Australian Privacy Principles (APPs)
Only when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists.
edition Privacy Act 1988, Schedule 1 (APP 1 to 13). 2 requirements cited here. Every Australian Privacy Principles clause we hold.
Personal information held is protected by reasonable steps against misuse, interference, loss and unauthorised access
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| APP 11 Australian Privacy Principles | Security of personal information Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed. evidence an assessor asks for Information security controls for personal information; Destruction/de-identification of redundant PI |
A clearly expressed, up-to-date privacy policy is published
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| APP 1 Australian Privacy Principles | Open and transparent management of personal information Manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy. evidence an assessor asks for Published APP privacy policy; Evidence of open data-handling practices; Policy review records |
Questions
- When does Australian Privacy Principles apply here?
- Only when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists.
- Which edition is held?
- Privacy Act 1988, Schedule 1 (APP 1 to 13)
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.