Australian Privacy Access Requests (APP 12): How to Respond

How to respond to an Australian Privacy Act access request under APP 12: timeframes, when you can charge a fee, the limited grounds for refusal, and a practical step-by-step process for small businesses.

Last updated: 2026-06-22

Under the Australian Privacy Act, people have the right to ask what personal information you hold about them — and you have to respond. This is Australian Privacy Principle 12 (APP 12), Australia's version of a data subject access request (DSAR). This guide explains exactly what is required and how to handle a request without tripping over the deadline.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Consult a qualified lawyer or privacy professional for guidance specific to your situation. Information is current as of the date below and is based on APP 12 and OAIC guidance.

Who Can Make a Request, and Who Must Respond

Any individual can ask an APP entity for access to the personal information it holds about them. If your business is covered by the Privacy Act — because you exceed $3 million in turnover or fall under an exception (see the small business exemption guide) — you must respond. Note that information about current and former employees may fall under the separate employee records exemption.

The Timeframe

This is the detail that catches businesses out, so be precise:

  • Agencies (government bodies) must respond within 30 calendar days.
  • Organisations (private-sector businesses) must respond within a "reasonable period." The OAIC's guidance states this should not exceed 30 calendar days.

In practice, treat 30 days as your working deadline regardless of which you are. Acknowledge the request promptly, and if it is genuinely complex, document why and keep the person informed.

Giving Access

  • Manner of access: Give access in the way the person asks (for example, an electronic copy) if it is reasonable and practicable to do so.
  • Fees: You must not charge a person for making a request. An organisation may charge a reasonable fee for giving access — but it must not be excessive and must not apply to the request itself. Agencies cannot charge for access.
  • Verify identity first: Make sure you are dealing with the right person (or an authorised representative) before releasing anything — but don't demand more identification than you reasonably need.

When You Can Refuse

You can refuse access only in limited circumstances. For organisations, APP 12 sets out grounds including where:

  • Giving access would pose a serious threat to the life, health, or safety of any individual, or to public health or safety;
  • Access would have an unreasonable impact on the privacy of other individuals;
  • The request is frivolous or vexatious;
  • The information relates to existing or anticipated legal proceedings and would not be accessible through discovery;
  • Giving access would reveal commercially sensitive evaluative information; or
  • Access would be unlawful, or denying it is required or authorised by law.

If you refuse — wholly or partly — you must give the person a written notice setting out the reasons (except where it would be unreasonable to do so) and the mechanisms available to complain. Where you can't give access to specific information, consider whether giving access through a mutually agreed intermediary would meet the need.

Access vs Correction

APP 12 is about access. If, having seen their information, a person believes it is inaccurate, out of date, incomplete, irrelevant, or misleading, they can ask you to fix it under APP 13 (correction). Treat the two as a pair: a well-run access process usually leads straight into a correction request, so be ready for both.

A Step-by-Step Process

  1. Log the request and the date received — your clock starts now.
  2. Verify identity proportionately.
  3. Search across everywhere personal information lives: email, your CRM, accounting software, SharePoint or Google Drive, file servers, and backups.
  4. Review for third-party information and any grounds for refusal.
  5. Respond within 30 days — provide the information in the requested format, or give written reasons for any refusal.
  6. Be ready for a correction request under APP 13.

Step 3 is where most of the time goes. A current data inventory — knowing in advance where personal information lives — is what turns a stressful scramble into a routine task.

If You Operate Across Borders

If you also serve customers in the UK, EU, Canada, or New Zealand, you face equivalent access rights with no small business exemption and varying deadlines (one month under the GDPR; 20 working days in New Zealand; 30 days under PIPEDA). Running one unified workflow is far easier than a separate process per law — see multi-jurisdiction privacy compliance and our DSAR Compliance Guide.

References

Last reviewed: June 2026. Verify all statutory references against the current text of the Act and consult qualified legal counsel before making compliance decisions for your business.


One Process for Every Access Request

Whether a request arrives under APP 12, the GDPR, or PIPEDA, the hard part is the same: finding the data and responding on time. Our DSAR Compliance Guide gives you one reliable workflow across every jurisdiction you serve.