Privacy Act 1988 — APP entities and material scope
The Privacy Act 1988 (Cth) regulates the handling of personal information by APP entities—Commonwealth and ACT agencies, and private-sector organisations that meet a statutory threshold or qualifying activity. The scope, key thresholds, and exemptions are set by the Act (particularly ss 6, 6C, 6D), the Privacy Regulations 2025, and authoritative guidance from the Office of the Australian Information Commissioner (OAIC).
## Recent material changes (2026)
1. Privacy Regulations 2025 (effective 1 April 2026). The Privacy Regulations 2025 replaced the 2013 Regulations and are now the governing regulations. While the stated intention was not to introduce substantive changes, all regulatory references should now cite the 2025 version.
2. Tranche 2 AML/CTF reporting entities — mandatory APP entity status (effective 1 July 2026). The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 expands the definition of APP entities: from 1 July 2026, new classes of Tranche 2 reporting entities—real estate professionals, lawyers, accountants, conveyancers, dealers in precious metals and stones, trust and company service providers—will become APP entities for any handling of personal information relating to their AML/CTF obligations, irrespective of annual turnover. This overrides the small business operator exemption where Tranche 2 activities are in scope. (Privacy Act 1988 s 6D(4), as amended).
3. Automated decision-making transparency (commences 10 December 2026). Under the Privacy and Other Legislation Amendment Act 2024, new transparency requirements will apply to APP entities that arrange for personal information to be used in automated decision-making likely to significantly affect individuals' rights or interests. From 10 December 2026, privacy policies must disclose relevant details about such automated processes (APP 1.7–1.9).
---
APP entities are thus defined, as of July 2026, as follows:
- Agencies: Commonwealth and ACT government agencies under s 6(1) (with ACT-specific parallel regime).
- Organisations: Individuals, bodies corporate, partnerships, unincorporated associations, and trusts not otherwise exempted. The general rule carves out small business operators (≤$3 million turnover, s 6D), but mandatory carve-ins (s 6D(4)) include health service providers, entities trading in personal information, credit reporting bodies, employee associations, certain providers under AML/CTF, PART IIIA, and, from 1 July 2026, Tranche 2 reporting entities for AML/CTF purposes.
- Entities may also opt in to APP status under s 6EA.
Exemptions and exclusions remain: employee records exemption for private-sector employers (s 7B(3)), journalism carve-out (s 7B(4)), and specific exemptions for court/tribunal activities, acts required or authorised by law, and personal/household use.
Territorial scope and the "Australian link" test (s 5B) are unchanged.
Future reform: The Privacy Act Review process is ongoing; additional reforms are anticipated in the coming legislative cycles.
Source: Privacy Act 1988 (Cth) s 6, 6C, 6D, 5B; as at July 2026, Privacy Regulations 2025, Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, OAIC — APP entity guidance, OAIC — Privacy law reform and AML/CTF update
Definition of "personal information" — s 6(1) triggering concept
The Privacy Act 1988 regulates the handling of personal information. Whether data falls within the Act's scope turns entirely on whether it meets the statutory definition in section 6(1). Personal information is defined as:
> information or an opinion about an identified individual, or an individual who is reasonably identifiable: (a) whether the information or opinion is true or not; and (b) whether the information or opinion is recorded in a material form or not.
This definition establishes four elements: (1) information or an opinion, (2) about an individual, (3) who is identified or reasonably identifiable, and (4) regardless of truth or recording format.
"Information or an opinion" — The definition captures both factual data and subjective assessments. A credit assessment, a performance review, an actuarial inference about behaviour, or a prediction about future conduct can all be personal information if the other elements are met. The OAIC's Chapter B guidance confirms that by explicitly including "opinion," the definition captures inferred information — data an entity derives or predicts about an individual, even if that individual never provided it directly. This matters for profiling, algorithmic scoring, and machine-learning outputs: if the output is about an identified or reasonably identifiable person, it is personal information.
"About an individual" — The information must be about the individual, not merely mentioning them or associated with them in passing. The OAIC guidance notes that information can have multiple subjects: for example, information that a deceased person had an inheritable genetic condition may be personal information about the deceased person's living descendants if they are identifiable, because it reveals an increased health risk for them. Metadata — IP addresses, device identifiers, location pings — remains a contested edge case. Whether metadata constitutes personal information depends on whether it is about the individual (not just generated by their device) and whether the individual is reasonably identifiable from it, either from the data itself or in combination with other information the entity holds or has access to.
"Identified or reasonably identifiable" — An individual is identified when their identity is apparent from the information (for example, their name appears). An individual is reasonably identifiable when their identity can be ascertained through reasonable means, considering the context and available information. The OAIC's guidance explains that "reasonably identifiable" requires two conditions: (1) it is technically possible for re-identification to occur (from the information itself or in combination with other information in the data-access environment), and (2) there is a reasonable likelihood of re-identification occurring. This is an objective test assessed from the perspective of the entity holding the information and, if the information is publicly released, a reasonable member of the public who accesses it. The test considers: the nature and amount of information; whether other information that could be linked to identify the individual is held by the entity or is publicly available; and the practicality of identification, including the cost, difficulty, and technology required. A single data point in isolation (a birth date, a postcode) is generally not personal information, but combined data points (birth date + suburb + gender) may render the individual reasonably identifiable. The OAIC encourages entities to err on the side of caution: where identifiability is uncertain, treat the information as personal information.
True or not; recorded or not — The definition applies to false information and unrecorded opinions. An incorrect address in a database, a mistaken belief about an individual's qualifications, and even a verbal opinion formed but not yet documented all qualify, provided the individual is identified or reasonably identifiable. This breadth ensures the APPs govern accuracy (APP 10) and correction (APP 13) regardless of recording medium.
De-identified information — Information ceases to be personal information when it is de-identified. Section 6(1) defines "de-identified" as information that "is no longer about an identifiable individual or an individual who is reasonably identifiable." De-identification requires removing or altering personal identifiers (name, address, date of birth) and applying additional techniques to obscure, aggregate, or protect the data so that individuals cannot be reasonably identified. The OAIC's de-identification guidance emphasises that context matters: entities must assess re-identification risk not only from the data itself but also from the environment into which the data will be released. Effective de-identification mitigates the risk until it is very low; it need not remove the risk entirely. Once information is genuinely de-identified, it is no longer governed by the APPs (though APP 11.2 requires entities to take reasonable steps to de-identify or destroy personal information they no longer need for any permitted purpose).
Individuals, not legal persons — "Individual" is defined in s 6(1) as "a natural person." The Privacy Act does not protect information about companies, trusts, partnerships, or other non-natural legal entities. Information about a sole trader or small-business owner may be personal information if the individual is identified or reasonably identifiable from it — business contact details, ABN records, and trading history can reveal the identity of the natural person behind the business. The OAIC guidance confirms that personal information is not limited to private or family life; it extends to information about an individual's work activities and business dealings.
Deceased persons — The ordinary meaning of "natural person" does not include deceased persons. Information about a deceased individual is not personal information about that deceased person. However, it may be personal information about living individuals if they are identifiable from it — for example, information about a deceased person's inheritable medical condition is personal information about the deceased's living descendants if they are identifiable.
Sensitive information and health information — The Privacy Act defines two subsets of personal information that attract heightened protection. Sensitive information (s 6(1)) includes information or opinion about an individual's racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, and biometric information or biometric templates. Health information (s 6FA) includes information or opinion about the health or a disability of an individual; an individual's expressed wishes about the future provision of health services; and a health service provided or to be provided to an individual. These subsets remain personal information but are subject to stricter collection, use, and disclosure rules under the APPs (notably APP 3.3–3.4 for collection of sensitive information).
Credit information — Credit-related personal information is also personal information but is regulated separately under Part IIIA of the Privacy Act, which establishes a parallel credit-reporting regime with its own definitions and privacy principles for credit reporting bodies and credit providers. An entity handling credit information must comply with both the general APPs (for non-credit personal information) and the Part IIIA regime (for credit information).
The 2020 Privacy Act Review and the government's September 2023 response proposed reforms to the definition of personal information, including express inclusion of inferred information and technical identifiers, replacement of "de-identified" with "anonymised" to align with international practice (GDPR), and new protections for anonymised data (extended APP 11, prohibition on re-identification). The Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) did not enact these definitional changes; they remain under consideration for future legislation.
Source: Privacy Act 1988 s 6(1) — definitions, OAIC — What is personal information?, OAIC — Australian Privacy Principles Guidelines, Chapter B (Key concepts)
Extraterritorial application — the "Australian link" test and carrying on business in Australia
The Privacy Act 1988 (Cth) applies extraterritorially to acts and practices done or engaged in outside Australia by agencies and organisations meeting the Australian-link threshold. This ensures that Australian-incorporated entities remain bound when processing personal information offshore, and that foreign entities with sufficient connection to Australia are also subject to the APPs.
Section 5B(1) provides that the Act, registered APP codes, and the registered CR code extend to acts or practices outside Australia and the external Territories by an agency or organisation. Australian Government and ACT agencies are therefore bound wherever they act in the world. For organisations and small business operators, the position is more nuanced: under s 5B(1A), the Act extends to acts or practices outside Australia if the organisation or small business operator has an Australian link. This threshold determines whether a foreign entity falls within the Commissioner's jurisdiction.
