Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches
Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs 1–13) + Notifiable Data Breaches scheme (Part IIIC)
- Requirements
- 24
- Last reviewed
- 15/04/2026
- Next review
- 15/04/2027
- Source
- Privacy Act 1988 current compilation (includes Privacy Act 1988 and Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 reforms; Privacy and Other Legislation Amendment Act 2024 first tranche)
Reconciliation notes
Curated build capturing the 13 Australian Privacy Principles (Schedule 1) plus Part IIIC Notifiable Data Breaches scheme. Westlink is an APP entity (turnover >$3M threshold). Scope notes: (1) Credit reporting (Part IIIA) is Not Applicable — Westlink is not a credit provider. (2) Tax File Number Rule is Applicable for payroll/HR records. (3) Privacy reforms pending: the Privacy and Other Legislation Amendment Act 2024 introduced the first tranche of reforms (statutory tort for serious invasions of privacy from 10 June 2025; children's privacy code; enhanced OAIC enforcement); further tranches expected 2026–27 (direct right of action, fair and reasonable test) — row PRV-REFORM-01 tracks as Reference-only. Total requirements: 24. Applicable: 23. Reference-only: 1. Coverage on Applicable rows: Full=1, Partial=14, Gap=8. Gap severities: Critical=2, High=6, Medium=0, Low=0. Evidence mapping is richer than HVNL because GOV-POL-015 Privacy Policy (Rev 3) exists and is APP-structured; main gaps are operational (Privacy Impact Assessments, breach-response operating procedure, APP 8 overseas disclosure register, APP 5 collection notices at customer/supplier onboarding).
Requirements
Showing 24 of 24 requirements
| ID | Clause | Requirement | Applicability | Coverage | Evidence | Gap |
|---|---|---|---|---|---|---|
| PRV-APP1-01 | APP 1.2 | An APP entity must take such steps as are reasonable in the circumstances to implement practices, procedures and systems relating to the entity's functions or activities that will ensure the entity complies with the APPs and enable the entity to deal with inquiries and complaints. | Applicable | Partial |
| High Policy-level commitment present; supporting operating procedures (PIA process, training records, periodic audit) not documented. Consider a Privacy Management Plan as the OAIC recommends for APP 1.2. |
| PRV-APP1-02 | APP 1.3 | An APP entity must have a clearly expressed and up-to-date APP privacy policy about the management of personal information by the entity. | Applicable | Full |
| |
| PRV-APP1-03 | APP 1.4 | The APP privacy policy must contain the kinds of personal information the entity collects and holds; how and from where it is collected; the purposes of collection, holding, use and disclosure; how individuals may access and correct personal information; how they may complain and how the entity will deal with the complaint; whether the entity is likely to disclose personal information to overseas recipients and if so, the countries. | Applicable | Partial |
| High Verify APP 1.4(f) specifics — policy must name the countries (or specify if not practicable) to which personal information is likely to be disclosed. Given international freight + chartered vessels, overseas recipients likely include foreign shipping agents, customs brokers, port agents. Audit the policy text against actual cross-border data flows. |
| PRV-APP2-01 | APP 2 | Individuals must have the option of not identifying themselves, or of using a pseudonym, when dealing with the entity in relation to a particular matter, unless it is impracticable or the entity is required by law to deal with identified individuals. | Applicable | Gap | — | Medium For most Westlink interactions (customers, suppliers, employees) anonymity is impracticable. Add explicit APP 2 position statement — e.g. "anonymous/pseudonymous dealing offered for general inquiries via website contact form; identified dealing required for service delivery, contracting, employment, DISP-compliant transactions." |
| PRV-APP3-01 | APP 3.1 / 3.2 | An APP entity must not collect personal information unless the information is reasonably necessary for, or directly related to, one or more of the entity's functions or activities. | Applicable | Full |
| |
| PRV-APP3-02 | APP 3.5 | An APP entity must collect personal information only by lawful and fair means. | Applicable | Gap | — | Medium APP 3.5 (lawful and fair means of collection) not addressed; GOV-POL-015 covers APP 3.1/3.2 and the collection notice only. |
| PRV-APP4-01 | APP 4 | Where an APP entity receives unsolicited personal information, the entity must determine within a reasonable period whether the information could have been collected under APP 3. If not, the entity must destroy or de-identify the information as soon as practicable (if lawful and reasonable). | Applicable | Gap | — | Medium No documented unsolicited-information handling process. Practical exposure: unsolicited job applications, third-party referrals, incidental information received during tenders. Add procedural hook in GOV-POL-015 / a supporting procedure. |
