Q: What is the focus of APP 1?
A: Open and transparent management of personal information (requires entities to have a clear privacy policy and practices to comply with the APPs).
Q: What does APP 2 provide for individuals?
A: The option of anonymity or pseudonymity when dealing with APP entities, unless impracticable or required by law.
Q: What does APP 3 regulate?
A: The collection of solicited personal information — it must be reasonably necessary for functions/activities, and sensitive information requires consent.
Q: What does APP 4 deal with?
A: Unsolicited personal information — entities must assess whether they could have collected it under APP 3, and if not, must destroy or de-identify it (if lawful and reasonable).
Q: What is required under APP 5?
A: Notification of collection — entities must inform individuals about collection details such as purpose, consequences, and possible overseas disclosure.
Q: What is the main rule in APP 6?
A: Use or disclosure of personal information must be only for the primary purpose unless consent is given or an exception applies.
Q: What does APP 7 cover?
Q: What does APP 8 regulate?
A: Cross-border disclosure — entities must ensure overseas recipients handle personal information in line with the APPs before disclosure.
Q: What does APP 9 restrict?
A: Adoption, use or disclosure of government-related identifiers — only allowed in limited circumstances.
Q: What is the requirement of APP 10?
A: Quality of personal information — entities must take reasonable steps to ensure collected, used, or disclosed information is accurate, up to date, complete, and relevant.
Q: What is required under APP 11?
A: Security of personal information — entities must protect it from misuse, interference, loss, and unauthorised access, and destroy/de-identify it when no longer needed.
Q: What rights are given under APP 12?
A: Access to personal information — individuals can request access to their personal information, which must generally be granted unless an exception applies.
Q: What does APP 13 require?
A: Correction of personal information — entities must correct inaccurate, out-of-date, incomplete, irrelevant, or misleading information, or attach a statement if correction is refused.