APP 11 — security of personal information
Privacy Act APP 11. Reasonable steps to protect personal information you hold, and to destroy or de-identify it when it is no longer needed. Technical and organisational measures. OAIC APP Guidelines Chapter 11.
Australian Privacy Principle 11 sits in Schedule 1 of the Privacy Act 1988. An APP entity that holds personal information must take reasonable steps to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure (APP 11.1). Separately, once the information is no longer needed for a purpose permitted under the APPs, the entity must take reasonable steps to destroy it or ensure it is de-identified (APP 11.2), unless an Australian law or a court/tribunal order requires retention.
Holds is broader than a rack you own. Under s 6(1), an entity holds personal information if it has possession or control of a record that contains it. OAIC Chapter 11 is explicit that outsourcing storage does not end APP 11 if you retain the right to deal with the information — including access and amendment. The cloud contract is not a privacy off-switch.
Reasonable steps are contextual: the amount and sensitivity of the information, the harm that could result from compromise, who you are, how hard protection is, and the cost. APP 11.3 says those steps include technical and organisational measures. OAIC examples of technical measures include access control to premises, encryption, anti-virus, and strong authentication; organisational measures include training, standard operating procedures, and policies for securing personal information. Layer them. A single control is a single point of failure.
APP 11 is not the Notifiable Data Breaches scheme. NDB is what you do after an eligible breach. APP 11 is the duty to reduce the chance of that breach and to stop keeping data you no longer need. Pair this page with the NDB clock, the serious-harm test, and your data-breach response plan. For worked examples of personal information security across the lifecycle, use the OAIC Guide to securing personal information alongside Chapter 11 of the APP Guidelines.
See also:
