Cyber Insurance Subjectivity Tracker

Rules

Privacy Act lines: Australia

Australian Privacy Principles (APPs)

Only when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists.

edition Privacy Act 1988, Schedule 1 (APP 1 to 13). 2 requirements cited here. Every Australian Privacy Principles clause we hold.

Personal information held is protected by reasonable steps against misuse, interference, loss and unauthorised access

ClauseThe held text, and the evidence an assessor asks for
APP 11
Australian Privacy Principles
Security of personal information

Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.

evidence an assessor asks for Information security controls for personal information; Destruction/de-identification of redundant PI

A clearly expressed, up-to-date privacy policy is published

ClauseThe held text, and the evidence an assessor asks for
APP 1
Australian Privacy Principles
Open and transparent management of personal information

Manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy.

evidence an assessor asks for Published APP privacy policy; Evidence of open data-handling practices; Policy review records

Questions

When does Australian Privacy Principles apply here?
Only when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists.
Which edition is held?
Privacy Act 1988, Schedule 1 (APP 1 to 13)
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.