Privacy by Design. Build it in. Do not bolt it on.
Privacy is engineering. The 7 foundational principles + the 8 technical controls below are how XIntelliSync satisfies APP 11 (reasonable security) and APP 8 (cross-border safeguards) — and how every Australian SMB should design their own systems. The OAIC Privacy Management Framework is the practical playbook.
What "Privacy by Design" looks like in production code
Privacy by Design is the engineering discipline of building privacy into the system from the first line of code, not bolting it on after a breach. Most SaaS does the second.
XIntelliSync did the first — two years of architectural discipline before you ever logged in. APP 11 reasonable security isn't a quarterly review on our side, it's a Stage 0 + Stage 1 + Stage 5 XGVS gate sequence on every action. APP 8 cross-border flow is a hosting-region constraint baked into the deployment, not a policy paragraph. APP 10 data quality is a cross-file consistency check that runs continuously. The OAIC Privacy Management Framework is the practical playbook — XIntelliSync architects against it.
What XIntelliSync deliberately does NOT do: write your privacy policy, run your governance committee, or train your staff. Privacy by Design starts in code on our side and continues in process on yours.
Seven foundational principles
Cavoukian's Privacy by Design (PbD).
Proactive not reactive — preventative not remedial
Build privacy controls into the system before personal information is collected. Threat-model every new feature for privacy risk during design, not after launch. Run a Privacy Impact Assessment (PIA) for any feature that processes sensitive information.
Privacy as the default setting
New users start with privacy-protective defaults. Marketing-list opt-in is unticked by default. Cross-business analytics opt-in is off by default. Cookies that are non-essential require active consent. APP 5 collection notice is shown at the first relevant interaction.
Privacy embedded into design
Privacy is not bolted on as a last-minute checkbox. It is part of the system architecture. Encryption-at-rest is the default storage layer. Access logs are first-class citizens, not an afterthought. Data deletion is a real operation, not a status flag.
Full functionality — positive-sum not zero-sum
You do not have to choose between security and usability. Strong authentication can be frictionless (passkeys, biometrics). End-to-end encryption can be transparent. Privacy and product quality are reinforcing — better privacy means better trust which means better product.
End-to-end security — full lifecycle protection
Personal information is protected from the moment it enters the system to the moment it is destroyed. Encryption in transit (TLS 1.3+). Encryption at rest (AES-256). Encryption in use where applicable (envelope encryption, key escrow). Audit-grade deletion when retention expires.
Visibility and transparency — keep it open
Customers can see what personal information you hold (APP 12), correct it (APP 13), and audit who has accessed it. Operators can see security events. Regulators can see the controls in place. Open documentation, public privacy policy, machine-readable transparency reports.
Respect for user privacy — keep it user-centric
The user is the centre of the privacy model. Informed consent. Granular opt-out. Easy data export. Easy account deletion. Reasonable response times for access + correction. The user owns their data — the platform stewards it.
Eight technical controls
What APP 11 reasonable security looks like in code.
These are the technical controls XIntelliSync runs to satisfy APP 11 + APP 8. They map to ISO/IEC 27001 Annex A, the ACSC Essential 8, and SOC 2 Trust Services Criteria where they overlap.
Encryption at rest + in transit
APP 11.1 reasonable steps
AES-256-GCM for data at rest. TLS 1.3+ for data in transit. Key management via dedicated KMS (AWS KMS / GCP KMS / Azure Key Vault) with audit logging on every key operation. Backups encrypted with separate keys.
Multi-factor authentication on admin access
APP 11.1 reasonable steps + Essential 8 ML 2
WebAuthn / passkey first; TOTP fallback. SMS OTP only for break-glass scenarios (SMS-OTP is phishable). MFA enforced on every admin account, every customer-data-access role, and every backup-access path. No exceptions, no shared accounts.
Least-privilege access control
APP 11.1 reasonable steps + APP 6 use limitation
Role-based access (RBAC) with attribute-based overlays (ABAC). Customer data is partitioned by tenancy boundary. Admin access requires JIT (just-in-time) elevation with audit log. Periodic access review (quarterly minimum) with revocation by default.
Audit logs on every sensitive query
APP 11.1 reasonable steps + Privacy Management Framework Step 3
Every read of personal information leaves an audit-grade record: who, what, when, why, from where. Logs are append-only, tamper-evident, retained for 7 years for financial data + 2 years for non-financial. Log alerting on anomalous patterns.
Cross-border safeguards (APP 8)
APP 8.1 + APP 8.2
Every overseas processor is contractually bound to APP-equivalent terms (or to GDPR/UK GDPR which exceeds APP standards). Destination countries are listed in the privacy policy. Sub-processors require advance notice + customer right to object. Cross-border data flow records maintained per OAIC guidance.
Incident response + tabletop exercises
APP 11.1 reasonable steps + Pt IIIC NDB scheme
Documented incident response plan with named on-call rotation. Tabletop exercises every 6 months. Pre-drafted Statement of Notifiable Data Breach template. