Who must comply with APP 3 collection of sensitive information?
The applicability test for APP 3 collection of sensitive information (OAIC), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.
What the obligation is
APP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
APP 3 restricts collection of sensitive information (health, religious beliefs, racial/ethnic origin, political opinions, criminal record, biometric data + similar) to circumstances where the individual consents + collection is reasonably necessary, or specified exceptions apply.
The applicability test
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.
How the regulator frames it: All APP entities collecting sensitive information.
What triggers it: Collecting sensitive information.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business holds health information: it then applies (annual turnover over $3M — an APP entity under the Privacy Act (s 6D) · Holds health information (sensitive information)).
- The business holds children's personal information: it then applies (annual turnover over $3M — an APP entity under the Privacy Act (s 6D) · Holds children's data).
- The business holds biometric information: it then applies (annual turnover over $3M — an APP entity under the Privacy Act (s 6D) · Holds biometric information (sensitive information)).
What you must do, and when
- When due
- At each collection event.
- Frequency
- Ongoing
- Evidence to keep
- Consent records; necessity assessment; collection notice.
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: Same penalty regime; class action exposure for biometric misuse (Clearview AI, 7-Eleven, Bunnings precedents)
Audit or assurance level
Self-assessment. Authority: Privacy Act 1988 (Cth) ss6D, 33C, Sch 1 APP 1; OAIC Guide to privacy regulatory action Ch 9.
Frequency: Ongoing. No mandated periodic audit. APP 1 requires an up-to-date privacy policy and reasonable practices and procedures.
Who can perform it: The entity itself. The OAIC may conduct a privacy assessment (s33C) at its discretion and can compel documents; you cannot commission an OAIC assessment as an audit.
Enforcement examples
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated critical priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Office of the Australian Information Commissioner.
OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
Privacy Act 1988: Federal privacy Act.
Free tools that help with this obligation:
Questions
- Who must comply with APP 3 collection of sensitive information?
- Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and sensitive information or children's data.
- Does APP 3 collection of sensitive information apply to sole traders?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Does APP 3 collection of sensitive information apply to businesses with 1–5 employees?
- No (1–5 employees, turnover $100K–$1M).
- When is "APP 3 collection of sensitive information" due?
- At each collection event.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.