Free tool · no signup · Privacy Act 1988

Australian Privacy Act Assessment

Score yourself against all 13 Australian Privacy Principles and the Notifiable Data Breaches scheme, and get an instant readiness score, your gap list, and exactly what to fix first.

APP 1

You have a clear, up-to-date privacy policy and a documented approach to managing personal information openly and transparently.

APP 2

Individuals can deal with you anonymously or under a pseudonym where it is lawful and practical.

APP 3

You only collect personal information that is reasonably necessary for your functions, and collect it lawfully and fairly.

APP 4

You have a process for dealing with unsolicited personal information — assessing and destroying/de-identifying it if you couldn’t have collected it.

APP 5

You notify individuals of the matters required (who you are, why you collect, disclosures) at or before the time of collection.

APP 6

You use and disclose personal information only for the primary purpose, or a permitted related purpose or exception.

APP 7

Direct marketing includes a simple opt-out and honours it; you don’t use sensitive information for marketing without consent.

APP 8

Before disclosing personal information overseas you take reasonable steps to ensure the recipient complies with the APPs.

APP 9

You do not adopt, use or disclose government-related identifiers (e.g. TFN, Medicare) as your own identifier except where permitted.

APP 10

You take reasonable steps to ensure the personal information you collect, use and disclose is accurate, up-to-date and complete.

APP 11

You protect personal information with reasonable security safeguards and destroy or de-identify it when no longer needed.

APP 12

You can give individuals access to their personal information on request, within the required timeframes.

APP 13

You can correct personal information on request and notify third parties of corrections where required.

NDB scheme

You have a data-breach response plan that can assess an eligible breach and notify the OAIC and affected individuals within 30 days.

Foundations

You maintain a current record of what personal information you hold, where it lives, and who it’s shared with.

Foundations

Staff who handle personal information receive privacy training, and there’s an owner accountable for privacy.

0/16 answered — answer all to see your readiness score.

Directional self-assessment against the 13 Australian Privacy Principles and the NDB scheme — not legal advice or an OAIC assessment. Your obligations depend on your organisation and how you handle personal information. Nothing you enter leaves your browser.

The Privacy Act & the APPs, explained

What are the Australian Privacy Principles?

The Australian Privacy Principles (APPs) are the 13 principles at the core of the Privacy Act 1988 that govern how organisations handle personal information — from open and transparent management (APP 1) and collection notices (APP 5) through use and disclosure, cross-border disclosure (APP 8), security (APP 11), and access and correction (APP 12–13). This tool scores you against all 13, plus the Notifiable Data Breaches scheme.

Who has to comply with the Privacy Act and the APPs?

Broadly, Australian Government agencies and private-sector organisations with an annual turnover above AU$3 million, plus some others regardless of size — including businesses that trade in personal information, health-service providers, and certain contractors. If you handle Australians’ personal information, it’s safest to treat the APPs as applying. Note that reforms are progressively expanding these obligations.

What is the Notifiable Data Breaches (NDB) scheme?

Under the NDB scheme, if you experience an eligible data breach — unauthorised access, disclosure or loss of personal information that is likely to result in serious harm — you must notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and generally complete your assessment within 30 days. This tool checks whether you have a response plan that can actually meet that.

What does APP 11 require for security?

APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure — and to destroy or de-identify it when it is no longer needed. In practice that means access controls, encryption, monitoring, vendor management and a tested breach-response capability. CATAAM automates and continuously proves exactly those safeguards.

Is this legal advice?

No. This is a free, directional self-assessment to help you find gaps and prioritise — not legal advice or an OAIC assessment. For binding interpretation of your obligations, consult a privacy professional. What CATAAM does is operationalise the security and evidence side of the APPs so compliance is provable, not just documented.