1. Entities should handle personal information openly and honestly. This includes a policy that describes how your personal information is managed.
2. Individuals should be allowed to remain anonymous if they so desire, and use pseudonyms for personal data when possible.
3. Organisations must demonstrate that it needs personal data for its functions or activities.
4. Organisations must prove that if personal information is solicited it could be collected according to Principle 3.
5. An entity collecting personal information should notify the individual from whom the data is collected.
6. Entities should only use personal data that is relevant to the original purpose for which the information was collected. If the individual explicitly allows use of their data for another purpose, or if the entity could reasonably expect such use, they may collect other data.
7. Organisations may not use private information for marketing unless individuals can reasonably expect such use of their information or individuals have provided their consent and have a clear way to opt out.
8. When an entity shares personal data with someone outside Australia, the recipient must comply with the Australian Privacy Principles via contractual obligation. This is unless the entity sharing the data believes the recipient maintains a similar privacy regulation to the APP in their location, or the individual consented to sharing of their data with overseas parties and understands the entity does not take responsibility over the privacy practices of the recipient.
9. An entity may not use a government-related identifier as their own, or disclose an identifier of a person, unless the entity is authorised to do so by laws, or the identifier is needed to verify the identity of the individual.
10. All information received by the entity must be accurate, complete and up to date, and the organisation may only disclose and use information if it verifies this.
11. Entities are required to implement measures specifically designed for the protection of stored personal information from data interference, loss, misuse and modification, as well as unauthorised access and disclosure.
12. Entities must give the individual access to their personal information on request.
13. Entities must collect accurate and complete information, update personal information, collect only relevant, non-misleading information, notify affected entities when any corrections are made while collecting personal data.