Secure Document Destruction Resource Centre
Whether you're managing your business records, complying with privacy legislation or simply deciding when it's time to securely destroy documents - this Resource Centre will be providing practical guides, checklists and direction to help Australian businesses protect their information. If you're after The DocShop to support, click the book now button below.
The Australian privacy Principles (APPs)
The principles of the Privacy Act 1988
Understanding the Australian Privacy Principles (APPs)
A Plain-English Guide for Australian Businesses
The Australian Privacy Principles (APPs) are 13 principles contained within the Privacy Act 1988 that set out how Australian businesses should collect, use, store and dispose of personal information.
For businesses that manage customer records, employee files, financial information or confidential documents, understanding the APPs is essential for maintaining privacy compliance and reducing the risk of data breaches and potential penalties.
Below is an explanation and simple overview of each principle.
Why the Australian Privacy Principles Matter
Privacy compliance is about more than collecting information correctly—it's also about managing it throughout its entire lifecycle.
That includes:
- Collecting only the information you need.
- Keeping records accurate and secure.
- Restricting access to authorised personnel.
- Retaining records only for as long as required.
- Securely destroying confidential documents when they are no longer needed.
For many Australian organisations, APP 11 is particularly important because it requires businesses to take reasonable steps to protect personal information and securely dispose of it when it is no longer required.
Implementing secure document destruction processes helps reduce privacy risks, supports regulatory compliance and protects your organisation from potential data breaches.
Disclaimer: This guide provides general information only and should not be considered legal advice. Organisations should seek professional advice regarding their specific privacy obligations under the Privacy Act 1988 (Cth).
Know secure document destruction
Protecting your privacy
Looking for something specific here? See here some common questions Australian businesses ask about secure information management and compliance.
What is NAID AAA Certification?
A business with NAID AAA certification goes through highly detailed and ongoing vetting to ensure the highest of standards.
This includes unannounced audits by highly trained independent security professionals.
NAID AAA certification is an internationally recognised gold standard for secure data destruction.
To be able to be certified as NAID AAA the endorsement criteria includes
- Collection of data
- Transportation of data
- Vehicle Security
- Facility Security
- Destruction
- Personnel Security
You can find more information on this at the Australian Government Security Construction and Equipment Committee website
What does it mean by "Secure document destruction"?
Secure document destruction refers to the disposal process of confidential or private information/data.
If you have any doubts over the way in which your data may be used, it is responsible to take the steps to ensure the correct disposal.
The best way to ensure your data is in safe hands is to have it destroyed and a certificate of completion provided by a NAID AAA certified company.
What happens with shredded paper?
This largely depends on how you have your paper shredded. If it is shredded in a private facility and disposed of in recycling bins or waste - it likely ends up in landfill.
Commercial shredding businesses will often shred, destroy and compress paper into massive bales for transport. Once these bales are ready, they will often be sent to paper mills. Once at a paper mill the bales are dismantled, washed, pulped, de-inked and turned into new products. This means less waste and a cleaner environment - if you are looking to shred paper this is by far the best option.
Some people will repurpose shredded paper as flooring in animal enclosures such as guinea pigs, rabbits or mice.
What is a certificate of destruction and why would I need one?
The truth is not everyone does need one.
But it is critical for peace of mind and risk management. A CoD (Certificate of Destruction) can only be issued by a certified service provider. It is a legally binding certificate that ensures you know your data has been permanently and securely destroyed.
A valid CoD will hold up in a regulatory audit or legal proceeding if you need to provide evidence that something has been destroyed.
Valid CoD should include:
- Vendor Details
- Client Details
- Asset Description
- Method Used
- Compliance Standard
- Date and Time
- Authorisation Signature
- Vendor Details
What is a PIA (Privacy Impact Assessment)?
A PIA is used to evaluate risk within your operating process when it comes to personal information.
Whether you are implementing a system change or starting a system - it is important to conduct a PIA to ensure you are meeting legal requirements.
Under the Privacy Act in Australia there are rules and regulations regarding how you manage, keep, store and dispose of personal information. Specifically and data that can identify a group or individual.
This is not legal advice.
Does all data need to be securely destroyed?
The short answer is no.
The detailed answer depends on your legal obligations and the nature of the data in question.
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) require organisations covered by the Act to take all reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps include up to the point of destruction.
Once personal information is no longer needed and there is no legal requirement to retain it, organisations are generally expected to take all reasonable steps to securely destroy or de-identify it.
Before destroying any business records, ensure you've met all applicable retention requirements. Depending on the type of record, businesses may be required to retain documents for several years under taxation, employment, corporate, healthcare or other legislation.
Employee Records Retention
How long do I need to keep employee records?
In Australia, employers are generally required to keep employee records for at least seven years after the employment relationship ends. Employee records normally include:
- Payroll information
- Timesheets
- Leave balances
- Superannuation records
- Employment agreements
- Termination details
Retaining records for the required period helps businesses comply with the Fair Work Act 2009 and ensures important information is available if required for audits, disputes, or legal obligations. Once the mandatory retention period has expired, records containing personal or confidential information should be disposed of securely rather than placed in general recycling or waste. Secure document destruction helps reduce the risk of identity theft, privacy breaches, and unauthorised access to sensitive employee information.
In some circumstances there may be instances where certain employee records are required to be kept for longer than seven years. It is always advised to check the legislation prior to shredding as storage may be a better option.
Disclaimer: This page provides general information only and is not legal advice. Record retention and destruction requirements vary depending on your industry, the type of information held and applicable legislation. Businesses should seek professional legal or regulatory advice where appropriate.



