Every day, Australian businesses store customer names, addresses, health details and payment records inside the software they use. That software might be a booking system, an accounting platform or a customer database. Whatever it is, Australian data privacy laws set clear rules for how it must protect that information. At the centre of those rules is APP 11 compliance, the part of the law that deals with security. It has become one of the most closely watched areas of business regulation in Australia, and the cost of getting it wrong has never been higher.
What APP 11 Asks of Your Business
The Privacy Act 1988 includes thirteen Australian Privacy Principles, or APPs. Principle 11 covers the security of personal information, and it has two parts.
The first part says you must take reasonable steps to protect the personal information you hold from misuse, interference, loss, unauthorised access, change or disclosure. The second part is often forgotten. Once you no longer need the information, you must take reasonable steps to destroy it or de-identify it, unless another law says you have to keep it.
Who has to follow these rules
The law mainly covers businesses with an annual turnover above $3 million, plus Australian Government agencies. Some smaller businesses are covered no matter their size. These include health service providers, businesses that trade in personal information, and businesses that choose to opt in. If you run a physio clinic with two staff, APP 11 still applies to you.
What “reasonable steps” means now
In December 2024, Parliament passed the Privacy and Other Legislation Amendment Act 2024. It made clear that reasonable steps include both technical measures and organisational measures. Technical measures include safeguards such as encryption and access controls. Organisational measures are things like staff training, written policies and a tested incident response plan. Buying good software is not enough on its own. Your people and processes must protect the information too.
Why Business Software Is Where Most Risk Sits
Software makes collecting data simple, but it can also make it easy to lose track of it. Old customer records often sit in legacy systems for years. Staff who left long ago may still have logins. Backups may be copied to places nobody tracks.
The numbers show just how serious this risk can be. The Office of the Australian Information Commissioner received 532 data breach notifications between January and June 2025, according to its latest published statistics. Malicious or criminal attacks caused 59 per cent of them. Human error caused 37 per cent, up sharply from 29 per cent in the previous period. Health providers reported the most breaches, followed by finance.
The same report pointed to a breach where a software developer’s unauthorised script exposed private documents. The Commissioner’s message was simple. You are responsible for the actions of your third-party providers.
Choosing and Managing Software Vendors
Many Australian businesses now run on cloud platforms hosted by outside companies. That does not move your legal duty onto the vendor. If your cloud provider suffers a breach, the Commissioner will still ask what you did to check that provider.
Before signing a contract, we suggest asking a vendor these questions:
- Where is our data stored? If it sits overseas, APP 8 adds extra duties. You can often remain accountable for how an overseas provider handles the data.
- What security certifications do you hold? The Commissioner’s office points to the ISO 27000 series as one useful benchmark.
- How quickly will you notify us if a data breach occurs? Put a firm timeframe in the contract.
- Can we delete data completely when we leave? This supports your destruction duty under APP 11.
For a deeper checklist, see evaluating cloud software vendors for privacy compliance.
Building APP 11 Compliance Into Daily Operations
The Commissioner’s Guide to securing personal information sets out what good practice looks like. We have grouped its key ideas into three habits.
Limit who can see what
Give staff access only to the data required for their role. Turn on multi-factor sign-in, which asks for a second check such as a phone code, especially for accounts that can view sensitive records. Keep audit logs that show who opened which file and when. Remove access on the same day an employee leaves.
Protect the data itself
Encrypt databases, backups and information moving between systems. Store your encryption keys somewhere separate and secure. Review these settings every year, because methods that were strong five years ago may now be weak.
Plan for the bad day
Write a data breach response plan, train staff on it and run practice drills. A plan that sits unread in a shared drive will not help you at 2 am during a ransomware attack. Our guide to creating a data breach response plan walks through each step.
What Happens When Businesses Fall Short
Penalties are now serious. For the most serious privacy breaches, a company can face the greater of $50 million, three times the benefit it gained, or 30 per cent of its adjusted turnover for the relevant period. The Commissioner can also now issue infringement notices for less serious breaches without going to court.
A real case shows how APP 11 plays out. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million after a 2022 cyber attack, as reported by Hamilton Locke. The court found weak security controls in a business the company had bought, along with poor incident response plans and training. That penalty was set under the old, lower maximum. The same failures today could cost far more.
People can also take action themselves. Since June 2025, individuals have been able to sue for serious invasions of privacy under a new statutory tort.
Preparing for Changes Still Ahead
More change is coming. From 10 December 2026, businesses must explain in their privacy policies when they use computer programs to make decisions that significantly affect people. If your software scores loan applicants or screens job seekers automatically, that rule applies to you.
A second round of reforms is still under discussion. The Government supports removing the small business exemption in principle, but no bill has passed and no start date is set. Smaller businesses that build good security habits now will be well placed whatever happens. Learn more in [Link: upcoming Privacy Act reforms for small business].
Conclusion
Privacy protection in Australia has moved from a box-ticking exercise to a core business duty with real consequences. Security under APP 11 depends on three things working together: the software you choose, the vendors you trust and the habits your team follows every day. The businesses that do well treat personal information as something borrowed from their customers. They keep only what they need, guard it carefully and let it go when its purpose ends. That mindset protects people, and it also protects the long-term trust every Australian business relies on.
Frequently Asked Questions
No. The law does not name any product. It judges whether your steps were reasonable given the sensitivity of the data, your size and the risk of harm. A hospital needs stronger controls than a local café.
If you suspect an eligible breach, you have up to 30 days to assess it. Once you confirm it is likely to cause serious harm, you must notify the Commissioner and affected people as soon as practicable.
Properly de-identified data generally falls outside the Act. However, if it can be re-identified by combining it with other data, it may count as personal information again.
Private sector employee records are partly exempt when used for employment purposes. Customer and supplier data gets no such exemption.

Leave a Reply