Skip to content
TB
TeamBenchResources

Australian Privacy Act Content Compliance

The Privacy Act 1988 and Australian Privacy Principles govern how organisations handle personal information in content. Learn how to review content for compliance.

TeamBench· Content Quality PlatformFebruary 19, 20267 min read

The Privacy Act 1988 and the Australian Privacy Principles (APPs) regulate how organisations collect, use, disclose, and store personal information. Administered by the Office of the Australian Information Commissioner (OAIC), the Act applies to Australian Government agencies, organisations with an annual turnover of more than $3 million, and certain other organisations regardless of turnover (including health service providers, those trading in personal information, and organisations related to entities covered by the Act).

For content teams, the Privacy Act creates specific obligations around how personal information appears in published content, how privacy policies and collection notices are drafted, and how data practices are communicated to customers. With the Australian Government progressing significant Privacy Act reforms following the Attorney-General's Privacy Act Review 2022, these obligations are expected to expand.

APPs That Affect Content

Not all 13 APPs directly affect content teams, but several have significant implications for published materials:

APPTitleContent Implication
APP 1Open and transparent managementPrivacy policy must be current, clear, and accessible
APP 5Notification of collectionCollection notices must be provided at or before the time of collection
APP 6Use or disclosureContent must not disclose personal information beyond consented purposes
APP 7Direct marketingMarketing content must comply with direct marketing rules including opt-out
APP 11SecurityContent systems must protect personal information from unauthorised access
APP 12Access to personal informationIndividuals can request access to information held about them
APP 13CorrectionIndividuals can request correction of inaccurate information

Privacy Policy Content Requirements

Under APP 1, organisations must have a clearly expressed and up-to-date privacy policy. The OAIC expects privacy policies to contain specific information:

Required elements:

  • The kinds of personal information collected and held
  • How personal information is collected and held
  • The purposes for which personal information is collected, held, used, and disclosed
  • How an individual may access their personal information and seek correction
  • How an individual may complain about a breach and how the complaint will be dealt with
  • Whether the organisation is likely to disclose personal information to overseas recipients, and if so, the countries where they are located

Quality standards:

  • Written in plain language understandable by the target audience
  • Available free of charge and easily accessible (prominently linked on website)
  • Current and reflecting actual data practices
  • Not excessively long or legalistic to the point of being inaccessible

Common Privacy Policy Failures

The OAIC has identified recurring issues in privacy policies:

  • Overly broad language that does not meaningfully inform individuals about data practices
  • Outdated policies that do not reflect current collection and use practices
  • Missing elements such as overseas disclosure information or complaint processes
  • Inaccessible language written in legal jargon rather than plain English
  • Buried location requiring multiple clicks to find on a website

Collection Notices

APP 5 requires organisations to notify individuals of certain matters at or before the time of collection. Collection notices must include:

  • The identity and contact details of the organisation
  • The purposes of collection
  • Whether collection is required or authorised by law
  • The consequences of not collecting the personal information
  • The organisation's usual disclosures of that kind of information
  • Information about the privacy policy including how to access it
  • Whether the information will be disclosed overseas and, if practical, the countries

Collection notices appear across multiple content types: website forms, app onboarding screens, email sign-up forms, survey introductions, event registration pages, and customer account creation flows. Each must meet APP 5 requirements.

Personal Information in Published Content

Content teams must be vigilant about personal information appearing in published materials:

Case studies and testimonials:

  • Obtain explicit consent before using personal information in case studies
  • Consent should be specific to the content type and publication channel
  • Individuals should have the opportunity to review content before publication
  • De-identification should be used where full identification is unnecessary

User-generated content:

  • Moderate user-generated content for inadvertent disclosure of third-party personal information
  • Have clear terms about personal information in user submissions
  • Respond promptly to requests to remove personal information from published content

Employee and team content:

  • Staff profiles, team pages, and "about us" content use personal information
  • Ensure employees understand and consent to the use of their personal information
  • Update or remove content promptly when employees leave

Data in reports and marketing:

  • Aggregated data used in marketing materials must be genuinely de-identified
  • Small sample sizes can enable re-identification even with aggregate data
  • Be cautious with demographic breakdowns that could identify individuals

Direct Marketing Compliance (APP 7)

Marketing content must comply with APP 7 restrictions on direct marketing:

  • Personal information collected directly from an individual can be used for direct marketing if the individual would reasonably expect it and an opt-out mechanism is provided
  • Personal information obtained from third parties can generally only be used for direct marketing with consent or if it is impracticable to obtain consent and an opt-out is provided
  • Sensitive information can only be used for direct marketing with consent
  • Every direct marketing communication must include a simple opt-out mechanism
  • Opt-out requests must be honoured promptly

Preparing for Privacy Act Reforms

The Australian Government's proposed Privacy Act reforms include several changes with direct content implications:

  • Expanded definition of personal information to include technical data, online identifiers, and inferred information
  • New requirements for privacy policies including greater specificity about data practices
  • Strengthened consent requirements including requirements for consent to be voluntary, informed, specific, current, and unambiguous
  • New right to erasure allowing individuals to request deletion of their personal information
  • Increased penalties for privacy breaches
  • Children's privacy with additional protections for minors' personal information

Content teams should begin reviewing their content practices against these proposed reforms to prepare for compliance when they take effect.

How Content Review Tools Support Privacy Compliance

Organisations produce significant volumes of content that touches on personal information, from privacy policies and collection notices to marketing emails, case studies, and website copy. Ensuring each piece complies with the Privacy Act is an ongoing challenge that scales with content volume.

Content review platforms can check privacy policies against APP 1 requirements, verify that collection notices include all APP 5 mandatory elements, flag personal information appearing in published content without clear consent documentation, and review marketing content for APP 7 compliance. By configuring review criteria based on the APPs and uploading OAIC guidance into a knowledge base, teams can systematically review content for privacy compliance.

This provides a practical first-pass review that catches common privacy issues in content before publication. It does not replace qualified privacy law advice for complex data handling questions, but it helps content teams maintain baseline compliance across their published materials.


This article provides general information about the Privacy Act 1988 and content compliance. It is not legal or privacy advice. Always consult the OAIC for current guidance and seek qualified privacy advice for your specific situation.

privacy-actappoaicpersonal-informationdata-privacycomplianceaustralia

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required