Why the Privacy Act Applies to Your End-of-Life Devices

Most Australian businesses know they have obligations under the Privacy Act 1988 when it comes to collecting and storing personal information. Far fewer realise those obligations extend to what happens when IT equipment reaches end of life. The Privacy Act doesn’t stop applying to personal data just because you’ve finished using the device it’s stored on. If personal information is on a device, the Act’s requirements follow that data until it’s properly destroyed.

This creates a practical problem for organisations that replace IT equipment without robust disposal processes. Every laptop, phone, server, and printer that leaves your premises with personal data still on it is a potential compliance failure and a data breach waiting to happen.

What the Privacy Act Actually Requires

The Privacy Act 1988 establishes the Australian Privacy Principles (APPs), which govern how organisations handle personal information. Several of these principles directly relate to IT equipment disposal:

APP 11 – Security of personal information: This is the most directly relevant principle. It requires organisations to take “reasonable steps” to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. When a device containing personal information is disposed of, APP 11 requires that the information is destroyed or de-identified. Simply deleting files or formatting a drive does not meet the “reasonable steps” threshold, as data can be recovered using readily available tools.

APP 11.2 – Destruction or de-identification: When personal information is no longer needed for any purpose permitted under the APPs, organisations must take reasonable steps to destroy or de-identify it. This obligation triggers when equipment is decommissioned, as the data on decommissioned devices is, by definition, no longer needed for its original purpose.

Key Privacy Act requirements for IT disposal:

  • Personal information must be destroyed when no longer needed (APP 11.2)
  • “Reasonable steps” must be taken to secure data throughout the disposal process (APP 11.1)
  • Destruction must be irreversible, not just deletion or formatting
  • The obligation applies to all personal information, not just sensitive categories
  • Organisations must maintain records of their data destruction processes

What Counts as “Reasonable Steps”

The Privacy Act uses the phrase “reasonable steps” rather than prescribing specific technical methods. What counts as reasonable depends on the nature and sensitivity of the information, the possible consequences of a breach, and the practicality of protective measures.

The Office of the Australian Information Commissioner (OAIC) has provided guidance indicating that reasonable steps for data destruction include using software that overwrites data to recognised standards such as NIST 800-88, physical destruction methods like shredding, degaussing, or disintegration for storage media, maintaining chain of custody records during the disposal process, and verifying that destruction has been completed successfully.

Simply formatting a drive, performing a factory reset, or deleting files is generally not considered sufficient. These methods leave data recoverable using standard forensic tools, meaning the personal information has not been effectively “destroyed” as the Act requires.

For a detailed comparison of destruction methods, see our guide to hard drive destruction methods.

Which Organisations Are Covered

The Privacy Act applies to most organisations with an annual turnover of more than $3 million, as well as all health service providers, organisations that trade in personal information, and certain other categories regardless of turnover.

However, many smaller organisations voluntarily comply with the Privacy Act as a matter of good practice, and some are required to by contracts with larger organisations or government agencies. If you handle personal information of any kind, treating the Privacy Act’s requirements as your minimum standard is a sensible approach regardless of your legal obligation.

Government agencies are covered by the Act but are subject to some different provisions. They’re generally held to the same or higher standards regarding data destruction.

The Notifiable Data Breaches Scheme

Since February 2018, the Notifiable Data Breaches (NDB) scheme has added teeth to the Privacy Act. If a data breach is likely to result in serious harm to any individual, the organisation must notify both the OAIC and the affected individuals.

Improper IT disposal is a recognised source of data breaches. If devices containing personal information are sold, donated, or recycled without proper data destruction, and someone accesses that data, it constitutes a breach that may trigger notification obligations.

The consequences of an NDB notification include regulatory investigation by the OAIC, potential enforcement action including civil penalties, reputational damage from public notification, legal liability to affected individuals, and the operational cost of managing the breach response.

Civil penalties under the Privacy Act can reach up to $50 million, three times the benefit obtained from the breach, or 30% of turnover for the relevant period, whichever is greater. While maximum penalties are rare, the OAIC has been increasingly active in enforcement actions.

Common Compliance Failures

These are the disposal practices that most commonly create Privacy Act compliance issues:

No formal disposal process: Equipment gets discarded ad hoc, with no consistent data destruction step. Different departments handle disposal differently, and there’s no central oversight or documentation.

Relying on deletion or formatting: IT teams delete files or format drives and consider the job done. This leaves data recoverable and doesn’t meet the “reasonable steps” standard.

Forgetting about non-obvious devices: Printers, multifunction devices, network equipment, and IoT devices all store data but are often disposed of without any data destruction. A printer’s internal hard drive can contain thousands of stored documents.

Poor handoff to third parties: Devices are given to recyclers or disposal companies without confirming their data destruction capabilities or requiring certificates of destruction. The organisation remains responsible for the data even after the physical device leaves their premises.

No documentation: Even when data destruction is performed, there’s no record of what was done, when, by whom, and to which devices. Without documentation, you can’t demonstrate compliance in an audit or investigation.

Building a Compliant Disposal Process

A Privacy Act-compliant IT disposal process doesn’t need to be complex, but it does need to be consistent and documented. The essentials are:

Asset register: Know what devices you have and what data they hold. You can’t dispose of data you don’t know about.

Standard destruction method: Choose a data destruction method appropriate to the sensitivity of the data. Software wiping to NIST 800-88 standards is appropriate for most business data. Physical destruction is warranted for highly sensitive information or when software wiping isn’t possible.

Verification: Confirm that destruction was successful. For software wiping, this means verification scans. For physical destruction, this means visual confirmation that the media is destroyed beyond recovery.

Documentation: Record what was destroyed, when, how, and by whom. Issue or obtain certificates of destruction with individual asset serial numbers.

Third-party management: If using external providers, verify their capabilities, certifications, and insurance. Include data destruction requirements in contracts and require certificates of destruction for every batch.

For more on building a compliant process, see our guide to building an IT asset disposal policy.

The OAIC’s Expectations

The OAIC has made it clear through guidance and enforcement actions that organisations are expected to have systematic processes for data destruction, not just good intentions. The Commissioner has specifically noted that personal information must be destroyed when it is no longer needed, destruction must render data unrecoverable, organisations must be able to demonstrate their destruction processes, and outsourcing disposal does not outsource the obligation.

In practical terms, this means that if a device you disposed of turns up with personal data still on it, saying “we gave it to a recycler” is not a defence. You need to be able to show that your process was designed to prevent that outcome and that you took reasonable steps to verify the recycler’s capabilities.

Minimum documentation for Privacy Act compliance:

  • Written IT disposal policy covering data destruction
  • Asset register tracking devices through to disposal
  • Certificates of destruction (individual serial numbers preferred)
  • Records of destruction method used for each device
  • Due diligence records for third-party disposal providers
  • Regular review and audit of the disposal process

Taking Action

If your organisation doesn’t have a documented IT disposal process that addresses data destruction, the time to create one is now, not after a breach. The Privacy Act’s requirements aren’t new, but enforcement is increasingly active, and the consequences of non-compliance are growing.

Start with an honest assessment of your current practices. Identify gaps. Implement a consistent destruction process with proper documentation. And if you use third parties for disposal, make sure they can demonstrate their own compliance through certifications and verifiable processes.

For a comprehensive overview of data destruction standards and methods, explore our complete guide to data destruction for Australian businesses.

EWV helps Victorian businesses manage e-waste and IT asset disposal compliantly and sustainably — including collection, certified data destruction, and recycling. Contact us for a free quote.