Skip to main content
Rules Mate

Who must comply with APP 2 — anonymity + pseudonymity for individuals?

The applicability test for APP 2 — anonymity + pseudonymity for individuals (OAIC), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Some businesses

Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out).

What the obligation is

Where reasonable, individuals must be able to deal with you anonymously or under a pseudonym.

APP 2 requires APP entities to provide individuals with the option of dealing anonymously or under a pseudonym, unless impracticable or required by law. Limits the default-required identification many businesses impose unnecessarily.

The applicability test

Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out).

How the regulator frames it: All APP entities.

What triggers it: Engaging with individuals where identification not strictly required.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (11 of 35: yes; 24 of 35: depends on size or structure).

IndustryAnswer
Real estate agentsYes
Accountants & bookkeepersYes
Lawyers & solicitorsYes
ConveyancersYes
Trust & company service providersYes
Precious metals & stones dealersYes
Banks & ADIsYes
Aged care providersYes
NDIS providersYes
Health practitionersYes
Gambling & wageringYes
Fintech (non-bank)Depends on size or structure
General insurersDepends on size or structure
Superannuation trusteesDepends on size or structure
Credit licensees & mortgage brokersDepends on size or structure
Medical devices & therapeutic goodsDepends on size or structure
Private health insurersDepends on size or structure
Cafés & restaurantsDepends on size or structure
Hotels, pubs & licensed venuesDepends on size or structure
Retail tradeDepends on size or structure
E-commerce & online retailDepends on size or structure
Construction (residential & commercial)Depends on size or structure
ManufacturingDepends on size or structure
Agriculture, forestry & fishingDepends on size or structure
Mining & resourcesDepends on size or structure
Road transport & logisticsDepends on size or structure
Aviation (incl. drones)Depends on size or structure
Maritime & portsDepends on size or structure
Education — registered training orgsDepends on size or structure
Education — higher education providersDepends on size or structure
Software & SaaSDepends on size or structure
Professional services (general)Depends on size or structure
Charities & not-for-profitsDepends on size or structure
Telecommunications carriers / CSPsDepends on size or structure
Media & publishingDepends on size or structure

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "depends on size or structure".

Size bandAnswer across all industries, any structure
No employees (turnover $100K–$1M)Depends on size or structure
1–5 employees (turnover $100K–$1M)Depends on size or structure
6–19 employees (turnover $1M–$3M)Depends on size or structure
20–99 employees (turnover $3M–$10M)Yes
100–499 employees (turnover $10M–$100M)Yes
500+ employees (turnover $100M–$1B)Yes

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: applies. AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A))
  • Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: does not apply. Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out)

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business deals in crypto-assets or runs a digital currency exchange: it then applies (AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A))).
  • The business is a registered NDIS provider: it then applies (provides a health service and holds health information — not covered by the small business exemption (Privacy Act s 6D(4)(b))).
  • The business is an approved aged care provider: it then applies (provides a health service and holds health information — not covered by the small business exemption (Privacy Act s 6D(4)(b))).
  • The business supplies government customers: it then applies (government customer — contracted service providers to the Commonwealth are covered (Privacy Act s 6D(4)(e))).

What you must do, and when

When due
Continuous.
Frequency
Ongoing
Evidence to keep
Workflow analysis; consent + opt-out options; identifiers minimised.
Status
Current
Priority
Medium

Penalty for not complying

Maximum penalty: Same penalty regime as broader Privacy Act breaches.

Audit or assurance level

Self-assessment. Authority: Privacy Act 1988 (Cth) ss6D, 33C, Sch 1 APP 1; OAIC Guide to privacy regulatory action Ch 9.

Frequency: Ongoing. No mandated periodic audit. APP 1 requires an up-to-date privacy policy and reasonable practices and procedures.

Who can perform it: The entity itself. The OAIC may conduct a privacy assessment (s33C) at its discretion and can compel documents; you cannot commission an OAIC assessment as an audit.

Obligations with the same applicability test

What usually applies alongside it

Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:

Where it sits in the corpus

Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated medium priority, and is an ongoing duty.

Regulator, legislation and tools

Regulated by Office of the Australian Information Commissioner.

OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.

Privacy Act 1988: Federal privacy Act.

Free tools that help with this obligation:

Questions

Who must comply with APP 2 — anonymity + pseudonymity for individuals?
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out).
Does APP 2 — anonymity + pseudonymity for individuals apply to sole traders?
Depends on size or structure. Across every industry and every size band, the engine's answer for a sole trader is: depends on size or structure.
Does APP 2 — anonymity + pseudonymity for individuals apply to businesses with 1–5 employees?
Depends on size or structure (1–5 employees, turnover $100K–$1M).
When is "APP 2 — anonymity + pseudonymity for individuals" due?
Continuous.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.