OAIC updates APP 3 guidance: what it means for practitioners thinking about practice closure

In May 2026, the Office of the Australian Information Commissioner released updated guidelines on Australian Privacy Principle 3 — the principle that governs when and how an entity can collect sensitive personal information, including health records.

The update is substantial. It expands existing guidance, incorporates recent determinations, and introduces clarifying changes in several areas that are directly relevant to practitioners who are planning for retirement, practice closure, or incapacity.

(Source: OAIC, May 2026)

What APP 3 governs

APP 3 deals with the collection of solicited personal information — that is, personal information an entity has actively taken steps to collect or receive. It sets out both when an entity can collect personal information and how that collection must occur.

For sensitive information — which includes health information — the requirements are more stringent than for general personal information. An entity may only collect sensitive information where the collection is reasonably necessary for its functions or activities, and either the individual consents to the collection, or a specific exception applies.

A broader understanding of what ‘collection’ means

One of the clarifications in the updated guidance concerns the definition of collection itself. The OAIC confirms that collection applies broadly — it includes gathering, acquiring or obtaining personal information from any source and by any means. In practice, all personal information held by an entity will generally be treated as information that was collected by that entity.

The guidance also confirms that an entity may collect personal information even where it receives it from another party rather than directly from the individual. Two entities can both be said to have collected the same personal information, and whether an entity with control but not direct possession has collected that information can depend on the contractual arrangements in place between them.

Collection must be reasonably necessary for the entity’s own functions

The updated guidance reinforces that an organisation may only collect personal information where it is reasonably necessary for one or more of the organisation’s own functions or activities. This is an objective test: whether a reasonable person who is properly informed would agree that the collection is necessary.

The guidance makes clear that proportionality is implicit in this requirement. Entities should adopt a data minimisation approach, limiting collection to the minimum amount necessary in the circumstances. Collection that is merely helpful, desirable, or convenient does not meet the standard.

The functions and activities of an organisation are to be determined objectively — by examining what the organisation actually does, not simply by reference to how it describes itself. An organisation’s ability to collect personal information only extends to functions or activities that are lawful.

Consent: what it actually requires

The guidance confirms that consent for collection of sensitive information requires four elements to be satisfied. The individual must be adequately informed before giving consent. The consent must be given voluntarily. The consent must be current and specific. And the individual must have the capacity to understand and communicate their consent.

The guidance is explicit that an entity cannot infer consent simply because it has provided individuals with notice of a proposed collection of personal information. Sending a notice does not satisfy the four elements of consent, because all four elements are unlikely to have been satisfied through notification alone. The guidance also notes that an entity should generally seek express consent before collecting an individual’s sensitive information, given the greater privacy impact this could have.

The role of notification

While notification does not constitute consent, the updated guidance makes clear that transparency with individuals remains important. Whether individuals are aware their personal information is being collected — including through privacy policies, collection notices, and other communications — is one of the factors relevant to whether a collection is by fair means under APP 3.5. Notification should be treated as a supporting safeguard, not as a substitute for consent or for a valid exception.

Collecting personal information from someone other than the individual

APP 3.6 provides that personal information must be collected directly from the individual, unless an exception applies. For organisations, the relevant exception is where it is unreasonable or impracticable to collect only from the individual.

Whether this exception applies depends on the circumstances of the particular case. Relevant considerations include whether the individual would reasonably expect their information to be collected from another source, the sensitivity of the information, and whether the burden of direct collection is excessive in all the circumstances. The guidance is clear that inconvenience or cost alone is not sufficient — these factors must make direct collection genuinely unreasonable or impracticable, not merely inconvenient.

Exceptions to the consent requirement

The guidance sets out several exceptions to the consent requirement for sensitive information under APP 3.4. The most broadly applicable exception for organisations is where the collection is required or authorised by or under an Australian law or a court or tribunal order. Where this exception applies, the entity should still collect only what sensitive information is reasonably necessary to fulfil its obligation under the relevant law, and should handle the information proportionately.

Other exceptions exist for permitted general situations — such as where collection is reasonably necessary to lessen or prevent a serious threat to life, health or safety — and for permitted health situations, including where health information is necessary to provide a health service.

What this means for practitioners planning ahead

The updated guidance raises questions that are relevant to any practitioner thinking about what happens to their patient health records when they retire, close their practice, or are no longer able to work.

Any person or entity that receives and holds patient health records following practice closure is likely to be collecting that information under APP 3, given the broad definition the OAIC applies. That entity will need to be able to point to a lawful basis for that collection — one that is connected to its own functions and activities, and that is satisfied by consent or a recognised exception.

Whether patients have been meaningfully informed — in a way that satisfies the four elements of consent, rather than simply notified — is a question that may need to be considered when reviewing existing arrangements. Practitioners who are planning for a future transition may wish to review how their current patient documentation addresses these matters.

These are not questions with simple universal answers. The position will depend on the specific circumstances of the practice, the jurisdiction, and the nature of the arrangements in place. Practitioners should seek their own independent legal advice when reviewing or establishing arrangements for the management of patient records following practice exit.

This article contains general information only and should not be taken as legal advice. Practitioners should seek independent legal advice regarding record-keeping, privacy obligations, contingency planning, and all other aspects of their practice.

Ready to safeguard your practice?

Explore the Contingency Plans or learn more about record custodianship with the Legacy Plan.