Automatic Australian link — s 5B(2). An organisation or small business operator has an Australian link if it is:
- an Australian citizen;
- a person whose continued presence in Australia is not subject to a time limitation imposed by law (a permanent resident or other lawful non-citizen not under a temporary visa);
- a partnership formed in Australia or an external Territory;
- a trust created in Australia or an external Territory;
- a body corporate incorporated in Australia or an external Territory; or
- an unincorporated association that has its central management and control in Australia or an external Territory (s 5B(2) read with s 6C(1)(c)).
An Australian-incorporated company therefore has an Australian link and is bound by the Privacy Act for all its data-handling worldwide, even if its operations, servers, and personnel are entirely offshore. The statute applies to the act or practice itself, not to the location of the data subject — an Australian entity processing personal information about EU residents in the EU must comply with the APPs (though s 13D provides a defence where an applicable foreign law requires the act or practice).
Carrying on business in Australia — s 5B(3). An organisation or small business operator that does not fall within s 5B(2) will nevertheless have an Australian link if it carries on business in Australia or an external Territory (s 5B(3)(b)). Before December 2022, s 5B(3) also required that the personal information was collected or held in Australia; the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (No. 83, 2022) repealed that element. Since 13 December 2022, the sole question is whether the foreign entity carries on business in Australia.
The phrase "carries on business in Australia" is not defined in the Privacy Act. The OAIC's Chapter B guidance draws on judicial consideration of the phrase in corporations law, consumer law, and taxation law. Two elements must be satisfied: (1) the entity carries on business (repetition of commercial acts on a systematic or continuing basis, with a profit motive for commercial entities or regularity for non-profits), and (2) the business is carried on in Australia (activity undertaken in Australia as part of the entity's business). Both are questions of fact assessed having regard to all relevant circumstances.
Common-law principles establish that there is "a need for some physical activity in Australia through human instrumentalities, being activity that itself forms part of the course of conducting business" (quoted in Chapter B para B.17, citing Hope v Council of the City of Bathurst (1980) 144 CLR 1 at 8). However, an entity may carry on business in Australia even if "the bulk of its business is conducted elsewhere and it maintains no office in Australia", provided there are acts within Australia which are part of the company's business (Bray v F Hoffman-La Roche Ltd (2002) 118 FCR 1 at [62], quoted in Chapter B para B.17). This means a single employee or agent acting on behalf of the foreign entity from Australia may be sufficient, if their activity forms part of the entity's business (for example, assessing purchase orders, uploading web content, or providing customer support).
Multi-factor assessment — the OAIC's guidance (Chapter B para B.19). In the context of the Privacy Act's operation in an online environment, the OAIC identifies non-exhaustive factors that may indicate an entity carries on business in Australia:
- People who undertake business acts for the entity are located in Australia (for example, an agent acting on the entity's behalf from a fixed place in Australia);
- the entity has a website that offers goods or services to countries including Australia;
- Australia is one of the countries on the drop-down menu appearing on the entity's website;
- web content that forms part of carrying on the business was uploaded by or on behalf of the entity, in Australia;
- business or purchase orders are assessed or acted upon in Australia;
- the entity is the registered proprietor of trademarks in Australia.
No single factor is determinative. The presence or absence of one factor does not conclusively establish whether the entity carries on business in Australia (Chapter B para B.20). The question is whether, assessed holistically, the entity is undertaking activity in Australia as part of its business. A foreign platform with no Australian employees, no Australian office, and no Australian presence — serving Australian users entirely from offshore servers — will generally not carry on business in Australia unless it can be shown that some business activity (beyond the passive availability of a website to Australian users) occurs in Australia. The distinction matters for enforcement: the Commissioner can investigate and issue determinations against foreign entities with an Australian link, but not against purely offshore entities with no Australian connection.
The 2022 reform and current scope. The December 2022 removal of the "collected or held in Australia" limb in s 5B(3) was a response to data-breach incidents involving foreign entities. The OAIC had recommended the change in its 2020 Privacy Act Review submission, noting that collection or holding of information in Australia should be considered an indicator of carrying on business in Australia, rather than a separate statutory requirement. The amendment means the Commissioner needs only establish that a foreign entity carries on business in Australia — the location where the personal information was collected or is held is now irrelevant to jurisdiction, though it remains probative of whether the entity is undertaking business activity in Australia.
Foreign entities assessing whether they have an Australian link should consider: incorporation (s 5B(2)(e) is a bright-line rule); the location of personnel undertaking business acts; whether they actively offer goods or services to the Australian market (not merely permitting Australians to access an offshore site); whether they target Australian customers through advertising, country selectors, or local pricing; and whether any business decisions, content moderation, or support functions are performed in Australia. Where an Australian link exists, the entity is an APP entity for all acts and practices to which the Act extends, and must comply with the 13 APPs, the Notifiable Data Breaches scheme (Part IIIC), and all other Privacy Act obligations.
Source: Privacy Act 1988 (Cth) s 5B (Extra-territorial operation of Act), Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) No. 83, 2022, OAIC — Australian Privacy Principles Guidelines, Chapter B (Key concepts), paras B.11–B.20
Employee records exemption — s 7B(3) carve-out for private-sector employers
Section 7B(3) of the Privacy Act 1988 (Cth) exempts private sector organisations from the Australian Privacy Principles (APPs) when handling employee records about current or former employees. This exemption removes the largest category of personal information from the Privacy Act's ordinary protections — but only where two cumulative conditions are met: the act or practice must be directly related to a current or former employment relationship between the employer (the organisation) and the individual, and must involve an employee record held by the organisation and relating to the individual.
The exemption applies exclusively to organisations (defined in s 6C as private-sector entities meeting the thresholds in the main scope-and-applicability section). It does not apply to agencies (Commonwealth and ACT government entities). Employee records held by Australian Government departments, Norfolk Island administration agencies, and Commonwealth statutory bodies remain subject to all 13 APPs, including access and correction rights under APPs 12 and 13. The exemption is therefore a private-sector-only carve-out.
"Employee record" — s 6(1) definition. An employee record is defined as "a record of personal information relating to the employment of the employee." The OAIC's guidance lists non-exhaustive examples: information about the engagement, training, disciplining, resignation, or termination of employment; terms and conditions of employment; the employee's personal and emergency contact details, performance or conduct, hours of employment, salary or wages; membership of a professional or trade association or trade union; recreation, long service, sick, maternity, paternity, or other leave; and the employee's taxation, banking, or superannuation affairs. Health information about an employee (fitness for work, workers' compensation claims, sick leave) also falls within the definition if it relates to the employment.
Not all information an employer holds about an individual employee is automatically an employee record. The OAIC cautions that "employers may not be able to assume that all the information they hold that relates to an individual employee would be an employee record." Information collected or used for purposes outside the employment relationship — for example, personal information shared with a third party for marketing purposes, or employee data used in commercial research — does not qualify as an employee record for exemption purposes, even if it originally formed part of the individual's employment file. The exemption is limited to acts and practices that are directly related to the employment relationship itself.
"Directly related" — narrow construction. The phrase "directly related" in s 7B(3) is interpreted narrowly by the OAIC and the courts. In ALI Group Australia Pty Ltd v AIC (Federal Court enforcement of an OAIC determination), an employer that disseminated medical details about an employee's health status to 101 head-office employees was found to have breached APP 6.1 because the disclosure was not directly related to the employment relationship with the affected employee. The OAIC held that "directly related" requires an absolute or exact connection — an indirect, consequential, or remote effect on the relationship is insufficient to enliven the exemption. The employer's stated workplace-health-and-safety justification did not bring the mass disclosure within the exemption; consent or an exception under APP 6 (such as the serious-threat exception) would have been required instead.
In contrast, in Madzikanda v Australian Information Commissioner [2023] FCA 1445, the Federal Court upheld an OAIC delegate's finding that an employer's monitoring of work emails on a work-issued laptop was exempt under s 7B(3), even though the specific emails monitored did not themselves relate to the employee's work. The Court accepted that the employer's monitoring activity — undertaken to manage the employer-employee relationship and enforce workplace policies — was directly related to the employment relationship. The distinction between ALI and Madzikanda turns on whether the challenged act or practice served an employment-management purpose: monitoring for compliance and workplace conduct is exempt; disclosing health information beyond what is necessary for managing the employment relationship is not.
Current or former employment relationships only. The exemption applies to a current or former employment relationship. It does not cover future or prospective employment relationships. The OAIC's guidance confirms that the exemption does not apply to the collection of personal information about job applicants who are subsequently not employed by the organisation (unsuccessful candidates). Once an employment relationship is formed, however, the records the employer holds relating to that individual's pre-employment checks (reference checks, qualification verifications, background screenings conducted during recruitment) become exempt, because those records now relate to a current employment relationship and are held as part of the employee record.
This temporal limitation means an organisation handling job-applicant data must comply with all APPs during the recruitment phase. Once the applicant becomes an employee, the exemption applies to the handling of the newly formed employee record going forward, including the pre-employment material already collected.
Who is an "employee"? The exemption is limited to individuals in an employment relationship with the organisation. It does not cover contractors, subcontractors, volunteers, or independent workers. The OAIC guidance states that "an organisation and a volunteer are not considered to have an employee relationship for the purposes of the employee record exemption in s 7B(3)." Similarly, a contractor engaged to provide services under a services agreement is generally not in an employment relationship (though the line between employee and contractor may turn on common-law tests for employment status, which are not defined in the Privacy Act).
Third-party service providers not covered. The exemption does not extend to third-party organisations that handle employee records on behalf of an employer. For example, organisations that provide recruitment, human resource management, payroll, medical, training, or superannuation services under contract to an employer are not exempt, even though the information they handle is employee-record information. When an organisation that is a contractor or subcontractor collects employee records about an individual from an employer, it must comply with the APPs in handling that information, including the notice requirements in APP 5. The OAIC guidance also clarifies that workers' compensation insurers that are not themselves the employer of the individual are not covered by the exemption.
This distinction matters for cloud HR platforms, payroll processors, and other enterprise SaaS providers: they are APP entities (if they meet the turnover or activity thresholds) and must comply with all APPs, including cross-border disclosure requirements under APP 8, when handling employee data received from client employers. The employer itself may be exempt when using and disclosing the employee record to the service provider (if directly related to managing the employment relationship), but the service provider is not exempt in its subsequent handling.
Tax file number information not exempt. Section 7 of the Privacy Act lists specific acts and practices that are exempt. Section 7B(3) operates as an exemption "for the purposes of paragraph 7(1)(ee)," meaning that if the conditions of s 7B(3) are met, the organisation's handling of the employee record is exempt. However, tax file number (TFN) information is subject to a separate statutory regime under Part IIIA of the Privacy Act and is not exempt under s 7B(3). Employers handling TFN information must comply with Part IIIA's TFN rules regardless of the employee records exemption.
Notifiable Data Breaches scheme — exemption applies. The employee records exemption extends to the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act. A private-sector employer experiencing a data breach involving employee records (for example, unauthorised access to payroll data, HR files, or leave records) is not required to notify the OAIC or affected employees under Part IIIC if the breach involves information covered by the s 7B(3) exemption. This creates a significant gap: employees whose sensitive health information, salary details, or disciplinary records are compromised in a breach have no statutory notification right if the employer's handling of that information is exempt. The employer may still have notification obligations under other frameworks (workplace health and safety laws, contractual duties, common-law negligence), but the Privacy Act NDB scheme does not apply.
The 2020 Privacy Act Review and proposed abolition. The Attorney-General's Department conducted a comprehensive review of the Privacy Act from 2020 to 2022. The government's response, released on 28 September 2023, committed in principle to removing the employee records exemption. The OAIC had recommended abolition in its submission to the review, arguing that the exemption creates regulatory uncertainty, leaves a large category of personal information unprotected, and is out of step with international practice (no comparable exemption exists in the GDPR, UK GDPR, or other major privacy regimes). The Fair Work Commission's 2019 decision in Lee v Superior Wood ([2019] FWCFB 2946) — holding that the exemption applies only to employee records already held, not to the collection of new information — had further exposed the complexity and narrow construction of the exemption, creating compliance uncertainty for employers.
If the exemption is removed by future legislation, private-sector employers will need to comply with all 13 APPs for employee data, including:
- APP 3 consent requirements for collecting sensitive information (health information, union membership, biometric data), unless an exception applies;
- APP 5 notification to employees about collection, use, and disclosure of their personal information;
- APP 6 limitations on use and disclosure for secondary purposes;
- APP 11 security safeguards and destruction/de-identification when no longer needed;
- APP 12 access rights (employees able to request access to their records);
- APP 13 correction rights (employees able to request correction of inaccurate information);
- Part IIIC Notifiable Data Breaches obligations for employee-record breaches.
The Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) did not remove or amend the employee records exemption; the change remains under consideration for future reform. Until legislation is enacted, s 7B(3) continues to exempt private-sector employers' handling of employee records directly related to current or former employment relationships.
Current practice and compliance posture. Prudent employers treat the exemption narrowly: limit reliance to core HR and payroll functions directly related to managing the employment relationship; apply the APPs voluntarily to employee data where the "directly related" nexus is unclear; ensure employee records are not used for purposes outside the employment relationship (marketing, research, third-party disclosure for non-employment purposes); and implement robust security and access controls even where exempt, given the sensitivity of employee information and the regulatory direction toward abolition. The exemption is a procedural safe harbour, not a license to mishandle employee information.
Source: Privacy Act 1988 (Cth) s 7B(3), Privacy Act 1988 (Cth) s 6(1) definition of "employee record", OAIC — Employee records exemption (guidance)
State and Territory privacy regimes — public-sector agencies not covered by the federal Privacy Act
The Privacy Act 1988 (Cth) does not apply to State or Territory government agencies (except for the ACT). Each Australian State and Territory has historically relied on separate privacy legislation—where enacted—or, in some cases, administrative directions and sectoral laws to govern personal information handling by government agencies. The primary framework remains a federal-state split: private-sector entities and Commonwealth/ACT agencies are governed by the Privacy Act 1988 and the Australian Privacy Principles (APPs), while State and Territory agencies are subject to local statutes and principles.
Key 2024–2026 statutory changes:
- Western Australia: As of 2024, there is a material legal development. WA has enacted the Privacy and Responsible Information Sharing Act 2024 (WA) (PRIS Act). For the first time, this creates a standalone, modern privacy regime for WA State public sector agencies. The bulk of privacy obligations commence 1 July 2026, with the Notifiable Data Breaches requirements commencing 1 January 2027. This replaces WA's former reliance on FOI principles and agency codes. Agencies, as defined, and contracted service providers will be covered by the new regime.
- Queensland: The Information Privacy and Other Legislation Amendment Act 2023 (Qld) (IPOLA Act) introduced significant amendments to Queensland's Information Privacy Act 2009 for public sector agencies. Key provisions, including expansion of breach-notification obligations, commence 1 July 2025 or 1 July 2026 (depending on section). Agencies and affected practitioners should refer to current status updates for commencement.
Jurisdictional snapshot (June 2026):
- Victoria: Privacy and Data Protection Act 2014 (Vic) (PDP Act)—covers public sector agencies and CSPs. No material amendment since 2021.
- New South Wales: Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act)—covers public sector, with NDB scheme in force since 2022. No material amendment as of June 2026.
- Queensland: Information Privacy Act 2009 (Qld), as amended by the IPOLA Act 2023—covers public sector and contractors. Key amendments take effect July 2025/2026.
- Western Australia: PRIS Act 2024—first comprehensive WA public sector regime, obligations commence 1 July 2026.
- ACT: Governed by the federal Privacy Act 1988 (Cth) for ACT Government agencies. Local health records law applies to health information.
- South Australia, Tasmania, Northern Territory: No comprehensive public sector privacy statute as of June 2026; administrative directions, codes, or sector-specific (mainly health) laws apply.
Compliance implications:
- National or cross-border businesses contracting with public sector agencies (especially in WA or Qld) should review service arrangements for new privacy compliance and data-breach notification triggers effective from the respective commencement dates.
- Private sector businesses remain governed by the federal Privacy Act unless handling personal information as CSPs for a covered State/Territory agency.
The landscape is evolving: only WA has recently created a new statute (in force 2026/2027). Qld, Vic, and NSW public-sector regimes remain statute-based but with notable recent or imminent amendment. Other jurisdictions rely on a patchwork of administrative direction or sectoral law.
Source: Privacy and Responsible Information Sharing Act 2024 (WA), Privacy and Data Protection Act 2014 (Vic), Privacy and Personal Information Protection Act 1998 (NSW), Information Privacy Act 2009 (Qld), as amended by IPOLA Act 2023, Privacy Act 1988 (Cth) s 6(1)
Sensitive information — s 6(1) statutory categories and heightened collection requirements
Sensitive information is a statutory subset of personal information that attracts heightened privacy protections under the Privacy Act 1988 (Cth). The definition in section 6(1) creates a closed list of eleven enumerated categories; information qualifies as sensitive only if it falls within one of these categories. The classification matters because Australian Privacy Principle 3 (APP 3) imposes stricter consent and necessity thresholds for collection of sensitive information than for ordinary personal information, and several other APPs include specific carve-outs or heightened obligations for sensitive information (notably APP 6 secondary-use restrictions, APP 8 cross-border disclosure, and APP 11 security safeguards).
Section 6(1) defines "sensitive information" to mean information or an opinion about an individual's:
- racial or ethnic origin;
- political opinions;
- membership of a political association;
- religious beliefs or affiliations;
- philosophical beliefs;
- membership of a professional or trade association;
- membership of a trade union;
- sexual orientation or practices;
- criminal record;
- health information (within the meaning of s 6FA);
- genetic information about the individual that is not otherwise health information;
- biometric information that is to be used for the purpose of automated biometric verification or biometric identification; or
- biometric templates.
The definition is exhaustive. Information about other sensitive topics — immigration status, financial distress, family relationships, domestic violence history — is personal information but not sensitive information for Privacy Act purposes unless it also reveals one of the thirteen enumerated categories (for example, domestic violence counselling records may constitute health information if they relate to a health service, triggering the sensitive-information rules).
