privacy-act-apps

Analyze Australian privacy law obligations for software systems under APP 1–13.

2|Updated May 13, 2026
One-click install
npx skills add https://github.com/jusso-dev/awesome-Australian-compliance --skill privacy-act-apps
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: privacy-act-apps
Source: https://github.com/jusso-dev/awesome-Australian-compliance/tree/main/skills/privacy-act-apps
Command: npx skills add https://github.com/jusso-dev/awesome-Australian-compliance --skill privacy-act-apps

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps organisations navigate Australian privacy obligations by providing guidance on the Privacy Act, Australian Privacy Principles (APPs), Notifiable Data Breaches (NDB), and related artefacts such as PIAs, collection notices, and cross-border data flows.

Core Features & Use Cases

  • Provides a structured, policy-aligned knowledge base for APPs 1–13, NDB, and privacy governance.
  • Assists in drafting privacy artefacts (PIAs, collection notices, NDB notifications) and mapping data flows for software systems.
  • Acts as a developer and security reviewer companion during privacy reviews, risk assessments, and compliance audits.

Quick Start

Provide a privacy compliance outline for a given system by mapping data flows to APP obligations and NDB considerations.

Frequently Asked Questions about privacy-act-apps

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map software data flows to Australian Privacy Principles obligations?

A Privacy Impact Assessment (PIA) is required under Australian privacy law when a software project introduces high privacy risks, involving the analysis of data collection practices against APP obligations to produce structured PIA reports and risk assessments.

How do I draft a Notifiable Data Breach notification for an Australian software system?

To draft a Notifiable Data Breach (NDB) notification, you assess the breach against NDB scheme criteria and apply OAIC-aligned guidance to generate notification templates, ensuring compliance with Australian privacy law obligations for eligible data breaches.

Does the OAIC require specific collection notices for cross-border data disclosures?

The OAIC requires specific collection notices for cross-border data disclosures under APP 5, where you must analyze data flows leaving Australia and generate policy templates that explicitly state the cross-border data sharing practices to comply with the Privacy Act.

What is the best way to align privacy reviews with ISM controls and OAIC guidance?

The best way to align privacy reviews with ISM controls and OAIC guidance is to map APP obligations against security controls during risk assessments, producing evidence lists and structured compliance outputs that bridge legal privacy requirements with technical safeguards.

Can I assess Privacy Act compliance for an existing application without a full audit?

You can assess Privacy Act compliance without a full audit by performing targeted privacy reviews that map specific application data flows to APP 1–13 obligations, generating risk assessments and evidence lists that highlight immediate compliance gaps and design decisions.