Secure Document Destruction Resource Centre

Whether you're managing your business records, complying with privacy legislation or simply deciding when it's time to securely destroy documents - this Resource Centre will be providing practical guides, checklists and direction to help Australian businesses protect their information. If you're after The DocShop to support, click the book now button below.

The Australian privacy Principles (APPs)

The principles of the Privacy Act 1988


The DocShop protects private information

Understanding the Australian Privacy Principles (APPs)

A Plain-English Guide for Australian Businesses

The Australian Privacy Principles (APPs) are 13 principles contained within the Privacy Act 1988 that set out how Australian businesses should collect, use, store and dispose of personal information.


For businesses that manage customer records, employee files, financial information or confidential documents, understanding the APPs is essential for maintaining privacy compliance and reducing the risk of data breaches and potential penalties.


Below is an explanation and simple overview of each principle.


  • APP 1 – Open and Transparent Management of Personal Information

    Businesses should have clear policies explaining how personal information is collected, stored, used and managed.


    In simple terms: Tell people what information you collect and what you do with it.

  • APP 2 – Anonymity and Pseudonymity

    Where practical, individuals should be given the option to deal with a business without identifying themselves, or by using a pseudonym. There are exceptions where identification is necessary or required by law.


    In simple terms: Don't ask people to identify themselves unless you genuinely need to know who they are.

  • APP 3 – Collection of Solicited Personal Information

    Businesses should only collect personal information that is reasonably necessary for their functions or activities. The information collected should be relevant and not excessive.


    In simple terms: Only collect the information you actually need and don't ask for information you don't.

  • APP 4 – Dealing with Unsolicited Personal Information

    Sometimes a business receives personal information it did not ask for. The business must determine whether it could have collected that information under APP 3. If it could not have collected it, the information should generally be destroyed or de-identified as soon as practicable, provided it is lawful and reasonable to do so.


    In simple terms: If you receive personal information you didn't ask for, don't keep it unless you have a legitimate reason to.

  • APP 5 – Notification of the Collection of Personal Information

    Businesses should take reasonable steps to tell individuals when they collect their personal information. This includes explaining why the information is being collected, how it will be used and who it may be disclosed to.


    In simple terms: Tell people when you're collecting their information and why you need it.

  • APP 6 – Use or Disclosure of Personal Information

    Personal information should generally only be used or disclosed for the purpose it was originally collected for, unless the individual has consented or another exception under the Privacy Act applies.


    In simple terms: Use people's information for the reason you collected it — don't use it for something completely different without a valid reason.

  • APP 7 – Direct Marketing

    Businesses must meet specific requirements when using personal information for direct marketing. Individuals must generally be given a straightforward way to opt out of receiving marketing communications.


    In simple terms: Don't use personal information for marketing without meeting the rules, and respect people's choice to opt out.

  • APP 8 – Cross-Border Disclosure of Personal Information

    Before sending personal information to an organisation overseas, businesses need to take reasonable steps to ensure the overseas recipient will handle that information in accordance with Australian privacy requirements, subject to certain exceptions.


    In simple terms: Be careful when sending personal information overseas — you still have privacy responsibilities.

  • APP 9 – Adoption, Use or Disclosure of Government Related Identifiers

    Government-issued identifiers such as Medicare numbers or Tax File Numbers generally cannot be used as your own customer identification system.


    In simple terms: Don't use government identification numbers unless the law allows it.

  • APP 10 – Quality of Personal Information

    Businesses should take reasonable steps to make sure the personal information they collect, use or disclose is accurate, complete and up to date.


    In simple terms: Keep personal information accurate and up to date.

  • APP 11 – Security of Personal Information

    Businesses must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. When information is no longer required, it should be securely destroyed or permanently de-identified.


    In simple terms: Protect sensitive information while you need it, and securely destroy it when you don't.


    Why it matters: For organisations managing paper files or archived records, secure document destruction is an important part of complying with APP 11.

  • APP 12 – Access to Personal Information

    Individuals generally have the right to request access to personal information a business holds about them. Businesses must provide access unless an exception under the Privacy Act applies.


    In simple terms: People can generally ask to see the personal information you hold about them.

  • APP 13 – Correction of Personal Information

    If personal information is inaccurate or out of date, businesses should take reasonable steps to correct it.


    In simple terms: Fix incorrect information when requested.

Why the Australian Privacy Principles Matter

Privacy compliance is about more than collecting information correctly—it's also about managing it throughout its entire lifecycle.

That includes:

  • Collecting only the information you need.
  • Keeping records accurate and secure.
  • Restricting access to authorised personnel.
  • Retaining records only for as long as required.
  • Securely destroying confidential documents when they are no longer needed.