"Health information" — the largest sensitive-information category. Section 6FA defines health information to include: (a) information or an opinion about the health or a disability (at any time) of an individual; (b) information or an opinion about an individual's expressed wishes about the future provision of health services to them; or (c) a health service provided, or to be provided, to an individual. The definition extends beyond medical diagnoses to encompass health-adjacent data: fitness-for-work assessments, workers' compensation claims, disability accommodation requests, vaccination status, sick leave records (when they reveal health conditions), employee assistance program participation, gym membership health screening, DNA ancestry results (when they disclose genetic health risks), mental health support, and counselling notes. Information is health information if it is about the individual's health, disability, health wishes, or health services received, regardless of who holds it. A payroll record noting "sick leave taken" is generally not health information (it is absence data); a payroll record noting "sick leave — influenza" is health information because it discloses the health condition.
The OAIC's Chapter B guidance confirms that health information is a subset of sensitive information: all health information (as defined in s 6FA) automatically qualifies as sensitive information under s 6(1). This means an entity collecting health information must comply with APP 3.3's heightened collection rule (consent or statutory authorisation required, with narrow exceptions) even if the information seems routine.
"Biometric information" and "biometric templates" — the 2014 APP reforms added these categories to address automated identity verification and surveillance technologies. Biometric information is information about an individual's physical, physiological, or behavioural characteristics that is to be used for the purpose of automated biometric verification (one-to-one matching, such as unlocking a phone with a fingerprint) or automated biometric identification (one-to-many matching, such as facial recognition to identify an unknown person in a crowd). The definition is purpose-limited: a photograph is not sensitive information merely because it depicts a face; it becomes sensitive information (biometric information) if and when it is to be processed for automated facial-recognition matching. Similarly, a recording of an individual's voice is not inherently sensitive; it becomes biometric information if it is to be used for automated voiceprint identification. This purpose-based trigger means the same data may be ordinary personal information in one context and sensitive information in another.
Biometric templates — mathematical representations of biometric features (for example, a numerical encoding of fingerprint minutiae, an iris hash, a faceprint vector) — are always sensitive information, regardless of whether they are currently being used for automated matching. The distinction reflects the permanence and uniqueness risk: templates cannot be reset if compromised.
"Genetic information" — section 6(1) defines this as information about the individual's genetic characteristics that is not otherwise health information. In practice, most genetic information is health information under s 6FA (DNA test results revealing disease predisposition, ancestry DNA results disclosing genetic health markers, genetic screening for inheritable conditions). Genetic information that is not health information — for example, raw genomic data held by a research laboratory that has not yet been analysed for health implications — remains sensitive information under the standalone genetic-information category.
"Criminal record" — information about an individual's criminal convictions, charges, or related criminal history. The OAIC guidance confirms this includes spent convictions (under Commonwealth, State, or Territory spent-convictions legislation) and criminal charges that did not result in conviction. The category does not extend to suspicion, allegations, or investigative interest absent a formal charge. Traffic infringements and civil penalties are generally not part of an individual's criminal record unless they constitute a criminal offence under the relevant jurisdiction's traffic laws.
"Political opinions," "membership of a political association," "religious beliefs or affiliations," "philosophical beliefs" — the OAIC's Chapter B guidance notes that these terms are not defined in the Privacy Act and take their ordinary meaning, interpreted broadly. The categories capture both formal affiliation (party membership, registered-voter records indicating a party preference, union membership in a politically active union) and opinion or belief (responses to a political survey, religious-practice requests in the workplace, conscientious-objection declarations). The phrase "information or an opinion about" means the data need not be self-reported: an employer's inference that an employee holds particular political views (based on the employee's social-media activity) is sensitive information if the inference relates to political opinions.
"Membership of a professional or trade association" and "membership of a trade union" — these categories protect information about collective affiliation in employment and professional contexts. Membership of a professional body (Law Society, medical college, engineering association) and trade-union membership are both sensitive. The categories do not extend to membership of recreational clubs, community groups, or social organisations unless those organisations also qualify as a professional, trade, or political association.
"Sexual orientation or practices" — interpreted broadly to include information about an individual's sexual identity, sexual behaviour, romantic partnerships, and gender identity (though "gender identity" is not expressly listed, the OAIC's practice guidance treats it as falling within this category or, where relevant, as health information if the individual is receiving gender-affirming health services).
Collection threshold — APP 3.3 consent or statutory authorisation. Australian Privacy Principle 3.3 provides that an APP entity must not collect sensitive information about an individual unless: (a) the individual consents to the collection and (i) if the entity is an agency, the information is reasonably necessary for one or more of the entity's functions or activities, or (ii) if the entity is an organisation, the collection is reasonably necessary for one or more of the entity's functions or activities; or (b) the collection is required or authorised by or under an Australian law or a court/tribunal order; or (c) a permitted general situation exists in relation to the collection (APP 3.4 lists these: necessary to lessen or prevent a serious threat to life, health, or safety; necessary for the establishment, exercise, or defence of a legal claim; reasonably necessary for a confidential alternative dispute resolution process; necessary for a diplomatic or consular function; reasonably necessary for a law-enforcement-related activity by an enforcement body); or (d) (for agencies only) the collection is reasonably necessary for the agency's functions or activities; or (e) (for organisations and health information only) a permitted health situation exists (s 16B lists eight health-specific exceptions, including: necessary to provide a health service and the individual would reasonably expect collection in the circumstances; necessary for research or compilation of statistics in the public interest if certain safeguards are met; necessary to locate a missing person; necessary for responsible management of genetic information by genetic-relatives notification).
The consent threshold in APP 3.3(a) is more demanding than the consent option for ordinary personal information. For sensitive information, consent must be express — the OAIC's guidance makes clear that silence, pre-ticked boxes, or inactivity do not constitute consent for sensitive-information collection. The consent must be voluntary, informed, specific, and current. The entity must also show that the collection is reasonably necessary for its functions or activities; consent alone is not sufficient if the collection is unnecessary.
No "reasonably necessary for a function or activity" carve-out for organisations collecting non-health sensitive information. Under APP 3.3, an organisation (private sector) can collect health information under a permitted health situation (APP 3.3(e) + s 16B) or ordinary personal information where collection is reasonably necessary for a function or activity (APP 3.5). But for non-health sensitive information (political opinions, religious beliefs, sexual orientation, biometric data, union membership, criminal record), an organisation has no general reasonably-necessary exception — it must obtain consent, or rely on statutory authorisation (APP 3.3(b)), a permitted general situation (APP 3.3(c)), or, in limited cases, a permitted health situation if the information also qualifies as health information. This asymmetry means organisations face a higher bar for collecting sensitive information than agencies do. An agency can collect sensitive information without consent if reasonably necessary for its functions (APP 3.3(d)); an organisation generally cannot.
Interaction with APP 3.4 — solicited vs unsolicited collection. APP 3.3 governs solicited collection (the entity requests or invites the information). If an APP entity receives sensitive information it did not solicit — for example, an applicant volunteers their disability status in a cover letter when the employer did not ask — APP 3.4 applies. The entity must determine within a reasonable period whether it could have collected the information under APP 3 (including APP 3.3 for sensitive information). If not, and retention is not required or authorised by law, the entity must destroy or de-identify the information as soon as practicable. This creates a compliance trap: an organisation that passively accepts unsolicited sensitive information (and retains it) must retrospectively establish that it could have collected the information under APP 3.3 — meaning consent, statutory authorisation, or a permitted situation would have existed had the entity solicited the information. Many organisations cannot meet this test and must destroy or de-identify the unsolicited sensitive information.
Employee context — interplay with employee records exemption. The employee records exemption (s 7B(3), discussed in a separate section of this guide) removes private-sector employers' handling of employee records relating to a current or former employment relationship from the APPs. If the exemption applies, the employer is not bound by APP 3.3's sensitive-information consent rule. This means a private-sector employer exempt under s 7B(3) can collect health information (fitness-for-work assessments, workers' compensation claims, sick leave), union membership, criminal records (background checks), and other sensitive information about employees without consent, provided the collection is directly related to the employment relationship and forms part of an employee record. Commonwealth and ACT government agencies (which are not exempt under s 7B(3)) must comply with APP 3.3 when collecting sensitive information about employees unless another exception applies (for example, APP 3.3(d) reasonably necessary for the agency's functions, or APP 3.3(b) required by law such as police vetting for security clearances).
Cross-border disclosure — APP 8 "reasonable steps" standard elevated for sensitive information. APP 8.1 permits cross-border disclosure of personal information if certain conditions are met; the OAIC's guidance confirms that the standard of "reasonable steps" to ensure the overseas recipient complies with the APPs is higher when the disclosed information is sensitive information. Entities should apply stricter contractual safeguards, conduct more rigorous due diligence, and limit cross-border flows of sensitive information unless robust protections are in place.
Security — APP 11 obligation intensity scales with sensitivity. APP 11.1 requires APP entities to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. "Reasonable steps" is a scalable standard — the OAIC's guidance expressly states that more rigorous security is required as the sensitivity of the information increases. Entities holding sensitive information (health records, biometric templates, criminal history, union membership) must implement stronger technical and organisational safeguards — encryption at rest and in transit, access controls, audit logging, staff training, incident-response capability — than would be reasonable for ordinary contact details or transactional data. A security posture that is "reasonable" for ordinary personal information may constitute a breach of APP 11 if applied to sensitive information.
