Personal Risk for Directors Who Overlook IT Disposal

When a data breach occurs because IT equipment was improperly disposed of, the consequences don’t stop at the organisation. Directors and officers can face personal liability for failing to ensure adequate data protection governance, including disposal practices. The trend in Australian regulation is toward greater personal accountability, and data protection is an area where this accountability is being actively enforced.

This isn’t theoretical risk. Regulatory bodies including the OAIC, APRA, and ASIC have all signalled that they expect Boards and senior management to take active responsibility for information security, which includes the secure disposal of IT assets.

The Legal Basis for Director Liability

Director liability for disposal-related breaches can arise from several legal sources:

Privacy Act 1988: Section 13G of the Privacy Act provides for civil penalties for serious or repeated interferences with privacy. While penalties are primarily directed at the organisation, individuals who are “involved in” a contravention can also be held liable. A director who was aware of inadequate disposal practices or who failed to establish appropriate governance could be considered “involved.”

Corporations Act 2001: Sections 180-184 impose duties on directors to act with reasonable care and diligence, in good faith, for proper purposes, and to not misuse their position. Failing to ensure adequate information security, including disposal, could constitute a breach of these duties if it leads to harm to the company or its stakeholders.

APRA CPS 234: For APRA-regulated entities, CPS 234 explicitly requires the Board to ensure information security is maintained. Board members who fail in this obligation face APRA enforcement action, which can include disqualification orders.

Work Health and Safety: While less commonly associated with data destruction, improper handling of e-waste (particularly batteries and hazardous materials) can engage WHS obligations, with directors bearing personal liability for safety failures.

Sources of director liability for disposal breaches:

  • Privacy Act s13G (involvement in contraventions)
  • Corporations Act ss180-184 (directors’ duties)
  • APRA CPS 234 (Board accountability for information security)
  • State privacy legislation (health records, state public sector)
  • Contract law (personal guarantees in service agreements)
  • Negligence (duty of care to affected individuals)

When Directors Are Personally Exposed

Director liability typically arises in situations characterised by knowledge or wilful ignorance:

Known risks not addressed: The Board was informed of inadequate disposal practices (through an audit finding, risk report, or management briefing) but failed to direct remediation. This demonstrates awareness coupled with inaction.

No governance framework: The organisation had no documented information security policy, no disposal procedures, and no Board-level oversight of data protection. This suggests the Board failed to establish basic governance.

Cost-cutting at the expense of security: The Board approved budget reductions that eliminated proper disposal processes in favour of cheaper, less secure alternatives. This directly links a Board decision to the resulting vulnerability.

Repeat incidents: A disposal-related breach occurred previously, and the Board failed to ensure corrective action was taken. A second breach in the same area is very difficult to defend against personal liability claims.

Regulatory warning ignored: A regulator (OAIC, APRA) provided guidance or issued a warning about disposal practices, and the Board didn’t act on it.

The Evolving Enforcement Landscape

Australian regulators are increasingly willing to pursue individuals, not just organisations, for data protection failures.

The OAIC’s enhanced enforcement powers following the 2022 Privacy Act amendments include the ability to seek civil penalties against individuals involved in privacy contraventions. The maximum penalties for serious or repeated interferences with privacy, which can reach $50 million or more for organisations, also extend to individuals at reduced but still significant levels.

APRA has demonstrated through its enforcement actions in other areas (notably the IOOF and Westpac matters) that it will pursue individual accountability when Board-level governance failures contribute to regulatory breaches. CPS 234’s explicit Board accountability provisions make it likely that APRA will apply the same approach to information security failures, including disposal-related breaches.

ASIC has also shown interest in cybersecurity governance as a director responsibility. ASIC’s public guidance to Boards emphasises that cyber resilience is a governance issue, not just a technical one, and that directors need to be able to demonstrate they took reasonable steps to manage cyber risks.

What Courts Look For

In assessing whether directors met their duty of care regarding data destruction, courts typically consider:

Industry standard: Did the organisation’s disposal practices meet the standard expected of a reasonable organisation of similar size and industry? If industry-standard tools and methods were available and the organisation chose not to use them, the directors’ position is weakened.

Proportionality: Was the level of investment in disposal processes proportionate to the risk? An organisation handling millions of customer records is expected to invest more in disposal security than a small business with minimal personal data.

Information available to the Board: What did the directors know, or what should they reasonably have known, about disposal risks? Regular Board reporting on information security, including disposal, is both expected and protective.

Expert advice: Did the Board seek and act on expert advice regarding data protection and disposal? Relying on qualified advisors (CISOs, external consultants, legal counsel) demonstrates diligence.

Response to warnings: How did the Board respond to audit findings, risk reports, or regulatory guidance about disposal practices? Prompt, documented action in response to warnings is strong evidence of due diligence.

Protecting Against Personal Liability

Directors can take several steps to manage their personal exposure regarding IT disposal:

Ensure governance exists: Verify that the organisation has a documented IT disposal policy that addresses data destruction, is approved at an appropriate level, and is reviewed periodically.

Receive regular reporting: Include IT disposal and data destruction in the Board’s regular information security reporting. This should cover volumes processed, methods used, third-party provider performance, and any incidents or audit findings.

Act on findings: When audit findings or risk assessments identify disposal gaps, ensure management develops and implements remediation plans within reasonable timeframes. Document the Board’s direction and monitor progress.

Seek expert input: Engage qualified information security professionals (internal or external) to assess your disposal practices. Act on their recommendations.

Maintain D&O insurance: Ensure your Directors’ and Officers’ insurance is adequate and that the policy conditions are being met. Review coverage annually with your broker.

Director protection framework:

  • Verified, documented IT disposal policy in place
  • Regular Board-level reporting on disposal and data destruction
  • Prompt action on audit findings and risk assessments
  • Expert advice sought and documented
  • Adequate D&O insurance maintained
  • Third-party provider due diligence documented
  • Board minutes recording disposal-related decisions and oversight

The Bottom Line for Directors

IT disposal might seem like an operational detail far removed from the boardroom, but a single disposal-related data breach can create personal liability for directors who didn’t ensure adequate governance was in place. The regulatory environment is moving firmly toward individual accountability, and “I didn’t know” is an increasingly inadequate defence when reasonable governance practices would have ensured you did know.

Directors don’t need to understand the technical details of NIST 800-88 or the difference between degaussing and shredding. They need to ensure that someone qualified does, that appropriate policies and processes are in place, and that the Board receives regular assurance that those processes are working. That’s the standard of care the law expects.

For more on building a comprehensive disposal framework, see our guide to building an IT asset disposal policy and our guide to breach prevention through proper disposal.

EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.