What Security Measures Does the Privacy Act Require?
Why APP 11 has no fixed checklist, what "reasonable steps" actually means, and the free tools to check your safeguards.
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure — and to destroy or de-identify it once it's no longer needed. There's no fixed checklist; what's "reasonable" scales with the sensitivity of the data and the size of the business.
Last updated: 2 July 2026
Quick reference
| Governing principle | APP 11 — Security of personal information |
| Standard applied | "Reasonable steps" — scales with data sensitivity and business size |
| Retention rule | Destroy or de-identify data once no longer needed (APP 11.2) |
| If a breach occurs anyway | Notifiable Data Breaches scheme, Part IIIC, if serious harm is likely |
Why "reasonable steps" trips businesses up
APP 11 deliberately doesn't name specific technologies — no mandated encryption standard, no mandated password policy. That flexibility is also the trap: businesses assume "we have a password on the laptop" satisfies a standard that the OAIC actually assesses against the sensitivity of the data and what's achievable for a business of that size.
Retention is the other half of APP 11 that's easy to miss. Data kept indefinitely "in case it's useful" — old customer records, expired job applications, historical payment details — is itself a compliance gap under APP 11.2, independent of whether it's ever accessed improperly.
Relevant free tools
Check your data security safeguards against APP 11 requirements.
Check whether the personal information you hold is accurate and up to date.
Check whether you're allowed to collect, use or adopt government identifiers.
Related Privacy Act questions
When to check your security safeguards
- — You've never documented what security safeguards your business actually has in place
- — You store sensitive information — health, financial, government identifiers — without extra protection
- — You're holding customer data with no defined retention or deletion schedule
- — You're newly covered by the 1 July 2026 exemption removal and haven't assessed your safeguards
- — A client or vendor has asked you to demonstrate your security posture
Frequently asked questions
What security measures does the Privacy Act require?
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure — and to destroy or de-identify it once it's no longer needed. There's no fixed checklist; what's "reasonable" scales with the sensitivity of the data and the size of the business.
Do I need to encrypt customer data?
Encryption isn't mandated by name in the Privacy Act 1988 (Cth), but it's widely treated as a reasonable step for sensitive or high-volume personal information, and its absence is commonly cited in OAIC findings after a breach involving unencrypted data.
How long can I keep personal information?
Only as long as it's needed for the purpose it was collected for, or a legal requirement to retain it. APP 11.2 requires destruction or de-identification of personal information once it's no longer needed, unless retention is required or authorised by law.
What if I have a breach despite reasonable safeguards?
You may still need to notify affected individuals and the OAIC under the Notifiable Data Breaches scheme (Part IIIC) if the breach is likely to result in serious harm. Having reasonable APP 11 safeguards in place reduces penalty exposure but doesn't remove the notification obligation.
Run the free security gap checker to see where your safeguards fall short of APP 11.
Check my security safeguards →