Reform trajectory — proposed expansion and express inclusion of inferred sensitive information. The Attorney-General's Privacy Act Review Report (2022) and the government's September 2023 response proposed expanding the sensitive-information definition to include inferred information: information an entity derives or infers about an individual that falls within a sensitive category, even if the individual never provided it. This reform would codify the OAIC's existing guidance (which treats inferred opinion as captured by the "information or an opinion about" language) and address algorithmic profiling and predictive analytics. The Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) did not enact this expansion; it remains under consideration for future legislation. If implemented, entities using machine learning to infer health conditions, political views, sexual orientation, or other sensitive attributes from behavioural data would face APP 3.3's consent threshold for the collection (or generation) of those inferences, not merely for the collection of the input data.
Current compliance practice. Entities should: classify data holdings by sensitivity at the point of collection; apply APP 3.3's consent + reasonable-necessity test to all sensitive-information collection (with particular care for biometric enrolment, health data, and employee sensitive information if the employer is not exempt); implement heightened security for sensitive-information repositories; limit secondary use and cross-border disclosure unless an APP 6 or APP 8 exception applies; train staff to recognise sensitive information (especially inferred or derived sensitive attributes); and audit consent mechanisms to ensure they meet the express, informed, voluntary standard. The OAIC's enforcement priorities since the December 2022 penalty increase have included health information breaches and biometric data collection without valid consent — sensitivity drives both harm assessment and regulatory attention.
Source: Privacy Act 1988 (Cth) s 6(1) — definition of "sensitive information", Privacy Act 1988 (Cth) s 6FA — definition of "health information", OAIC — Australian Privacy Principles Guidelines, Chapter B (Key concepts) — Sensitive information, OAIC — Appendix A: Key terms (data breach guidance) — Sensitive information
The 13 Australian Privacy Principles — Schedule 1 substantive obligations overview
Once an entity is an APP entity within the scope of the Privacy Act 1988 (Cth), it must comply with the 13 Australian Privacy Principles (APPs) set out in Schedule 1 to the Act. The APPs replaced the former Information Privacy Principles (IPPs for agencies) and National Privacy Principles (NPPs for organisations) on 12 March 2014, creating a unified privacy framework that applies to both Commonwealth and ACT government agencies and to private-sector organisations meeting the statutory thresholds. Section 15 of the Privacy Act states the core obligation: "An APP entity must not do an act, or engage in a practice, that breaches an Australian Privacy Principle." A breach of an APP is an interference with the privacy of an individual under s 13 and may result in a binding determination, civil penalties, or enforceable undertakings imposed by the Australian Information Commissioner.
The APPs are principles-based rather than prescriptive rules. This gives entities flexibility to tailor their compliance measures to their size, business model, and the sensitivity of the information they handle, but it also means compliance requires contextual, risk-based judgment. The OAIC's Australian Privacy Principles Guidelines (APP Guidelines, first published February 2014, updated periodically) provide the Commissioner's authoritative interpretation of each principle, binding guidance on what constitutes reasonable steps, and worked examples. Courts and tribunals accord significant weight to the APP Guidelines when determining whether an entity has breached the Privacy Act.
## Structure — five functional parts
The 13 APPs are grouped into five functional parts corresponding to the privacy information lifecycle: (1) open and transparent management of personal information; (2) collection of personal information; (3) dealing with personal information (use, disclosure, and cross-border transfers); (4) integrity of personal information (data quality and security); and (5) access and correction. Each principle addresses a discrete stage or obligation, but the principles interact and complement one another. For example, when collecting personal information (Part 2), an entity must simultaneously consider the notification requirements in APP 5, the use-and-disclosure restrictions in APP 6, the security safeguards in APP 11, and the data-minimisation and quality requirements in APP 3 and APP 10.
## Part 1 — Open and transparent management (APP 1)
APP 1 requires an APP entity to manage personal information in an open and transparent way. This is the foundation for accountability. Under APP 1.2, the entity must take reasonable steps to implement practices, procedures, and systems that (a) ensure compliance with the APPs and any registered APP code binding the entity, and (b) enable the entity to deal with inquiries or complaints about compliance. This obligation is technology- and sector-neutral: what is reasonable depends on the entity's size, resources, the volume and sensitivity of personal information it handles, and the risk of harm from misuse or breach.
APP 1.3 and 1.4 mandate that the entity have a clearly expressed and up-to-date APP privacy policy covering how the entity manages personal information. The policy must set out, at a minimum: the kinds of personal information the entity collects and holds; how it collects and holds that information; the purposes for which it collects, holds, uses, and discloses personal information; how an individual may access and seek correction of their information; how an individual may complain about a breach of the APPs or a registered APP code and how the entity will handle such complaints; whether the entity is likely to disclose personal information to overseas recipients; and, if so, the countries in which such recipients are likely to be located (if practicable to specify). APP 1.5 requires the entity to take reasonable steps to make its APP privacy policy available free of charge, usually by publishing it on the entity's website; APP 1.6 requires the entity to provide a copy in a particular form upon request (for example, large print, accessible PDF).
Effective 10 December 2026, APP 1.7, 1.8, and 1.9 (inserted by the Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024)) impose additional transparency obligations where the entity arranges for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect the rights or interests of an individual. This targets automated decision-making (ADM), profiling, and algorithmic systems. The APP privacy policy must include: a statement that the entity engages in such ADM; an explanation in clear and plain language of the factors and categories of data used; contact details for a person or body whom the individual may contact to raise concerns about the decision; and other matters (if any) prescribed by regulation. These amendments align Australia with international practice (Art. 22 GDPR automated decision-making safeguards) and respond to the 2020 Privacy Act Review.
## Part 2 — Collection of personal information (APPs 3, 4, 5)
APP 3 governs what may be collected and how. APP 3.1 states that an entity must not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of the entity's functions or activities. For sensitive information (racial or ethnic origin, political opinions, union membership, religious or philosophical beliefs, sexual orientation, criminal record, health information, genetic or biometric data—defined in s 6(1)), APP 3.3 raises the bar: the entity must not collect sensitive information unless (a) the individual consents to the collection and (b) the information is reasonably necessary for one or more of the entity's functions or activities, or an exception applies. The APP 3.4 exceptions include: the collection is required or authorised by law; a permitted general situation exists (defined in s 16A, covering enforcement, legal claims, serious threats to life or health, and other statutory carve-outs); a permitted health situation exists (defined in s 16B, for health service providers); or the entity is a non-profit organisation and the sensitive information relates to the individual's membership or support for the organisation (APP 3.4(e)). Consent under APP 3 must be voluntary, informed, specific, and current (APP Guidelines Chapter 3 para 3.52); mere notification or an opt-out is generally insufficient for sensitive information.
APP 3.5 and 3.6 require that personal information be collected directly from the individual unless an exception applies, and that it be solicited (actively sought by the entity) rather than unsolicited. APP 4 addresses unsolicited personal information — information an entity receives but did not solicit. If the entity receives unsolicited information, it must determine whether it could have collected that information under APP 3 if it had solicited it. If not, the entity must destroy the information or ensure it is de-identified, provided it is lawful and reasonable to do so (APP 4.2). This prevents entities from circumventing the collection restrictions by accepting information thrust upon them.
APP 5 requires notification or disclosure of certain matters at or before collection, or as soon as practicable afterwards. The entity must take reasonable steps to notify the individual of: the entity's identity and contact details; the fact and circumstances of collection; whether collection is required or authorised by law; the purposes for which the information is collected; the consequences if the information is not collected; to whom the information is likely to be disclosed (including overseas recipients); the entity's APP privacy policy; and whether the entity is likely to disclose the information to overseas recipients. This transparency obligation ensures individuals understand why their information is being collected and what will happen to it.
## Part 3 — Dealing with personal information (APPs 6, 7, 8, 9)
APP 6 restricts use and disclosure of personal information to the primary purpose of collection, unless an exception applies. If an entity collected information for one purpose (the primary purpose), it must not use or disclose it for another purpose (a secondary purpose) unless: (a) the individual has consented to the secondary use or disclosure; (b) the individual would reasonably expect the secondary use or disclosure and it is directly related (for sensitive information) or related (for non-sensitive information) to the primary purpose; (c) the use or disclosure is required or authorised by or under an Australian law or a court/tribunal order; (d) a permitted general situation exists (s 16A); (e) for organisations, a permitted health situation exists (s 16B); (f) the entity reasonably believes the use or disclosure is reasonably necessary for an enforcement-related activity conducted by or on behalf of an enforcement body; or (g) for written-request enforcement disclosures under APP 6.3, the recipient is a Commonwealth, State, or Territory enforcement body and the entity reasonably believes the disclosure is reasonably necessary for enforcement-related activities.
APP 6 embodies the purpose limitation principle: data collected for one purpose cannot be repurposed without legal authority, consent, or an applicable exception. The OAIC has held that reasonable expectation is assessed objectively, considering the nature of the relationship, the entity's APP privacy policy and collection notices, and industry practice; wishful thinking by the entity is insufficient.
APP 7 governs direct marketing. An organisation must not use or disclose personal information it holds for the purpose of direct marketing unless an exception applies. For information collected directly from the individual, the organisation may use or disclose it for direct marketing if (a) the individual would reasonably expect it, (b) the organisation provides a simple opt-out, and (c) the individual has not opted out. For information collected from a third party or for sensitive information, the organisation must not use or disclose it for direct marketing unless the individual has consented (APP 7.3) or it is impracticable to obtain consent and certain additional safeguards are met (APP 7.4). Every direct marketing communication must include a prominent statement that the individual may request not to receive further direct marketing communications and a simple means to make such a request (APP 7.6). If the individual requests not to receive direct marketing or requests the source of their information, the organisation must comply (APP 7.7, 7.8).
