Privacy Act 1988 — Children's Online Privacy Code (s 26GC), APP 8, APP 11
Privacy Act 1988 (Cth) — authorised compilation No. 104 (C2026C00227, in force from 2026-06-04), Federal Register of Legislation.
26GC Development of APP codes by the Commissioner—Children’s Online Privacy Code
Children’s Online Privacy Code
(1) The Commissioner must develop an APP code (the Children’s Online Privacy Code) about online privacy for children.
(2) The other provisions of this Division (including section 26C) apply in relation to the Children’s Online Privacy Code subject to this section.
Note: Section 26C deals with requirements for APP codes generally.
Matters covered by code
(3) For the purposes of paragraph 26C(2)(a), the Children’s Online Privacy Code must set out how one or more of the Australian Privacy Principles are to be applied or complied with in relation to the privacy of children.
(4) For the purposes of subsections 26C(3) and (4), the Children’s Online Privacy Code may provide for one or more of the matters mentioned in those subsections in relation to the privacy of children. However, despite paragraph 26C(3)(b), the code must not cover an act or practice that is exempt within the meaning of subsection 7B(1), (2) or (3).
Note: Codes may provide differently for different things: see subsection 26C(4A).
Entities bound by code
- (a) all of the following apply:
- (i) the entity is a provider of a social media service, relevant electronic service or designated internet service (all within the meaning of the Online Safety Act 2021);
- (ii) the service is likely to be accessed by children;
- (iii) the entity is not providing a health service; or
- (b) the entity is an APP entity, or an APP entity in a class of entities, specified in the code for the purposes of this paragraph. Note: In relation to subparagraph (a)(ii), see subsection (11).
Specified entities not bound by code
(7) Despite subsection (5), an APP entity is not bound by the Children’s Online Privacy Code if the entity is an APP entity, or an APP entity in a class of entities, specified in the code for the purposes of this subsection.
Requirements
- (a) consult with:
- (i) children; and
- (ii) relevant organisations or bodies concerned with children’s welfare; and
- (iia) industry organisations or bodies representing the interests of one or more entities that may potentially be bound by the Code;
- (iii) the eSafety Commissioner; and
- (iv) the National Children’s Commissioner; and
- (b) consult any other person the Commissioner considers appropriate.
- (a) make a draft of the code publicly available; and
- (b) invite the public to make submissions to the Commissioner about the draft within a specified period (which must run for at least 60 days); and
- (c) give consideration to any submissions made within the specified period; and
- (d) consult with:
- (i) the eSafety Commissioner; and
- (ii) the National Children’s Commissioner. Time by which code must be made
(10) The Commissioner must develop and register the Children’s Online Privacy Code within the period of 24 months beginning on the day the Privacy and Other Legislation Amendment Act 2024 receives the Royal Assent.
Services likely to be accessed by children
(11) The Commissioner may make written guidelines to assist entities to determine if a service is likely to be accessed by children for the purposes of subparagraph (5)(a)(ii).
8 Australian Privacy Principle 8—cross-border disclosure of personal information
8.1 Before an APP entity discloses personal information about an individual to a person (the overseas recipient):
- (a) who is not in Australia or an external Territory; and
- (b) who is not the entity or the individual;
the entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information.
Note: In certain circumstances, an act done, or a practice engaged in, by the overseas recipient is taken, under section 16C, to have been done, or engaged in, by the APP entity and to be a breach of the Australian Privacy Principles.
8.2 Subclause 8.1 does not apply to the disclosure of personal information about an individual by an APP entity to the overseas recipient if:
- (a) the entity reasonably believes that:
- (i) the recipient of the information is subject to a law, or binding scheme, that has the effect of protecting the information in a way that, overall, is at least substantially similar to the way in which the Australian Privacy Principles protect the information; and
- (ii) there are mechanisms that the individual can access to take action to enforce that protection of the law or binding scheme; or
- (aa) subclause 8.3 applies in relation to the disclosure of the information; or
- (b) both of the following apply:
- (i) the entity expressly informs the individual that if he or she consents to the disclosure of the information, subclause 8.1 will not apply to the disclosure;
- (ii) after being so informed, the individual consents to the disclosure; or
- (c) the disclosure of the information is required or authorised by or under an Australian law or a court/tribunal order; or
- (d) a permitted general situation (other than the situation referred to in item 4 or 5 of the table in subsection 16A(1)) exists in relation to the disclosure of the information by the APP entity; or
- (e) the entity is an agency and the disclosure of the information is required or authorised by or under an international agreement relating to information sharing to which Australia is a party; or
- (f) the entity is an agency and both of the following apply:
- (i) the entity reasonably believes that the disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body;
- (ii) the recipient is a body that performs functions, or exercises powers, that are similar to those performed or exercised by an enforcement body. Note: For permitted general situation, see section 16A.
8.3 This subclause applies in relation to the disclosure of personal information (the relevant personal information) about an individual by an APP entity to an overseas recipient if:
- (a) the recipient of the relevant personal information is:
- (i) subject to the laws of a country that is prescribed by the regulations; or
- (ii) a participant in a binding scheme that is prescribed by the regulations; and
- (b) if the country or binding scheme is prescribed subject to conditions—those conditions are satisfied. Note: There are prerequisites that must be satisfied before the matters mentioned in this subclause are prescribed: see subsection 100(1A).
11 Australian Privacy Principle 11—security of personal information
11.1 If an APP entity holds personal information, the entity must take such steps as are reasonable in the circumstances to protect the information:
- (a) from misuse, interference and loss; and
- (b) from unauthorised access, modification or disclosure.
- (a) an APP entity holds personal information about an individual; and
- (b) the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity under this Schedule; and
- (c) the information is not contained in a Commonwealth record; and
- (d) the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information;
the entity must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified.
11.3 For the purposes of subclauses 11.1 and 11.2, without limiting those subclauses or any other provision of this Act, such steps include technical and organisational measures.
Meta
Extracted verbatim from the Federal Register of Legislation's compilation epub XHTML (C2026C00227) by tools/frl-au/build_au.py. The FRL OData API resolves the latest compilation's registerId, which is pinned here — verify fails as soon as a newer compilation is registered. "Note:" paragraphs are part of the official text and kept (italicised). APP clause numbers repeat body section numbers, so Schedule-1 targets are sliced within the Schedule 1 region. Anchors: {#app11-11-1} = APP 11.1, {#s26gc-1} = s 26GC(1).