Skip to content

What security does APP 11.1 actually require from a small real-estate business?

Reasonable steps, judged against your circumstances, not enterprise security. APP 11.1 requires such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. APP 11.1(b) had never been judicially considered until AIC v Australian Clinical Labs (No 2) [2025] FCA 1224; at [50] the Federal Court held the "circumstances" include the sensitivity of the information, the potential harm to individuals and the size and sophistication of the entity. A four-person office is not judged against a bank.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What does "reasonable steps" mean for an office of five?

It means proportionate, and it means you can explain your reasoning. The Act prescribes no particular controls, nothing in APP 11 names a technology, and there is no certification to buy.

Two factors push the standard up regardless of your size, and both apply to real estate:

What pushes the standard down is genuine resource constraint. You are not expected to run a security team. At [51] the Court noted the obligation does not require the optimal steps or a "one true path": what counts is whether the steps taken in their totality were reasonable.

Note also APP 11.3, which confirms that reasonable steps expressly include technical and organisational measures. Policy and training count, not only software.

Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 at [48], [50] to [52] · OAIC APP Guidelines chapter 11 · OAIC APP guidelines

What is the practical minimum?

None of these is named in the Act. The nearest official list is Pacific Lutheran College (Privacy) [2023] AICmr 98 at [174], where the Commissioner set out what that school ought to have had: a designated staff member, privacy training, documented practices for removing personal information from email accounts, adequate password security, and multi-factor authentication effectively implemented. Ours, for a real-estate office:

Sources: none of the seven is prescribed by the Act. APP 11.1 sets the standard; these are our recommendations for a real-estate office. Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · Pacific Lutheran College [2023] AICmr 98 at [169], [174] · Datateks [2023] AICmr 97 at [35] · Australian Clinical Labs [2025] FCA 1224 at [53] · OAIC APP Guidelines chapter 11 · OAIC notifiable data breaches · See also data-breach response for real estate

Does using a cloud CRM satisfy our obligation?

It helps, and it does not transfer the duty. Under s 6(1) you "hold" information if you have possession or control of the record, so a supplier's server is still your holding. In Pacific Lutheran College [2023] AICmr 98 at [173]: "under the Privacy Act the obligation to implement reasonable security steps rests with the respondent who holds the personal information".

What the supplier gives you is infrastructure security you could not build yourself. What remains yours:

The reasonable question to ask a provider is not "are you secure" but "what can I configure, and what will you tell me if something happens, and how fast".

Sources: Privacy Act 1988 (Cth), APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 8 and 11 · See also overseas disclosure and offshore CRMs

A staff member is leaving with a work laptop and their phone. What do we do?

Treat it as a checklist rather than a conversation, because each item gets harder to verify once the person has gone.

Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 11 · See also an agent joining with an old database

How does security connect to the breach obligations?

Directly, and it is worth understanding before you need it. A security failure is an APP 11.1 problem. What happens next is a Part IIIC problem.

If you have reasonable grounds to suspect an eligible data breach, s 26WH(2) requires "a reasonable and expeditious assessment" and all reasonable steps to complete it within 30 days. "Expeditious" is why 30 days is a ceiling, not a target. On reasonable grounds to believe, s 26WK(2) requires a statement to the Commissioner as soon as practicable, then s 26WL(2) cascades: notify each individual the information relates to; or if that is impracticable, each individual at risk; or if neither, publish the statement on your website and take reasonable steps to publicise it.

The practical consequence is that the security work and the response plan are the same investment. Good access records make the assessment fast, because you can tell who saw what. Poor records mean the assessment is guesswork under a deadline.

Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) and Part IIIC, ss 26WE, 26WH(2), 26WK(2), 26WL(2) · OAIC notifiable data breaches

→ The free 2-minute audit covers the access and offboarding gaps on this page. Can you name today who still has a login and should not?