Under the Privacy Act 1988, APP entities must destroy or de-identify personal information once it is no longer needed for any permitted purpose.
Reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose it may be used or disclosed for.
2 provisions of the Privacy Act 1988 apply to these records. Each one is set out below.
The terms
Conditions and exceptions Caution
This is not a fixed retention period. APP 11.2 does not apply to information in a Commonwealth record, or that the entity is required to keep by or under an Australian law or a court or tribunal order.
From the provisions:
- The information is not contained in a Commonwealth record
- The entity is not required by or under an Australian law, or a court/tribunal order, to retain the information
- Information contained in a Commonwealth record
- Information the entity is required by law or court/tribunal order to retain
- Only if it is lawful and reasonable to do so
- The information must not be contained in a Commonwealth record
- Does not apply if the information is contained in a Commonwealth record (subclause 4.4 then applies APP 5-13 instead)
The law
Other terms that apply to these records
This page covers personal information no longer needed on their own. The same file is often caught by other laws as well, with different periods and start dates. See why a legal term is not a schedule.
4 records. 4 sets of rules. They don't agree.
One business file can hold all of these at once.
Now do that for every record your organisation holds, and redo it when the law changes. ScheduleOne has done that work, and keeps it current.
See ScheduleOne →