Law / Australia

Privacy Act 1988 (Cth), Schedule 1, Sensitive and Biometric Information

Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principle 3, read with s. 6

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 12 March 2014.

A sensitive categories rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not collect sensitive information about an individual, including biometric information used for automated biometric verification or identification, or a biometric template, unless the individual consents and the collection is reasonably necessary for the entity's functions, or a listed exception in Australian Privacy Principle 3.4 applies.

If you get it wrong

Private right of actionNo

Who enforces it

Enforcement body

Office of the Australian Information Commissioner (OAIC)

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

An APP entity must not collect sensitive information about an individual, defined to include biometric information used for automated biometric verification or identification and biometric templates, unless the individual consents and the collection is reasonably necessary for the entity's functions, or a listed exception applies.

This is the provision that reaches a voiceprint or faceprint collected for biometric identification, on top of the entity's general Australian Privacy Principle 3 duty for ordinary personal information.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models

Read the law

official consolidated Act text, Federal Register of Legislation

Back to the example  ·  Lint your app