Complete Guide to Document Destruction & Privacy Act Compliance in Australia
Australian businesses collect and store an enormous amount of personal and confidential information — from customer records and employee files to financial documents, medical information, contracts and identification documents.
But what happens when those records are no longer needed?
Deleting an electronic file or putting paper documents in a recycling bin does not necessarily mean confidential information has been securely destroyed. For organisations covered by the Privacy Act 1988 (Cth), Australian Privacy Principle 11 (APP 11) requires reasonable steps to protect personal information and, when it is no longer needed and no retention requirement applies, to destroy or de-identify it.
This makes secure document destruction an important part of an organisation’s information lifecycle and privacy management process.
In this guide, we explain what Australian businesses should know about document destruction, privacy compliance, retention periods, secure shredding and the disposal of confidential records.
Important: This article provides general information about privacy and secure document destruction. It is not legal advice. Document retention requirements vary depending on your industry, the type of record and applicable Australian laws.
What us the ptivacy Act 1988?
The Privacy Act 1988 is Australia’s federal privacy framework governing how covered organisations handle personal information.
It establishes the Australian Privacy Principles (APPs), which cover areas including the collection, use, disclosure, security, access and correction of personal information.
For document destruction, one of the most relevant requirements is APP 11 — Security of personal information.
APP 11 requires an organisation to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
It also requires an organisation to take reasonable steps to destroy or de-identify personal information when it no longer needs the information for a purpose permitted under the APPs, unless an exception applies — such as where another Australian law or a court or tribunal order requires the information to be retained.
Why does this matter for paper documents?
Personal information does not only exist in computers and databases.
It can also be stored in:
- Printed customer records
- Employee and HR files
- Invoices and receipts
- Tax records
- Contracts and agreements
- Legal documents
- Medical and health records
- Identification documents
- Financial records
- Printed reports
- Customer applications
- Business correspondence
- Archived files and boxes
The OAIC specifically recognises physical destruction methods such as shredding, disintegrating and pulping as examples of technical measures that may be appropriate for destroying personal information.
What Does APP 11 mean for document destruction?
APP 11 is not simply about keeping documents locked away.
It covers the information lifecycle — including what happens when information is no longer required.
The OAIC explains that organisations should actively consider whether personal information needs to be retained and take reasonable steps to destroy or de-identify information that is no longer needed.
For paper records, ordinary rubbish or recycling collection would not ordinarily constitute reasonable destruction where confidential personal information is still readable.
The OAIC notes that hard-copy personal information may need to be destroyed through a process such as shredding, pulping, pulverising or disintegrating so that it can no longer be retrieved.
This is why confidential documents should not simply be placed in a standard recycling bin.
Does every document need to be destroyed immediately?
No.
Privacy compliance does not mean destroying every document as soon as it has been used.
Some records must be retained because of:
- Tax and financial requirements
- Employment obligations
- Legal requirements
- Contractual obligations
- Industry-specific regulations
- Court orders or legal proceedings
- Regulatory requirements
- Internal record-keeping policies
The OAIC states that APP 11 does not require destruction where an Australian law or court or tribunal order requires the information to be retained.
The correct approach is therefore:
Retain what you are required to retain. Securely destroy what you no longer need.


The document retention and destruction Process
A good document destruction program should not begin with a shredder.
It should begin with a document retention policy.
Step 1: Identify the information you hold
Create an inventory of the types of information your organisation stores.
For example:
- Customer information
- Employee records
- Financial information
- Supplier records
- Contracts
- Legal files
- Medical information
- Identification documents
- Tax records
- Printed reports
- Archived files
Step 2: Determine how long records need to be retained
Retention periods can vary significantly.
Do not automatically destroy a document simply because it appears old.
Check the applicable legislation, regulatory requirements, contracts, litigation holds and your organisation’s retention policy before authorising destruction.
Step 3: Separate confidential records from general waste
Confidential documents should have a clearly defined disposal process.
A standard office recycling bin is not a secure destruction system.
Step 4: Store documents securely while waiting for destruction
Documents awaiting destruction should remain protected from unauthorised access.
