Do I Have Reasonable Security Safeguards in Place?
Select the security safeguards your business has in place. Get an instant APP 11 check across 17 common Australian safeguards.
Under APP 11 of the Privacy Act 1988 (Cth), a business must take reasonable steps to protect the personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. APP 11.2 separately requires destroying or de-identifying personal information once it's no longer needed for any purpose it may lawfully be used or disclosed for. Select the safeguards that apply to your business to see where your security posture needs attention.
Last updated: 2 July 2026
How each safeguard is scored
| Result | Meaning |
|---|---|
| Compliant | You've confirmed this safeguard is currently in place |
| Gap | This safeguard applies to your business, and it isn't confirmed as in place yet |
Why APP 11 is broader than "we use a secure system"
APP 11 isn't satisfied by a single control. It covers technical safeguards like encryption and access restrictions, organisational safeguards like vendor agreements and staff training, physical safeguards for paper records, and — a step many businesses skip entirely — actually destroying or de-identifying personal information once there's no lawful purpose left to hold it under. A business can have strong encryption and still be exposed by a shared admin login, an unlocked filing cabinet, or years of customer records no one ever reviewed for deletion.
The Notifiable Data Breaches (NDB) scheme raises the stakes further. When a suspected breach happens, a business has 30 days to assess it — and that assessment is far faster and more accurate with a written response plan and access logging already in place, rather than being built from scratch under pressure.
Security gap check
Select every safeguard that applies to your business. For each one, tell us whether it's currently in place. You'll get an instant APP 11 report at a permanent URL you can revisit or share.
When you need a security gap check
- — You've never reviewed your access controls, encryption or vendor security terms against APP 11
- — You're newly covered by the Privacy Act following the 1 July 2026 threshold removal
- — You don't have a written data breach response plan aligned with the Notifiable Data Breaches scheme
- — You're not sure how or when old records get destroyed or de-identified
- — You're preparing for an OAIC inquiry, a compliance audit, or a vendor due diligence questionnaire
Frequently asked questions
What does APP 11 of the Privacy Act require?
APP 11 requires a business to take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it once it's no longer needed for any purpose it may lawfully be used or disclosed for.
What counts as a "reasonable step" under APP 11?
There's no fixed checklist in the Act itself, but OAIC guidance and enforcement outcomes consistently point to access controls, encryption, vendor security agreements, staff training, monitoring, and a documented breach response plan as baseline expectations.
Is a data breach response plan legally required?
A written plan isn't explicitly mandated, but the Notifiable Data Breaches scheme requires an eligible breach to be assessed within 30 days — a plan is what makes that deadline achievable.
What does the free security gap check check?
It checks the safeguards you select against a catalogue of 17 common Australian security practices, flagging which are confirmed in place and which are still gaps under APP 11.
Select your safeguards above to get an instant APP 11 security gap report.
Get my security gap report →