Skip to main content
Rules Mate

Do trust and company service providers need to publish a Privacy Policy that meets APP 1?

A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.

Short answer: Yes

Yes. This obligation applies to trust and company service providers whatever their structure or size. The deciding fact: AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A)).

The obligation in brief

Publish a Privacy Policy that meets APP 1. 3 requires every APP entity to have a clearly-expressed and up-to-date Privacy Policy. 4 prescribes minimum content: kinds of personal information collected, how it is collected and held, purposes, disclosure (including overseas), complaint handling, and access/correction processes.

Trigger: Being an APP entity that handles personal information.

Why trust & company service providers get a different answer

Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 24 of those industries the answer for "Publish a Privacy Policy that meets APP 1" is it depends on structure or size. Trust & company service providers is one of the 11 where the answer is different: yes.

The deciding fact for trust and company service providers: AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A))

About the industry: Entities providing trust or company formation, registered agent, or nominee services. Tranche 2 captured.

Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out)).

Answer by business structure and size

Each cell is the engine's outcome for a business in trust & company service providers with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.

"Publish a Privacy Policy that meets APP 1": outcome for trust and company service providers by structure and size
StructureNo employees1–5 employees6–19 employees20–99 employees100–499 employees500+ employees
Sole traderYesYesYesYesYesYes
PartnershipYesYesYesYesYesYes
TrustYesYesYesYesYesYes
Pty Ltd companyYesYesYesYesYesYes
Public companyYesYesYesYesYesYes
Not-for-profit (unregistered)YesYesYesYesYesYes
Registered charityYesYesYesYesYesYes
Super fundYesYesYesYesYesYes
Foreign companyYesYesYesYesYesYes

What the obligation requires

When due
Before collecting personal information. Reviewed regularly.
Evidence to keep
Published Privacy Policy with version history.
Maximum penalty
Civil penalties up to $50M for serious or repeated interferences with privacy
Regulator
OAIC
Jurisdiction
Commonwealth (national)

Other obligations where trust & company service providers differ from the norm

Other industries with a non-default answer

Questions

Do trust and company service providers need to publish a Privacy Policy that meets APP 1?
Yes. This obligation applies to trust and company service providers whatever their structure or size. The deciding fact: AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A)).
Is the answer the same for every industry?
No. For 24 of the 35 industries Rules Mate maps, the answer is it depends on structure or size. Trust & company service providers is one of 11 industries with a different answer.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.