How Each Relevant APP Connects to Device Disposal

The Australian Privacy Principles (APPs) are the cornerstone of privacy regulation in Australia, forming the core of the Privacy Act 1988. There are 13 APPs in total, and while the entire set governs how personal information is handled, several principles have direct and specific relevance to IT equipment disposal. Understanding these connections helps organisations build disposal processes that are compliant by design rather than by accident.

APP 1 – Open and Transparent Management

APP 1 requires organisations to manage personal information in an open and transparent way. This includes having a clearly expressed and up-to-date privacy policy that describes how personal information is handled, including how it is destroyed or de-identified.

For IT disposal, this means your privacy policy should address what happens to personal information when the equipment it’s stored on reaches end of life. You don’t need to detail your specific destruction methods in the public policy, but you should indicate that personal information is destroyed when no longer needed and that appropriate measures are taken to ensure secure destruction.

Internally, APP 1 also requires that your practices match your policy. If your privacy policy states that personal information is securely destroyed, your disposal process needs to deliver on that commitment. A gap between your stated policy and your actual practice is a compliance failure under APP 1.

APP 6 – Use or Disclosure of Personal Information

APP 6 restricts how personal information can be used or disclosed. When IT equipment is disposed of without proper data destruction, the personal information on it becomes accessible to whoever receives the equipment, whether that’s a recycler, a second-hand buyer, or someone who finds it in a skip bin.

This unintended accessibility constitutes a “disclosure” under APP 6, and unless the disclosure falls within one of the permitted exceptions, it’s a breach. The exceptions (consent, direct relationship to the primary purpose, legal requirement, etc.) are unlikely to cover an accidental disclosure through improper disposal.

The practical takeaway: every device that leaves your organisation with personal information intact represents a potential APP 6 breach, regardless of whether anyone actually accesses the data.

APP 8 – Cross-Border Disclosure

APP 8 imposes additional requirements when personal information is disclosed to overseas recipients. If devices containing personal information are exported for recycling, sold to overseas buyers, or sent to international ITAD facilities, APP 8 is engaged.

Before disclosing personal information to an overseas recipient, you must take reasonable steps to ensure the recipient complies with the APPs. You remain accountable for breaches by the overseas recipient as if you had committed them yourself.

This accountability provision is significant for disposal. If you send unwiped equipment overseas and a breach occurs, you’re treated as though you caused the breach. The simplest way to avoid this liability is to destroy all personal information before any device leaves Australia.

APPs most relevant to IT disposal:

  • APP 1: Transparent management, including destruction practices
  • APP 6: Restrictions on use/disclosure (disposal = potential disclosure)
  • APP 8: Cross-border disclosure (international disposal)
  • APP 11: Security and destruction obligations (core disposal APP)
  • APP 12: Access rights (what if someone requests data you’ve destroyed?)

APP 11 – Security of Personal Information

APP 11 is the most directly relevant principle for IT disposal. It has two key components.

APP 11.1 requires organisations to take “reasonable steps” to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. This obligation applies throughout the entire data lifecycle, including during the disposal process. Reasonable steps during disposal include secure storage of decommissioned devices, chain of custody controls during transport, using certified destruction methods, and verifying that destruction was successful.

APP 11.2 requires organisations to take reasonable steps to destroy or de-identify personal information when it is no longer needed for any purpose permitted under the APPs. This is the destruction obligation. “No longer needed” is triggered when the device is decommissioned, as the data’s original purpose has concluded.

The OAIC has provided guidance on what “reasonable steps” means in the context of data destruction. Factors include the nature and sensitivity of the information, the possible consequences of a breach, the practical means available for destruction, and the cost of those means relative to the risk.

For standard business personal information, software wiping to NIST 800-88 Purge standard is generally considered reasonable. For sensitive information (health, financial, identity), higher assurance methods such as physical destruction may be expected. Simple deletion, formatting, or factory resets are generally not considered adequate.

APP 12 – Access to Personal Information

APP 12 gives individuals the right to access their personal information. This creates an interesting intersection with disposal: what happens if someone requests access to information that has already been destroyed?

If you’ve destroyed personal information in compliance with APP 11.2 (it was no longer needed), you can lawfully deny the access request on the grounds that you no longer hold the information. You should be able to explain that the information was destroyed as part of your normal data management processes.

However, if you destroy information specifically to avoid responding to an access request, that’s a different matter entirely. APP 12 requires you to respond to access requests within a reasonable period. Destroying data to frustrate a request is not compliant and could attract regulatory scrutiny.

This means your disposal timing and justification should be documented. Regular, policy-driven disposal is defensible. Sudden, ad hoc destruction following a specific request is not.

APP 13 – Correction of Personal Information

While less commonly discussed in the disposal context, APP 13’s requirement to correct inaccurate information has a practical connection to device disposal. If a correction request is received for information that exists on devices scheduled for disposal, you need to either correct the information before disposal or note that the information is being destroyed in accordance with APP 11.2.

This reinforces the importance of timely disposal. Devices sitting in a disposal queue for extended periods create ongoing obligations under APP 12 and APP 13 until the data is actually destroyed.

What “Reasonable Steps” Looks Like in Practice

The OAIC has provided guidance through its publications, determinations, and Commissioner-initiated investigations that helps define what reasonable steps for disposal include. Based on OAIC guidance, a compliant disposal process includes:

A documented disposal policy covering all device types and data classifications. Destruction methods that render personal information unrecoverable (not just deleted). Verification that destruction was successful. Certificates of destruction with individual asset identification. Due diligence on third-party disposal providers. Chain of custody documentation from decommission to destruction. Regular auditing of disposal practices. Staff training on disposal procedures.

The absence of any of these elements doesn’t automatically constitute a breach, but it weakens the argument that reasonable steps were taken if a breach does occur.

The Notifiable Data Breaches Connection

The Notifiable Data Breaches scheme interacts with the APPs to create additional consequences for disposal failures. Under the scheme, if personal information is improperly disclosed through failed disposal and the breach is likely to cause serious harm, the organisation must notify both the OAIC and the affected individuals.

A disposal-related NDB notification triggers OAIC scrutiny of whether the organisation complied with APP 11. If the investigation reveals inadequate disposal practices, it can lead to formal determinations, enforceable undertakings, or civil penalty proceedings.

The NDB scheme effectively raises the stakes of APP compliance for disposal. Before the scheme, a disposal failure might go unnoticed or unaddressed. Now, there’s a legal obligation to report it, investigate it, and notify affected people, creating multiple points of accountability.

APP-compliant disposal summary:

  • Privacy policy addresses data destruction (APP 1)
  • Data destroyed before devices change hands (APP 6)
  • Data destroyed before any international movement (APP 8)
  • Destruction methods render data unrecoverable (APP 11)
  • Destruction occurs when data is no longer needed (APP 11.2)
  • Access and correction requests managed before disposal (APPs 12-13)
  • Breaches from failed disposal reported under NDB scheme

The APPs provide a clear framework for responsible data handling through disposal. Organisations that align their disposal processes with these principles protect both their compliance position and the privacy of the individuals whose data they hold.

For practical guidance on implementing compliant destruction, see our complete guide to data destruction and our NIST 800-88 explainer.

EWV helps Victorian businesses manage e-waste and IT asset disposal compliantly and sustainably — including collection, certified data destruction, and recycling. Contact us for a free quote.