Free resource · Privacy Act 1988

Australian Privacy Principles Checklist

All 13 APPs plus the Notifiable Data Breaches scheme, obligation by obligation. Work through it below, or download the CSV with status, evidence and owner columns.

APP 1Open and transparent management

  • Clearly expressed, up-to-date privacy policy
  • Documented practices, procedures and systems for APP compliance

APP 2Anonymity and pseudonymity

  • Individuals can deal with you anonymously or under a pseudonym unless impractical or law requires ID

APP 3Collection of solicited information

  • Only collect what is reasonably necessary for your functions
  • Collect lawfully and fairly; consent for sensitive information

APP 4Unsolicited personal information

  • Process to assess unsolicited information and destroy / de-identify if you could not have collected it

APP 5Notification of collection

  • Collection notice: identity, purposes, disclosures (incl. overseas), at or before collection

APP 6Use or disclosure

  • Use / disclose only for the primary purpose or a permitted related purpose / exception

APP 7Direct marketing

  • Simple opt-out honoured
  • No sensitive information for marketing without consent; disclose source on request

APP 8Cross-border disclosure

  • Reasonable steps to ensure overseas recipients handle information consistently with the APPs

APP 9Government related identifiers

  • Do not adopt / use / disclose government identifiers (TFN, Medicare…) as your own except where permitted

APP 10Quality of personal information

  • Reasonable steps to keep information accurate, up-to-date, complete and relevant

APP 11Security of personal information

  • Reasonable safeguards: access control, encryption, monitoring, vendor management
  • Destroy or de-identify information when no longer needed

APP 12Access to personal information

  • Give individuals access to their personal information within required timeframes

APP 13Correction of personal information

  • Correct information on request and notify third parties of corrections where required

NDBNotifiable Data Breaches scheme

  • Response plan able to assess an eligible breach
  • Notify OAIC + affected individuals; assessment within 30 days

Summarised from the Privacy Act 1988 (Cth) and OAIC guidance — see oaic.gov.au for the authoritative text. Not legal advice.

APP checklist FAQ

What is the Australian Privacy Principles checklist?
It is a practical list of every obligation under the 13 Australian Privacy Principles (APPs) in the Privacy Act 1988, plus the Notifiable Data Breaches scheme — with room to record your current status, evidence and an owner for each. It turns "are we compliant with the Privacy Act?" into a concrete, obligation-by-obligation tracker.
Is the APP checklist free?
Yes — the full checklist is on this page and free to download as a CSV, no signup. Open it in Excel or Google Sheets and work through it. If you would rather operationalise the security obligations (APP 11) and prove them continuously, that is exactly what CATAAM automates.
Who needs to comply with the Australian Privacy Principles?
Broadly, Australian Government agencies and private-sector organisations with turnover above AU$3 million, plus certain others regardless of size (businesses trading in personal information, health-service providers and some contractors). Ongoing reforms are expanding these obligations, so if you handle Australians’ personal information it is safest to treat the APPs as applying.
Which APP is about security?
APP 11 covers security of personal information: you must take reasonable steps to protect it from misuse, interference, loss and unauthorised access, and destroy or de-identify it when no longer needed. It is the principle CATAAM most directly automates — access control, encryption, monitoring, vendor management and breach readiness.

Make APP 11 provable, not just documented

CATAAM operationalises the security obligations behind the APPs and continuously proves the safeguards — access, encryption, monitoring and breach readiness.