In January 2026, the Office of the Australian Information Commissioner launched its first-ever formal compliance sweep, reviewing around 60 organisations across six sectors. The message was clear: Australia’s privacy regulator has moved from publishing guidance to actively looking for gaps. If your IT asset disposal process is not documented and defensible, that gap could be next.

What APP 11 actually requires

Under the Privacy Act 1988, Australian Privacy Principle 11 requires covered entities to take reasonable steps to destroy or de-identify personal information they no longer need. Most organisations focus on network security, access controls, and breach response plans. Far fewer have applied the same rigour to what happens when a server, laptop, or storage device is retired. That is APP 11 in practice, and it now has more teeth.

A December 2024 amendment introduced APP 11.3, which requires that reasonable steps include technical and organisational measures for information held from that date forward. Informal disposal, reimaging, or simply handing equipment to a general recycler does not meet that standard. The recognised benchmark for media sanitisation is NIST 800-88 Rev. 2, which covers overwriting, purging, and physical destruction of drives. For an Australian context, AS/NZS 5377 governs the collection and handling of end-of-life electrical equipment. When a regulator or auditor asks how your organisation destroys personal information on retired hardware, those are the benchmarks they check against.

The penalty stakes have changed

The Privacy and Other Legislation Amendment Act 2024 raised maximum penalties for serious or repeated privacy interferences to the greater of $50 million, three times the value of any benefit obtained from the conduct, or 30 per cent of adjusted turnover. For a mid-size Victorian business, those numbers are not hypothetical. The OAIC has indicated its 2026 enforcement priorities include entities with prior data breach history. Organisations that disposed of hardware informally and later found that data was recovered from resold or auctioned devices have faced exactly this kind of scrutiny in comparable markets overseas.

The Victorian overlay

Victorian businesses carry an additional compliance layer. The state’s e-waste landfill ban, which has been in effect since 1 July 2019, prohibits disposing of IT equipment through general waste streams. A properly documented ITAD process through an AS/NZS 5377-aligned provider addresses both the Privacy Act destruction requirement and the landfill ban in a single auditable step. You do not need two separate compliance programs. They resolve together.

What a defensible disposal program looks like

A program that can withstand an OAIC audit has five elements. First, a written procedure that specifies how retired devices move from decommission to destruction. Second, a provider that documents sanitisation to NIST 800-88 Rev. 2 or performs physical destruction for drives that cannot be sanitised. Third, a certificate of destruction for every asset, linking the serial number to the method and date. Fourth, a chain of custody record covering every stage from collection to processing. Fifth, material reporting covering CO2e avoided and diversion from landfill, if you have sustainability reporting obligations under ASRS or equivalent frameworks. EWV’s CircularTrack reporting tool produces all of this in one place, aligned to ISO 14001 and ISO 27001 Annex A.8.10.

The window to act is now

The OAIC covered six sectors in its January sweep. More will follow. Organisations that can show a documented, standards-aligned IT disposal process answer regulator questions quickly and move on. Those that cannot face extended investigation and potential penalty notices.

If you are not confident your IT disposal process would hold up to a privacy audit, contact EWV to review your current program and put the right documentation in place before a regulator asks to see it.