📜 Privacy Act🔒 APP 11

What Does the Privacy Act Require for Destroying Personal Information?

The Privacy Act does not just govern how you collect and use personal information. It governs how you get rid of it. Australian Privacy Principle 11 requires you to destroy or de-identify personal information once it is no longer needed, and to protect it in the meantime. On a retired device, that means certified destruction. This guide explains what the obligation actually requires, and where reform is heading.

Data Destroyed to a Standard Certificate as Evidence

The Quick Answer

What does the Privacy Act require when destroying personal information?

Australian Privacy Principle 11 requires an organisation to take reasonable steps to protect personal information from misuse, loss and unauthorised access, and to destroy it or de-identify it once it is no longer needed for any purpose the organisation is permitted to use it for. On a retired device, meeting that obligation means the data has to be genuinely destroyed, not merely deleted, because deleted or reset data remains recoverable. In practice that is certified wiping to a recognised standard, or physical destruction, with a record to show reasonable steps were taken. The Privacy Act does not prescribe a specific method, but the combination of the destruction duty and the reasonable-steps duty points clearly to secure, documented destruction. That is what a certified data destruction process provides.

The disposal end of the Privacy Act is the part organisations most often overlook. A lot of care goes into consent, collection and use, and then a laptop full of the same personal information is retired with a factory reset and forgotten. APP 11 closes that loop: the obligation to protect personal information runs until the information is destroyed, and the destruction itself is a requirement, not a courtesy. This guide sets out what the principle requires today, and how the Privacy Act reforms may sharpen it.

What APP 11 Actually Says

The principle has two limbs, and both bear directly on how you dispose of IT.

Australian Privacy Principle 11 has two parts. The first, often called APP 11.1, requires an entity to take reasonable steps to protect the personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. The second, APP 11.2, requires the entity to take reasonable steps to destroy the information or ensure it is de-identified once it no longer needs the information for any purpose for which it may be used or disclosed, and is not otherwise required by law to retain it. Read together, the two limbs describe a duty that runs across the whole time you hold personal information and culminates in destroying it: protect it while you have it, and destroy or de-identify it when you no longer need it.

The phrase that does the work is "reasonable steps". The Act does not name a technique, because what is reasonable scales with the sensitivity of the information and the risk to the individuals if it were exposed. For a device holding ordinary personal information, reasonable steps mean a genuine, verifiable destruction of the data rather than a delete. For a device holding sensitive information, health records, financial details, identity documents, the bar is correspondingly higher, and physical destruction or a verified purge with a certificate is the natural reading. The OAIC's guidance on APP 11 sets out the reasonable-steps expectation in more detail.

Why "delete" does not satisfy APP 11

Deleting a file or resetting a device removes the pointers to the data, not the data itself, so the information remains recoverable. Since APP 11.2 requires the information to be destroyed or de-identified, a method that leaves it recoverable has not destroyed it. This is why the destruction obligation, on modern storage, means certified wiping to a recognised standard such as NIST 800-88, or physical destruction, rather than a delete or a factory reset.

What "Reasonable Steps" Looks Like at Disposal

Four things together make up a defensible reading of reasonable steps for destroying personal information on retired IT.

1

Destroy, do not delete

Genuinely destroy the data by certified wiping to a recognised standard, or physical destruction where a drive cannot be verifiably wiped, matched to the media so it is actually unrecoverable.

2

Scale the method to the sensitivity

Ordinary personal information warrants a verified wipe; sensitive information such as health or financial records warrants the higher assurance of physical destruction or a verified purge. Reasonable steps are proportionate to the risk.

3

Protect it until it is destroyed

APP 11.1 applies right up to destruction, so the device must be secured and tracked in the meantime. A documented chain of custody is how you protect the information between retirement and destruction.

4

Keep evidence

A certificate for each device demonstrates that reasonable steps were taken. If your handling is ever examined, evidence of the destruction is what shows the obligation was met.

