| name | australia-privacy-act |
| title | Australia Privacy Act Compliance (2024 Amendments) |
| description | Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Covers automated decision-making transparency, children's privacy code, individual rights expansion, enforcement strengthening, and the Australian Privacy Principles (APPs). Keywords: Australia Privacy Act, APPs, OAIC, automated decisions, children privacy code, privacy reform. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/australia-privacy-act |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | au |
| practice | data-protection |
| language | en |
Australia Privacy Act Compliance (2024 Amendments)
Overview
Australia's Privacy Act 1988 (Cth) is the primary federal data protection legislation, administered and enforced by the Office of the Australian Information Commissioner (OAIC). The Privacy Act applies to Australian Government agencies, private sector organisations with an annual turnover of more than AUD 3 million, and certain other organisations regardless of turnover (health service providers, organisations trading in personal information, credit reporting bodies).
The Australian Government's 2024 Privacy Act Reform Amendments (building on the Attorney-General's Department Privacy Act Review Report of February 2023) introduced significant reforms including a statutory tort for serious invasions of privacy, enhanced individual rights, automated decision-making transparency obligations, a children's privacy code, and strengthened enforcement powers.
Australian Privacy Principles (APPs)
The 13 APPs
| APP | Subject | Key Requirement |
|---|
| APP 1 | Open and transparent management | Maintain a clear privacy policy; take reasonable steps to implement practices that ensure compliance |
| APP 2 | Anonymity and pseudonymity | Give individuals the option of dealing anonymously or under a pseudonym where practicable |
| APP 3 | Collection of solicited personal information | Collect only information reasonably necessary for functions/activities; collect sensitive information only with consent |
| APP 4 | Dealing with unsolicited personal information | If unsolicited information could not have been collected under APP 3, destroy or de-identify it |
| APP 5 | Notification of collection | Notify individuals of: identity, purpose, third-party disclosures, overseas disclosures, access/correction rights, complaint mechanism |
| APP 6 | Use or disclosure | Use or disclose only for the purpose of collection or a directly related secondary purpose within reasonable expectations |
| APP 7 | Direct marketing | May use for direct marketing if individual would reasonably expect it and opt-out is provided; sensitive information requires consent |
| APP 8 | Cross-border disclosure | Before disclosing overseas, take reasonable steps to ensure the overseas recipient complies with the APPs |
| APP 9 | Adoption, use, or disclosure of government identifiers |