Regulation and standard

What privacy training does the Privacy Act and the APPs expect?

Short answer

The Privacy Act 1988 does not set a universal training course, but the Australian Privacy Principles (APPs) require APP entities to take reasonable steps to comply, and the Office of the Australian Information Commissioner (OAIC) names regular staff training as one of those steps under APP 1 and APP 11. Australian Government agencies have an explicit duty: privacy training at induction and annually for staff who handle personal information.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
7 min
Jurisdiction
Australia (Commonwealth)
Regulator
Office of the Australian Information Commissioner (OAIC)

Key takeaways

  • APP 1.2 requires practices, procedures and systems that ensure APP compliance; OAIC guidance lists regular staff training as an example.
  • APP 11 security steps include technical and organizational measures (APP 11.3, in force since December 11, 2024), and the OAIC counts staff training as an organizational measure.
  • The Privacy (Australian Government Agencies: Governance) APP Code 2017 requires privacy training at induction and annually for agency staff with access to personal information.
  • Failure to implement privacy practices, procedures and systems is now a factor a court may weigh when deciding whether an interference with privacy is serious.
  • Automated decision making transparency obligations commence on December 10, 2026, and a second tranche of reform was released as an exposure draft in August 2026.

Who do the Privacy Act training expectations apply to?

They apply to every APP entity: Australian Government agencies and private sector organizations covered by the Privacy Act 1988 (Cth). As at September 2026, a business with annual turnover of $3 million or less is generally exempt, but the OAIC lists exceptions that are covered regardless of size, including health service providers, businesses that trade in personal information, Commonwealth contractors, and AML/CTF reporting entities.

Training duties sit in two layers. For every APP entity, training is one of the reasonable steps expected under the APPs. For agencies, a registered code turns training into a specific, auditable obligation. Organizations regulated elsewhere often face overlapping duties, for example APRA CPS 234 security awareness or AUSTRAC AML/CTF training.

What do the APPs actually require about training?

The APPs require reasonable steps, not a named course, and the OAIC's guidelines identify staff training as one of those steps. Two principles carry most of the weight.

APP 1.2 requires an entity to take reasonable steps to implement practices, procedures and systems that ensure it complies with the APPs and can deal with privacy inquiries and complaints. The OAIC's APP 1 guidelines list, as an example of those practices, "regular staff training and information bulletins on how the APPs apply to the entity, and its practices, procedures and systems developed under APP 1.2", alongside appropriate supervision of staff who regularly handle personal information.

APP 11.1 requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. The OAIC's APP 11 guidelines treat "governance, culture and training" as an area where reasonable steps are expected, and describe organizational measures as including staff training on privacy and security obligations.

What changed in December 2024

The Privacy and Other Legislation Amendment Act 2024 inserted APP 11.3, which states that reasonable security steps "include technical and organisational measures". It commenced on December 11, 2024. The OAIC's APP 11 guidelines give staff training as an example of an organizational measure, so a regulator reviewing a breach is now directed by the text of the Act to look beyond technology.

What must Australian Government agencies do?

Agencies must train staff at induction and annually. Section 16 of the Privacy (Australian Government Agencies: Governance) APP Code 2017 sets an explicit privacy training obligation for agencies.

  • Section 16(1): an agency must include appropriate privacy education or training in any staff induction program. It must address the privacy obligations of agency staff and agency policies and procedures relating to privacy.
  • Section 16(2): an agency must take reasonable steps to provide appropriate privacy education or training annually to all staff who have access to personal information in the course of their duties.
  • Section 17: an agency must regularly review and update its privacy practices, procedures and systems, which in practice includes the training itself.

Agencies also carry protective security training duties under the PSPF, so many combine privacy and security awareness in one annual cycle while keeping separate completion evidence for each obligation.

What has commenced from the 2024 reforms, and what is still coming?

Most of the Privacy and Other Legislation Amendment Act 2024 is already in force; the automated decision making provisions commence on December 10, 2026. The Act received assent on December 10, 2024, and its commencement table sets the dates below.

Privacy and Other Legislation Amendment Act 2024: commencement and training relevance, as at September 2026
ChangeCommencementWhy it matters for training
APP 11.3 technical and organizational measuresDecember 11, 2024Makes organizational controls such as training part of the statutory security standard
New civil penalty tiers and infringement notices (sections 13G, 13H, 13K)December 11, 2024A mid tier penalty of up to 2,000 penalty units applies to interferences with privacy that are not serious
Seriousness factors in section 13G(1B)December 11, 2024A court may consider whether the entity failed to implement practices, procedures and systems that contributed to the interference
Statutory tort for serious invasions of privacy (Schedule 2)By Proclamation, or at the latest 6 months after assent (June 10, 2025)Staff conduct can expose the organization to individual claims
Automated decision making disclosures in privacy policies (Schedule 1, Part 15)December 10, 2026Staff who design or run automated decisions need to know what the privacy policy must disclose

The second tranche is not law. The Attorney-General's Department opened consultation on an exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 on August 31, 2026 and closed it on September 18, 2026. Training content should not teach draft provisions as obligations until a bill passes.

