Australian Privacy Act 1988 — Australian Privacy Principles
Australia's primary privacy legislation governing how personal information is collected, used, stored, disclosed, and destroyed. The 13 Australian Privacy Principles apply to all Australian Government agencies and private sector organisations with annual turnover exceeding $3 million.
See where NodeZero appliesWhat is the Privacy Act?
The Privacy Act 1988 is Australia's primary privacy legislation, administered by the Office of the Australian Information Commissioner (OAIC). It establishes 13 Australian Privacy Principles (APPs) that govern the handling of personal information by Australian Government agencies and private sector organisations. For cyber security teams, the critical obligation is APP 11 -- the requirement to take "reasonable steps" to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
The Act also includes the Notifiable Data Breaches (NDB) scheme, which requires organisations to notify the OAIC and affected individuals when a data breach is likely to result in serious harm. Following the Privacy Act Review, penalties were increased in 2022 to a maximum of $50 million, three times the benefit obtained from the breach, or 30 per cent of adjusted turnover -- whichever is greatest. The combination of the "reasonable steps" test, mandatory breach notification, and substantially increased penalties means that demonstrating effective security controls is no longer just good practice -- it is a direct legal obligation.
Where NodeZero applies
NodeZero addresses the security obligation at the heart of the Privacy Act — APP 11's requirement to take "reasonable steps" to protect personal information. Autonomous pentesting generates evidence that access controls around PII systems hold under real attack, that credential-based and lateral-movement paths to personal data are identified and closed, and — via Advanced Data Pilfering — classifies exactly what personal information an attacker could exfiltrate. For the NDB scheme, NodeZero produces preventive evidence (what could become a notifiable breach) and post-incident verification (whether the remediation holds). Governance obligations under APPs 1, 3-7, 9-10, and 12-13 sit outside autonomous testing — we flag each explicitly.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Please note the following require separate evidence: APP 1 -- Open and transparent management and Collection, use, and disclosure obligations (APPs 3-7, 9-10, 12-13).
Showing coverage grouped by compliance category.
APP 11 -- Security of personal information
Strong alignment. NodeZero generates evidence that technical controls protecting PII hold under real attack.
Internal pentestingCore
Proof-of-exploit evidence of whether the "reasonable steps" against unauthorised access, modification or disclosure actually hold — the test OAIC applies when investigating a breach.
Web application pentestingPriced separately
Where personal information sits behind a customer portal, WebApp Pentesting tests the portal itself — broken access control, IDOR and authentication weaknesses that expose one individual's records to another — and covers the development limb of OAIC's testing recommendation by testing before release as well as after. Whether steps are reasonable in the circumstances remains a risk-assessment judgement.
AD Password AuditCore
Credential audit is a technical measure — weak and reused credentials are among the leading entry points in OAIC-notified cyber breaches, and APP 11.3 explicitly includes technical measures within the scope of "reasonable steps".
Advanced Data PilferingElite only
Auto-classifies the PII an attacker could exfiltrate — surfaces whether APP 11-covered personal information is reachable. Processing happens locally on your Docker host; no data leaves your network.
Segmentation testingCore
Proves that boundaries around PII systems actually contain an attacker's lateral movement — the core of "reasonable steps".
NodeZero TripwiresPro & Elite
Decoys planted on high-risk assets fire a high-fidelity alert the moment an attacker touches them — validating whether your monitoring would notice an intruder near personal information. This tests detection; it is not a substitute for the ongoing access monitoring OAIC recommends.
Insider Threat TestingCore
Starts from an authenticated user's own credentials and proves the reach of over-provisioned or stale access — direct evidence of whether the "need to know" restriction actually holds, distinct from AD Password Audit's credential-strength focus above.
Cloud pentestingCore
Where personal information sits in AWS or Azure/Entra ID, credentialed cloud pentesting is exactly this independent testing and validation — proving whether IAM misconfiguration, privilege escalation, or on-prem/cloud pivots expose that data. AWS, Azure/Entra ID and Kubernetes only — no standalone GCP coverage.
Notifiable Data Breaches scheme (Part IIIC)
Preventive coverage. NodeZero identifies exploitable paths to PII before they become notifiable breaches.
Internal pentestingCore
Every NodeZero finding comes with proof of exploitation — removes ambiguity about whether a weakness could cause unauthorised access that meets the s 26WE(2)(a) threshold.
Advanced Data PilferingElite only
Emulates stealthy exfiltration — slow transfer, impersonated-user access — to test whether your defences would notice data leaving at all. Speaks directly to whether the "unauthorised access or disclosure" that triggers s 26WE(2)(a) would even be detected — distinct from the data-reach classification ADP provides for the s 26WG limbs below.
Rapid ResponsePro & Elite
Rapid Response validates, often within hours of disclosure, whether a newly disclosed CVE is actually exploitable in your environment — preventive evidence that lowers the chance of a breach in the first place. It does not perform the breach assessment s 26WH(2) requires.
Quick VerifyCore
Evidence you can put in front of an assessor that remedial action closed the exploitation path — the factual basis for the s 26WF(1) remediation exception.
APP 8 -- Cross-border disclosure
Minimal coverage. NodeZero tests segmentation between domestic and offshore systems.
Segmentation testingCore
Tests whether an attacker can cross the network boundary between your Australian and offshore-connected systems. This is a thin technical slice only — APP 8 is chiefly about accountability for authorised disclosures to overseas recipients, which sits outside autonomous testing.
See every control mapped to NodeZero
The full control-by-control coverage map — every Privacy Act (APPs)requirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
The Privacy Act applies to Australian Government agencies, private sector organisations with annual turnover exceeding $3 million, health service providers regardless of turnover, organisations that trade in personal information, credit reporting bodies and credit providers, employee records-related entities (for TFN information), and organisations that have opted in to the regime. Some small business operators are exempt, but the $3 million threshold captures most organisations of any significant size.
The NDB scheme applies to all entities covered by the Privacy Act. If your organisation experiences an eligible data breach -- unauthorised access to, or disclosure of, personal information that is likely to result in serious harm -- you must notify the OAIC and affected individuals. The OAIC has signalled that failure to have adequate security measures in place is itself a factor in determining whether a breach was avoidable and what enforcement action is appropriate.
The Privacy Act Review reforms are now landing: a statutory tort for serious invasions of privacy commenced in June 2025 and APP 11.3 has strengthened the security obligation, with a Children's Online Privacy Code to follow. Organisations should treat the current "reasonable steps" standard as a floor, not a ceiling.
Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.