What security does APP 11.1 actually require from a small real-estate business?
Reasonable steps, judged against your circumstances, not enterprise security. APP 11.1 requires such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. APP 11.1(b) had never been judicially considered until AIC v Australian Clinical Labs (No 2) [2025] FCA 1224; at [50] the Federal Court held the "circumstances" include the sensitivity of the information, the potential harm to individuals and the size and sophistication of the entity. A four-person office is not judged against a bank.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What does "reasonable steps" mean for an office of five?
It means proportionate, and it means you can explain your reasoning. The Act prescribes no particular controls, nothing in APP 11 names a technology, and there is no certification to buy.
Two factors push the standard up regardless of your size, and both apply to real estate:
- The sensitivity of what you hold. Identity documents, income evidence, bank details and tenancy histories are the raw material of identity theft. That is a higher-consequence holding than a mailing list, so more is expected of you than of a business holding names and emails.
- The consequence if it goes wrong. At [52] the Court weighed "the volume and sensitivity of the information" and the risk of harm to individuals if it were disclosed without authorisation. What a breach would do to the people in your files is the measure.
What pushes the standard down is genuine resource constraint. You are not expected to run a security team. At [51] the Court noted the obligation does not require the optimal steps or a "one true path": what counts is whether the steps taken in their totality were reasonable.
Note also APP 11.3, which confirms that reasonable steps expressly include technical and organisational measures. Policy and training count, not only software.
Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 at [48], [50] to [52] · OAIC APP Guidelines chapter 11 · OAIC APP guidelines
What is the practical minimum?
None of these is named in the Act. The nearest official list is Pacific Lutheran College (Privacy) [2023] AICmr 98 at [174], where the Commissioner set out what that school ought to have had: a designated staff member, privacy training, documented practices for removing personal information from email accounts, adequate password security, and multi-factor authentication effectively implemented. Ours, for a real-estate office:
- Multi-factor authentication on email, for every staff member without exception, and legacy authentication switched off. In Pacific Lutheran College (Privacy) [2023] AICmr 98 at [169] MFA was in place and the attacker still got in over IMAP, because legacy authentication cannot enforce it. Turning MFA on is not the same as it being enforced.
- Individual logins, never shared ones. A shared reception account means you cannot tell who accessed a record, which defeats both your own investigation and any assessment you have to do later.
- Access scoped to the role. Not everyone needs the identity documents. Not everyone needs the trust ledger. Open your CRM user list and check what a new property manager can see on day one.
- A documented offboarding step. When someone leaves, access is revoked the same day, across email, the CRM, cloud storage, the portal logins and the shared drive.
- Encrypted devices. Full-disk encryption ships with current operating systems and does not need to be bought, but it is not always switched on: check FileVault on each Mac and device encryption on each PC rather than assuming.
- Attachments out of email. In Datateks Pty Ltd (Privacy) [2023] AICmr 97 at [35] the personal information sat in the general account's "sent" folder, "retained and not deleted for audit trail purposes": driver licences, bank details, Medicare numbers, tax file numbers. Move applications and ID into the system of record, then delete the mail copies.
- A written response plan. In AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 the Federal Court ordered A$4,200,000 for the APP 11.1(b) failure alone, and at [53] counted playbooks that "did not clearly define roles and responsibilities for incident response efforts" and contained "limited detail on containment processes" as part of that failure. That was an ASX-listed company and 223,000 people, not an agency, but named roles and a containment step are exactly what a plan is for.
Sources: none of the seven is prescribed by the Act. APP 11.1 sets the standard; these are our recommendations for a real-estate office. Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · Pacific Lutheran College [2023] AICmr 98 at [169], [174] · Datateks [2023] AICmr 97 at [35] · Australian Clinical Labs [2025] FCA 1224 at [53] · OAIC APP Guidelines chapter 11 · OAIC notifiable data breaches · See also data-breach response for real estate
Does using a cloud CRM satisfy our obligation?
It helps, and it does not transfer the duty. Under s 6(1) you "hold" information if you have possession or control of the record, so a supplier's server is still your holding. In Pacific Lutheran College [2023] AICmr 98 at [173]: "under the Privacy Act the obligation to implement reasonable security steps rests with the respondent who holds the personal information".
What the supplier gives you is infrastructure security you could not build yourself. What remains yours:
- Who has an account, and at what permission level. The provider's certifications say nothing about the accounts you created. Count the active users in your CRM today and see whether the number matches your staff list.
- Whether departed staff still have access.
- What is exported. A spreadsheet downloaded to a laptop is outside every control the platform has.
- Where the data sits. If the provider hosts or supports from overseas, APP 8 may be engaged, because APP 8.1 attaches to disclosure to an overseas recipient rather than to storage as such. That is a separate analysis.
The reasonable question to ask a provider is not "are you secure" but "what can I configure, and what will you tell me if something happens, and how fast".
Sources: Privacy Act 1988 (Cth), APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 8 and 11 · See also overseas disclosure and offshore CRMs
A staff member is leaving with a work laptop and their phone. What do we do?
Treat it as a checklist rather than a conversation, because each item gets harder to verify once the person has gone.
- Revoke access on the last day, not the following week: email, CRM, cloud storage, portal logins, the shared drive, any third-party tool they were given, and any shared password vault entry.
- Retrieve or wipe the devices. If a personal phone was used for work email, remove the work account from it. Where your email platform supports a selective wipe, it removes the work data and leaves personal data alone.
- Check what left with them. Downloaded exports, files in a personal cloud account, a contacts sync. Ask directly and record the answer.
- Change any shared credential they knew. This is why shared logins are a problem: one departure means changing something everybody uses.
- Deal with the buyer or landlord database question explicitly. If they take a client list to a new employer, that is a collection problem for the receiving business and a security problem for you.
Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 11 · See also an agent joining with an old database
How does security connect to the breach obligations?
Directly, and it is worth understanding before you need it. A security failure is an APP 11.1 problem. What happens next is a Part IIIC problem.
If you have reasonable grounds to suspect an eligible data breach, s 26WH(2) requires "a reasonable and expeditious assessment" and all reasonable steps to complete it within 30 days. "Expeditious" is why 30 days is a ceiling, not a target. On reasonable grounds to believe, s 26WK(2) requires a statement to the Commissioner as soon as practicable, then s 26WL(2) cascades: notify each individual the information relates to; or if that is impracticable, each individual at risk; or if neither, publish the statement on your website and take reasonable steps to publicise it.
The practical consequence is that the security work and the response plan are the same investment. Good access records make the assessment fast, because you can tell who saw what. Poor records mean the assessment is guesswork under a deadline.
Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) and Part IIIC, ss 26WE, 26WH(2), 26WK(2), 26WL(2) · OAIC notifiable data breaches
→ The free 2-minute audit covers the access and offboarding gaps on this page. Can you name today who still has a login and should not?