Home » IT Glossary » Australian Privacy Principles (APPs)

What is Australian Privacy Principles (APPs)?

The Australian Privacy Principles are 13 principles in the Privacy Act 1988 governing how organisations collect, use, store, disclose and give access to personal information. They cover everything from transparent privacy policies and direct marketing rules to data quality, security and cross-border disclosure.

Why Australian Privacy Principles matters for Australian businesses

Australian businesses face a growing web of regulatory obligations, from the Privacy Act and Essential Eight to industry-specific standards like PCI DSS. Non-compliance can result in significant fines, reputational damage, and loss of client trust. Understanding these frameworks helps you build a security posture that satisfies regulators and reassures your clients.

For small and medium businesses in particular, the APPs can make a real difference in maintaining a secure, efficient, and resilient IT environment. Whether you are reviewing your current setup or planning improvements, understanding the role of the APPs in your broader IT strategy will help you have more informed conversations with your IT provider and make better decisions for your business.

Related terms

Privacy Act 1988Notifiable Data BreachesData Governance

How All IT Services can help

At All IT Services, we help businesses across Sydney, Brisbane, Melbourne, and regional NSW implement and manage the APPs as part of our comprehensive compliance services. If you have questions about how this fits into your IT strategy, contact our team for a no-obligation consultation.

Frequently Asked Questions

What are the Australian Privacy Principles?

Thirteen legally binding principles under the Privacy Act setting out how personal information must be collected, used, secured, disclosed and made available for access and correction.

Which APPs matter most for security?

APP 11 requires reasonable steps to protect personal information and to destroy or de-identify it when no longer needed — the principle most cyber controls support.

Do the APPs apply to small businesses?

Many small businesses under $3 million turnover are exempt, but exceptions apply — including health service providers and businesses trading in personal information.

← Back to IT Glossary