Privacy Act 1988

SCHEDULE 1 - AUSTRALIAN PRIVACY PRINCIPLES  

Note: See section 14 .


Overview of the Australian Privacy Principles

Overview

This Schedule sets out the Australian Privacy Principles.

Part 1 sets out principles that require APP entities to consider the privacy of personal information, including ensuring that APP entities manage personal information in an open and transparent way.

Part 2 sets out principles that deal with the collection of personal information including unsolicited personal information.

Part 3 sets out principles about how APP entities deal with personal information and government related identifiers. The Part includes principles about the use and disclosure of personal information and those identifiers.

Part 4 sets out principles about the integrity of personal information. The Part includes principles about the quality and security of personal information.

Part 5 sets out principles that deal with requests for access to, and the correction of, personal information.

Australian Privacy Principles

The Australian Privacy Principles are:

  • • Australian Privacy Principle 1 - open and transparent management of personal information
  • • Australian Privacy Principle 2 - anonymity and pseudonymity
  • • Australian Privacy Principle 3 - collection of solicited personal information
  • • Australian Privacy Principle 4 - dealing with unsolicited personal information
  • • Australian Privacy Principle 5 - notification of the collection of personal information
  • • Australian Privacy Principle 6 - use or disclosure of personal information
  • • Australian Privacy Principle 7 - direct marketing
  • • Australian Privacy Principle 8 - cross-border disclosure of personal information
  • • Australian Privacy Principle 9 - adoption, use or disclosure of government related identifiers
  • • Australian Privacy Principle 10 - quality of personal information
  • • Australian Privacy Principle 11 - security of personal information
  • • Australian Privacy Principle 12 - access to personal information
  • • Australian Privacy Principle 13 - correction of personal information
  • PART 4 - INTEGRITY OF PERSONAL INFORMATION  

    11   Australian Privacy Principle 11 - security of personal information  

    11.1    
    If an APP entity holds personal information, the entity must take such steps as are reasonable in the circumstances to protect the information:


    (a) from misuse, interference and loss; and


    (b) from unauthorised access, modification or disclosure.

    11.2    
    If:


    (a) an APP entity holds personal information about an individual; and


    (b) the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity under this Schedule; and


    (c) the information is not contained in a Commonwealth record; and


    (d) the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information;

    the entity must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified.





    This information is provided by CCH Australia Limited Link opens in new window. View the disclaimer and notice of copyright.