Skip to main content
Rules Mate

Who must comply with APP 3 collection of sensitive information?

The applicability test for APP 3 collection of sensitive information (OAIC), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Only if

Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.

What the obligation is

APP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.

APP 3 restricts collection of sensitive information (health, religious beliefs, racial/ethnic origin, political opinions, criminal record, biometric data + similar) to circumstances where the individual consents + collection is reasonably necessary, or specified exceptions apply.

The applicability test

Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.

How the regulator frames it: All APP entities collecting sensitive information.

What triggers it: Collecting sensitive information.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (35 of 35: no).

The answer is the same in every industry: no. Industry does not change who must comply.

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "no".

Size does not change the answer across all industries: at every size band the answer is "no".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business holds health information: it then applies (annual turnover over $3M — an APP entity under the Privacy Act (s 6D) · Holds health information (sensitive information)).
  • The business holds children's personal information: it then applies (annual turnover over $3M — an APP entity under the Privacy Act (s 6D) · Holds children's data).
  • The business holds biometric information: it then applies (annual turnover over $3M — an APP entity under the Privacy Act (s 6D) · Holds biometric information (sensitive information)).

What you must do, and when

When due
At each collection event.
Frequency
Ongoing
Evidence to keep
Consent records; necessity assessment; collection notice.
Status
Current
Priority
Critical

Penalty for not complying

Maximum penalty: Same penalty regime; class action exposure for biometric misuse (Clearview AI, 7-Eleven, Bunnings precedents)

Audit or assurance level

Self-assessment. Authority: Privacy Act 1988 (Cth) ss6D, 33C, Sch 1 APP 1; OAIC Guide to privacy regulatory action Ch 9.

Frequency: Ongoing. No mandated periodic audit. APP 1 requires an up-to-date privacy policy and reasonable practices and procedures.

Who can perform it: The entity itself. The OAIC may conduct a privacy assessment (s33C) at its discretion and can compel documents; you cannot commission an OAIC assessment as an audit.

Enforcement examples

Where it sits in the corpus

Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated critical priority, and is an ongoing duty.

Regulator, legislation and tools

Regulated by Office of the Australian Information Commissioner.

OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.

Privacy Act 1988: Federal privacy Act.

Free tools that help with this obligation:

Questions

Who must comply with APP 3 collection of sensitive information?
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.
Does APP 3 collection of sensitive information apply to sole traders?
No. Across every industry and every size band, the engine's answer for a sole trader is: no.
Does APP 3 collection of sensitive information apply to businesses with 1–5 employees?
No (1–5 employees, turnover $100K–$1M).
When is "APP 3 collection of sensitive information" due?
At each collection event.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.