| PRV-APP5-01 | APP 5 | At or before the time (or as soon as practicable after) the entity collects personal information about an individual, it must take reasonable steps to notify the individual of matters listed in APP 5.2 — including identity of entity, purposes of collection, consequences of not providing information, usual disclosures, link to APP privacy policy, overseas disclosures. | Applicable | Partial |
| High Audit collection notices: (a) employment application forms, (b) customer onboarding forms, (c) supplier onboarding forms, (d) website contact forms. Each should contain an APP 5 collection statement. High-risk gap because operational notices often omit APP 5.2(i) overseas disclosure and APP 5.2(j) privacy-policy link. |
| PRV-APP6-01 | APP 6 | An APP entity that holds personal information collected for a particular purpose (the primary purpose) must not use or disclose the information for another purpose (a secondary purpose) unless consent is obtained, the individual would reasonably expect use/disclosure for the secondary purpose and it is related (or directly related for sensitive information) to the primary purpose, or another APP 6.2/6.3 exception applies. | Applicable | Full |
| |
| PRV-APP7-01 | APP 7 | An organisation must not use or disclose personal information for direct marketing unless an exception applies (consent, reasonable expectation, simple opt-out provided). Spam Act 2003 and Do Not Call Register Act 2006 provide parallel electronic/telemarketing restrictions. | Applicable | Full |
| |
| PRV-APP8-01 | APP 8.1 | Before an APP entity discloses personal information about an individual to an overseas recipient, the entity must take such steps as are reasonable to ensure that the overseas recipient does not breach the APPs in relation to the information. Accountability for overseas breaches under s.16C applies unless an exception at APP 8.2 applies. | Applicable | Full |
| |
| PRV-APP8-02 | APP 8.2 | APP 8.1 does not apply if the entity reasonably believes the recipient is subject to a law/binding scheme substantially similar to the APPs, the individual consents after being informed APP 8.1 will not apply, or another exception (required by law, enforcement body) applies. | Applicable | Full |
| |
| PRV-APP9-01 | APP 9 | An organisation must not adopt a government-related identifier (e.g. TFN, Medicare number, driver's licence number) as its own identifier of an individual, and must not use or disclose such identifiers except in limited circumstances. | Applicable | Gap | — | Medium TFN collection is governed by the TFN Rule (Privacy (Tax File Number) Rule 2015) in addition to APP 9 — ensure payroll processes comply (notice, secure storage, restricted use). Confirm Westlink does not use TFN or driver's licence as internal identifier. |
| PRV-APP10-01 | APP 10 | An APP entity must take reasonable steps to ensure the personal information it collects is accurate, up-to-date and complete; and that personal information it uses or discloses is accurate, up-to-date, complete and relevant. | Applicable | Partial |
| Medium Align with GOV-SCH-001 Document Retention Schedule — ensure retention decisions factor data quality (destroy/correct stale data). Consider periodic employee-record verification and customer/supplier contact verification as minimum quality controls. |
| PRV-APP11-01 | APP 11.1 | An APP entity must take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. | Applicable | Full |
| |
| PRV-APP11-02 | APP 11.2 | Where an APP entity holds personal information that is no longer needed for any purpose for which it may be used or disclosed, the entity must take reasonable steps to destroy or de-identify the information (unless the information is required to be retained by law or a court/tribunal order). | Applicable | Full |
| |
| PRV-APP11-03 | APP 11 / OAIC Guide | Reasonable steps to protect personal information should be proportionate to risk and include: governance, information-security risk assessment, access controls, physical security, ICT security, data breach response plan, training, workplace policies, third-party arrangements, ICT system design. | Applicable | Partial |
| High Data breach response plan (distinct from generic incident response) not documented as a standalone operational procedure. See PRV-NDB-01..03 for NDB-specific gaps. |
| PRV-APP12-01 | APP 12 | On request from an individual, an APP entity must give the individual access to personal information about them that is held by the entity, unless a specified exception applies. Entity must respond within a reasonable period (30 days as OAIC benchmark) and at no or minimal charge. | Applicable | Partial |
| High Add an access-request handling procedure (template request form + workflow) as an operational annex to GOV-POL-015. Low inherent volume expected; but the process must exist before an OAIC complaint. |