APP 8 regulates cross-border disclosure of personal information to overseas recipients. Before disclosing personal information to an overseas recipient, an entity must take reasonable steps to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information (APP 8.1). This extraterritorial accountability obligation means Australian entities cannot evade the Privacy Act by offshoring processing or storage. An entity is deemed accountable under s 16C: if the overseas recipient mishandles the information in a way that would breach the APPs if done by the entity in Australia, the entity itself is taken to have breached the APPs. APP 8.2 provides six exceptions to the reasonable-steps obligation: (a) the entity reasonably believes the overseas recipient is subject to a law or binding scheme that overall is at least substantially similar to the APPs and the individual can enforce those protections; (b) the individual consents after being expressly informed the entity will not be required to take reasonable steps and will not be accountable under s 16C; (c) the disclosure is required or authorised by law; (d) a permitted general situation exists; (e) a permitted health situation exists; or (f) the entity is an agency and the disclosure is to an agency in a foreign country under arrangements approved by the responsible Minister. The OAIC's Chapter 8 guidance emphasises that exception (a) requires a country-level or sector-level law substantially similar to the APPs; contractual data-protection clauses alone are insufficient unless paired with enforceable legal protections in the recipient country.
APP 9 addresses government-related identifiers. An organisation must not adopt a government-related identifier (such as a Medicare number, driver licence number, passport number, or tax file number) as its own identifier for an individual unless an exception applies (APP 9.1). This prevents the proliferation of universal identifiers across sectors. An organisation must not use or disclose a government-related identifier unless: the use or disclosure is reasonably necessary to verify the individual's identity for the organisation's functions or activities; the use or disclosure is reasonably necessary for the organisation to fulfill its obligations to a government agency or authority; the use or disclosure is required or authorised by law; a permitted general situation exists; or for health service organisations, a permitted health situation exists (APP 9.2). These restrictions limit the use of government identifiers to their intended purposes and reduce identity-fraud risk.
## Part 4 — Integrity of personal information (APPs 10, 11)
APP 10 mandates data quality. An entity must take reasonable steps to ensure that the personal information it collects is accurate, up-to-date, and complete (APP 10.1). An entity must take reasonable steps to ensure that personal information it uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete, and relevant (APP 10.2). The reasonableness standard considers the volume and sensitivity of the information, whether it is publicly available, the consequences of inaccuracy, the practicality of verification, and the individual's ability to update it. The OAIC's guidance emphasises that APP 10 is a positive obligation — entities must actively verify and update information, not merely correct errors when notified.
APP 11 requires security safeguards and retention limits. Under APP 11.1, an entity must take reasonable steps to protect personal information it holds from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. What is reasonable depends on: the amount and sensitivity of the information; the possible adverse consequences for an individual if a security breach occurs; the current state of technology and security measures; the cost of implementing safeguards; whether a third party will handle the information; and whether the entity has previously experienced breaches (APP Guidelines Chapter 11 para 11.13–11.16). Technical measures (encryption at rest and in transit, access controls, intrusion detection, multi-factor authentication) and organisational measures (staff training, background checks, incident-response plans, vendor due diligence) are both relevant.
APP 11.2 requires that if an entity no longer needs personal information for any purpose permitted by the Privacy Act, the entity must take reasonable steps to destroy the information or ensure it is de-identified. This retention-limitation principle prevents indefinite data hoarding. The OAIC guidance notes that information is still needed if required by law, for enforcement, for a permitted general or health situation, or for a use or disclosure the entity is authorised to make. When assessing destruction obligations, entities should consider records-retention statutes, contractual obligations, and limitation periods for legal claims.
## Part 5 — Access and correction (APPs 12, 13)
APP 12 grants individuals a right of access to their personal information held by an entity. If an entity holds personal information about an individual, the entity must, on request by the individual, give the individual access to that information (APP 12.1). The entity must respond to the request within a reasonable period and give access in the manner requested by the individual (if reasonable and practicable). The entity may charge a fee for access, but the fee must not be excessive and must not apply to the making of the request itself (APP 12.8). APP 12.3 sets out exceptions under which access may be refused or restricted: the access would pose a serious threat to life, health, or safety; the access would have an unreasonable impact on the privacy of others; the request is frivolous or vexatious; the information relates to enforcement-related activity or legal proceedings and disclosure would be unlawful or prejudice those activities; denying access is required or authorised by law; access would prejudice negotiations with the individual; access would be unlawful; or the entity suspects unlawful activity or misconduct and giving access would be likely to prejudice the investigation. If access is refused or restricted, the entity must give written notice of the reasons (unless unreasonable to do so) and the mechanisms available to complain (APP 12.10).
APP 13 grants a right to correction. If an entity holds personal information about an individual and the individual requests correction because the individual believes the information is inaccurate, out-of-date, incomplete, irrelevant, or misleading, the entity must take reasonable steps to correct the information to ensure it is accurate, up-to-date, complete, relevant, and not misleading (APP 13.1). If the entity corrects personal information, and has previously disclosed the uncorrected information to another entity, the individual may request that the entity notify the recipient of the correction; the entity must take reasonable steps to give that notification unless it is impracticable or unlawful (APP 13.3).
If the entity refuses to correct the information as requested, the entity must give written reasons and inform the individual of the complaints mechanisms available (APP 13.4). The entity must also take reasonable steps to associate a statement with the information that the individual believes it is inaccurate, out-of-date, incomplete, irrelevant, or misleading, in such a way that the statement will be apparent to users of the information (APP 13.5). This ensures the individual's objection becomes part of the record. Corrections and responses must be made without charge to the individual (APP 13.6).
## Interplay with other Privacy Act regimes
The APPs are the core privacy obligations, but the Privacy Act also establishes parallel or supplementary regimes:
- Part IIIA — Credit reporting (separate privacy principles for credit reporting bodies and credit providers; credit-information definitions and rules operate alongside the APPs).
- Part IIIC — Notifiable Data Breaches (commenced 22 February 2018; imposes mandatory notification duties for eligible data breaches that are likely to result in serious harm, discussed in the breach-notification guide).
- Section 17 and Tax File Number Guidelines — TFN information subject to specific rules in addition to the APPs.
- Registered APP codes — Industry or sectoral codes registered under Part IIIB that provide binding APP variations or additional obligations (for example, the CR Code, the APP Code for private health insurers). Where a registered code binds an entity, the entity must comply with both the APPs and the code.
An act or practice is not an interference with privacy unless it breaches an APP, a registered APP code, a registered CR code, or a Part IIIA credit-reporting privacy obligation (s 13). Consequently, every enforcement action, determination, civil penalty, or enforceable undertaking under the Privacy Act ultimately turns on whether the entity breached one or more of the 13 APPs or the parallel regimes.
## Penalties and enforcement
Section 13G (as amended by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022, No. 83, 2022, effective 13 December 2022) creates a civil penalty for a serious or repeated interference with privacy. The maximum civil penalty for a body corporate is the greater of: (a) A$50 million; (b) three times the value of any benefit obtained through the misuse of information (if the court can determine that value); or (c) 30% of the entity's adjusted turnover in the relevant period (if the court cannot determine the benefit value). For individuals, the maximum penalty is A$2.5 million. These substantially increased penalties reflect the government's response to the 2022 Optus and Medibank data breaches and align Australia with international practice (GDPR two-tier fines).
The OAIC enforces the APPs through complaint investigation (Part V of the Act), binding determinations (s 52), civil penalty proceedings in the Federal Court (s 80W, 80U), enforceable undertakings (s 33E), and public reporting. The Commissioner may also conduct own-motion investigations (s 40(2)) and issue formal guidance.
## Amendments and future reforms
The 2020 Privacy Act Review (the government released its response on 28 September 2023) committed to wide-ranging reforms, including strengthening consent, expanding the definition of personal information to expressly include inferred information, replacing "de-identified" with "anonymised," creating a fair and reasonable test for collection and use, strengthening children's privacy protections, and extending access and erasure rights. The Privacy and Other Legislation Amendment Act 2024 enacted the first tranche: automated-decision-making transparency (APP 1.7–1.9, effective 10 December 2026), a ministerial power to direct the Commissioner to develop binding APP codes, and a mandate to develop a Children's Online Privacy Code. Further legislative amendments are expected in 2026–2027 to implement the remaining Review commitments.
Source: Privacy Act 1988 (Cth) — Schedule 1, Australian Privacy Principles, OAIC — Australian Privacy Principles Guidelines, OAIC — Read the Australian Privacy Principles
Small business operator exemption — s 6D threshold, carve-out exceptions, and irrevocable opt-in (s 6EA)
The Privacy Act 1988 (Cth) excludes "small business operators" from the scope of the Australian Privacy Principles (APPs), subject to several exceptions that bring certain low-turnover businesses into scope. Section 6D defines a small business operator as an organisation with an annual turnover of $3 million or less in an income year, but the details and carve-ins are complex.
Annual turnover calculation (s 6DA): Turnover is calculated as the total consideration received in the course of business, excluding GST and payments to related bodies corporate. The turnover test looks to the entity's income years (not the financial year generally), and must be recalculated each year. If turnover exceeds $3 million in a subsequent year, the organisation ceases to be exempt from the start of that year.
