Skip to main content
Skip to content

APP 11 Reasonable Steps

APP 11 Reasonable Steps: What Businesses in Australia Should Actually Be Doing

The OAIC sets out what APP 11 requires. This page covers the harder part: what reasonable steps look like inside a working business, and how you produce dated evidence that they were actually taken across your people, processes and systems.

General information only. This page is not legal advice.

What APP 11 really points toward

1
Active protection of personal information APP 11 is about taking reasonable steps, not passively assuming things are fine.
2
Technical and organisational measures Reasonable steps are broader than software settings alone.
3
Practical accountability People need to know what they are responsible for and what good handling looks like.
4
Evidence of ongoing effort Businesses are in a stronger position when they can show active training and compliance visibility over time.
Reasonable steps are ongoing, not a one-off
Technical controls are only part of APP 11.3
Training and accountability are organisational measures
Dated evidence is what gets tested
The 2024 change

APP 11.3: reasonable steps now include organisational measures

The Privacy and Other Legislation Amendment Act 2024 added a new subclause to clause 11 of Schedule 1 to the Privacy Act 1988. Since 11 December 2024, APP 11.3 provides that, for the purposes of APP 11.1 and APP 11.2, and without limiting them, “such steps include technical and organisational measures”. It applies to personal information held from that date, whether the information was acquired or created before or after it.

Sources: Privacy Act 1988 (Cth), Schedule 1, APP 11 · Privacy and Other Legislation Amendment Act 2024 (Cth), Sch 1 Pt 5, items 34–35 · OAIC, APP Guidelines Chapter 11

Measure What it covers Who usually owns it
Technical Technological controls and physical measures relating to software and hardware. For example: identity and access management, anti-malware, encryption, data loss prevention, physical controls. Your IT provider or internal IT team.
Organisational Policies, processes and procedures that protect the security of information. For example: oversight, accountability, staff training, and information security risk management across the organisation. Management. This is the part that gets assumed, and the part that has to be evidenced.

What this means for you

Reasonable steps are no longer arguable as a purely technical question. Firewalls and MFA are one part of the clause; the other is whether someone owns each obligation, whether staff were trained, and whether the business can show a dated record of both. Cleverer is built for that second part.

Read the clause and the OAIC’s guidance on it in Chapter 11 of the APP Guidelines, then see what the records look like in practice or check what you could prove today.

Plain English

What APP 11 data security means in practice

In plain English, APP 11 means your business should not just collect and hold personal information without taking practical steps to protect it. What is reasonable depends on your situation, including the type of information you hold, the risks you face, and the size and nature of your organisation.

1

Identify risk

Understand what information you hold, where it sits, and what could go wrong.

2

Put measures in place

Use practical controls across technology, people, and business processes.

3

Train and assign responsibility

Make sure people know what is expected and who is accountable for what.

4

Keep it active

Review, refresh, and keep evidence visible over time instead of treating compliance as a one-off event.

Common blind spots

Where businesses often fall short

📄

Relying on documents alone

Policies matter, but they do not prove that the organisation is actively maintaining practical compliance.

👥

Not training people properly

If staff and managers do not understand expectations, your compliance position weakens quickly.

🧭

Weak accountability

It is harder to show reasonable steps when nobody can clearly explain who was responsible for what.

🕒

No ongoing visibility

Effort fades over time when there is no system for tracking current status, overdue actions, or recurring training.

What you should be able to show

  • That staff were trained appropriately for their role.
  • That managers and leadership had relevant obligations assigned.
  • That compliance activity remained visible and current over time.
  • That the organisation was taking practical steps, not relying on vague intention.

What is harder to defend

  • Generic awareness with no clear completion evidence.
  • Policies with no visible accountability behind them.
  • Old training records with no recertification or status tracking.
  • Compliance effort that only appears after a problem has already happened.
Self-Assessment

Would your reasonable steps hold up if the OAIC reviewed your practices?

Answer 10 questions to assess whether your organisation is meeting its APP 11 obligations and whether your evidence would be sufficient if tested.

Privacy Act Compliance Assessment

Are You Meeting Your Privacy Act Obligations?

The Privacy Act 1988 and APP 11 require organisations to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. This assessment helps identify where your obligations may not be met.

Answer 10 questions to identify where your business may not be taking reasonable steps.

Step 1 of 3

Data & Handling

1. Does your business have a documented process for how personal information is collected, stored, and disposed of?

2. Have all staff who handle personal data completed cyber compliance obligations appropriate to their role?

3. Can you produce evidence of compliance if requested by an insurer, client, or regulator today?

Step 2 of 3

Processes & Evidence

4. Does your business have a documented data breach response plan that staff have been made aware of?

5. Are compliance certifications tracked with expiry dates and renewal processes?

6. Do managers and team leaders understand their oversight responsibilities for cyber compliance?

Step 3 of 3

Governance & Oversight

7. Has a director or senior leader reviewed the organisation's cyber compliance posture in the last 12 months?

8. Does your business differentiate compliance obligations by role (staff, managers, directors)?

9. Are third-party access and data sharing arrangements documented and reviewed?

10. Does your business review and update its compliance measures at least annually?

How Cleverer helps

Cleverer runs the organisational side of APP 11.3. It assigns each obligation to a named person, delivers role-based training and records who completed it and when, versions your policies with an approval trail, and drives the recurring reviews that keep the position current. When a client, insurer, board or regulator asks what you actually did, you export the record instead of reconstructing it.

Practical outcomes

Why training and accountability matter under APP 11

Training becomes visible

You can more easily show that people were trained and when they completed required pathways.

Responsibilities are clearer

Different roles can be assigned different obligations rather than relying on one generic expectation for everyone.

Ongoing effort is easier to explain

Recurring status, certification, and overdue visibility help support a more defensible ongoing compliance position.

Need a more practical way to support APP 11 reasonable steps?

Cleverer helps make the people-side of compliance visible through training, accountability, certification evidence, and recurring status tracking.

FAQ

Common questions about APP 11 reasonable steps

What does APP 11 require for data security?

APP 11 requires an APP entity to take reasonable steps to protect the personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure. Since 11 December 2024, APP 11.3 states those steps include technical and organisational measures.

Does APP 11 prescribe a fixed checklist?

No. Reasonable steps depend on context, including the nature of the information held, the risk environment, and the size and type of organisation.

Are technical controls enough on their own?

Usually not. Technical measures matter, but training, accountability, and organisational practices are also highly relevant to a practical compliance position.

Why does training matter for APP 11?

Because people still handle information, make decisions, and create risk. Untrained staff weaken the organisation’s overall security posture.

Can a platform make a business APP 11 compliant on its own?

No. APP 11.3 covers both technical and organisational measures. In practice the technical measures usually sit with your IT provider and the organisational measures with management. Cleverer runs the organisational side and produces the evidence behind it. The technical controls still have to be in place.

What evidence supports a reasonable steps position?

Records that show the steps were real and ongoing: dated policies with approval trails, named training completions matched to roles, obligations assigned to specific people, and review cycles that ran on schedule rather than being reconstructed after an incident.

© 2026 Cleverer. Human-layer cyber compliance for Australian businesses.