APP 11: Security of Personal Information
Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team
Australian Privacy Principle 11 requires you to take reasonable steps to protect personal information you hold from misuse, interference, loss, unauthorised access, modification, or disclosure — and to destroy or de-identify it once it is no longer needed for any purpose permitted under the Act. There is no fixed technical checklist; what counts as "reasonable" scales with the sensitivity and volume of the information, and this principle is the foundation underpinning the Notifiable Data Breaches scheme in Part IIIC.
| Governing provision | Privacy Act 1988 (Cth), Schedule 1, APP 11 |
| Two limbs | Protect information you hold + destroy/de-identify when no longer needed |
| Standard | Reasonable steps — scales with data sensitivity and volume, no fixed checklist |
| Downstream consequence | A security failure often triggers Part IIIC (NDB scheme) obligations |
| Maximum penalty | Up to $50M for serious or repeated failures |
What APP 11 actually requires
APP 11.1 requires reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. What is "reasonable" is assessed against factors including the nature of your business, the amount and sensitivity of the information held, the possible adverse consequences for individuals if it is compromised, and the practicability and cost of available security measures.
APP 11.2 imposes a separate, ongoing obligation: once personal information is no longer needed for any purpose for which it may be used or disclosed under the APPs, and you are not required by law to retain it, you must take reasonable steps to destroy it or de-identify it. Retention "just in case" is itself a compliance risk, not a safe default.
How this connects to data breach obligations
APP 11 is the principle that, when it fails, typically produces a notifiable data breach under Part IIIC of the Act. A ransomware attack, a misconfigured cloud storage bucket, or a lost unencrypted laptop are all APP 11 security failures that can separately trigger the 30-day NDB assessment and notification obligations if serious harm is likely.
Common SME failure modes
- No baseline security measures — no password policy, no encryption for sensitive files, no access controls limiting who can see customer data.
- Indefinite retention — customer and former-employee records kept with no defined destruction schedule.
- Shared or generic logins for systems holding personal information, making it impossible to trace access.
- No plan for lost or stolen devices — no remote wipe capability, no process to act quickly.
- Third-party access without review — contractors or former staff retaining system access after their engagement ends.
Practical compliance steps
- Apply access controls so staff can only see the personal information relevant to their role.
- Enable multi-factor authentication on any system holding customer or employee data.
- Encrypt sensitive data at rest and in transit where practicable.
- Set and follow a retention schedule — destroy or de-identify data once its purpose has ended.
- Revoke access promptly when staff or contractors leave.
- Have a basic incident response plan so containment doesn't start from scratch during a live breach.
Frequently asked questions
Do I need a specific certification like ISO 27001 to meet APP 11?
No. The Act does not mandate a specific standard or certification. "Reasonable steps" is assessed against your business's size, the sensitivity of the data you hold, and what is practicable — a small business is not expected to match enterprise-grade security infrastructure, but is expected to take genuine, proportionate steps.
How long can I keep customer data before I'm required to destroy it?
There is no single fixed period under APP 11 itself — it depends on how long you have a legitimate, permitted purpose to hold the data, and any other law requiring longer retention (for example, tax record-keeping requirements). Once that purpose ends, destruction or de-identification is required.
Does encrypting data mean a breach involving it isn't notifiable?
Not automatically. Strong encryption reduces the likelihood that a breach results in serious harm, which is relevant to the NDB threshold assessment, but it is not an automatic exemption — the specific circumstances of the breach still need to be assessed.
Use the free Security Gap Check to see how your safeguards measure up against APP 11, across 17 common Australian scenarios.
Check my security safeguards →Explore more of the Privacy Act
- APP 1: Open and Transparent Management of Personal Information
- APP 2: Anonymity and Pseudonymity
- APP 3: Collection of Solicited Personal Information
- APP 4: Dealing with Unsolicited Personal Information
- Does the Privacy Act Apply to My Australian Small Business?
- What Is ADM Disclosure and Does My Australian Business Need One?