Australian Privacy Principles (APPs)
Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Part 1 - Consideration of Personal Information Privacy
Manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy.
- Published APP privacy policy
- Evidence of open data-handling practices
- Policy review records
- No APP privacy policy
- Policy out of date
- Practices not transparent
Give individuals the option of not identifying themselves, or of using a pseudonym, unless an exception applies.
- Anonymity/pseudonymity options where practicable
- Documented exceptions
- No anonymity option
- Identification required without lawful basis
Part 2 - Collection of Personal Information
Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.
- Justification of necessity for collection
- Lawful and fair collection methods
- Heightened protection for sensitive information
- Over-collection
- Unlawful/unfair collection
- Sensitive info collected without consent
Where unsolicited personal information is received, determine whether it could have been collected under APP 3 and, if not, destroy or de-identify it.
- Process for handling unsolicited personal information
- Destruction/de-identification records
- Unsolicited PI retained without assessment
- No handling procedure
Notify individuals of the collection of their personal information and the matters set out in APP 5.
- Collection notices (APP 5 matters)
- Timing of notification
- No collection notice
- Notice missing APP 5 matters
Part 3 - Dealing with Personal Information
Only use or disclose personal information for the purpose it was collected (primary purpose) or a permitted secondary purpose.
- Use/disclosure tied to primary or permitted purpose
- Records of use and disclosure
- Use/disclosure for unrelated purpose
- No basis recorded
Only use or disclose personal information for direct marketing where permitted, with a simple means to opt out.
- Basis for direct marketing
- Opt-out mechanism honoured
- Direct marketing without basis
- No opt-out
Before disclosing personal information overseas, take reasonable steps to ensure the overseas recipient does not breach the APPs.
- Overseas disclosure assessment
- Contractual safeguards with overseas recipients
- Records of cross-border disclosures (APP 8.4)
- Overseas disclosure without safeguards
- No assessment of recipient
Do not adopt, use or disclose a government related identifier unless an exception applies.
- Controls on government identifier use
- Documented exceptions
- Government identifier used as own identifier
- No control over identifier handling
Part 4 - Integrity of Personal Information
Take reasonable steps to ensure the personal information collected, used or disclosed is accurate, up to date and complete.
- Data quality controls
- Correction processes feeding quality
- No data quality controls
- Inaccurate information used
Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.
- Information security controls for personal information
- Destruction/de-identification of redundant PI
- PI not secured
- Redundant PI retained
Part 5 - Access to, and Correction of, Personal Information
Give individuals access to their personal information on request, subject to exceptions.
- Access request process
- Records of access requests and responses
- Documented refusals/exceptions
- No access process
- Access refused without basis
Correct personal information on request or when satisfied it is inaccurate, out of date, incomplete, irrelevant or misleading.
- Correction request process
- Records of corrections
- Notification of correction to third parties where required
- No correction process
- Correction requests not actioned
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australian Privacy Principles (APPs) framework page.