Privacy in Australia runs on two tracks, and the split confuses people who expect a single national scheme. The Privacy Act 1988 (Cth) is Commonwealth law and applies to private sector businesses across every state and territory uniformly, so a compliant APP privacy policy works nationwide for a commercial operator. The complication arises with public sector and health information, where states run their own regimes on top of the federal Act.
New South Wales governs its public agencies through the Privacy and Personal Information Protection Act 1998 (NSW) and health data through the Health Records and Information Privacy Act 2002 (NSW). A private business selling to NSW government or handling NSW health records may find these state statutes reaching into its contracts, so a policy that references them where relevant is stronger than one that assumes the Commonwealth Act is the whole story.
Victoria operates the Privacy and Data Protection Act 2014 (Vic) for its public sector and the Health Records Act 2001 (Vic) for health information. Victorian contractors delivering services to state departments are routinely bound to comply with these instruments through their service agreements, which means the obligation can attach even to a small private supplier.
Queensland applies the Information Privacy Act 2009 (Qld), which sets its own privacy principles for state agencies and, by extension, for the private contractors they engage. Businesses tendering for Queensland government work should expect the tender documents to require alignment with that Act.
For most private businesses operating purely in the commercial market, the federal APPs remain the controlling framework and the template is drafted to them. The state overlays matter chiefly when you deal with a government body or handle health records, and in those cases the safer course is to check the specific instrument that applies to that dealing.