On this page
Privacy laws
Privacy laws regulate how organisations handle personal information. They can affect information your not-for-profit collects about clients, service users, members, donors, employees, volunteers and other people.
Whether privacy legislation applies to your organisation depends on matters including:
- its annual turnover
- the activities and services it provides
- the types of information it handles
- whether it provides services under a government contract or funding agreement
- whether state or territory privacy laws apply
Not-for-profit organisations covered by the Privacy Act 1988 (Cth) must comply with the Australian Privacy Principles when handling personal information.
Organisations should also consider whether privacy obligations apply under:
- state or territory legislation
- health privacy legislation
- funding agreements
- government contracts
- service agreements
- professional or regulatory requirements
Even where privacy legislation does not apply, good privacy practices can help protect individuals, reduce the effects of data breaches and maintain community trust.
Organisations should only collect personal information they need, protect it appropriately, review whether it should still be retained and destroy or de-identify it when it is no longer required.
Privacy guide
We have published a privacy guide to help not-for-profit organisations understand Australian privacy laws and improve their privacy practices.
The guide covers:
- information protected by privacy laws
- when privacy laws apply
- Commonwealth, state and territory privacy laws
- exemptions from the Privacy Act 1988 (Cth)
- the Australian Privacy Principles
- privacy policies and collection notices
- collecting, using, disclosing and protecting personal information
- consent and direct marketing
- access to and correction of personal information
- artificial intelligence, automated decision-making and privacy
- the Notifiable Data Breaches scheme
- privacy complaints, regulatory action and penalties
The guide also explains how privacy issues can arise when organisations use artificial intelligence tools and automated decision-making systems.
More information
See the Office of the Australian Information Commissioner (OAIC) website, for guidance on privacy for not-for-profits, including charities.
Related legal issues
Confidentiality
Privacy and confidentiality are related but different legal concepts.
An obligation to keep information confidential may arise from:
- a contract or funding agreement
- the nature of the information
- the circumstances in which the information was provided
- an equitable duty of confidence
- professional or regulatory obligations
Confidential information is not limited to information about individuals. It may include commercial information, financial information, internal documents, intellectual property or information belonging to another organisation.
An organisation may have a duty to keep information confidential even if privacy legislation does not apply.
Surveillance
Commonwealth, state and territory laws regulate surveillance, recording, monitoring and the interception of communications.
These laws may apply to:
- video surveillance
- audio recording
- computer and internet monitoring
- telephone monitoring
- location and tracking technology
Different rules apply across Australia. Before using surveillance or monitoring technology, an organisation should identify the laws that apply in each relevant jurisdiction and consider workplace, privacy, notification and consent requirements.
More information
For more information, see the Office of the Australian Information Commissioner's guidance on surveillance and monitoring.
Direct marketing and research
Different laws regulate direct marketing through email, text message, telephone, fax, post, social media and online advertising.
Depending on the communication and the organisation involved, relevant laws may include:
- the Privacy Act 1988 (Cth), including Australian Privacy Principle 7
- the Spam Act 2003 (Cth)
- the Do Not Call Register Act 2006 (Cth)
- fundraising legislation and standards
Direct marketing can include fundraising communications. Organisations should identify the rules applying to each method of communication, provide any required opt-out mechanism and act on opt-out requests.
More information
For more information, see the Australian Communications and Media Authority (ACMA) and the Do Not Call Register websites.
Freedom of information
Freedom of information laws generally apply to government agencies and certain public bodies. However, a freedom of information request may affect a not-for-profit that holds information for a government agency or under a government contract.
If your organisation receives a freedom of information request, or a government agency asks it to search for or provide documents, check:
- the relevant contract or funding agreement
- which freedom of information legislation applies
- who is responsible for responding
- any confidentiality, privacy and document preservation obligations
Seek legal advice if it is unclear whether your organisation must provide information.
More information
For more information, see the the Victorian Information Commissioner’s information about freedom of information and the Office of the Australian Information Commissioner’s information about freedom of information.
Common questions about privacy laws
Does the Privacy Act apply to charities?
The Privacy Act 1988 (Cth) applies to many charities with annual turnover of more than $3 million. It can also apply to smaller charities because of the services they provide, the information they handle or their relationship with another organisation.
For example, the Privacy Act may apply to a smaller charity that:
- provides a health service and holds health information
- trades in personal information
- handles tax file number information
- provides services under an Australian Government contract, or
- is related to an organisation covered by the Privacy Act
State or territory privacy laws, contracts and funding agreements may impose additional obligations.
Charity registration does not, by itself, determine whether the Privacy Act applies. An organisation needs to consider its activities, structure, contracts and the information it handles.
For more information, see our privacy guide.
What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It can be true or untrue and recorded or unrecorded.
Examples may include:
- a person’s name, address or contact details
- client, member, donor or volunteer records
- photographs and video or audio recordings
- financial or payment information
- online identifiers and location information
- opinions about an identifiable person
Some personal information is also sensitive information. This can include information about a person’s health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record. Stricter rules generally apply to sensitive information.
Whether information identifies a person depends on its context. Information that does not identify someone on its own may do so when combined with other information.
For more information, see our privacy guide.
What are the Australian Privacy Principles?
The Australian Privacy Principles, often called the APPs, are 13 legally binding principles in the Privacy Act 1988 (Cth). They regulate how covered organisations and Australian Government agencies handle personal information.
The APPs deal with:
- open and transparent privacy practices
- anonymity and pseudonymity
- collecting solicited personal information
- unsolicited personal information
- notification when collecting personal information
- use and disclosure
- direct marketing
- overseas disclosure
- government-related identifiers
- information quality
- security, retention and destruction
- access
- correction
What an organisation must do in a particular situation depends on the relevant APP and the circumstances.
The OAIC’s Australian Privacy Principles Guidelines explain the APPs and the OAIC’s interpretation of their requirements.
For more information, see our privacy guide.
What rules apply to direct marketing?
The applicable rules depend on how your organisation communicates and whether the Privacy Act 1988 (Cth) covers it.
Australian Privacy Principle 7 restricts the use and disclosure of personal information for direct marketing. Where direct marketing is permitted, an organisation must provide a simple way to opt out and must act on an opt-out request. Additional restrictions apply to sensitive information.
The Spam Act 2003 (Cth) regulates commercial electronic messages, including many emails and text messages. The Do Not Call Register Act 2006 (Cth) and related standards regulate telemarketing and fax marketing, although exemptions can apply.
Fundraising communications can constitute direct marketing. An exemption under one law does not necessarily remove obligations under another law.
For more information, see our privacy guide.
The content on this webpage was last updated in September 2026 and is not legal advice. See full disclaimer and copyright notice.