Guidance
Copies of public regulator guidance, kept by Comms.ID to cite in its controls. The publisher owns each text and its licence; every document names its source URL. Not legal advice, and not an official copy.
For agents: /llms.txt, /index.json, /freshness.json. Every document is Markdown at /<collection>/<slug>.md.
asd-ism
asd-ism · 26 documents · release 2026.09.4
asd-pqc
asd-pqc · 1 documents
ASIC IDR Data Reporting
asic-regulatory-guides/idr-data-reporting · 1 documents
- IDR data reporting handbook source
ASIC's current IDR reporting handbook, including the data dictionary, data glossary, report-file schema, validation rules, submission process and checklist.
ASIC Regulatory Guide 267
asic-regulatory-guides/rg-267 · 1 documents
ASIC Regulatory Guide 271
asic-regulatory-guides/rg-271 · 1 documents
- RG 271 Internal dispute resolution source
ASIC's enforceable IDR standards and requirements covering complaints, accessibility, acknowledgement, response contents and timeframes, systemic issues, governance, records and improvement.
AUSTRAC customer due diligence
austrac-cdd · 13 documents
digital-id-accreditation
digital-id-accreditation · 28 documents
- Applying for accreditation source
ACCC guidance on the Digital ID accreditation framework, application evidence, assessment, conditions, changes and compliance obligations.
- Guidance for accredited entities in Australia's Digital ID System source
ACCC guidance on maintaining accreditation, annual reviews, changes, notification duties, compliance and enforcement.
- Internal review of Digital ID Regulator decisions source
ACCC factsheet on internally reviewable Digital ID decisions, application timing, standing, process and outcomes.
- Organisation and Authorised Officer form source
Regulator form for registering an organisation and its accountable Authorised Officer.
- Service and Contact Person form source
Regulator form for registering a service and its operational contact people.
- Accreditation application form source
Digital ID accreditation application questions, document uploads, testing evidence and organisational assurances.
- Declaration for entities seeking accreditation source
Authorised Officer declarations that an accreditation application is complete, correct and compliant.
- Declaration technical testing attestation statement for entities seeking accreditation source
Regulator attestation that applicable Digital ID technical testing requirements have been met.
- Approval to participate in the AGDIS form source
Application form for approval to participate in the Australian Government Digital ID System.
- Plans and procedure declarations for relying parties applying to participate in the AGDIS source
Relying-party declaration covering notification procedures, cyber security, fraud, disaster recovery and business continuity plans.
- Plans and procedures declaration for accredited entities seeking approval to participate in the AGDIS source
Declaration that an accredited entity has required System Administrator notification procedures.
- Declaration for compliance for all entities applying to participate in the AGDIS source
Declaration that an AGDIS applicant will comply with applicable Digital ID legislation.
- Final Declaration for all entities seeking approval to participate in the AGDIS source
Final Authorised Officer declaration that AGDIS application information is true and complete.
- AGDIS exemptions for participating relying parties form source
Application form for a participating relying party seeking exemption from the voluntariness requirement.
- Application to vary participation start date for AGDIS approval source
Application form to vary the start date for an entity's AGDIS participation.
- Evidence it is appropriate to accredit or approve the organisation source
Regulator form for organisational evidence supporting the appropriateness assessment.
- Fit and proper person declaration for associated persons source
Personal declaration supporting the Regulator's fit-and-proper assessment of associated persons.
- Conditions on accreditation or AGDIS approval form source
Application form to impose, vary or revoke a condition on accreditation or AGDIS approval.
- Revocation of Accreditation or AGDIS approval form source
Application form for voluntary revocation of accreditation or AGDIS approval.
- Suspension of accreditation or AGDIS approval form source
Application form for suspension of accreditation or AGDIS approval.
- Application to vary accreditation or AGDIS approval form source
Application form to vary organisation or service names on accreditation or AGDIS approval.
- Handling personal information when providing accredited Digital ID services source
OAIC guidance on Digital ID-specific collection, use, disclosure, retention, destruction and prohibited handling of personal information.
- Handling biometric information when providing accredited Digital ID services source
OAIC guidance on permitted and prohibited biometric handling, express consent, matching and destruction deadlines.
- Law enforcement access to Digital ID information source
OAIC guidance on permitted law-enforcement access, warrants, consent and prohibited enforcement purposes.
- Express consent in Australia's Digital ID System source
OAIC guidance on the meaning, elements, timing, withdrawal and evidencing of express consent under the Digital ID Act.
- Interaction between the Digital ID Act and the Privacy Act source
OAIC guidance on how Digital ID privacy safeguards interact with the Privacy Act and comparable state or territory laws.
- Relying parties privacy obligations when handling personal information source
OAIC guidance on privacy obligations for participating and non-participating relying parties handling Digital ID information.
- Applicable notifiable data breach and privacy obligations for accredited entities source
OAIC guidance on NDB coverage, response plans and additional Digital ID Regulator notification duties for accredited entities.
oaic-privacy
oaic-privacy · 44 documents
- Preface source
OAIC context for the status, purpose and use of the Australian Privacy Principles Guidelines.
- Summary of version changes to APP Guidelines source
OAIC change history for the Australian Privacy Principles Guidelines.
- Chapter A: Introductory matters source
OAIC guidance on APP scope, structure, accountability and interpretation.
- Chapter B: Key concepts source
OAIC interpretation of consent, APP-entity coverage, reasonable necessity, reasonable steps and other Privacy Act concepts.
- Chapter C: Permitted general situations source
OAIC guidance on the Privacy Act's permitted general situations, including suspected unlawful activity and serious threats.