For businesses handling significant volumes of confidential paper, locked security bins can help control access between the point of disposal and final destruction.
Step 5: Use a secure destruction method
Once records are authorised for destruction, use a method that makes the information irretrievable.
For paper records, secure commercial shredding is one recognised destruction method.
Step 6: Keep evidence of destruction
For organisations with formal information-management procedures, maintaining a record of what was destroyed and when can help demonstrate that the destruction process is controlled.
A Certificate of Destruction can provide documented confirmation that material collected for destruction has been securely destroyed.
What documents should businesses securely shred?
If a document contains personal, financial, confidential or commercially sensitive information, consider whether it should enter your secure document destruction process once its retention period has expired.
Common examples include:
Customer records
- Customer names and contact details
- Applications
- Account information
- Identification documents
- Service records
- Correspondence
Employee and HR records
- Employee files
- Payroll information
- Leave records
- Performance records
- Recruitment applications
- Personnel correspondence
Financial records
- Invoices
- Receipts
- Bank documents
- Payment records
- Financial reports
- Tax documents
Legal and professional records
- Contracts
- Agreements
- Legal correspondence
- Case files
- Client records
- Confidential reports
Healthcare and personal information
- Patient records
- Medical information
- Health forms
- Personal details
- Referral documents
Business information
- Internal reports
- Strategic documents
- Pricing information
- Supplier information
- Business correspondence
- Confidential meeting documents
Why putting confidential documents in recycling is risk?
Recycling is designed to recover materials — not protect confidential information.
A document containing a customer’s name, address, financial information or other personal details may remain readable if it is placed directly into general recycling.
The OAIC states that disposal through garbage or recycling collection would not ordinarily constitute reasonable steps to destroy hard-copy personal information unless the information has already been destroyed through an appropriate process such as shredding.
For businesses, secure shredding provides a controlled alternative.
Instead of asking employees to decide how confidential paperwork should be disposed of each time, organisations can establish a consistent process:
Use → Retain → Review → Secure → Destroy
What is a secure document shredding service?
A professional document destruction service is designed to control the handling of confidential records from collection through to destruction.
Depending on the service, this may include:
- Secure collection
- Locked document bins or containers
- Controlled handling
- Secure transportation
- Commercial shredding
- Recycling of shredded paper
- Certificate of Destruction
For businesses, the benefit is not simply that the paper is shredded.
It is the ability to establish a repeatable and documented destruction process.
What is a Certificate of Destruction?
A Certificate of Destruction (COD) is documentation confirming that materials collected for destruction have been destroyed.
Businesses may use destruction records as part of their internal information governance and record-keeping procedures.
A Certificate of Destruction can help answer an important question:
“Can we demonstrate what happened to these confidential records after they were authorised for destruction?”
The exact documentation and retention requirements should be determined by your organisation’s legal and compliance requirements.
Privacy Act reforms and the future of small businesses
Privacy regulation in Australia is continuing to evolve.
The Australian Government has agreed in principle to remove the existing small-business exemption, subject to further work including impact analysis, appropriate support and determining a proportionate way for small businesses to meet their obligations.
In August 2026, the Government released a consultation paper and exposure draft legislation proposing further privacy reforms. The proposed reforms include stronger privacy protections, changes concerning consent and a proposed right to erasure for certain personal information. The exposure draft remains subject to further consideration and should not be treated as current law unless and until enacted.
For businesses, the practical message is straightforward:
Do not wait until privacy requirements change to review how confidential records are stored and destroyed.
A documented information lifecycle can help businesses prepare for changing privacy expectations while reducing the amount of unnecessary personal information they retain.
A practical document destruction checklist for Australian businesses
Use this checklist when reviewing your confidential document disposal
Document retention
☐ Do we have a documented retention policy?
☐ Do we know which records must legally be retained?
☐ Do we review records when their retention period expires?
☐ Do we have a process for approving documents for destruction?
Secure storage
☐ Are confidential documents separated from general waste?
☐ Are documents awaiting destruction stored securely?
☐ Do employees know what should go into secure document destruction bins?
☐ Is access to confidential records controlled?
