
Thirteen rules, one $3 million line. Most tradies are on the exempt side — with exceptions.
The Australian Privacy Principles (APPs) are 13 rules in the Privacy Act 1988 governing how organisations collect, store, use, disclose and correct personal information. Most businesses with annual turnover of $3 million or less are exempt — but not health providers, not anyone trading in personal information, and not you if a client’s contract requires compliance.
The thirteen principles, in one list
The APPs sit in Schedule 1 of the Privacy Act 1988 and apply to “APP entities” — Australian Government agencies and the organisations the Act covers. The OAIC quick reference lists them as follows.
- KNDR·01APP 1 — Open and transparent managementHave a clear, current privacy policy and the practices to back it.
- KNDR·02APP 2 — Anonymity and pseudonymityLet people deal with you anonymously where that is practicable.
- KNDR·03APP 3 — Collection of solicited personal informationCollect only what is reasonably necessary, by lawful and fair means.
- KNDR·04APP 4 — Dealing with unsolicited personal informationIf you receive information you did not ask for, decide whether you could have collected it; if not, destroy or de-identify it.
- KNDR·05APP 5 — Notification of collectionTell people what you are collecting, why, and who you share it with.
- KNDR·06APP 6 — Use or disclosureUse information for the purpose you collected it, or a related purpose people would expect.
- KNDR·07APP 7 — Direct marketingMarketing to individuals has its own rules, including a simple way to opt out.
- KNDR·08APP 8 — Cross-border disclosureSending personal information overseas — including to a US-hosted SaaS product — carries obligations.
- KNDR·09APP 9 — Government related identifiersDo not adopt a Medicare or licence number as your own customer ID.
- KNDR·10APP 10 — QualityKeep information accurate, up to date and complete.
- KNDR·11APP 11 — SecurityProtect it from misuse, interference, loss and unauthorised access, and destroy it when no longer needed.
- KNDR·12APP 12 — AccessGive people access to their own information on request.
- KNDR·13APP 13 — CorrectionCorrect it when it is wrong.
Who is exempt, and who is not
Most small businesses are exempt, and most tradies are among them. The OAIC small business guidance (updated 5 September 2024) defines a small business as one with annual turnover of $3 million or less, and the Act does not cover such businesses unless an exception applies. Since ASBFEO counts 92% of small businesses as turning over under $2 million (ASBFEO, August 2025), the exemption covers the large majority of Australian businesses.
The exceptions are the part to read. Regardless of turnover, the Act applies to health service providers, businesses that trade in personal information, contracted service providers under a Commonwealth contract, credit reporting bodies, residential tenancy database operators, reporting entities under the AML/CTF Act, and any business that opts in (same OAIC page). An NDIS provider or an allied-health clinic is covered at any size. So is a cleaning contractor with a Commonwealth contract.
The AML/CTF exception widened on 1 July 2026, when tranche 2 of that regime brought real estate agents, lawyers, conveyancers and accountants into scope — over 100,000 businesses that become Privacy Act entities when handling that data, whatever their turnover (Biztech Lawyers, 20 May 2026). And exempt or not, 77% of Australians think small businesses should have to protect personal information the same way as larger ones (OAIC Australian Community Attitudes to Privacy Survey, August 2023).
What changed in December 2024, and what is still coming
The first tranche of reform is law. The Privacy and Other Legislation Amendment Act 2024 received royal assent on 10 December 2024; a statutory tort for serious invasions of privacy commenced on 10 June 2025; and from 10 December 2026 privacy policies must disclose automated decision-making that significantly affects people, with a Children’s Online Privacy Code due by the same date (MinterEllison; OAIC).
Penalties now have three tiers. Serious interference: the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. Non-serious interference: up to $3.3 million per contravention. Administrative breaches: infringement notices of up to $330,000 (Clyde & Co, 25 November 2024).
The second tranche is on the table now. The government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August 2026, with around 40 proposals including a “fair and reasonable” test for collection and use, a 72-hour data breach notification window, and a right to erasure limited to platforms with $500 million in revenue or 2.5 million monthly users (Clayton Utz, 2 September 2026). Consultation closes 18 September 2026. The small business exemption is not repealed in the draft (Colin Biggers & Paisley, 1 September 2026). That could change before a bill passes; check the date on anything you read about it, including this.
The breach numbers
Breaches are at a record. The OAIC received 1,205 data breach notifications in calendar 2025, up 8% from 1,112 in 2024 and the highest annual total since the scheme began; 59% (716) were from malicious or criminal attacks (OAIC, 6 July 2026). Health service providers reported the most at 225 (19%), then financial services at 157 and the Australian Government at 118.
Those are only the notifications from entities the Act covers. Exempt small businesses do not have to notify, so the count under the $3 million line is unknown. The ABS found 21% of all businesses experienced a cyber security incident in 2024–25 (ABS Characteristics of Australian Business 2024–25, 25 June 2026), which suggests the unreported figure is not small.
Customers feel it. In the OAIC Australian Community Attitudes to Privacy Survey (August 2023), 47% of Australians said an organisation had told them their data was in a breach in the previous twelve months, 47% said they would close an account or stop using a service after a breach, and 62% called protecting their personal information a major concern in their life.
Where the APPs bite in a small business’s software
APP 11, security, is where most small businesses would fail an assessment, and it is a software question as much as a policy one. A shared inbox with ten years of quotes, a spreadsheet of tenant details on an unencrypted laptop: each is personal information held, and each needs reasonable steps to protect it and a plan to destroy it.
APP 8, cross-border disclosure, catches almost every SaaS product you run. If the vendor hosts in the United States, you are disclosing overseas, and the Act asks you to take reasonable steps to ensure the recipient handles the information consistently with the APPs. Read the hosting region in the vendor’s terms before you sign, and keep the answer — customer intake is the point where this decision usually gets made without anyone noticing.
And AI tools are personal-information processors. The OAIC guidance on commercially available AI products (21 October 2024) recommends not entering personal information, particularly sensitive information, into publicly available generative AI tools, and 96% of Australians want conditions such as human review before AI makes decisions about them (OAIC Australian Community Attitudes to Privacy Survey, August 2023). What an AI agent is covers what that means for an agent reading your inbox, and compliance documents covers generating the records that show you did it properly.
What we do and do not claim
Kindra AI has not been independently assessed against the Australian Privacy Principles, so we do not describe our builds as “APP compliant.” That phrase means something specific — an assessment by someone qualified — and using it loosely is how a website earns a complaint.
What we can say is narrower and checkable. The systems we build hold the least personal information they need to do the job, log who accessed what, store credentials outside the code, and can be switched off by you. Where a build sends data overseas — through a US-hosted API, say — we say so in the documentation. Ownership and security sets out the practice; how we work sets out where in a build those decisions get made.
If you are a covered entity — an NDIS provider, a clinic, a Commonwealth contractor — get a privacy professional to assess the whole system, including the parts we did not build. We will hand them the documentation.
The questions people actually ask.
01My turnover is under $3 million. Can I ignore all of this?
Legally, mostly, unless one of the exceptions applies — health services, trading in personal information, a Commonwealth contract, AML/CTF reporting. Practically, no: your covered clients will ask, 77% of the public already expects it of you (OAIC survey, August 2023), and a breach costs you customers whether or not it costs you a penalty. The cheap version — a true one-page policy, a rule about who sees records, a checked hosting region, a habit of deleting — is worth doing exempt or not.
02Is my Xero or ServiceM8 data “overseas disclosure”?
It depends where the vendor hosts, which is in their terms. If the servers are outside Australia, APP 8 treats it as a cross-border disclosure and asks you to take reasonable steps about how the recipient handles it. Reading the hosting clause and keeping a note of it is most of that step for a small business.
03Will the small business exemption be removed?
Not in the exposure draft released 31 August 2026 — it does not repeal the exemption, according to the law firms that have read it. It has been proposed before and could return before a bill passes. Anything you read on this, including this page, should carry a date, and you should check the OAIC for the current position.

Stop bending.
Start shipping.
Bring the one flow that keeps costing you a Tuesday afternoon. We map it live and tell you what we'd build, what we wouldn't, and what it costs.