Skip to content

What security does APP 11.1 actually require from a small real-estate business?

Reasonable steps, judged against your circumstances, not enterprise security. APP 11.1 requires such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. What is reasonable scales with the sensitivity of the information and the size and resources of the business, so a four-person office is not held to a bank's standard. It is held to a standard it could actually have met.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What does "reasonable steps" mean for an office of five?

It means proportionate, and it means you can explain your reasoning. The Act does not prescribe controls, and there is no certification to buy.

Two factors push the standard up regardless of your size, and both apply to real estate:

What pushes the standard down is genuine resource constraint. You are not expected to run a security team. You are expected to have done the obvious things.

Note also APP 11.3, which confirms that reasonable steps expressly include technical and organisational measures. Policy and training count, not only software.

Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines

What is the practical minimum?

Ordered by how often the failure actually causes a breach in this industry:

1. Multi-factor authentication on email, for every staff member without exception. A compromised staff mailbox is the single most common real-world cause of an agency data breach, because the mailbox contains attachments nobody remembers sending: applications, ID scans, ledgers. 2. Individual logins, never shared ones. A shared reception account means you cannot tell who accessed a record, which defeats both your own investigation and any assessment you have to do later. 3. Access scoped to the role. Not everyone needs the identity documents. Not everyone needs the trust ledger. Most systems allow this and most offices never configure it. 4. A documented offboarding step. When someone leaves, access is revoked the same day, across email, the CRM, cloud storage, the portal logins and the shared drive. 5. Encrypted devices. Laptop and phone full-disk encryption is on by default on current operating systems, so this is usually a matter of confirming it, not buying it. 6. Attachments out of email. Email is the least controlled place a document can live. Move applications and ID out of inboxes into the system of record, then delete the mail copies. 7. A written response plan, so that if something does happen the clock is not spent deciding who is in charge.

Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · OAIC APP Guidelines chapter 11 · OAIC notifiable data breaches · See also data-breach response for real estate

Does using a cloud CRM satisfy our obligation?

It helps, and it does not transfer the duty. You remain responsible for the personal information you hold, including information held for you in a supplier's system.

What the supplier gives you is infrastructure security you could not build yourself. What remains yours:

The reasonable question to ask a provider is not "are you secure" but "what can I configure, and what will you tell me if something happens, and how fast".

Sources: Privacy Act 1988 (Cth), APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 8 and 11 · See also overseas disclosure and offshore CRMs

A staff member is leaving with a work laptop and their phone. What do we do?

Treat it as a checklist rather than a conversation, because this is one of the most common quiet exposures in the industry and it is entirely preventable.

Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 11 · See also an agent joining with an old database

How does security connect to the breach obligations?

Directly, and it is worth understanding before you need it. A security failure is an APP 11.1 problem. What happens next is a Part IIIC problem.

If you have reasonable grounds to suspect an eligible data breach, s 26WH(2) requires all reasonable steps to complete an assessment within 30 days, which the OAIC treats as a ceiling rather than a target. If you have reasonable grounds to believe there has been one, you notify the affected individuals and the Commissioner.

The practical consequence is that the security work and the response plan are the same investment. Good access records make the assessment fast, because you can tell who saw what. Poor records mean the assessment is guesswork under a deadline.

Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) and Part IIIC, ss 26WE, 26WH(2) · OAIC notifiable data breaches

→ The free 2-minute audit covers the access and offboarding gaps that cause most agency breaches.