Privacy Ready
Security Gap Check · APP 11 security of personal information

Do I Have Reasonable Security Safeguards in Place?

Select the security safeguards your business has in place. Get an instant APP 11 check across 17 common Australian safeguards.

Under APP 11 of the Privacy Act 1988 (Cth), a business must take reasonable steps to protect the personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. APP 11.2 separately requires destroying or de-identifying personal information once it's no longer needed for any purpose it may lawfully be used or disclosed for. Select the safeguards that apply to your business to see where your security posture needs attention.

Last updated: 2 July 2026

How each safeguard is scored

Result Meaning
Compliant You've confirmed this safeguard is currently in place
Gap This safeguard applies to your business, and it isn't confirmed as in place yet

Why APP 11 is broader than "we use a secure system"

APP 11 isn't satisfied by a single control. It covers technical safeguards like encryption and access restrictions, organisational safeguards like vendor agreements and staff training, physical safeguards for paper records, and — a step many businesses skip entirely — actually destroying or de-identifying personal information once there's no lawful purpose left to hold it under. A business can have strong encryption and still be exposed by a shared admin login, an unlocked filing cabinet, or years of customer records no one ever reviewed for deletion.

The Notifiable Data Breaches (NDB) scheme raises the stakes further. When a suspected breach happens, a business has 30 days to assess it — and that assessment is far faster and more accurate with a written response plan and access logging already in place, rather than being built from scratch under pressure.

Free diagnostic tool

Security gap check

Select every safeguard that applies to your business. For each one, tell us whether it's currently in place. You'll get an instant APP 11 report at a permanent URL you can revisit or share.

Which safeguards apply to your business?

Select all that apply, then tell us whether each one is currently in place.

Access controls

Staff use individual logins to systems holding personal information, not a shared team login is currently in place
Multi-factor authentication (MFA) is required for admin or privileged access to systems holding personal information is currently in place
Access to personal information is restricted by role, not open to every staff member by default is currently in place
A documented offboarding process revokes system access when a staff member leaves is currently in place

Technical safeguards

Personal information held in databases or file storage is encrypted at rest is currently in place
Personal information is encrypted in transit (HTTPS/TLS) between systems, forms and integrations is currently in place
Systems and software holding personal information are kept up to date with security patches is currently in place
Backups containing personal information are access-restricted and periodically tested is currently in place

Third-party & device security

Cloud and SaaS vendors handling personal information are bound by a written agreement covering security is currently in place
Staff devices used to access personal information (including personal phones/laptops) are covered by security controls such as screen lock, encryption or remote wipe is currently in place

Physical security

Paper records containing personal information are stored in a locked or restricted-access area is currently in place
Visitors and contractors can't access work areas holding personal records unsupervised is currently in place

Destruction & retention

Retention periods are documented, with a process to destroy or de-identify personal information once it's no longer needed is currently in place
Paper records are destroyed by secure shredding rather than put in general rubbish or recycling is currently in place
Old devices, hard drives and decommissioned cloud storage are securely wiped before disposal or reuse is currently in place

Breach detection & response

A written data breach response plan exists, aligned with the Notifiable Data Breaches (NDB) scheme is currently in place
Systems holding personal information have logging or monitoring in place to detect unauthorised access is currently in place
Staff are trained to recognise and report a suspected data breach is currently in place

When you need a security gap check

  • You've never reviewed your access controls, encryption or vendor security terms against APP 11
  • You're newly covered by the Privacy Act following the 1 July 2026 threshold removal
  • You don't have a written data breach response plan aligned with the Notifiable Data Breaches scheme
  • You're not sure how or when old records get destroyed or de-identified
  • You're preparing for an OAIC inquiry, a compliance audit, or a vendor due diligence questionnaire

Frequently asked questions

What does APP 11 of the Privacy Act require?

APP 11 requires a business to take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it once it's no longer needed for any purpose it may lawfully be used or disclosed for.

What counts as a "reasonable step" under APP 11?

There's no fixed checklist in the Act itself, but OAIC guidance and enforcement outcomes consistently point to access controls, encryption, vendor security agreements, staff training, monitoring, and a documented breach response plan as baseline expectations.

Is a data breach response plan legally required?

A written plan isn't explicitly mandated, but the Notifiable Data Breaches scheme requires an eligible breach to be assessed within 30 days — a plan is what makes that deadline achievable.

What does the free security gap check check?

It checks the safeguards you select against a catalogue of 17 common Australian security practices, flagging which are confirmed in place and which are still gaps under APP 11.

Select your safeguards above to get an instant APP 11 security gap report.

Get my security gap report →