Retention comes before destruction

APP 11.2 only requires destruction once the information is no longer needed and is not required by law to be retained. Many records must be kept for set periods under other laws, tax, employment, health and financial rules among them. So the sequence is: retain what you are required to keep by archiving it to current systems, then destroy the old hardware. The destruction obligation and retention obligations work together, not against each other.

Where Privacy Reform Is Heading

The Privacy Act is being reformed in stages. The destruction duty is current; some proposals may strengthen it further.

Now
APP 11.2 is the current, live obligation: destroy or de-identify personal information once no longer needed
Privacy Act 1988
2024
The Privacy and Other Legislation Amendment Act 2024 passed as a first tranche of reforms
Source: OAIC
Proposed
A statutory right to erasure was proposed in the Privacy Act Review and is under consideration, not yet law
Source: Attorney-General's Department

It is worth being precise about what is in force and what is not. The destruction duty under APP 11.2 is current law and applies today. The Privacy Act is separately undergoing the most significant reform in decades: the Privacy and Other Legislation Amendment Act 2024 passed as a first tranche, and the Privacy Act Review put forward a broader set of proposals for future tranches, among them a possible statutory right for individuals to request erasure of their personal information. That right to erasure is a proposal under consideration, not yet enacted, so no business should treat it as a current obligation. What the reform direction does signal, though, is that the expectation to destroy personal information you no longer need is strengthening, not weakening. An organisation that already destroys retired data to a recognised standard and documents it is well placed for whatever the later tranches bring, because it is already doing the substance of what the reforms point toward.

Privacy Act & Data Destruction: FAQ

The questions organisations ask most about the destruction obligation.

Yes. Australian Privacy Principle 11.2 requires an organisation to take reasonable steps to destroy or de-identify personal information once it is no longer needed for any permitted purpose and is not required by law to be retained. On a retired device, that means genuinely destroying the data, not merely deleting it, because deleted data remains recoverable. The obligation is current law.

The Act does not prescribe a method; reasonable steps scale with the sensitivity of the information and the risk to individuals if it were exposed. For ordinary personal information, that means a genuine, verifiable destruction of the data. For sensitive information such as health or financial records, the bar is higher, pointing to physical destruction or a verified purge with a certificate. Proportionality is the principle.

Generally no. A factory reset or file deletion leaves the underlying data recoverable, and APP 11.2 requires the information to be destroyed or de-identified. Since a method that leaves the data recoverable has not destroyed it, reasonable steps on modern storage mean certified wiping to a recognised standard, or physical destruction, rather than a reset. Documentation of that destruction is what demonstrates compliance.

Not currently as a standalone statutory right. A right to erasure was proposed in the Privacy Act Review and is under consideration for future reform, but it is not yet law, so it should not be treated as a current obligation. What is current is APP 11.2, the duty to destroy or de-identify personal information once no longer needed. Organisations that meet that duty are already aligned with the direction the reforms point.

APP 11.2 only requires destruction once the information is no longer needed and is not required by law to be retained. Many records must be kept for set periods under tax, employment, health and financial rules. So retain what you are required to keep by archiving it to your current systems, then destroy the old hardware. The destruction and retention obligations work together.

With evidence that reasonable steps were taken: a certificate for each device recording the destruction, backed by a chain-of-custody record showing the device was protected until destroyed. If your handling of personal information is ever examined, that documentation is what shows the destruction obligation under APP 11 was met, rather than leaving you to assert it.

Want disposal that meets APP 11, with evidence? Contact our team or call 1300 048 226.

Meet the Destruction Obligation, With Proof

See how ITC destroys personal information on retired IT to a recognised standard, matched to the sensitivity of the data, protected by a chain of custody and evidenced with a certificate for every device.

Evidence for your auditor

Disposal that stands up to a compliance review

Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.

Talk to a compliance specialist View certifications

Book Your Free Collection

Request a callback