Secure destruction
☐ Are confidential paper records shredded rather than placed directly into recycling?
☐ Do we use a controlled destruction process?
☐ Can we identify when documents were collected for destruction?
☐ Do we receive documentation confirming destruction?
Governance
☐ Is responsibility for document destruction clearly assigned?
☐ Are staff trained in confidential document disposal?
☐ Do we periodically review our destruction process?
☐ Do our policies cover both paper and electronic information?
Which Australian Businesses should consider secure document shredding?
Secure document destruction can be relevant to organisations across many industries, including:
- Legal firms
- Accounting firms
- Financial organisations
- Medical and healthcare businesses
- Government organisations
- Schools and education providers
- Real estate businesses
- Property management companies
- Construction businesses
- Retail businesses
- IT companies
- Professional services firms
- Human resources departments
- Recruitment agencies
- Not-for-profit organisations
The type of information handled — and the legal requirements applying to that information — will vary between industries.
How Nationalshredcan help with secure document destruction
NationalShred provides professional confidential document destruction services for Australian businesses.
Depending on your requirements, documents can be placed into secure shredding bins or other approved collection options before being collected for destruction.
Our document destruction process is designed to provide businesses with a controlled way to dispose of confidential paper records while reducing the risk associated with unsecured document disposal.
NationalShred can provide:
- Secure document shredding
- Locked shredding bins
- Scheduled document collection
- One-off document destruction
- Archive box destruction
- Certificate of Destruction
- Confidential document disposal
- Business document shredding
- Secure paper shredding across Australia
Whether you are clearing an office, disposing of archived records or establishing an ongoing document destruction program, the right solution depends on your document volumes, collection frequency and retention requirements.
Ready to securely dispose of confidential documents?
Frequently Asked
The Privacy Act does not prescribe one universal shredding method for every document. However, APP 11 requires covered organisations to take reasonable steps to protect personal information and, when it is no longer needed and no retention exception applies, to destroy or de-identify it. The OAIC recognises shredding as one possible physical destruction method.
Generally, confidential paper containing personal information should not simply be placed in ordinary recycling while it remains readable. The OAIC states that ordinary garbage or recycling collection would not ordinarily constitute reasonable destruction of hard-copy personal information.
There is no single retention period for every Australian business or every type of record. Retention requirements depend on the document, industry, applicable legislation, contractual requirements and other circumstances. Businesses should establish a documented retention policy and obtain professional advice where necessary.
Most small businesses with annual turnover of $3 million or less are currently generally exempt from the Privacy Act, although important exceptions apply. The OAIC currently lists exceptions including certain health service providers, businesses trading in personal information, certain Commonwealth contractors and other specified entities.
The Government has also agreed in principle to remove the small-business exemption, subject to further work and reform.
Secure shredding can be an important part of a privacy and information-security program, but shredding alone does not make an organisation fully Privacy Act compliant.
Businesses also need to consider how they collect, use, store, access, disclose, retain and destroy personal information.
A Certificate of Destruction is documentation confirming that material collected for destruction has been destroyed. Businesses can retain this documentation as part of their internal destruction and information-management records.
Shredded paper can be processed for recycling where appropriate. The important first step is ensuring that confidential information has been securely destroyed so that it is no longer readable or retrievable.
Yes. NationalShred provides document destruction options for businesses clearing archived records and confidential paperwork. Archive box destruction can be particularly useful when businesses have accumulated older records that have reached the end of their authorised retention period.
Protect confidential information throughout its entire lifecycle
Privacy is not only about what happens when information is collected.
It also matters what happens when information is no longer needed.
A strong document management process should answer four questions:
What information do we have?
How long do we need to keep it?
How do we protect it while we have it?
How do we securely destroy it when we no longer need it?
For organisations covered by the Privacy Act, APP 11 provides an important framework for protecting personal information and dealing with information that is no longer required.
By combining a clear retention policy with secure storage, controlled destruction and appropriate documentation, Australian businesses can reduce unnecessary information exposure and create a more consistent approach to confidential document disposal.
Need help securely destroying confidential documents?
Contact NationalShred today to organise secure document shredding for your business.

