Privacy Act 1988 (Australia)
Australian Privacy Act including the Australian Privacy Principles
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Awareness
| Code | Title |
|---|---|
| AU-PA-17 | Training and Awareness |
Data Collection
| Code | Title |
|---|---|
| AU-PA-03 | Collection of Solicited Personal Information (APP 3) |
Data Lifecycle
| Code | Title |
|---|---|
| AU-PA-04 | Dealing with Unsolicited Personal Information (APP 4) |
Data Quality
| Code | Title |
|---|---|
| AU-PA-10 | Quality of Personal Information (APP 10) |
Data Subject Rights
| Code | Title |
|---|---|
| AU-PA-02 | Anonymity and Pseudonymity (APP 2) |
| AU-PA-05 | Notification of the Collection of Personal Information (APP 5) |
| AU-PA-12 | Access to Personal Information (APP 12) |
| AU-PA-13 | Correction of Personal Information (APP 13) |
Data Transfers
| Code | Title |
|---|---|
| AU-PA-08 | Cross-Border Disclosure of Personal Information (APP 8) |
Data Use
| Code | Title |
|---|---|
| AU-PA-06 | Use or Disclosure of Personal Information (APP 6) |
Governance
| Code | Title |
|---|---|
| AU-PA-01 | Open and Transparent Management of Personal Information (APP 1) |
| AU-PA-19 | Accountability and Privacy Management Framework |
Incident Management
| Code | Title |
|---|---|
| AU-PA-14 | Notifiable Data Breaches (NDB) Scheme |
Information Security
| Code | Title |
|---|---|
| AU-PA-11 | Security of Personal Information (APP 11) |
Marketing
| Code | Title |
|---|---|
| AU-PA-07 | Direct Marketing (APP 7) |
Privacy Act 1988 (Australia): Accountability & Compliance
Demonstration of compliance and accountability (Privacy Act 1988 (Australia))
| Code | Title |
|---|---|
| APA-25 | Compliance monitoring and auditing |
| APA-26 | Training and awareness programs |
| APA-27 | Regulatory reporting and cooperation |
| APA-28 | Complaints handling and resolution |
| APA-29 | Enforcement and penalties awareness |
Privacy Act 1988 (Australia): Data Collection & Consent
Requirements for lawful collection and consent management (Privacy Act 1988 (Australia))
| Code | Title |
|---|---|
| APA-01 | Notice and transparency requirements |
| APA-02 | Consent management and withdrawal |
| APA-03 | Lawful basis for processing |
| APA-04 | Purpose limitation and specification |
| APA-05 | Data minimization requirements |
Privacy Act 1988 (Australia): Data Governance
Organizational governance of personal data processing (Privacy Act 1988 (Australia))
| Code | Title |
|---|---|
| APA-19 | Data protection officer designation |
| APA-20 | Records of processing activities |
| APA-21 | Data protection impact assessments |
| APA-22 | Privacy by design and default |
| APA-23 | Data processing agreements |
| APA-24 | Cross-border transfer safeguards |
Privacy Act 1988 (Australia): Data Security
Technical and organizational security measures (Privacy Act 1988 (Australia))
| Code | Title |
|---|---|
| APA-13 | Encryption of personal data |
| APA-14 | Pseudonymization techniques |
| APA-15 | Access control for personal data |
| APA-16 | Data breach notification requirements |
| APA-17 | Security incident response procedures |
| APA-18 | Regular security testing and assessment |
Privacy Act 1988 (Australia): Data Subject Rights
Individual rights regarding their personal data (Privacy Act 1988 (Australia))
| Code | Title |
|---|---|
| APA-06 | Right of access to personal data |
| APA-07 | Right to rectification of inaccurate data |
| APA-08 | Right to erasure and deletion |
| APA-09 | Right to data portability |
| APA-10 | Right to restrict processing |
| APA-11 | Right to object to processing |
| APA-12 | Automated decision-making protections |
Risk Management
| Code | Title |
|---|---|
| AU-PA-16 | Privacy Impact Assessment (PIA) |
Special Categories
| Code | Title |
|---|---|
| AU-PA-09 | Adoption, Use, or Disclosure of Government Related Identifiers (APP 9) |
| AU-PA-15 | Sensitive Information Handling |
Third Party Management
| Code | Title |
|---|---|
| AU-PA-18 | Vendor and Outsourcing Management |
Your Compliance Coverage
If you comply with Privacy Act 1988 (Australia), you already cover:
Norway PDPA
25%
12 controls mapped
Compare →Jamaica DPA
25%
12 controls mapped
Compare →CCPA/CPRA
25%
12 controls mapped
Compare →+ 606 more: Virginia CDPA (25%), Peru DPL (25%)
See all 609 mapped frameworks ↓Maps to 609 other frameworks
Frequently Asked Questions
What is Privacy Act 1988 (Australia)?
Privacy Act 1988 (Australia) is a compliance framework from Australia with 19 domains and 48 controls. Australian Privacy Act including the Australian Privacy Principles It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Privacy Act 1988 (Australia) have?
Privacy Act 1988 (Australia) has 48 controls organised across 19 domains. The largest domains are Privacy Act 1988 (Australia): Data Subject Rights (7 controls), Privacy Act 1988 (Australia): Data Governance (6 controls), Privacy Act 1988 (Australia): Data Security (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Privacy Act 1988 (Australia) map to?
Privacy Act 1988 (Australia) maps to 609 other compliance frameworks. The top mapping partners are Norway PDPA (25% coverage), Jamaica DPA (25% coverage), CCPA/CPRA (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Privacy Act 1988 (Australia) compliance?
Start your Privacy Act 1988 (Australia) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Privacy Act 1988 (Australia) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required