What security does APP 11.1 actually require from a small real-estate business?
Reasonable steps, judged against your circumstances, not enterprise security. APP 11.1 requires such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. What is reasonable scales with the sensitivity of the information and the size and resources of the business, so a four-person office is not held to a bank's standard. It is held to a standard it could actually have met.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What does "reasonable steps" mean for an office of five?
It means proportionate, and it means you can explain your reasoning. The Act does not prescribe controls, and there is no certification to buy.
Two factors push the standard up regardless of your size, and both apply to real estate:
- The sensitivity of what you hold. Identity documents, income evidence, bank details and tenancy histories are the raw material of identity theft. That is a higher-consequence holding than a mailing list, so more is expected of you than of a business holding names and emails.
- The consequence if it goes wrong. APP 11 is assessed on what a breach would do to the people in your files, not on what it would cost you.
What pushes the standard down is genuine resource constraint. You are not expected to run a security team. You are expected to have done the obvious things.
Note also APP 11.3, which confirms that reasonable steps expressly include technical and organisational measures. Policy and training count, not only software.
Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines
What is the practical minimum?
Ordered by how often the failure actually causes a breach in this industry:
1. Multi-factor authentication on email, for every staff member without exception. A compromised staff mailbox is the single most common real-world cause of an agency data breach, because the mailbox contains attachments nobody remembers sending: applications, ID scans, ledgers. 2. Individual logins, never shared ones. A shared reception account means you cannot tell who accessed a record, which defeats both your own investigation and any assessment you have to do later. 3. Access scoped to the role. Not everyone needs the identity documents. Not everyone needs the trust ledger. Most systems allow this and most offices never configure it. 4. A documented offboarding step. When someone leaves, access is revoked the same day, across email, the CRM, cloud storage, the portal logins and the shared drive. 5. Encrypted devices. Laptop and phone full-disk encryption is on by default on current operating systems, so this is usually a matter of confirming it, not buying it. 6. Attachments out of email. Email is the least controlled place a document can live. Move applications and ID out of inboxes into the system of record, then delete the mail copies. 7. A written response plan, so that if something does happen the clock is not spent deciding who is in charge.
Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.3 (Schedule 1) · OAIC APP Guidelines chapter 11 · OAIC notifiable data breaches · See also data-breach response for real estate
Does using a cloud CRM satisfy our obligation?
It helps, and it does not transfer the duty. You remain responsible for the personal information you hold, including information held for you in a supplier's system.
What the supplier gives you is infrastructure security you could not build yourself. What remains yours:
- Who has an account, and at what permission level. This is where most cloud exposure actually comes from, not from the provider being breached.
- Whether departed staff still have access.
- What is exported. A spreadsheet downloaded to a laptop is outside every control the platform has.
- Where the data sits. If the provider hosts or supports from overseas, APP 8 applies as well, and that is a separate analysis.
The reasonable question to ask a provider is not "are you secure" but "what can I configure, and what will you tell me if something happens, and how fast".
Sources: Privacy Act 1988 (Cth), APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 8 and 11 · See also overseas disclosure and offshore CRMs
A staff member is leaving with a work laptop and their phone. What do we do?
Treat it as a checklist rather than a conversation, because this is one of the most common quiet exposures in the industry and it is entirely preventable.
- Revoke access on the last day, not the following week: email, CRM, cloud storage, portal logins, the shared drive, any third-party tool they were given, and any shared password vault entry.
- Retrieve or wipe the devices. If a personal phone was used for work email, remove the work account from it. Most email platforms support a selective remote wipe that removes the work data and leaves personal data alone.
- Check what left with them. Downloaded exports, files in a personal cloud account, a contacts sync. Ask directly and record the answer.
- Change any shared credential they knew. This is why shared logins are a problem: one departure means changing something everybody uses.
- Deal with the buyer or landlord database question explicitly. If they take a client list to a new employer, that is a collection problem for the receiving business and a security problem for you.
Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 11 · See also an agent joining with an old database
How does security connect to the breach obligations?
Directly, and it is worth understanding before you need it. A security failure is an APP 11.1 problem. What happens next is a Part IIIC problem.
If you have reasonable grounds to suspect an eligible data breach, s 26WH(2) requires all reasonable steps to complete an assessment within 30 days, which the OAIC treats as a ceiling rather than a target. If you have reasonable grounds to believe there has been one, you notify the affected individuals and the Commissioner.
The practical consequence is that the security work and the response plan are the same investment. Good access records make the assessment fast, because you can tell who saw what. Poor records mean the assessment is guesswork under a deadline.
Sources: Privacy Act 1988 (Cth), APP 11.1 (Schedule 1) and Part IIIC, ss 26WE, 26WH(2) · OAIC notifiable data breaches
→ The free 2-minute audit covers the access and offboarding gaps that cause most agency breaches.