Privacy Act 1988 (Cth) and the Australian Privacy Principles
Below is what the official text of Privacy Act 1988 (Cth) and the Australian Privacy Principles states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit business established in Australia: Applies, or may apply: conditions to check.
- A US business with users in Australia: Not triggered by these answers.
- A US business with no users in Australia: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | The Act's objects include promoting the protection of the privacy of individuals with respect to their personal information.Official wordingThe objects of this Act are: (a) to promote the protection of the privacy of individuals with respect to their personal information; | www.legislation.gov.au read 2026-10-06 |
| When it applies to a business | The Act extends to acts done or practices engaged in outside Australia by an organisation (or small business operator) that has an Australian link (s.5B); under s.5B(2)-(3) that includes Australian citizens, Australian-formed bodies, and organisations that carry on business in Australia. Conditions to check: We test whether the business is established in Australia, a proxy for the s.5B(2) Australian link (citizens, permanent residents, bodies incorporated or formed in Australia, central management and control in Australia). Under s.5B(3) other organisations that 'carry on business in Australia' also have an Australian link; our questions cannot express that, so a foreign business with Australian customers is not marked as applying. Small business exemption: a business with annual turnover of AUD 3,000,000 or less is a small business (s.6D(1)) and a small business operator is not an 'organisation' (s.6C), so it is outside the APPs unless an exception in s.6D(4) applies (e.g. it provides a health service and holds health information, discloses personal information for a benefit, service or advantage, or is a credit reporting body). The AUD threshold is in Australian dollars, so we do not test it. Other exclusions (registered political parties, employee records, etc.) were not analysed. Official wording(1A) This Act, a registered APP code and the registered CR code extend to an act done, or practice engaged in, outside Australia and the external Territories by an organisation, or small business operator, that has an Australian link. | www.legislation.gov.au read 2026-10-06 |
| In force from | Not stated on the official pages we read. The compilation records only that the Act commenced on 1 Jan 1989; the date from which the Act's obligations reached private-sector organisations is not in the text we read. | — |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. The text read does not state a requirement for a privacy officer or data protection officer for organisations. | — |
| Breach notification | Included in the paid checklist. See the checklist | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here