Who must publish a Privacy Policy that meets APP 1?
The applicability test for Publish a Privacy Policy that meets APP 1 (OAIC), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out).
What the obligation is
Every APP entity needs a clearly-expressed Privacy Policy covering APP 1.4 requirements.
APP 1.3 requires every APP entity to have a clearly-expressed and up-to-date Privacy Policy. APP 1.4 prescribes minimum content: kinds of personal information collected, how it is collected and held, purposes, disclosure (including overseas), complaint handling, and access/correction processes. Policies must be made freely available.
The applicability test
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out).
How the regulator frames it: All APP entities. If the small business exemption is removed in a future reform tranche (proposed, not yet law), ~2M additional businesses would be captured.
What triggers it: Being an APP entity that handles personal information.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (11 of 35: yes; 24 of 35: depends on size or structure).
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "depends on size or structure".
| Size band | Answer across all industries, any structure |
|---|---|
| No employees (turnover $100K–$1M) | Depends on size or structure |
| 1–5 employees (turnover $100K–$1M) | Depends on size or structure |
| 6–19 employees (turnover $1M–$3M) | Depends on size or structure |
| 20–99 employees (turnover $3M–$10M) | Yes |
| 100–499 employees (turnover $10M–$100M) | Yes |
| 500+ employees (turnover $100M–$1B) | Yes |
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: applies. AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A))
- Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: does not apply. Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out)
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business deals in crypto-assets or runs a digital currency exchange: it then applies (AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A))).
- The business is a registered NDIS provider: it then applies (provides a health service and holds health information — not covered by the small business exemption (Privacy Act s 6D(4)(b))).
- The business is an approved aged care provider: it then applies (provides a health service and holds health information — not covered by the small business exemption (Privacy Act s 6D(4)(b))).
- The business supplies government customers: it then applies (government customer — contracted service providers to the Commonwealth are covered (Privacy Act s 6D(4)(e))).
What you must do, and when
- When due
- Before collecting personal information. Reviewed regularly.
- Frequency
- Ongoing
- Evidence to keep
- Published Privacy Policy with version history.
- Status
- Current
- Priority
- High
Penalty for not complying
Maximum penalty: Civil penalties up to $50M for serious or repeated interferences with privacy.
Audit or assurance level
Self-assessment. Authority: Privacy Act 1988 (Cth) ss6D, 33C, Sch 1 APP 1; OAIC Guide to privacy regulatory action Ch 9.
Frequency: Ongoing. No mandated periodic audit. APP 1 requires an up-to-date privacy policy and reasonable practices and procedures.
Who can perform it: The entity itself. The OAIC may conduct a privacy assessment (s33C) at its discretion and can compel documents; you cannot commission an OAIC assessment as an audit.
Enforcement examples
Obligations with the same applicability test
If this obligation applies to you, so do these 4: the engine uses the same rule for each.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Office of the Australian Information Commissioner.
OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
Privacy Act 1988: Federal privacy Act.
Free tools that help with this obligation:
Questions
- Who must publish a Privacy Policy that meets APP 1?
- Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out).
- Do sole traders need to publish a Privacy Policy that meets APP 1?
- Depends on size or structure. Across every industry and every size band, the engine's answer for a sole trader is: depends on size or structure.
- Do businesses with 1–5 employees need to publish a Privacy Policy that meets APP 1?
- Depends on size or structure (1–5 employees, turnover $100K–$1M).
- When is "Publish a Privacy Policy that meets APP 1" due?
- Before collecting personal information. Reviewed regularly.
Related
- Publish a Privacy Policy that meets APP 1: full obligation detail
- Who must comply: all obligations
- Who must comply with Notifiable Data Breach (NDB) scheme
- Does it apply to real estate agents?
- Does it apply to accountants & bookkeepers?
- Does it apply to lawyers & solicitors?
- Does it apply to trust & company service providers?
- Does it apply to precious metals & stones dealers?
- Does it apply to aged care providers?
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.