For many Australian organisations, APP 11 is particularly important because it requires businesses to take reasonable steps to protect personal information and securely dispose of it when it is no longer required.

Implementing secure document destruction processes helps reduce privacy risks, supports regulatory compliance and protects your organisation from potential data breaches.




Disclaimer: This guide provides general information only and should not be considered legal advice. Organisations should seek professional advice regarding their specific privacy obligations under the Privacy Act 1988 (Cth).


Know secure document destruction

Protecting your privacy

Looking for something specific here? See here some common questions Australian businesses ask about secure information management and compliance.

  • What is NAID AAA Certification?

    A business with NAID AAA certification goes through highly detailed and ongoing vetting to ensure the highest of standards.


    This includes unannounced audits by highly trained independent security professionals.


    NAID AAA certification is an internationally recognised gold standard for secure data destruction.


    To be able to be certified as NAID AAA the endorsement criteria includes 


    • Collection of data 
    • Transportation of data 
    • Vehicle Security 
    • Facility Security 
    • Destruction 
    • Personnel Security

     You can find more information on this at the Australian Government Security Construction and Equipment Committee website  


  • What does it mean by "Secure document destruction"?

    Secure document destruction refers to the disposal process of confidential or private information/data.


    If you have any doubts over the way in which your data may be used, it is responsible to take the steps to ensure the correct disposal.


    The best way to ensure your data is in safe hands is to have it destroyed and a certificate of completion provided by a NAID AAA certified company.

  • What happens with shredded paper?

    This largely depends on how you have your paper shredded. If it is shredded in a private facility and disposed of in recycling bins or waste - it likely ends up in landfill.


    Commercial shredding businesses will often shred, destroy and compress paper into massive bales for transport.  Once these bales are ready, they will often be sent to paper mills.  Once at a paper mill the bales are dismantled, washed, pulped, de-inked and turned into new products.  This means less waste and a cleaner environment - if you are looking to shred paper this is by far the best option.


    Some people will repurpose shredded paper as flooring in animal enclosures such as guinea pigs, rabbits or mice.

  • What is a certificate of destruction and why would I need one?

    The truth is not everyone does need one.


    But it is critical for peace of mind and risk management.  A CoD (Certificate of Destruction) can only be issued by a certified service provider. It is a legally binding certificate that ensures you know your data has been permanently and securely destroyed.


    A valid CoD will hold up in a regulatory audit or legal proceeding if you need to provide evidence that something has been destroyed.


    Valid CoD should include:

    • Vendor Details
    • Client Details
    • Asset Description
    • Method Used
    • Compliance Standard
    • Date and Time
    • Authorisation Signature


  • What is a PIA (Privacy Impact Assessment)?

    A PIA is used to evaluate risk within your operating process when it comes to personal information.


    Whether you are implementing a system change or starting a system - it is important to conduct a PIA to ensure you are meeting legal requirements.


    Under the Privacy Act in Australia there are rules and regulations regarding how you manage, keep, store and dispose of personal information.  Specifically and data that can identify a group or individual.  


    This is not legal advice.


Does all data need to be securely destroyed?


The short answer is no.


The detailed answer depends on your legal obligations and the nature of the data in question.


The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) require organisations covered by the Act to take all reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps include up to the point of destruction.


Once personal information is no longer needed and there is no legal requirement to retain it, organisations are generally expected to take all reasonable steps to securely destroy or de-identify it.


Before destroying any business records, ensure you've met all applicable retention requirements. Depending on the type of record, businesses may be required to retain documents for several years under taxation, employment, corporate, healthcare or other legislation.




Employee Records Retention



How long do I need to keep employee records?


In Australia, employers are generally required to keep employee records for at least seven years after the employment relationship ends. Employee records normally include:

  • Payroll information
  • Timesheets
  • Leave balances
  • Superannuation records
  • Employment agreements
  • Termination details

Retaining records for the required period helps businesses comply with the Fair Work Act 2009 and ensures important information is available if required for audits, disputes, or legal obligations. Once the mandatory retention period has expired, records containing personal or confidential information should be disposed of securely rather than placed in general recycling or waste. Secure document destruction helps reduce the risk of identity theft, privacy breaches, and unauthorised access to sensitive employee information.


In some circumstances there may be instances where certain employee records are required to be kept for longer than seven years. It is always advised to check the legislation prior to shredding as storage may be a better option.


Read More

Disclaimer: This page provides general information only and is not legal advice. Record retention and destruction requirements vary depending on your industry, the type of information held and applicable legislation. Businesses should seek professional legal or regulatory advice where appropriate.