A Shifting Regulatory Landscape
The regulatory environment around data destruction in Australia has been evolving rapidly. Between Privacy Act reform proposals, new state-level initiatives, international developments, and changes to industry standards, organisations need to track multiple regulatory streams to ensure their disposal practices remain compliant. Here’s what’s changed, what’s pending, and what it means for your data destruction processes.
Privacy Act Reform
The most significant regulatory development for Australian data destruction is the ongoing reform of the Privacy Act 1988. Following the Attorney-General’s review and the Privacy Act Review Report, several proposed changes directly affect disposal obligations.
The reforms are expected to strengthen individual rights around data handling, including more explicit rights to erasure. While the Privacy Act already requires destruction of personal information that’s no longer needed (APP 11.2), the reforms propose making this obligation more prescriptive, with clearer guidance on timelines and methods.
Enhanced enforcement powers for the OAIC are part of the reform package. This includes greater capacity to investigate and penalise non-compliance, including failures in data destruction. The OAIC has signalled its intention to use these powers more actively, particularly in areas where compliance has historically been weak.
The proposed expansion of the Privacy Act’s coverage to include all organisations regardless of turnover (removing the current $3 million threshold) would bring many more businesses under its data destruction obligations. Small businesses that currently don’t have formal disposal processes would need to develop them.
- Privacy Act reform expanding coverage and enforcement
- Potential statutory right to erasure (GDPR-style)
- PCI DSS v4.0 full enforcement (mandatory since March 2025)
- ISO 27001:2022 transition completion
- State-level e-waste and data protection developments
- International data transfer framework changes
PCI DSS v4.0 Full Enforcement
PCI DSS v4.0 became fully mandatory in March 2025, replacing v3.2.1. While the core disposal requirements haven’t changed dramatically, v4.0 introduces a more flexible, risk-based approach that requires organisations to demonstrate the effectiveness of their controls rather than simply ticking boxes.
For data destruction specifically, v4.0 emphasises customised approaches. Organisations can now propose alternative controls to meet requirements, as long as they can demonstrate equivalent security outcomes. This flexibility is useful for organisations with unique disposal challenges, but it also requires more robust documentation of why specific methods were chosen.
v4.0 also strengthens requirements around targeted risk analysis and documentation, meaning disposal processes need to be clearly linked to a documented risk assessment that justifies the destruction methods used.
ISO 27001:2022 Transition
The transition period from ISO 27001:2013 to ISO 27001:2022 has been a significant compliance event. The 2022 version restructured the Annex A controls and introduced new controls relevant to disposal, including A.8.10 (Information deletion) which explicitly addresses data lifecycle management including destruction.
Organisations transitioning to the 2022 standard need to review their disposal controls against the new control set. While the fundamental requirements haven’t changed dramatically, the restructuring means that disposal-related controls are now more explicitly called out and auditors will expect to see them addressed clearly in the Statement of Applicability.
State-Level Developments
Several Australian states have been active in the data protection and e-waste space:
Victoria continues to lead on e-waste regulation. The Victorian e-waste landfill ban (in effect since July 2019) has been the template for other states considering similar measures. Victoria’s Recycling Victoria policy includes ongoing investment in e-waste collection and processing infrastructure.
Other states are examining or implementing similar e-waste landfill bans. As these come into effect, the intersection of environmental disposal requirements (e-waste must be recycled) and data protection requirements (data must be destroyed) creates a dual obligation that organisations need to manage together.
State government cyber security policies are being updated across multiple jurisdictions, with implications for how government contractors handle IT disposal. These updates generally align with the ASD Essential Eight and ISM, creating more explicit expectations for disposal practices in the government supply chain.
International Developments Affecting Australia
Several international regulatory changes have flow-on effects for Australian organisations:
GDPR enforcement continues to intensify, with European data protection authorities issuing significant fines for data handling failures, including disposal-related breaches. Australian organisations that handle EU data need to remain current with GDPR enforcement trends.
The evolving landscape of international data transfer frameworks affects how devices containing cross-border data can be disposed of. Changes to adequacy decisions, Standard Contractual Clauses, and other transfer mechanisms can affect disposal logistics for multinational organisations.
The US is also tightening data protection at both federal and state levels. The California Consumer Privacy Act (CCPA) and similar state laws include disposal-related obligations that affect Australian businesses serving US customers.
Critical Minerals and Right to Repair
Two policy areas that indirectly affect data destruction are critical minerals policy and right to repair legislation.
Australia’s Critical Minerals Strategy emphasises the recovery of valuable materials from e-waste, including rare earth elements, cobalt, lithium, and precious metals. This policy direction supports the growth of domestic e-waste recycling infrastructure, which in turn creates more options for organisations seeking certified disposal services.
Right to repair legislation, which is advancing in Australia following the Productivity Commission’s inquiry, will increase the lifespan of electronic devices by making repair more accessible. While this is primarily an environmental benefit, it also has data implications: devices that are repaired and returned to service (rather than disposed of) still need data protection throughout the repair process.
What Organisations Should Do Now
In response to this evolving regulatory landscape, organisations should:
Review current disposal processes: Assess whether your current practices meet both existing and anticipated requirements. If the Privacy Act reforms proceed as proposed, organisations not currently covered will need to develop disposal processes from scratch.
Update policies: Ensure your data destruction policy references current standards and regulations. Policies that reference ISO 27001:2013 or PCI DSS v3.2.1 need updating.
Strengthen documentation: The trend across all frameworks is toward more detailed documentation and evidence of compliance. Invest in documentation quality now rather than scrambling to improve it when new requirements take effect.
Assess provider readiness: Check whether your disposal providers are keeping pace with regulatory changes. Their certifications, processes, and documentation need to evolve alongside your requirements.
Monitor legislative progress: Assign responsibility for tracking relevant regulatory changes. The Attorney-General’s Department, the OAIC, APRA, and state regulators all publish consultation papers, guidance updates, and enforcement actions that signal regulatory direction.
- Audit current disposal processes against both current and anticipated requirements
- Update policies to reference current versions of all applicable standards
- Strengthen documentation and record-keeping
- Assess provider certifications against current standard versions
- Plan for expanded Privacy Act coverage if reforms proceed
- Monitor OAIC, APRA, and state regulator publications for guidance updates
- Include regulatory change management in your annual disposal review
The regulatory direction is clear: more organisations covered, stricter enforcement, and higher expectations for documentation and verification. Organisations that proactively strengthen their disposal practices now will be well-positioned regardless of the specific timing and form of regulatory changes.
For a comprehensive overview of current requirements, see our complete guide to data destruction and our overview of e-waste laws and regulations in Australia.
EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.
