Skip to content

Evidence request lists

Australian Privacy Principles (APPs)

Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Part 1 - Consideration of Personal Information Privacy

APP-1
APP 1 - Open and transparent management of personal information

Manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy.

Artefacts an auditor will ask for
  • Published APP privacy policy
  • Evidence of open data-handling practices
  • Policy review records
Where this commonly fails
  • No APP privacy policy
  • Policy out of date
  • Practices not transparent
APP-2
APP 2 - Anonymity and pseudonymity

Give individuals the option of not identifying themselves, or of using a pseudonym, unless an exception applies.

Artefacts an auditor will ask for
  • Anonymity/pseudonymity options where practicable
  • Documented exceptions
Where this commonly fails
  • No anonymity option
  • Identification required without lawful basis

Part 2 - Collection of Personal Information

APP-3
APP 3 - Collection of solicited personal information

Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.

Artefacts an auditor will ask for
  • Justification of necessity for collection
  • Lawful and fair collection methods
  • Heightened protection for sensitive information
Where this commonly fails
  • Over-collection
  • Unlawful/unfair collection
  • Sensitive info collected without consent
APP-4
APP 4 - Dealing with unsolicited personal information

Where unsolicited personal information is received, determine whether it could have been collected under APP 3 and, if not, destroy or de-identify it.

Artefacts an auditor will ask for
  • Process for handling unsolicited personal information
  • Destruction/de-identification records
Where this commonly fails
  • Unsolicited PI retained without assessment
  • No handling procedure
APP-5
APP 5 - Notification of the collection of personal information

Notify individuals of the collection of their personal information and the matters set out in APP 5.

Artefacts an auditor will ask for
  • Collection notices (APP 5 matters)
  • Timing of notification
Where this commonly fails
  • No collection notice
  • Notice missing APP 5 matters

Part 3 - Dealing with Personal Information

APP-6
APP 6 - Use or disclosure of personal information

Only use or disclose personal information for the purpose it was collected (primary purpose) or a permitted secondary purpose.

Artefacts an auditor will ask for
  • Use/disclosure tied to primary or permitted purpose
  • Records of use and disclosure
Where this commonly fails
  • Use/disclosure for unrelated purpose
  • No basis recorded
APP-7
APP 7 - Direct marketing

Only use or disclose personal information for direct marketing where permitted, with a simple means to opt out.

Artefacts an auditor will ask for
  • Basis for direct marketing
  • Opt-out mechanism honoured
Where this commonly fails
  • Direct marketing without basis
  • No opt-out
APP-8
APP 8 - Cross-border disclosure of personal information

Before disclosing personal information overseas, take reasonable steps to ensure the overseas recipient does not breach the APPs.

Artefacts an auditor will ask for
  • Overseas disclosure assessment
  • Contractual safeguards with overseas recipients
  • Records of cross-border disclosures (APP 8.4)
Where this commonly fails
  • Overseas disclosure without safeguards
  • No assessment of recipient
APP-9
APP 9 - Adoption, use or disclosure of government related identifiers

Do not adopt, use or disclose a government related identifier unless an exception applies.

Artefacts an auditor will ask for
  • Controls on government identifier use
  • Documented exceptions
Where this commonly fails
  • Government identifier used as own identifier
  • No control over identifier handling

Part 4 - Integrity of Personal Information

APP-10
APP 10 - Quality of personal information

Take reasonable steps to ensure the personal information collected, used or disclosed is accurate, up to date and complete.

Artefacts an auditor will ask for
  • Data quality controls
  • Correction processes feeding quality
Where this commonly fails
  • No data quality controls
  • Inaccurate information used
APP-11
APP 11 - Security of personal information

Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.

Artefacts an auditor will ask for
  • Information security controls for personal information
  • Destruction/de-identification of redundant PI
Where this commonly fails
  • PI not secured
  • Redundant PI retained

Part 5 - Access to, and Correction of, Personal Information

APP-12
APP 12 - Access to personal information

Give individuals access to their personal information on request, subject to exceptions.

Artefacts an auditor will ask for
  • Access request process
  • Records of access requests and responses
  • Documented refusals/exceptions
Where this commonly fails
  • No access process
  • Access refused without basis
APP-13
APP 13 - Correction of personal information

Correct personal information on request or when satisfied it is inaccurate, out of date, incomplete, irrelevant or misleading.

Artefacts an auditor will ask for
  • Correction request process
  • Records of corrections
  • Notification of correction to third parties where required
Where this commonly fails
  • No correction process
  • Correction requests not actioned
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australian Privacy Principles (APPs) framework page.