Handling and security Current

Securely disposing of client records once retention periods expire

A practical approach to closing out the retention lifecycle.

Setting a retention period is only half the task; disposing of records securely once that period ends is the other half. This guide sets out a practical approach grounded in OAIC's own guidance. It is general information, not legal or compliance advice.

Action plan

1 Confirm the record is genuinely no longer needed Disposal is only appropriate once a record has no remaining purpose it may lawfully be used for.

OAIC's guidance requires taking reasonable steps to destroy or de-identify personal information once it's no longer needed for any purpose it may be used or disclosed for, except where the information is part of a Commonwealth record or the firm is required by law or a court order to retain it. Confirm both conditions before disposing of a record: the retention period has ended, and no other legal requirement to retain it still applies.

  • Confirm the record's retention period under your firm's schedule has actually ended
  • Check no separate legal requirement or court order still requires retention
  • Don't dispose of a record purely because one retention period ended if another still applies

Done when: The record has been confirmed genuinely no longer needed and free of any other retention requirement

OAIC: APP 11 security of personal information
2 Choose destruction or de-identification, and use reasonable technical measures OAIC's guidance names specific technical measures for irretrievable destruction.

OAIC's guidance describes reasonable technical measures for destroying personal information as including shredding, disintegrating and pulping physical records, and sanitisation of hardware and de-identification techniques for electronic records. A record is destroyed once it can no longer be retrieved, not merely deleted from an index or moved to an unused folder.

  • For physical records, use shredding or equivalent destruction methods
  • For electronic records, use hardware sanitisation or genuine de-identification, not a simple delete
  • Confirm the record can no longer be retrieved before treating it as destroyed

Done when: The record has been destroyed or de-identified using a method that makes it genuinely irretrievable

OAIC: APP 11 security of personal information
3 Record what was disposed of and when A record of disposal is itself part of your firm's evidence of compliance.

Keep a record of what was disposed of, when, and by what method, separate from the disposed record itself. This lets your firm demonstrate its retention and disposal practice was actually followed, not just documented as a policy.

  • Log the record type, disposal date, and method used
  • Keep this disposal log separate from the disposed records themselves
  • Retain the disposal log according to your firm's own governance practice

Done when: A record of the disposal itself has been kept, separate from the disposed record

See setting a record-retention schedule for compliance evidence