WhenToDeletePowered by ScheduleOneSearch the register
Privacy and customersCommonwealthDestruction / de-identification duty

Personal information no longer needed

How long do personal information no longer needed need to be kept in Australia?

DutyDestroy or de-identify
Clock startsNo longer needed for any permitted purposeExceptions apply
Applies toAPP entitiesMost businesses with turnover over $3 million, and some smaller ones

General information, not legal advice or permission to destroy a record. Coverage may be incomplete or out of date. Check the official text, other applicable obligations and any investigations, disputes or legal holds before disposal. Get advice for your situation. Terms of use.

Under the Privacy Act 1988, APP entities must destroy or de-identify personal information once it is no longer needed for any permitted purpose.

Reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose it may be used or disclosed for.

2 provisions of the Privacy Act 1988 apply to these records. Each one is set out below.

The terms

Schedule 1, APP 11.2Privacy Act 1988
Destroy or de-identify
the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity under this Schedule
Schedule 1, APP 4.3Privacy Act 1988
Destroy or de-identify
the entity determines that the entity could not have collected the personal information; and the information is not contained in a Commonwealth record

Conditions and exceptions Caution

This is not a fixed retention period. APP 11.2 does not apply to information in a Commonwealth record, or that the entity is required to keep by or under an Australian law or a court or tribunal order.

From the provisions:

  • The information is not contained in a Commonwealth record
  • The entity is not required by or under an Australian law, or a court/tribunal order, to retain the information
  • Information contained in a Commonwealth record
  • Information the entity is required by law or court/tribunal order to retain
  • Only if it is lawful and reasonable to do so
  • The information must not be contained in a Commonwealth record
  • Does not apply if the information is contained in a Commonwealth record (subclause 4.4 then applies APP 5-13 instead)

The law

Privacy Act 1988, Schedule 1, APP 11.2 · Australian Privacy Principle 11—security of personal informationOfficial text ↗
the entity must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de‑identified.
Text as at 4 June 2026
Privacy Act 1988, Schedule 1, APP 4.3 · Australian Privacy Principle 4—dealing with unsolicited personal informationOfficial text ↗
the entity must, as soon as practicable but only if it is lawful and reasonable to do so, destroy the information or ensure that the information is de‑identified.
Text as at 4 June 2026

Other terms that apply to these records

This page covers personal information no longer needed on their own. The same file is often caught by other laws as well, with different periods and start dates. See why a legal term is not a schedule.

4 records. 4 sets of rules. They don't agree.

One business file can hold all of these at once.

Personal information no longer neededDestroyPrivacy Act 1988, Schedule 1, APP 11.2, APP 4.3 · no longer needed for any permitted purpose
Employee pay records7yFair Work Act 2009, s 535(1) · not stated in the Act
Business tax records5yIncome Tax Assessment Act 1936, s 262A(1), (4) · later of preparation or the transaction
Customer due diligence (KYC) records7yAnti-Money Laundering and Counter-Terrorism Financing Act 2006, s 111(2), s 114(1), s 35F(2), s 35F(3) · the business relationship ends

Now do that for every record your organisation holds, and redo it when the law changes. ScheduleOne has done that work, and keeps it current.

See ScheduleOne →