What should privacy training cover to meet the reasonable steps test?

It should cover how the APPs apply to the entity's own processes, not the APPs in the abstract. The OAIC's example is training on how the APPs apply to the entity and its APP 1.2 practices, which points to role based content tied to real systems and procedures.

Human error is a recurring breach cause. The OAIC reported that human error accounted for 37% of notified data breaches (193 notifications) from January to June 2025, up from 29% in the previous period. The mapping below is an illustrative starting point for turning obligations into assessable outcomes.

Illustrative mapping: privacy obligation to learning outcome to assessment evidence
ObligationLearning outcomeAssessment evidence
APP 1.2 practices, procedures and systemsExplains where the entity's privacy policy and procedures apply to their roleScenario questions using the entity's own procedures, with recorded results
APP 3 and APP 5 collection and noticeIdentifies when collection is reasonably necessary and when a collection notice is requiredReview of a sample form or script, marked against a rubric
APP 6 use and disclosureDecides whether a proposed disclosure is permitted and escalates when unsureBranching scenario with a pass mark and retained attempt data
APP 11 security, including APP 11.3Applies handling rules for personal information, such as email addressing and access controlsKnowledge check plus sign off on handling procedures
Notifiable data breaches schemeRecognizes a suspected breach and reports it internally within the entity's timeframeIncident reporting drill with a time stamped record

The same structure works for any obligation. The method is set out in how to map training to compliance obligations, and the evidence side in how to prepare training records for an audit.

How do you evidence privacy training to the OAIC?

Keep records that show training was designed for the entity's actual risks, delivered to the right people, understood, and kept current. Completion data alone shows attendance, not the reasonable steps the APPs require.

  1. A current register linking each APP and code obligation to the training that addresses it.
  2. Role based audiences: who handles personal information, at what sensitivity, and which module applies.
  3. Assessment results, not just completions, with pass marks and remediation for those who fail.
  4. Version history showing the content was updated for the December 2024 amendments and will be updated for the December 2026 automated decision making obligations.
  5. For agencies, induction records and annual completion records that map directly to section 16 of the agency APP Code.

How does Knowledge Foundry approach this?

Knowledge Foundry records each APP and code obligation as a source, links it to defined concepts and assessment points, and keeps provenance for every training item built from it. When the Privacy Act changes, affected concepts and the content that depends on them can be identified and reviewed before the next training cycle.

Frequently asked questions

Is privacy training mandatory for private sector organizations?

No provision of the Privacy Act names a mandatory course for private sector APP entities. However, APP 1.2 and APP 11 require reasonable steps, and the OAIC's guidelines give staff training as an example of those steps. An organization that cannot show any training will find it hard to argue it took reasonable steps after a breach.

How often should staff complete privacy training?

Commonwealth agencies must provide it at induction and take reasonable steps to provide it annually to staff with access to personal information. For other APP entities the Act sets no frequency, but the OAIC refers to regular training, and annual refreshers with updates after legal or process changes are a common benchmark.

Does the statutory privacy tort change training needs?

It adds a reason to train. Since the tort commenced, individuals can sue for serious invasions of privacy involving intrusion upon seclusion or misuse of information. Training that covers access to records without a work reason, and misuse of customer information, reduces the likelihood of conduct that could found a claim.

Should training cover the proposed tranche 2 reforms?

Not as obligations. As at September 2026 the Privacy Amendment (Personal Data Protection) Bill 2026 is an exposure draft whose consultation closed on September 18, 2026. Privacy and compliance teams can brief leaders on the proposals, but staff training should teach the law in force and be revised if a bill passes.

Sources

  1. Chapter 1: APP 1 Open and transparent management of personal information, Office of the Australian Information Commissioner
  2. Chapter 11: APP 11 Security of personal information, Office of the Australian Information Commissioner
  3. Privacy (Australian Government Agencies: Governance) APP Code 2017, Office of the Australian Information Commissioner
  4. Privacy and Other Legislation Amendment Act 2024, Federal Register of Legislation
  5. Privacy Reform: Consultation on Exposure Draft legislation, Attorney-General's Department
  6. Latest Notifiable Data Breach statistics for January to June 2025, Office of the Australian Information Commissioner
  7. Small business, Office of the Australian Information Commissioner

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.