Exceptions to the exemption (s 6D(4)) create mandatory inclusion for certain activities, regardless of turnover:
- Health service providers (any entity providing a health service, broadly defined, regardless of size)
- Entities trading in personal information (offering products or services in exchange for personal data, or selling/disclosing personal data for benefit, payment, or advantage)
- Credit reporting bodies/providers
- Employee associations (as defined by Fair Work legislation)
- Entities subject to the AML/CTF Act 2006 as reporting entities
- Entities holding records under Commonwealth contracts
Voluntary irrevocable opt-in (s 6EA): A small business operator may elect to be treated as an organisation (and thus, an APP entity) by notifying the Commissioner in writing. Once made, this election is irrevocable while the business continues to operate. The opt-in is attractive for businesses seeking to signal compliance to partners, customers, or for government procurement, but imposes full statutory obligations.
Regulatory guidance: The OAIC's Key Concepts guideline and Small Business Checklist stress that the carve-out is interpreted strictly, and any uncertainty over the $3 million threshold should be resolved with documentary evidence. Health providers, data traders, and cloud/SaaS providers with ambiguous business lines should closely examine whether the carve-in exceptions apply. There is no partial application of the APPs: an exempt operator is out of scope for all but a few areas (tax file number rules, mandatory data breach notification if otherwise exempt, etc.).
Current reform status: The 2020 Privacy Act Review (govt response Sept 2023) considered reducing the threshold to include more small businesses, but as of June 2026, the $3 million test and current carve-ins remain unchanged. Future amendments may further narrow the small business exemption—but until enacted, the s 6D/6EA rules apply.
Source: Privacy Act 1988 (Cth) ss 6D, 6DA, 6EA, OAIC — Australian Privacy Principles Guidelines, Chapter B (Key concepts)
APP codes and the new Children’s Online Privacy Code — binding sectoral overlays post-2024 amendment
The Privacy Act 1988 (Cth) permits the creation of sector-specific privacy codes called APP codes—either industry-driven or, since 2024, at the direction of the Minister. Statutory authority for APP codes is found in Part IIIB of the Act (ss 26C–26NB). An APP code may impose requirements additional to or more stringent than the Australian Privacy Principles (APPs) but cannot preclude or undercut the baseline APP obligations.
Ministerial Power for Binding Codes (2024 Amendment): Before 2024, APP codes could be developed by industry or the Australian Information Commissioner, registered by the Commissioner, and were binding on entities that had agreed or were covered by the code's scope. The Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024), which commenced in May 2024, introduced new ss 26N–26NB. These sections empower the Minister to direct the Commissioner to develop an APP code for a specified sector or practice. A Minister-directed code binds all entities in scope, without requiring voluntary sign-up (s 26N). This marks a shift from past practice, enabling targeted privacy regulation by government direction in high-risk or priority sectors.
Children’s Online Privacy Code: A headline requirement of the 2024 amendments is a Ministerial directive to the OAIC to develop a binding code for the handling of children’s personal information online (the “Children’s Online Privacy Code”). The statutory framework prescribes that the Commissioner must consult with the public, affected businesses, and relevant experts in drafting the code, which is then submitted to the Minister for approval and registration (s 26NB). Details—including the obligations and precise commencement—will be guided by the code’s drafting and consultation. As of June 2026, the code is in development, not yet in force. Its exact operative date and final requirements will be determined following formal consultation and Ministerial approval. The code is expected to overlay the APPs for digital service providers likely to be accessed by children, with enhanced consent, transparency and data-handling standards.
APP codes, once registered, have the same force as the APPs (s 26G): breach of a binding code is treated as an interference with privacy under the Act and subject to OAIC investigation and enforcement. Further sectoral codes may be developed in other areas by similar process if directed, but as of 2026, only the Children’s Online Privacy Code is legislatively mandated.
Source: Privacy Act 1988 (Cth) Pt IIIB ss 26C–26NB, incorporating Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024), OAIC — Children’s Online Privacy Code
Journalism exemption — s 7B(4) carve-out and the 'publicly committed privacy standards' test for media organisations
Section 7B(4) of the Privacy Act 1988 (Cth) creates a broad exemption for media organisations in relation to acts or practices engaged in by them in the course of journalism, provided two strict conditions are met: (1) the media organisation is publicly committed to observing published privacy standards, and (2) the act or practice is in the course of journalism. This journalism exemption is a key material-scope limitation and a source of ongoing litigation and OAIC enforcement focus.
Statutory language and thresholds (s 7B(4)): The Act provides that "an act done, or practice engaged in, by a media organisation in the course of journalism is exempt if the organisation is publicly committed to observing standards that deal with privacy in the context of the activities of media organisations and have been published in writing by the organisation or a relevant association."
The OAIC's Key Concepts guideline and its decision in 'WC v Nationwide News Pty Ltd' [2017] AICmr 75 clarify each element:
- Media organisation: Defined in s 6 as "an organisation whose business consists of the collection, preparation and dissemination of news, current affairs, information or documentaries." This excludes entities that are not primarily engaged in such activities or that do not serve a public audience.
- Course of journalism: OAIC guidance (Chapter B, para B.159) confirms this includes news reporting, investigative journalism, documentaries, and current affairs; it does not include advertising, promotional material, or non-journalistic activities by media organisations.
- Publicly committed privacy standards: The media organisation must have privacy standards dealing with the privacy of individuals in the context of journalism, and must demonstrate a public commitment to observe those standards. Common examples include published Codes of Practice under the Australian Press Council or Commercial Television Industry Codes. The standards must be accessible and specific to privacy: generic codes or unpublished internal policies do not suffice. If an organisation relies on an association’s code, it must publicly state its commitment.
- OAIC position: In 'WC v Nationwide News' the OAIC held that a newspaper's editorial conduct in publishing details about an individual was exempt because the publisher was bound by and publicly committed to the Australian Press Council Privacy Standards. In contrast, an entity that lacks published, accessible privacy standards—or fails to comply with them—cannot rely on the s 7B(4) exemption.
- Public interest overlay: While the Privacy Act does not itself impose a public interest override, the OAIC has emphasised that media privacy standards generally contain a public interest test. Journalists must weigh privacy against the public’s right to know in line with their code, but the OAIC cannot scrutinise the balance directly once the threshold for the exemption is met.
Edge cases and reform proposals: The exemption does not extend to non-media platforms (social media, tech companies, ad-tech) unless their dominant business is journalism and they meet the published standards test. There is no coverage for freelancers unless associated with a qualifying organisation. The 2020 Privacy Act Review proposed narrowing the scope, but as of June 2026, s 7B(4) remains unamended.
Compliance posture: Media organisations should review and update published privacy standards, ensure public commitment (clear, accessible online notice), and apply standards consistently to maintain eligibility. The OAIC can investigate whether the conditions for exemption are actually met on the facts of a complaint.
Source: Privacy Act 1988 (Cth) s 7B(4), OAIC — Key concepts: journalism exemption (Chapter B, para B.157–B.165)
Household and personal-use exception — Privacy Act non-applicability to individuals acting in a private capacity
The Privacy Act 1988 (Cth) does not contain a formal household or "private use" exemption analogous to the "household exception" in Article 2(2)(c) of the EU GDPR. However, as a matter of statutory construction and regulator guidance, the Privacy Act regulates the handling of personal information only by "APP entities"—that is, defined agencies, organisations, and certain small business operators (ss 6(1), 6C, 6D)—and not acts or practices by individuals acting solely in their private or personal capacity.
Section 6(1) specifically defines "organisation" as "an individual (including a sole trader)" except when the individual is "acting other than in a personal capacity". The effect of this drafting is that an individual's private activities—such as maintaining a personal address book, using home security cameras for purely personal reasons, or posting about acquaintances on social media for non-commercial purposes—are generally outside the scope of the Act. The OAIC's "Australian Privacy Principles Guidelines" (Chapter B, Key concepts) affirm that "the Privacy Act does not regulate the handling of personal information by an individual acting in a personal capacity. However, it will apply to an individual if they carry on a business or commercial activity."
This non-applicability means everyday personal activities are not regulated by the Privacy Act. For example, an individual who films visitors on a home CCTV system for household security, or keeps photos of friends and family, is not regulated unless those activities are part of a business. The OAIC has given further clarity in published guidance, noting that once an individual begins to use personal information for business or commercial activities—even as a sole trader, influencer, or in the context of a home business—they may cross into the definition of "organisation" and thus become subject to the Act.
Key implications for practitioners:
- There is no blanket "household exception" in the statutory language, but individual, non-commercial activity is out of scope by virtue of the limiting definitions of "organisation” and “APP entity” (see s 6(1)).
- Once an individual engages in business-like activities (for instance, selling footage from a home security system, running a blog or app as a commercial venture, or offering personal-data handling services to others), they may become an "organisation" subject to the Privacy Act requirements.
- Where individuals act on behalf of incorporated associations, charities, or businesses, their handling of personal information falls within the scope of the Act via the entity (and potentially themselves if they otherwise meet the definition).
This treatment differs from other major data protection regimes, such as GDPR and UK GDPR, which expressly denote a household exemption. In practice, the effect is equivalent: purely personal or household uses by natural persons remain outside Australia's federal privacy regulation, while any business or commercial activity triggers application.