- Chapter D: Permitted health situations source
OAIC guidance on permitted health situations for collection, use and disclosure.
- Chapter 1: APP 1 Open and transparent management of personal information source
OAIC guidance on privacy governance, practices and APP privacy-policy contents.
- Chapter 2: APP 2 Anonymity and pseudonymity source
OAIC guidance on offering anonymous or pseudonymous dealings and the available exceptions.
- Chapter 3: APP 3 Collection of solicited personal information source
Current OAIC guidance on solicited collection, sensitive information, consent, proportionality, data minimisation, AI and facial recognition.
- Chapter 4: APP 4 Dealing with unsolicited personal information source
OAIC guidance on assessing, retaining, destroying or de-identifying unsolicited personal information.
- Chapter 5: APP 5 Notification of the collection of personal information source
OAIC guidance on collection notices, timing and required notification matters.
- Chapter 6: APP 6 Use or disclosure of personal information source
OAIC interpretation of primary purposes, secondary uses and disclosures, consent, reasonable expectations and statutory exceptions.
- Chapter 7: APP 7 Direct marketing source
OAIC guidance on direct-marketing restrictions, consent and opt-out requirements.
- Chapter 8: APP 8 Cross-border disclosure of personal information source
OAIC guidance on overseas recipients, contractor access, effective control, reasonable steps, accountability and exceptions.
- Chapter 9: APP 9 Adoption, use or disclosure of government related identifiers source
OAIC guidance on adopting, using and disclosing government-related identifiers.
- Chapter 10: APP 10 Quality of personal information source
OAIC guidance on reasonable steps to ensure personal information quality for its intended handling.
- Chapter 11: APP 11 Security of personal information source
OAIC guidance on protecting held personal information and destroying or de-identifying it when no permitted purpose or retention law remains.
- Chapter 12: APP 12 Access to personal information source
OAIC guidance on individual access requests, response handling, refusal grounds and notices.
- Chapter 13: APP 13 Correction of personal information source
OAIC guidance on correction duties, third-party notification, refusal notices and associated statements.
- Guidance on privacy and developing and training generative AI models source
OAIC guidance on privacy by design, collection, transparency, consent and secondary use when personal information trains AI models.
- Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act source
OAIC guidance on Privacy Act scope, collection, notices, use, overseas disclosure, security, retention and deletion for AML/CTF reporting entities and authorised agents.
- Tips for good privacy practice source
OAIC operational checklist spanning privacy by design, policies, minimisation, consent, third parties, security, breach readiness and governance.
- Privacy by design source
OAIC guidance on embedding privacy controls throughout product and service design.
- Guide to developing an APP privacy policy source
OAIC guidance on the required content, structure, accessibility and maintenance of an APP privacy policy.
- De-identification and the Privacy Act source
OAIC guidance on when information is de-identified, re-identification risk and governance of de-identification decisions.
- Sending personal information overseas source
OAIC guidance on overseas disclosures, cloud and contractor arrangements, accountability and APP 8 exceptions.
- Guide to securing personal information source
OAIC guidance on the reasonable steps, governance, ICT, access, lifecycle and destruction controls expected under APP 11.
- Privacy management framework: enabling compliance and encouraging good practice source
OAIC governance framework covering leadership, privacy capability, risk controls, assurance and continuous improvement.
- Handling privacy complaints source
OAIC guidance and checklist for receiving, investigating, responding to, recording and learning from privacy complaints.
- Notifiable data breaches source
OAIC NDB hub covering prevention, preparation, response, reporting and current operational guidance.
- About the Notifiable Data Breaches scheme source
OAIC overview of NDB scheme coverage and the duty to notify eligible data breaches.
- When to report a data breach source
OAIC guidance on the eligible-data-breach test, likely serious harm, remedial action and assessment.
- Report a data breach source
OAIC instructions for preparing and submitting an eligible data-breach statement and notifying individuals.
- Quick reference guide for responding to data breaches source
OAIC quick-reference sequence for containing, assessing, notifying and reviewing a data breach.
- Data breach preparation and response source
OAIC guide landing page, revision context and routes for preparing for and responding to breaches under the Privacy Act.
- Preventing data breaches: advice from the Australian Cyber Security Centre source
OAIC-hosted ACSC advice on staff awareness, credentials, authentication, patching and other controls that reduce data-spill and breach risk.
- Guidance for entities in preparing for and responding to cyber incidents source
OAIC guidance on breach plans, information inventories, providers, access and audit controls, harm minimisation and cyber-incident prevention.
- Purpose and structure of the data breach preparation and response guide source
OAIC explanation of the guide's objectives, preparation and response lifecycle, and relationship to NDB obligations.
- Part 1: Data breaches and the Australian Privacy Act source
OAIC guidance on breach types, causes, harms and Privacy Act security obligations.
- Part 2: Preparing a data breach response plan source
OAIC guidance on response-plan contents, escalation, team membership, authority, testing and review.
- Part 3: Responding to data breaches – four key steps source
OAIC four-step response process covering containment, assessment, notification and review.
- Part 4: Notifiable Data Breach (NDB) Scheme source
Detailed OAIC guidance on eligible breaches, serious harm, assessments, remedial action, notification and exceptions.
- Part 5: Other sources of information source
OAIC routes to complementary cyber-security, identity, financial, health and government breach resources.
- Appendix A: Key terms source
Definitions used throughout the OAIC data-breach preparation and response guide.
ORIC governance and authority
oric-governance · 6 documents