The OAIC’s Guide to securing personal information was recently updated to reflect the 2024 Privacy Act reforms, including a new obligation, APP 11.3. It raises the bar on data security for every Australian organisation that holds personal information. It’s also notable for what it leaves out: it benchmarks security against the ISO 27000 series but says nothing about artificial intelligence. For any business now putting personal information through AI, that gap matters.
What APP 11 requires
Australian Privacy Principle 11 governs the security of personal information. In short:
- APP 11.1: take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
- APP 11.2: destroy or de-identify personal information once you no longer need it.
What’s new: APP 11.3 and “technical and organisational measures”
The reforms added APP 11.3, which makes explicit that the “reasonable steps” to secure personal information include technical and organisational measures. It applies to personal information held after 11 December 2024, regardless of when that information was first collected.
That wording is significant. Security is no longer framed as just an IT problem. The law now expressly expects a combination of technical controls (the systems) and organisational controls (the governance, policies, training and process around them). That is almost word-for-word the definition of an information security management system.
Update, 3 September 2026: this provision is proposed to be renumbered, and joined by a new duty. The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, released on 31 August and open for consultation until 18 September, indicates that a new APP 11.4(a) would preserve what is currently APP 11.3, so the obligation survives but the numbering moves. Alongside it the draft would add that “an entity must regularly assess the effectiveness of its compliance with APP 11”, covering the reasonable steps taken and whether information that was de-identified has stayed de-identified. It would also require entities to be able to identify the personal information they hold in the first place. Read as an auditor, that is monitoring, internal audit and management review, and it is the part a policy-only privacy program produces no evidence for. It remains a draft and may change. We work through what it would mean in practice in what your data breach response plan has to prove.
Key takeaways from the OAIC’s guide
- “Reasonable steps” is contextual: scaled to your size and resources, the sensitivity of the information, and the risk of harm if it’s compromised.
- Security is a lifecycle: govern it, build it into your ICT and access controls, manage third parties and cloud providers, plan for data breaches, and destroy or de-identify data you no longer need.
- You still “hold” information you outsource: using a cloud or third-party provider doesn’t transfer your APP 11 obligations; you must manage those providers.
- Document your practices: APP 1.2 expects documented practices, procedures and systems that are kept current.
- The OAIC benchmarks against ISO: it points to the AS/NZS ISO/IEC 27000 series, and even asks whether your cloud providers are certified to it.
- Privacy Impact Assessments help: a PIA surfaces security risks early, before you collect or build.
How ISO 27001 maps to APP 11.3
If APP 11.3 asks for technical and organisational measures, ISO 27001 is the established, auditable framework that delivers exactly that:
| What APP 11 expects | How ISO 27001 delivers it |
|---|---|
| Reasonable, risk-based steps | ISMS risk assessment and Statement of Applicability |
| Technical measures | Annex A technological controls: access control, cryptography, logging, malware protection |
| Organisational measures | Annex A organisational & people controls: policies, roles, awareness training, supplier security |
| Documented practices (APP 1.2) | ISMS documented information, reviewed and maintained |
| Managing third parties & cloud | Supplier and cloud security controls |
| Destruction / de-identification (APP 11.2) | Information lifecycle and secure disposal controls |
| Breach readiness | Information security incident management |
Certification isn’t an automatic tick of legal compliance, but it’s a recognised, independently audited way to show you’ve taken the technical and organisational measures APP 11.3 now expects.

The gap: APP 11, the OAIC guide, and AI
Here’s what neither APP 11 nor the OAIC guide mentions: artificial intelligence. Yet organisations are now feeding personal information into AI systems, including training models, chatbots, analytics and automated decisions. That creates risks a traditional ISMS was never designed to govern: personal data being absorbed into models, sensitive attributes being inferred, opaque automated decisions, third-party model providers, and data leaking through prompts.
The obligation to take “reasonable steps” under APP 11.3 logically extends to how you govern AI that touches personal information, even though the guidance hasn’t caught up yet.
Where ISO 42001 comes in
ISO 42001 is the international AI management system standard, the same technical-and-organisational discipline applied to AI. It governs how you assess AI risks, control AI systems, manage the data your AI uses, and keep humans accountable for AI-driven outcomes. Used alongside ISO 27001, it closes the AI gap: 27001 secures the information, 42001 governs the AI that uses it.
What this means for your business
If you hold personal information and use AI, APP 11.3’s “technical and organisational measures” now reach across both your information security and your AI governance. The practical answer is an integrated approach: ISO 27001 for information security and ISO 42001 for AI, ideally run as one integrated management system rather than two silos.
How Streamline can help
We help Australian organisations meet their APP 11 obligations with practical ISO 27001 information security, and govern AI responsibly with ISO 42001, as a single, integrated system where it makes sense. The goal is real protection for the personal information you hold, not a binder that satisfies no one.
This article is general information, not legal advice. For advice on your specific Privacy Act obligations, consult a qualified legal practitioner.
APP 11.3, ISO 27001 and AI: FAQs
What is APP 11.3?
A 2024 addition to Australian Privacy Principle 11 clarifying that the reasonable steps to secure personal information include technical and organisational measures. It applies to personal information held after 11 December 2024.
Does ISO 27001 mean I comply with the Privacy Act?
Not automatically; compliance depends on your specific circumstances. But ISO 27001 is a recognised, independently audited way to demonstrate the technical and organisational measures APP 11.3 expects.
Do I need ISO 42001 as well as ISO 27001?
If you use AI with personal information, yes. ISO 42001 governs the AI-specific risks that ISO 27001 doesn’t fully cover. Together they give you security and AI governance in one consistent system.
Speak with an experienced ISO auditor
Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











