Australian Privacy Principle 11 requires organisations covered by the Privacy Act to take reasonable steps to protect the personal information they hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. It also requires information to be destroyed or de-identified once it is no longer needed.
Since December 2024, APP 11 expressly states that reasonable steps include technical and organisational measures. For a body corporate, penalties for serious interferences with privacy can reach the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover.
In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million, the first civil penalty under the Privacy Act, after finding it failed to adequately protect personal information on its Medlab systems and to assess and notify the breach promptly.