| PRV-APP13-01 | APP 13 | An APP entity must take reasonable steps to correct personal information if the entity is satisfied the information is inaccurate, out of date, incomplete, irrelevant or misleading; or an individual requests correction. Must respond within a reasonable period and notify downstream recipients where practicable. | Applicable | Partial |
| Medium Correction process doubles with access-request procedure (PRV-APP12-01). |
| PRV-NDB-01 | s.26WE — eligible data breach | Where there is unauthorised access to, or unauthorised disclosure of, personal information (or loss of personal information in circumstances where such access/disclosure is likely), and a reasonable person would conclude the access/disclosure would be likely to result in serious harm to any individual to whom the information relates, the entity must assess whether the breach is an eligible data breach. | Applicable | Full |
| |
| PRV-NDB-02 | s.26WH, s.26WK, s.26WL — assessment, statement and notification | Where an entity has reasonable grounds to believe an eligible data breach has occurred, it must as soon as practicable prepare a statement and give a copy to the Commissioner (OAIC) and notify affected individuals; if an entity suspects but does not have reasonable grounds to believe, it must carry out a reasonable and expeditious assessment within 30 days. | Applicable | Full |
| |
| PRV-NDB-03 | s.26WK(3), OAIC guidance — data breach response plan | Entities should maintain a data breach response plan setting out roles, response team, containment/assessment/notification/review phases, and integration with IT incident response, business continuity and communications plans. | Applicable | Full |
| |
| PRV-TFN-01 | Privacy (Tax File Number) Rule 2015 | Where an entity collects a Tax File Number, it must only use or disclose the TFN for a lawful purpose and securely destroy it when no longer required. TFN collection is voluntary unless authorised by taxation, assistance agency or superannuation law. | Applicable | Gap | — | Medium Verify payroll system and HR records apply TFN-specific controls (restricted access, secure destruction, separation from non-tax-purpose identifiers). |
| PRV-REFORM-01 | Privacy and Other Legislation Amendment Act 2024 + pending tranches | First-tranche reforms commenced 10 June 2025 (statutory tort for serious invasions of privacy; enhanced enforcement; children's privacy code in development). Further tranches expected 2026–27 including direct right of action against APP entities and a "fair and reasonable" test for handling personal information. | Reference only | Referenced-only |
| Track for incorporation at next review cycle. When the fair and reasonable test commences, expect significant uplift needed across collection, use/disclosure, and overseas-disclosure practices. |
Source document
Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs 1–13) + Notifiable Data Breaches scheme (Part IIIC)
24 normative shall-statements extracted from Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches (source: Privacy Act 1988 (Cth) — Schedule 1 (APPs) + Part IIIC (NDB)). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.
Coverage summary
| Coverage | Count |
|---|---|
| ✅ Full | 11 |
| 🟡 Partial | 7 |
| 🟠 Ref-only | 1 |
| 🔴 Gap | 5 |
| — N/A | 0 |
Gap severity distribution
| Severity | Count |
|---|---|
| 🔴 Critical | 0 |
| 🟠 High | 5 |
| 🟡 Medium | 7 |
| 🟢 Low | 0 |
Requirements
Clause APP 1
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP1-01 | 🟡 Partial | [GOV-POL-015 §Purpose / Policy Commitments](/wms/GOV-POL-015#sPurpose / Policy Commitments) | 🟠 High | Policy-level commitment present; supporting operating procedures (PIA process, training records, periodic audit) not documented. Consider a Privacy Management Plan as the OAIC recommends for APP 1.2. |
| PRV-APP1-02 | ✅ Full | [GOV-POL-015 §whole document](/wms/GOV-POL-015#swhole document) | ||
| PRV-APP1-03 | 🟡 Partial | [GOV-POL-015 §Organisational Context](/wms/GOV-POL-015#sOrganisational Context) | 🟠 High | Verify APP 1.4(f) specifics — policy must name the countries (or specify if not practicable) to which personal information is likely to be disclosed. Given international freight + chartered vessels, overseas recipients likely include foreign shipping agents, customs brokers, port agents. Audit the policy text against actual cross-border data flows. |
Clause APP 10
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP10-01 | 🟡 Partial | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) | 🟡 Medium | Align with GOV-SCH-001 Document Retention Schedule — ensure retention decisions factor data quality (destroy/correct stale data). Consider periodic employee-record verification and customer/supplier contact verification as minimum quality controls. |
Clause APP 11
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP11-01 | ✅ Full | TEC-POL-001 TEC-POL-002 [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) [GOV-POL-016 §Policy Commitments](/wms/GOV-POL-016#sPolicy Commitments) | ||
| PRV-APP11-02 | ✅ Full | GOV-SCH-001 [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) |
Clause APP 11 / OAIC Guide
