APP 11 Reasonable Steps
for Your Website & Data

APP 11 requires organisations to take reasonable steps to protect personal information. Here’s what that means for your website, member portal and the systems behind them, and how to show you’ve done it.

Pixelbird client
Pixelbird client
Pixelbird client

Over a decade of website security expertise

What APP 11 Actually Asks

Australian Privacy Principle 11 requires organisations covered by the Privacy Act to take reasonable steps to protect the personal information they hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. It also requires information to be destroyed or de-identified once it is no longer needed.

Since December 2024, APP 11 expressly states that reasonable steps include technical and organisational measures. For a body corporate, penalties for serious interferences with privacy can reach the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover.

In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million, the first civil penalty under the Privacy Act, after finding it failed to adequately protect personal information on its Medlab systems and to assess and notify the breach promptly.

Businessman Wearing Headset Talking To Caller In Busy Customer Services Centre

What Reasonable

Steps Look Like

on a

Website

What Reasonable Steps

Look Like on a Website

What Reasonable Steps

Look Like on a Website

There is no checklist in the Act, and what is reasonable depends on the information you hold and the harm a breach could cause. For most organisations, a website and its integrations hold some of the most sensitive data, so the technical steps matter.

In practice that means supported, patched platforms; no abandoned plugins or end-of-life CMS versions; controlled admin access with multi-factor authentication; payment and form scripts you know and monitor; vendors with only the access they need; tested backups; and personal information deleted when it’s no longer needed.

Our Website Security Audit documents where you stand against those steps, giving your board dated, independent evidence. It is not legal advice and it doesn’t make you “compliant”.

Smiling mature confident professional executive manager at office.

Why It

Matters to

Your Board

Why It Matters

to Your Board

Why It Matters

to Your Board

Penalties Are Real

The first civil penalty under the Privacy Act, $5.8 million, turned on a failure to take reasonable steps and to assess a breach promptly.

Technical Measures Count

APP 11 now names technical and organisational measures. Out-of-date platforms and abandoned plugins are hard to defend as reasonable.

Evidence Beats Assurance

A dated, independent assessment shows what was checked, found and fixed, which carries far more weight than a verbal “we’re fine”.

$ 0 m+

Maximum Penalty for a Body Corporate

0 +

People Affected in the Medlab Breach

0

Data Breaches Notified to the OAIC in 2025

0

Days to Assess a Suspected Eligible Breach

How It Works

We confirm what personal information your website and systems hold and where it goes, and give you a fixed price.

Young African businessman looking at data on computer screen

Step 2: Technical

Assessment

Our engineers check your platforms, plugins, access, scripts, vendors and backups against reasonable technical steps.

Group of young happy business people looking at laptop screen, communocating and discussing work

Step 3: Evidence

& Fixes

You get a board-ready report with rated findings and fixes, and we can carry out the work for you.

Brands We Have Helped

What People Say

Makes the Magic Happen

“Love the professional finishes . Dustin and the team know how to make the magic happen.”

Sam Hunter

Sam Hunter

Corporate Headshot Photographer

Always Shows Up

“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”

Kym Bolger

Kym Bolger

Social Media Marketing

Responsive Professionalism

“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”

Ivan Huang

Ivan Huang

CPA

What You Can Expect

Reasonable Step

What We Check

Common Gap

Supported Software

With Us

CMS, plugins and PHP versions in support

With Them

End-of-life platforms still running

Patching

With Us

Security updates applied and tested promptly

With Them

Updates months behind

Access Control

With Us

Admin accounts, roles and MFA reviewed

With Them

Shared logins and old accounts

Third-Party Scripts

With Us

Every script on forms and payment pages known

With Them

Unknown scripts loaded on checkout

Vendors

With Us

Agencies, plugins and SaaS with data access mapped

With Them

No record of who can reach data

Data Minimisation

With Us

Forms collect only what’s needed

With Them

Collecting everything, keeping it forever

Retention

With Us

Old submissions and exports deleted

With Them

Years of form entries in the database

Backups

With Us

Off-site, encrypted and restore-tested

With Them

Backups that have never been restored

Monitoring

With Us

File changes, logins and uptime watched

With Them

Breaches found by customers

Response Plan

With Us

A plan for assessing a suspected breach

With Them

Working it out on the day

Frequently Asked Questions

It isn’t defined by a checklist. It depends on the type and amount of personal information you hold, the harm a breach could cause and what protections are practical. The OAIC’s guidance and your legal advisers can help you judge your position.

It applies to organisations covered by the Privacy Act, which generally includes those with annual turnover over $3 million, health service providers and organisations that trade in personal information, among others. Get advice on your own position.

The Privacy and Other Legislation Amendment Act 2024 added that reasonable steps include technical and organisational measures, introduced tiered civil penalties and gave the OAIC new infringement notice powers.

No single activity is. An audit identifies the technical gaps and documents what you’ve done. Reasonable steps also include policies, training, vendor management and fixing what the audit finds.

No. We are software engineers. We provide the technical facts and evidence; your legal advisers interpret your obligations.

Show Your Board the Reasonable Steps You’ve Taken