Privacy Act 1988 compliance for a mobile app
Privacy Act 1988 (Cth) and the Australian Privacy Principles. This page applies it to one kind of product (mobile app), so you get the obligations that are actually yours instead of a summary of the whole statute.
Does it apply to you?
Businesses with A$3M+ turnover, plus certain small businesses handling sensitive data.
What a mobile app typically processes
- device identifiers and advertising IDs
- device permissions such as camera, location or contacts
- crash reporting and mobile analytics SDKs
- in-app purchases through the store
Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.
Documents you need
The intersection of what Privacy Act 1988 requires and what a mobile app actually does:
- Privacy policy
Rights you must honour
Privacy Act 1988 gives people in Australia the right to:
- Access a copy of their data
- Correct inaccurate data
- Object to certain processing
Cookies and trackers
Trackers may load by default, but the visitor needs a working way to opt out, and you must honour it.
On mobile, the store asks too
There is no cookie banner in a native app, but Apple App Privacy and Google Play Data Safety both make you declare the same processing — and a declaration that contradicts your privacy policy is the version reviewers notice. The policy has to be reachable at a public URL before you submit.
See what your site is actually missing
Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.
No signup · result in seconds
Primary sources
- Privacy Act 1988 — Privacy Act 1988 (Cth) and the Australian Privacy Principles · official text · Office of the Australian Information Commissioner (OAIC)
- APP 1 — Open and transparent management: you must have a privacy policy
- APP 5 — Notify the individual when you collect their data
- APP 6 — Limits on use and disclosure
- APP 12 — Give the individual access to their data
Privacy Act 1988 for other kinds of product
Other frameworks for a mobile app
This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.