← Compliance glossary

APP 11 (Australian Privacy Principle 11)

FRT & privacy

APP 11 of the Privacy Act 1988 (Cth) requires reporting entities to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. For FRT systems, APP 11 is the substantive duty against which vendor controls (encryption at rest, access controls, data-residency, breach notification, template-hashing) are tested. APP 11 also requires destruction or de-identification once the information is no longer needed.

This term sits in the FRT & privacy section of the working glossary — vocabulary covering facial-recognition controls and the Privacy Act 1988 (Cth), including the Australian Privacy Principles and the Notifiable Data Breaches scheme.

Read more

Operational pillar pages

Related terms

Other terms in FRT & privacy