Skip to content
APN

Professional privacy services

Privacy that fits the way your organisation actually works.

Choose a focused document review, build the foundations properly or examine the whole operation. APN agrees the boundary, deliverables and price in writing before paid work begins.

The first conversation establishes whether APN is the right fit. If a regulator, lawyer, cyber specialist or another provider is better placed to help, we say so.

Request a scoped quote

No payment is taken from this page.

What we review.

Public-facing documents

  • Privacy policies
  • Website privacy statements
  • Collection notices
  • Consent language
  • Website forms
  • Booking and enquiry forms
  • Cookie and tracking information
  • Application and onboarding wording

Internal practices

  • Staff responsibilities
  • Access and correction
  • Complaint handling
  • Retention and disposal
  • Incident and breach response
  • Approval and escalation
  • Internal guidance
  • Practical record keeping

Data and systems

  • Information flows
  • Storage systems
  • Software providers
  • Contractor access
  • Overseas processing
  • Analytics
  • Advertising technology
  • AI systems
  • Automated decisions

Implementation

  • Gap analysis
  • Risk-ranked recommendations
  • Publication-ready documents
  • Action plans
  • Practical internal steps
  • Ongoing review

How we work.

  1. 1Understand the organisation
  2. 2Map the information handled
  3. 3Review documents and systems
  4. 4Identify gaps and priorities
  5. 5Improve policies and practices
  6. 6Implement practical changes
  7. 7Review and maintain

Services available for enquiry

Choose the smallest service that solves the real problem.

Each engagement is scoped against the organisation in front of us. The lists below show the expected boundary, not a promise to sell unnecessary work.

Privacy Statement Review

For organisations that already have a privacy policy and want it reviewed against their current website, forms and operations.

Typical review boundary

  • Current privacy policy
  • Website and primary collection points
  • High-impact wording and operational mismatches

What you receive

A plain-English findings summary, practical corrections and agreed replacement or redrafted wording.

Discuss a privacy-statement review

Privacy Foundations

For small or growing organisations that need their core privacy documents and data-collection practices brought together properly.

Typical review boundary

  • Core collection and consent wording
  • Public-facing privacy documents
  • Responsibilities, requests and incident basics

What you receive

An agreed foundation pack and a prioritised implementation list your organisation can actually use.

Discuss privacy foundations

Privacy Operations Review

For organisations with staff, contractors, multiple systems, customer records or more complex information handling.

Typical review boundary

  • Information flows and providers
  • Access, retention and disposal
  • Incidents, complaints, AI and automated decisions

What you receive

A risk-ranked review of the real operation, documented gaps and an implementation plan with accountable next steps.

Discuss an operations review

Complex and Commercial Operations

For mine sites, maritime operations, resources organisations, multi-location businesses, technology platforms, regulated sectors and organisations with complex information flows.

Typical review boundary

  • Defined operational boundary
  • Roles, controls and evidence requirements
  • Staged delivery and handover

What you receive

A scoped work package built around the operation, its risk, its people and the decisions that must be supportable.

Discuss your requirements

Ongoing Privacy Support

For organisations that need regular updates as staff, systems, forms and legal obligations change.

Typical review boundary

  • Scheduled document and practice reviews
  • Change-triggered updates
  • Questions, handover and maintenance records

What you receive

A clearly agreed support rhythm. Nothing renews or expands without the arrangement being understood first.

Discuss ongoing support

Pricing and engagement

No mystery package and no surprise renewal.

1

Explain the need

Send a short description, the organisation type and any deadline that genuinely matters.

2

Confirm the fit

APN identifies the suitable service, any important limit and whether another provider should be involved.

3

Agree the scope

You receive a written boundary, deliverables, price and assumptions before paid work begins.

4

Complete and hand over

Work is delivered with practical next steps and a clear record of what was and was not covered.

Privacy landscape

What is changing — and what businesses should review.

Australian privacy requirements and regulatory expectations continue to develop. Some changes are already operating, some have confirmed future commencement dates and others remain under development.

Statutory tort for serious invasions of privacy

In effect · 10 June 2025

Individuals now have an additional pathway to seek redress through the courts for serious invasions of privacy where the legal requirements are met. Organisations should be able to explain and support their information-handling decisions, not merely point to a policy document.

Practical review: Check collection practices, access controls, disclosures, surveillance, sensitive information and complaint escalation.

Source: Office of the Australian Information Commissioner →

Expanded regulatory and enforcement framework

In effect

Recent reforms expanded the privacy regulator’s investigation and enforcement options, including additional civil-penalty and compliance mechanisms. Policies, notices and operating practices should be current, supportable and capable of being implemented in practice.

Practical review: Check whether documented practices match what staff, systems and suppliers actually do.

Source: Office of the Australian Information Commissioner →

Automated-decision transparency

Confirmed commencement · 10 December 2026

Certain organisations covered by the Australian Privacy Principles will need to include additional information in their privacy policies where personal information is used in automated decisions that may significantly affect a person’s rights or interests.

Practical review: Identify where computer programs use personal information to make or materially support significant decisions. Record the information used, the kinds of decisions made and what affected people are told.

Source: Office of the Australian Information Commissioner →

Children’s Online Privacy Code

Under development · Target 10 December 2026

A Children’s Online Privacy Code is being developed for online services likely to be accessed by children. This may affect websites, apps, platforms, games, education services and online communities used by children, even where children are not the sole intended audience.

Practical review: Consider whether children are likely to access the service, what information is collected, whether the design is appropriate and how notices and consent operate.

Source: Office of the Australian Information Commissioner →

Privacy-policy scrutiny

Current regulatory focus

The privacy regulator has undertaken targeted reviews of privacy policies and has publicly emphasised that policies should be clear, current and compliant with Australian Privacy Principle requirements.

Practical review: Confirm the policy explains what is collected, why, how it is used, who receives it, overseas disclosure, access and correction, complaints, retention and automated decision-making where required.

Source: Office of the Australian Information Commissioner →

This information is general and does not constitute legal advice. The obligations applying to an organisation depend on its circumstances, activities and legal status.

Last reviewed against OAIC sources: August 2026.

What organisations can review now.

Data collection

Identify every form, platform, device and process through which personal information enters the organisation.

Purpose

Confirm why each category is collected and whether all of it is necessary.

Notices

Check what staff, customers, contractors and website visitors are told when information is collected.

Systems and providers

Identify where information is stored, which providers receive it and whether information is processed outside Australia.

AI and automation

Record where software assists with or makes decisions involving people.

Retention

Decide how long information should be kept and how it is securely disposed of when no longer required.

Individual requests

Ensure access, correction and privacy complaints have a clear internal pathway.

Incident readiness

Confirm who responds when information is lost, accessed improperly or disclosed without authority.

Review your business privacy practices