Free resource · Privacy Act 1988
Australian Privacy Principles Checklist
All 13 APPs plus the Notifiable Data Breaches scheme, obligation by obligation. Work through it below, or download the CSV with status, evidence and owner columns.
APP 1 — Open and transparent management
- Clearly expressed, up-to-date privacy policy
- Documented practices, procedures and systems for APP compliance
APP 2 — Anonymity and pseudonymity
- Individuals can deal with you anonymously or under a pseudonym unless impractical or law requires ID
APP 3 — Collection of solicited information
- Only collect what is reasonably necessary for your functions
- Collect lawfully and fairly; consent for sensitive information
APP 4 — Unsolicited personal information
- Process to assess unsolicited information and destroy / de-identify if you could not have collected it
APP 5 — Notification of collection
- Collection notice: identity, purposes, disclosures (incl. overseas), at or before collection
APP 6 — Use or disclosure
- Use / disclose only for the primary purpose or a permitted related purpose / exception
APP 7 — Direct marketing
- Simple opt-out honoured
- No sensitive information for marketing without consent; disclose source on request
APP 8 — Cross-border disclosure
- Reasonable steps to ensure overseas recipients handle information consistently with the APPs
APP 9 — Government related identifiers
- Do not adopt / use / disclose government identifiers (TFN, Medicare…) as your own except where permitted
APP 10 — Quality of personal information
- Reasonable steps to keep information accurate, up-to-date, complete and relevant
APP 11 — Security of personal information
- Reasonable safeguards: access control, encryption, monitoring, vendor management
- Destroy or de-identify information when no longer needed
APP 12 — Access to personal information
- Give individuals access to their personal information within required timeframes
APP 13 — Correction of personal information
- Correct information on request and notify third parties of corrections where required
NDB — Notifiable Data Breaches scheme
- Response plan able to assess an eligible breach
- Notify OAIC + affected individuals; assessment within 30 days
Summarised from the Privacy Act 1988 (Cth) and OAIC guidance — see oaic.gov.au for the authoritative text. Not legal advice.
APP checklist FAQ
- What is the Australian Privacy Principles checklist?
- It is a practical list of every obligation under the 13 Australian Privacy Principles (APPs) in the Privacy Act 1988, plus the Notifiable Data Breaches scheme — with room to record your current status, evidence and an owner for each. It turns "are we compliant with the Privacy Act?" into a concrete, obligation-by-obligation tracker.
- Is the APP checklist free?
- Yes — the full checklist is on this page and free to download as a CSV, no signup. Open it in Excel or Google Sheets and work through it. If you would rather operationalise the security obligations (APP 11) and prove them continuously, that is exactly what CATAAM automates.
- Who needs to comply with the Australian Privacy Principles?
- Broadly, Australian Government agencies and private-sector organisations with turnover above AU$3 million, plus certain others regardless of size (businesses trading in personal information, health-service providers and some contractors). Ongoing reforms are expanding these obligations, so if you handle Australians’ personal information it is safest to treat the APPs as applying.
- Which APP is about security?
- APP 11 covers security of personal information: you must take reasonable steps to protect it from misuse, interference, loss and unauthorised access, and destroy or de-identify it when no longer needed. It is the principle CATAAM most directly automates — access control, encryption, monitoring, vendor management and breach readiness.
Make APP 11 provable, not just documented
CATAAM operationalises the security obligations behind the APPs and continuously proves the safeguards — access, encryption, monitoring and breach readiness.