A Cross-Reference Guide to Destruction Obligations
Australian organisations rarely operate under a single compliance framework. A financial services company might need to satisfy APRA CPS 234, PCI DSS, the Privacy Act, ISO 27001, and contractual requirements from its clients, all simultaneously. Almost every major compliance framework that deals with information security includes requirements for data destruction, though they express those requirements differently.
This guide maps the data destruction requirements across the frameworks most commonly encountered by Australian businesses, helping you understand your obligations and identify a unified approach that satisfies all of them.
Australian Privacy Act 1988
Destruction trigger: When personal information is no longer needed for any purpose permitted under the Australian Privacy Principles.
Standard required: “Reasonable steps” to destroy or de-identify. The OAIC’s guidance indicates this means rendering data unrecoverable using recognised methods. Simple deletion or formatting is insufficient.
Documentation required: Not explicitly mandated by the Act, but the OAIC expects organisations to demonstrate their processes. Certificates of destruction are considered best practice.
Applies to: Organisations with annual turnover exceeding $3 million, health service providers, and certain other categories.
Notifiable Data Breaches Scheme
Relevance to destruction: Improper disposal that results in unauthorised access to personal information triggers notification obligations if serious harm is likely. This makes proper destruction both a preventive measure and a compliance obligation.
Timeline: 30-day assessment period from when the organisation becomes aware of a suspected breach. If notifiable, notify the OAIC and affected individuals as soon as practicable.
Consequence of failure: Civil penalties up to $50 million or 30% of turnover for serious or repeated interferences with privacy.
ISO 27001:2022
Relevant controls: A.7.14 (Secure disposal or re-use of equipment), A.7.10 (Storage media), A.5.9 (Asset inventory), A.8.10 (Information deletion).
Standard required: Risk-based approach. Destruction method must be proportionate to the data classification. Higher sensitivity requires more rigorous destruction. Must verify that data has been removed or securely overwritten.
Documentation required: Extensive. Policy documentation, risk assessments, destruction records, supplier assessments, audit evidence, and management review records.
Applies to: Any organisation seeking or maintaining ISO 27001 certification.
- Documented policy: ISO 27001, PCI DSS, APRA CPS 234, NIST CSF
- Asset-level tracking: ISO 27001, PCI DSS, APRA CPS 234, ASD ISM
- Specific destruction standards: NIST 800-88, ASD ISM, PCI DSS
- Certificates of destruction: All frameworks (as evidence of compliance)
- Third-party assessment: ISO 27001, PCI DSS, APRA CPS 234
- Board-level reporting: APRA CPS 234, Corporations Act duties
PCI DSS v4.0
Relevant requirements: Requirement 3 (Protect stored account data), Requirement 9 (Restrict physical access), Requirement 12 (Policy framework).
Standard required: Cardholder data must be rendered unrecoverable. References industry standards for destruction methods. Methods must be appropriate to the media type (different approaches for HDD vs SSD).
Documentation required: Disposal policy, destruction records, service provider management documentation, and evidence of quarterly reviews.
Applies to: Any organisation that processes, stores, or transmits payment card data.
APRA CPS 234
Relevant requirements: Information asset identification, security capability, policy framework, incident management, third-party management, Board accountability.
Standard required: Information security capability commensurate with threats. For disposal, this means processes appropriate to the volume and sensitivity of data on decommissioned equipment.
Documentation required: Policy framework, asset classification, third-party assessments, incident records, Board reporting.
Applies to: All APRA-regulated entities (banks, insurers, super funds).
ASD Information Security Manual (ISM)
Relevant controls: Media sanitisation and destruction controls, classified at different levels based on data sensitivity.
Standard required: Prescriptive by classification level. OFFICIAL/OFFICIAL:Sensitive requires Clear or Purge-level sanitisation. PROTECTED requires Purge. SECRET and above requires physical destruction to specified particle sizes.
Documentation required: Sanitisation records, verification evidence, personnel clearance records for those performing destruction.
Applies to: Commonwealth government agencies (mandatory), defence contractors and government suppliers (typically contractual).
NIST 800-88 Rev. 2
Nature: A guideline rather than a regulatory requirement, but widely referenced by other frameworks as the technical standard for media sanitisation.
Levels: Clear (protects against simple recovery), Purge (protects against laboratory techniques), Destroy (renders media physically unusable). Each level specifies methods for different media types.
Documentation required: Sanitisation verification records, decision rationale for chosen level.
Applies to: Referenced by Privacy Act guidance, ISO 27001 implementations, PCI DSS, ASD ISM, and most other frameworks as the de facto technical standard.
GDPR
Relevant articles: Article 5 (Data minimisation), Article 17 (Right to erasure), Article 25 (Privacy by design), Article 28 (Processor obligations), Article 32 (Security of processing).
Standard required: Data must be erased “without undue delay” when the legal basis for processing no longer applies. Erasure must render data irrecoverable.
Documentation required: Records of processing activities (Article 30), data protection impact assessments where applicable, processor agreements covering destruction.
Applies to: Australian organisations handling personal data of EU residents.
AS/NZS 5377
Nature: Australian/New Zealand standard for the collection, storage, transport, and treatment of end-of-life electrical and electronic equipment.
Relevance to destruction: Provides the framework for e-waste handling processes, including data-bearing devices. Certification demonstrates compliant handling of e-waste throughout the disposal chain.
Documentation required: Operational procedures, quality management records, environmental compliance records.
Applies to: E-waste recyclers and ITAD providers seeking certification. Referenced by organisations selecting disposal providers.
Building a Unified Approach
Rather than maintaining separate processes for each framework, organisations benefit from a single disposal process designed to satisfy the most demanding requirements.
In practice, this means adopting NIST 800-88 Purge-level sanitisation as the default method (satisfies all frameworks), using physical destruction for highly sensitive data or when software wiping isn’t possible (satisfies ASD ISM SECRET+ requirements and provides maximum assurance), maintaining asset-level documentation with serial numbers, destruction method, date, and verification (satisfies all documentation requirements), conducting third-party provider due diligence with formal assessments and contractual controls (satisfies ISO 27001, PCI DSS, and APRA requirements), and reporting disposal activities to senior management and the Board (satisfies APRA CPS 234 and Corporations Act duties).
- Data destruction to NIST 800-88 Purge (or Destroy for high-sensitivity data)
- Individual asset tracking with serial numbers
- Certificates of destruction for every disposal event
- Documented chain of custody from decommission to destruction
- Assessed and contracted third-party providers
- Written policy approved at senior management or Board level
- Regular internal audits of disposal processes
- Incident response procedures for disposal-related security events
This unified approach costs no more than a framework-specific approach but provides compliance assurance across all applicable frameworks. It also simplifies audit preparation, as the same evidence base satisfies multiple auditors.
For detailed guidance on implementing these methods, see our NIST 800-88 guide and our complete guide to data destruction for Australian businesses.
EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.
