straight into your APP 11 evidence.

One evidence set, cross-mapped: satisfy the APPs, GDPR, DPDP, SOC 2 and ISO 27001 from the same controls, so the multi-framework burden doesn’t multiply.

How it works

01

Enrol and inherit the APP program

Enrol your organization in the Australian Privacy Principles. CATAAM scaffolds the full control set — all 13 APPs plus the NDB scheme — and inherits a library of privacy policies (privacy, collection notice, retention, breach response, direct marketing) automatically.

02

Reuse your GDPR work

The APPs overlap heavily with the GDPR. CATAAM cross-maps a single evidence set, so consent, notices, data inventory, retention, access, correction and breach controls you already built for GDPR carry straight into your APP program — you only add the genuinely AU-specific pieces.

03

Prove APP 11 security with real evidence

APP 11 requires reasonable security safeguards but sets no checklist. CATAAM validates each one — encryption, access control, monitoring — with a native, evidence-gated test against your live environment, so what you show a regulator is proof, not a policy PDF.

04

Stay breach-ready and audit-ready

Keep your eligible-breach assessment and OAIC/individual notification process current for the NDB clock, generate your records, and hand an auditor a tokenized, read-only evidence portal.

Australian Privacy Principles FAQ

What are the Australian Privacy Principles and who must comply?
The Australian Privacy Principles (APPs) are the 13 principles in Schedule 1 of the Privacy Act 1988 that govern how personal information is collected, used, disclosed, secured, accessed and corrected. They apply to "APP entities" — most Australian businesses and organisations with an annual turnover above AUD $3 million, plus all health service providers regardless of size, and certain other organisations. The Notifiable Data Breaches (NDB) scheme applies alongside them.
How does CATAAM automate Australian Privacy Principles compliance?
CATAAM ships the APPs as a first-class framework covering all 13 principles plus the NDB scheme. The security requirements of APP 11 are validated by native, evidence-gated tests against your live environment, while the policy and process controls — collection notices, direct-marketing opt-out, cross-border accountability, access and correction, and eligible-breach notification — are tracked with managed evidence.
We already comply with GDPR — do we start the APPs from scratch?
No. The Australian Privacy Principles overlap heavily with the GDPR, and CATAAM cross-maps a single evidence set across both. A GDPR-ready organisation auto-satisfies most of the APPs and only builds the genuinely Australia-specific controls — the APP Privacy Policy, anonymity/pseudonymity, government related identifiers, and the Notifiable Data Breaches scheme.
What is the Notifiable Data Breaches (NDB) scheme?
Under the NDB scheme, an APP entity that suspects an eligible data breach — unauthorised access, disclosure or loss of personal information likely to result in serious harm — must carry out a reasonable and expeditious assessment within 30 days and, if it is an eligible breach, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. CATAAM keeps the control evidence and incident records current so your statement is ready when you need it.
How do the APPs differ from GDPR?
The APPs cover much of the same ground as GDPR but with Australia-specific mechanics: an option of anonymity or pseudonymity (APP 2), a bar on adopting government related identifiers like the Tax File Number (APP 9), a distinct cross-border accountability model (APP 8), direct-marketing rules tied to the Spam Act and Do Not Call Register (APP 7), and the NDB scheme in place of GDPR breach reporting. CATAAM ships dedicated controls for each so your GDPR foundation extends cleanly.

WATCH

The Australian Privacy Principles, explained

Two minutes: what the 13 APPs are, who must comply, the 30-day Notifiable Data Breaches clock, how they map to GDPR, and how CATAAM automates the Privacy Act.

Get APP-ready with CATAAM

Enrol in the Australian Privacy Principles framework, reuse the GDPR evidence you already have, and prove your APP 11 safeguards actually work — transparently priced from $149/mo.