Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Securing Personal Information Under APP 11.3: Where ISO 27001 and ISO 42001 Fit

The OAIC’s Guide to securing personal information was recently updated to reflect the 2024 Privacy Act reforms, including a new obligation, APP 11.3. It raises the bar on data security for every Australian organisation that holds personal information. It’s also notable for what it leaves out: it benchmarks security against the ISO 27000 series but says nothing about artificial intelligence. For any business now putting personal information through AI, that gap matters.

What APP 11 requires

Australian Privacy Principle 11 governs the security of personal information. In short:

  • APP 11.1: take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
  • APP 11.2: destroy or de-identify personal information once you no longer need it.

What’s new: APP 11.3 and “technical and organisational measures”

The reforms added APP 11.3, which makes explicit that the “reasonable steps” to secure personal information include technical and organisational measures. It applies to personal information held after 11 December 2024, regardless of when that information was first collected.

That wording is significant. Security is no longer framed as just an IT problem. The law now expressly expects a combination of technical controls (the systems) and organisational controls (the governance, policies, training and process around them). That is almost word-for-word the definition of an information security management system.

Update, 3 September 2026: this provision is proposed to be renumbered, and joined by a new duty. The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, released on 31 August and open for consultation until 18 September, indicates that a new APP 11.4(a) would preserve what is currently APP 11.3, so the obligation survives but the numbering moves. Alongside it the draft would add that “an entity must regularly assess the effectiveness of its compliance with APP 11”, covering the reasonable steps taken and whether information that was de-identified has stayed de-identified. It would also require entities to be able to identify the personal information they hold in the first place. Read as an auditor, that is monitoring, internal audit and management review, and it is the part a policy-only privacy program produces no evidence for. It remains a draft and may change. We work through what it would mean in practice in what your data breach response plan has to prove.

Key takeaways from the OAIC’s guide

  • “Reasonable steps” is contextual: scaled to your size and resources, the sensitivity of the information, and the risk of harm if it’s compromised.
  • Security is a lifecycle: govern it, build it into your ICT and access controls, manage third parties and cloud providers, plan for data breaches, and destroy or de-identify data you no longer need.
  • You still “hold” information you outsource: using a cloud or third-party provider doesn’t transfer your APP 11 obligations; you must manage those providers.
  • Document your practices: APP 1.2 expects documented practices, procedures and systems that are kept current.
  • The OAIC benchmarks against ISO: it points to the AS/NZS ISO/IEC 27000 series, and even asks whether your cloud providers are certified to it.
  • Privacy Impact Assessments help: a PIA surfaces security risks early, before you collect or build.

How ISO 27001 maps to APP 11.3

If APP 11.3 asks for technical and organisational measures, ISO 27001 is the established, auditable framework that delivers exactly that:

What APP 11 expectsHow ISO 27001 delivers it
Reasonable, risk-based stepsISMS risk assessment and Statement of Applicability
Technical measuresAnnex A technological controls: access control, cryptography, logging, malware protection
Organisational measuresAnnex A organisational & people controls: policies, roles, awareness training, supplier security
Documented practices (APP 1.2)ISMS documented information, reviewed and maintained
Managing third parties & cloudSupplier and cloud security controls
Destruction / de-identification (APP 11.2)Information lifecycle and secure disposal controls
Breach readinessInformation security incident management

Certification isn’t an automatic tick of legal compliance, but it’s a recognised, independently audited way to show you’ve taken the technical and organisational measures APP 11.3 now expects.

Tilt-shift miniature of an AI data centre and microchip: securing personal information under APP 11.3
APP 11.3 applies to personal information held after 11 December 2024, regardless of when it was first collected.

The gap: APP 11, the OAIC guide, and AI

Here’s what neither APP 11 nor the OAIC guide mentions: artificial intelligence. Yet organisations are now feeding personal information into AI systems, including training models, chatbots, analytics and automated decisions. That creates risks a traditional ISMS was never designed to govern: personal data being absorbed into models, sensitive attributes being inferred, opaque automated decisions, third-party model providers, and data leaking through prompts.

The obligation to take “reasonable steps” under APP 11.3 logically extends to how you govern AI that touches personal information, even though the guidance hasn’t caught up yet.

Where ISO 42001 comes in

ISO 42001 is the international AI management system standard, the same technical-and-organisational discipline applied to AI. It governs how you assess AI risks, control AI systems, manage the data your AI uses, and keep humans accountable for AI-driven outcomes. Used alongside ISO 27001, it closes the AI gap: 27001 secures the information, 42001 governs the AI that uses it.

What this means for your business

If you hold personal information and use AI, APP 11.3’s “technical and organisational measures” now reach across both your information security and your AI governance. The practical answer is an integrated approach: ISO 27001 for information security and ISO 42001 for AI, ideally run as one integrated management system rather than two silos.

How Streamline can help

We help Australian organisations meet their APP 11 obligations with practical ISO 27001 information security, and govern AI responsibly with ISO 42001, as a single, integrated system where it makes sense. The goal is real protection for the personal information you hold, not a binder that satisfies no one.

This article is general information, not legal advice. For advice on your specific Privacy Act obligations, consult a qualified legal practitioner.

APP 11.3, ISO 27001 and AI: FAQs

What is APP 11.3?

A 2024 addition to Australian Privacy Principle 11 clarifying that the reasonable steps to secure personal information include technical and organisational measures. It applies to personal information held after 11 December 2024.

Does ISO 27001 mean I comply with the Privacy Act?

Not automatically; compliance depends on your specific circumstances. But ISO 27001 is a recognised, independently audited way to demonstrate the technical and organisational measures APP 11.3 expects.

Do I need ISO 42001 as well as ISO 27001?

If you use AI with personal information, yes. ISO 42001 governs the AI-specific risks that ISO 27001 doesn’t fully cover. Together they give you security and AI governance in one consistent system.

Speak with an experienced ISO auditor

Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • A human hand over a softly glowing network of nodes, representing responsible AI governance
    ISO 42001 Certification Cost & Timeline in Australia…

Filed Under: Articles Tagged With: #informationsecurity, #iso27001, #iso42001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire