click to skip link menu
space gif between side menu and page content sections

Information Sheet 2: National Privacy Principles (NPPs)

Summary only: not the full version of the NPPs (click here for full NPPs)

This is an old information sheet which expired on 17/9/2001 and has been superseded by the release of new information sheets 18/9/2001.


NPP 1 – Collection

Collection of personal information must be fair, lawful and not intrusive. A person must be told the organisation’s name, the purpose of collection, that the person can get access to their personal information and what happens if the person does not give the information.

Back to Top

NPP 2 – Use & Disclosure

An organisation should only use or disclose information for the purpose it was collected unless the person has consented, or the secondary purpose is related to the primary purpose and a person would reasonably expect such use or disclosure, or the use is for direct marketing in specified circumstances, or in circumstances related to public interest such as law enforcement and public or individual health and safety.

Back to Top

NPP 3 – Data Quality

An organisation must take reasonable steps to make sure that the personal information it collects, uses or discloses is accurate, complete and up-to date.

Back to Top

NPP 4 – Data Security

An organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access modification or disclosure.

Back to Top

NPP 5 – Openness

An organisation must have a policy document outlining its information handling practices and make this available to anyone who asks.

Back to Top

NPP 6 – Access & Correction

Generally speaking, an organisation must give an individual access to personal information it holds about that individual on request.

Back to Top

NPP 7 – Identifiers

Generally speaking an organisation must not adopt, use or disclose, an identifier that has been assigned by a Commonwealth government ‘agency’.

Back to Top

NPP 8 – Anonymity

Organisations must give people the option to interact anonymously whenever it is lawful and practicable to do.

Back to Top

NPP 9 – Transborder Data Flows

An organisation can only transfer personal information to a recipient in a foreign country in circumstances where the information will have appropriate protection.

Back to Top

NPP 10 – Sensitive Information

An organisation must not collect sensitive information unless the individual has consented, it is required by law – or in other special specified circumstances, for example, relating to health services provision and individual or public health or safety).

For further information please contact

Privacy Commissioner
GPO Box 5218
Sydney NSW 1042

Privacy Hotline: 1300 363 992
Telephone: (02) 9284 9800
Fax: (02) 9284 9666

E-mail: privacy@privacy.gov.au

Back to Top