APP 11 Reasonable Steps
APP 11 Reasonable Steps: What Businesses in Australia Should Actually Be Doing
The OAIC sets out what APP 11 requires. This page covers the harder part: what reasonable steps look like inside a working business, and how you produce dated evidence that they were actually taken across your people, processes and systems.
General information only. This page is not legal advice.
What APP 11 really points toward
APP 11.3: reasonable steps now include organisational measures
The Privacy and Other Legislation Amendment Act 2024 added a new subclause to clause 11 of Schedule 1 to the Privacy Act 1988. Since 11 December 2024, APP 11.3 provides that, for the purposes of APP 11.1 and APP 11.2, and without limiting them, “such steps include technical and organisational measures”. It applies to personal information held from that date, whether the information was acquired or created before or after it.
Sources: Privacy Act 1988 (Cth), Schedule 1, APP 11 · Privacy and Other Legislation Amendment Act 2024 (Cth), Sch 1 Pt 5, items 34–35 · OAIC, APP Guidelines Chapter 11
| Measure | What it covers | Who usually owns it |
|---|---|---|
| Technical | Technological controls and physical measures relating to software and hardware. For example: identity and access management, anti-malware, encryption, data loss prevention, physical controls. | Your IT provider or internal IT team. |
| Organisational | Policies, processes and procedures that protect the security of information. For example: oversight, accountability, staff training, and information security risk management across the organisation. | Management. This is the part that gets assumed, and the part that has to be evidenced. |
What this means for you
Reasonable steps are no longer arguable as a purely technical question. Firewalls and MFA are one part of the clause; the other is whether someone owns each obligation, whether staff were trained, and whether the business can show a dated record of both. Cleverer is built for that second part.
Read the clause and the OAIC’s guidance on it in Chapter 11 of the APP Guidelines, then see what the records look like in practice or check what you could prove today.
What APP 11 data security means in practice
In plain English, APP 11 means your business should not just collect and hold personal information without taking practical steps to protect it. What is reasonable depends on your situation, including the type of information you hold, the risks you face, and the size and nature of your organisation.
Identify risk
Understand what information you hold, where it sits, and what could go wrong.
Put measures in place
Use practical controls across technology, people, and business processes.
Train and assign responsibility
Make sure people know what is expected and who is accountable for what.
Keep it active
Review, refresh, and keep evidence visible over time instead of treating compliance as a one-off event.
Where businesses often fall short
Relying on documents alone
Policies matter, but they do not prove that the organisation is actively maintaining practical compliance.
Not training people properly
If staff and managers do not understand expectations, your compliance position weakens quickly.
Weak accountability
It is harder to show reasonable steps when nobody can clearly explain who was responsible for what.
No ongoing visibility
Effort fades over time when there is no system for tracking current status, overdue actions, or recurring training.
What you should be able to show
- That staff were trained appropriately for their role.
- That managers and leadership had relevant obligations assigned.
- That compliance activity remained visible and current over time.
- That the organisation was taking practical steps, not relying on vague intention.
What is harder to defend
- Generic awareness with no clear completion evidence.
- Policies with no visible accountability behind them.
- Old training records with no recertification or status tracking.
- Compliance effort that only appears after a problem has already happened.
Would your reasonable steps hold up if the OAIC reviewed your practices?
Answer 10 questions to assess whether your organisation is meeting its APP 11 obligations and whether your evidence would be sufficient if tested.
Are You Meeting Your Privacy Act Obligations?
The Privacy Act 1988 and APP 11 require organisations to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. This assessment helps identify where your obligations may not be met.
Answer 10 questions to identify where your business may not be taking reasonable steps.
How Cleverer helps
Cleverer runs the organisational side of APP 11.3. It assigns each obligation to a named person, delivers role-based training and records who completed it and when, versions your policies with an approval trail, and drives the recurring reviews that keep the position current. When a client, insurer, board or regulator asks what you actually did, you export the record instead of reconstructing it.
Why training and accountability matter under APP 11
Training becomes visible
You can more easily show that people were trained and when they completed required pathways.
Responsibilities are clearer
Different roles can be assigned different obligations rather than relying on one generic expectation for everyone.
Ongoing effort is easier to explain
Recurring status, certification, and overdue visibility help support a more defensible ongoing compliance position.
Related compliance resources
- Privacy Act & compliance frameworks
- What regulators check under the Privacy Act
- How to prove cyber compliance
- Notifiable Data Breach obligations
- SMB1001: a structured way to do the same work
- The records that make reasonable steps demonstrable
- AI and reasonable steps: what generated documents cannot show
Need a more practical way to support APP 11 reasonable steps?
Cleverer helps make the people-side of compliance visible through training, accountability, certification evidence, and recurring status tracking.
Common questions about APP 11 reasonable steps
What does APP 11 require for data security?
APP 11 requires an APP entity to take reasonable steps to protect the personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure. Since 11 December 2024, APP 11.3 states those steps include technical and organisational measures.
Does APP 11 prescribe a fixed checklist?
No. Reasonable steps depend on context, including the nature of the information held, the risk environment, and the size and type of organisation.
Are technical controls enough on their own?
Usually not. Technical measures matter, but training, accountability, and organisational practices are also highly relevant to a practical compliance position.
Why does training matter for APP 11?
Because people still handle information, make decisions, and create risk. Untrained staff weaken the organisation’s overall security posture.
Can a platform make a business APP 11 compliant on its own?
No. APP 11.3 covers both technical and organisational measures. In practice the technical measures usually sit with your IT provider and the organisational measures with management. Cleverer runs the organisational side and produces the evidence behind it. The technical controls still have to be in place.
What evidence supports a reasonable steps position?
Records that show the steps were real and ongoing: dated policies with approval trails, named training completions matched to roles, obligations assigned to specific people, and review cycles that ran on schedule rather than being reconstructed after an incident.