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP11-03 | 🟡 Partial | TEC-POL-001 [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟠 High | Data breach response plan (distinct from generic incident response) not documented as a standalone operational procedure. See PRV-NDB-01..03 for NDB-specific gaps. |
Clause APP 12
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP12-01 | 🟡 Partial | [GOV-POL-015 §Policy Commitments / Responsibilities](/wms/GOV-POL-015#sPolicy Commitments / Responsibilities) | 🟠 High | Add an access-request handling procedure (template request form + workflow) as an operational annex to GOV-POL-015. Low inherent volume expected; but the process must exist before an OAIC complaint. |
Clause APP 13
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP13-01 | 🟡 Partial | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) | 🟡 Medium | Correction process doubles with access-request procedure (PRV-APP12-01). |
Clause APP 2
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP2-01 | 🔴 Gap | — | 🟡 Medium | For most Westlink interactions (customers, suppliers, employees) anonymity is impracticable. Add explicit APP 2 position statement — e.g. “anonymous/pseudonymous dealing offered for general inquiries via website contact form; identified dealing required for service delivery, contracting, employment, DISP-compliant transactions. |
Clause APP 3
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP3-01 | ✅ Full | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) | ||
| PRV-APP3-02 | 🔴 Gap | — | 🟡 Medium | APP 3.5 (lawful and fair means of collection) not addressed; GOV-POL-015 covers APP 3.1/3.2 and the collection notice only. |
Clause APP 4
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP4-01 | 🔴 Gap | — | 🟡 Medium | No documented unsolicited-information handling process. Practical exposure: unsolicited job applications, third-party referrals, incidental information received during tenders. Add procedural hook in GOV-POL-015 / a supporting procedure. |
Clause APP 5
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP5-01 | 🟡 Partial | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) | 🟠 High | Audit collection notices: (a) employment application forms, (b) customer onboarding forms, (c) supplier onboarding forms, (d) website contact forms. Each should contain an APP 5 collection statement. High-risk gap because operational notices often omit APP 5.2(i) overseas disclosure and APP 5.2(j) privacy-policy link. |
Clause APP 6
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP6-01 | ✅ Full | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) |
Clause APP 7
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP7-01 | ✅ Full | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) |
Clause APP 8
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP8-01 | ✅ Full | [GOV-PRO-006 §‘Cross-Border Disclosure of Personal Information’](/wms/GOV-PRO-006#s’Cross-Border Disclosure of Personal Information’) | ||
| PRV-APP8-02 | ✅ Full | [GOV-PRO-006 §‘Cross-Border Disclosure of Personal Information’](/wms/GOV-PRO-006#s’Cross-Border Disclosure of Personal Information’) |
Clause APP 9
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-APP9-01 | 🔴 Gap | — | 🟡 Medium | TFN collection is governed by the TFN Rule (Privacy (Tax File Number) Rule 2015) in addition to APP 9 — ensure payroll processes comply (notice, secure storage, restricted use). Confirm Westlink does not use TFN or driver’s licence as internal identifier. |
Clause Privacy (Tax File Number) Rule 2015
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-TFN-01 | 🔴 Gap | — | 🟡 Medium | Verify payroll system and HR records apply TFN-specific controls (restricted access, secure destruction, separation from non-tax-purpose identifiers). |
Clause Privacy and Other Legislation Amendment Act 2024 + pending tranches
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-REFORM-01 | 🟠 Ref-only | [GOV-POL-015 §Organisational Context](/wms/GOV-POL-015#sOrganisational Context) | Track for incorporation at next review cycle. When the fair and reasonable test commences, expect significant uplift needed across collection, use/disclosure, and overseas-disclosure practices. |
Clause s
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| PRV-NDB-01 | ✅ Full | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) QHSE-PRO-001 [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) TEC-PRO-001 §‘Responsibilities’ [GOV-PRO-006 §‘Eligible Data Breach Assessment’](/wms/GOV-PRO-006#s’Eligible Data Breach Assessment’) | ||
| PRV-NDB-02 | ✅ Full | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) TEC-PRO-001 §‘Responsibilities’ [GOV-PRO-006 §‘Notification / NDB Statement Content’](/wms/GOV-PRO-006#s’Notification / NDB Statement Content’) | ||
| PRV-NDB-03 | ✅ Full | [GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments) [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) [GOV-PRO-006 §‘Data Breach Response Plan’](/wms/GOV-PRO-006#s’Data Breach Response Plan’) |
Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.