Source: Privacy Act 1988 (Cth) ss 6(1), 6C, OAIC — APP Guidelines Chapter B (Key concepts), para B.3–B.6
Federal courts and tribunals — scope of Privacy Act coverage and the s 7(1)(a)-(b) judicial function exemption
The Privacy Act 1988 (Cth) sets complex boundaries for its application to federal courts and tribunals. Section 7(1)(a) expressly exempts "an act done, or practice engaged in, by a court or tribunal" unless it is "of an administrative nature." This dichotomy—judicial/tribunal vs. administrative acts—determines whether the Australian Privacy Principles (APPs) apply to courts and tribunals in handling personal information.
Statutory exemption (s 7(1)(a)–(b)). Federal courts and tribunals are not regarded as "agencies" for Privacy Act purposes when performing judicial or tribunal functions. Section 7(1)(a) carves out:
> “an act done, or practice engaged in, by a court or tribunal, other than an act done or practice engaged in by the court or tribunal of an administrative nature.”
Section 7(1)(b) similarly exempts practices covered by regulations or other enactments about proceedings before a court/tribunal.
Judicial/tribunal function vs. administrative function. The core test is functional, not institutional. The OAIC’s Key Concepts guideline (Chapter B) and multiple FOI/Privacy determinations confirm that any act "in the course of hearing and determining disputes, making orders, or conducting judicial/tribunal proceedings" is judicial (or quasi-judicial) and exempt. This covers: acceptance of evidence, case management orders, judgments, assembling or admitting records for proceedings, producing transcripts, or distributing decisions. Conversely, internal court administration—staff HR files, facilities management, registry management, contracts for IT services—are administrative and not exempt. Handling of staff records, security access, procurement, and IT (outside of proceedings) is subject to the APPs like any other agency. The Federal Court in Choi v The Presiding Officer [2021] FCA 1161 and subsequent OAIC determinations have held that the distinction is fact-dependent.
Non-federal courts and state tribunals. The above rules bind only Commonwealth courts and federal tribunals. State and territory courts are not generally covered by the Privacy Act, but are regulated under local privacy legislation (see 'State and Territory privacy regimes' in this guide).
Implications for parties and professionals. Information filed in a court or tribunal proceeding—including sensitive personal information—is not governed by APPs for proceedings-handling purposes: courts cannot be subject to access, withdrawal, or correction requests for evidence, records, or judgments under the Privacy Act. However, parties, practitioners, and court officials should be alert to the boundary between proceedings (exempt) and administrative data-handling (covered)—especially in grey areas such as general registry operations, user-facing portals, or unconnected correspondence.
Source: Privacy Act 1988 (Cth) s 7(1), OAIC — APP Guidelines on 'agencies', Chapter B, para B.122–B.136
Who is a "health service provider" under the Privacy Act? – s 6(1) definition and sectoral scope
The Privacy Act 1988 (Cth) covers all "health service providers" as APP entities regardless of annual turnover, making the scope and definition of "health service provider" exceptionally broad compared with the general small business carve-out. Section 6(1) defines "health service" as an activity performed in relation to an individual that is intended or claimed (expressly or otherwise) to assess, record, maintain, improve, or manage an individual's health, care for or treat a disability, diagnose or treat an illness or disability, or impact health or well-being in any way. The definition captures services provided by:
- Traditional medical providers: general practitioners, hospitals, day surgeries, specialists, dentists, mental health practitioners, allied health professionals (physiotherapists, psychologists, occupational therapists, speech therapists, pharmacists, podiatrists), and
- Non-traditional or "complementary" services: naturopaths, chiropractors, acupuncturists, homeopaths, massage therapists, and others who claim to provide physical or mental health-related services, regardless of conventional medical accreditation.
Section 6(1) goes further, covering any "health-related disability, injury, or condition" and any act "for the reason that the individual is or may be sick, injured, or disabled." It also includes "a health assessment for insurance purposes," thus catching a range of non-clinical or assessment-type activities. OAIC guidance confirms this scope: "If you provide a health service, you are a health service provider for Privacy Act purposes," regardless of registration with AHPRA or presence on a statutory professional register.
Fitness and wellbeing apps/services: The OAIC's guideline frames digital health apps and wellness services as providing a health service if they collect or use information to assess or manage health (for example, telehealth platforms, mental health chatbots, fitness trackers giving tailored health guidance). Services targeted solely to general fitness or lifestyle improvement may not be covered unless they cross the line into individual assessment, monitoring, or provision of information about actual or suspected health conditions.
Corporate, school, and workplace health services: Entities providing health services within a workplace or educational setting—including on-site first aid, employee assistance programs, immunisation clinics, and school counsellors—are health service providers to the extent that they assess or treat individual health issues. Even small pop-up, volunteer, or part-time services come within scope regardless of business size or turnover.
Implications: Any entity meeting the "health service" definition is treated as an APP entity, sidestepping the <$3 million small business exemption (s 6D(4)(c)). This brings a significant number of start-up telehealth providers, non-profit community clinics, solo practitioners, and health-related tech developers within the Act. Failing to identify as a health service provider is a recurring compliance fault: OAIC enforcement focuses on improper collection, disclosure, and security of sensitive health information, even by small or informal operators.
Current statutory language and OAIC position: The current text of s 6(1) is interpreted broadly; there is no limiting requirement for medical registration. OAIC's "Who must comply" guidance and Chapter B Key Concepts (B.99–B.102) both stress that intention, claim, and effect of the service are determinative, not formal regulatory status. The Privacy Act Review (2023 government response) did not propose to narrow this definition; the coverage of health service providers remains intentionally expansive.
Source: Privacy Act 1988 (Cth) s 6(1), s 6D(4)(c), OAIC — Australian Privacy Principles Guidelines, Chapter B: Key concepts (paras B.99–B.102), OAIC — Who must comply with the Privacy Act
Credit reporting entities and Part IIIA — when credit data is in-scope and relationship to APP entity test
Credit reporting bodies and credit providers are regulated under a distinct regime—Part IIIA of the Privacy Act 1988 (Cth)—which both overlays and, in practice, expands material and entity scope for businesses handling credit information.
Part IIIA creates specific rules for the collection, use, and disclosure of "credit information," "credit eligibility information," and "credit reporting information." It applies to two principal classes of APP entities: credit reporting bodies (CRBs), who collect and hold personal credit information about individuals for the purpose of providing credit reports to third parties, and credit providers, which include banks, finance companies, energy and telecommunication providers, some B2B creditors, and others extending credit in the ordinary course of business (s 6(1), s 6L, s 6P). Importantly, entities can be swept in as APP entities by virtue of their credit reporting activities even where they would otherwise be exempt—most notably, small business operators with annual turnover below A$3 million are not exempt where they are a credit reporting body or credit provider for Part IIIA purposes (see s 6D(4)(b),(e), and (f)).
Scope of "credit information" and its handling:
- "Credit information" includes information about an individual’s identification, consumer credit liability, repayment history, defaults, payment arrangements, court judgments, insolvency, and requests for information about credit (s 6N). "Credit eligibility information" is information derived from a credit report obtained from a CRB, and "credit reporting information" is information provided by a CRB.
- The definition extends to both consumer credit and, for certain classes, commercial credit dealings by individuals (sole traders, partnerships where credit is given personally). CRBs that hold such data, and credit providers who use report-derived information to manage accounts, are regulated under Part IIIA even if they do not otherwise meet the general APP entity test.
Overlap and interface with the APPs:
- While CRBs and credit providers must comply with the Australian Privacy Principles for all personal information handling, the credit reporting rules in Part IIIA and the binding CR Code (currently v2.2) constitute a parallel, and sometimes overriding, regime specifically for credit information. Where an act or practice is regulated under Part IIIA and the APPs, the more specific rule governs. For example, access and correction rights for credit information primarily follow the processes in Part IIIA and the CR Code (see APP 12.2, Privacy Act s 20R–20T, CR Code s 19–21).
- Part IIIA also contains standalone notification, disclosure, access and correction, data quality, and security requirements. Failure to meet these is an interference with privacy and may be investigated by OAIC.
- Other entities (including SaaS and fintech providers) may be swept in by function: a business handling credit information on behalf of a credit provider/CRB may come within the APPs as a processor or through agency principles, depending on the structure of its engagement.
Exemptions and carve-outs:
- The small business operator exemption under s 6D does not apply for any period in which a business is a credit reporting body or a credit provider (s 6D(4)(b),(e)). Many small businesses that act as B2B creditors or supply utilities on deferred payment terms may be captured without realising they fall within the statutory definition, triggering full APP and Part IIIA obligations.
- Employee records exemption (s 7B(3)) generally does not apply to credit information handled for credit reporting or providing purposes; acts done in the course of credit reporting by employment-screening companies, for example, remain in scope.
- The journalism exemption and other APP entity carve-outs do not generally impact Part IIIA obligations for covered entities.
Current reform and summary: The 2020 Privacy Act Review and 2023 government response signalled likely reforms to further clarify scope and strengthen protections for credit information, but as of June 2026, the split regime and carve-in for credit bodies and providers remains central to applicability analysis. Practitioners should closely map their activities to the Part IIIA definitions and the CR Code, as relying solely on the general APP entity status or turnover threshold can lead to inadvertent non-compliance.
Source: Privacy Act 1988 (Cth) ss 6D(4), 6N, 6L, 6P, Part IIIA, OAIC — Credit reporting: obligations and entities covered, OAIC — Credit providers and reporting bodies guidance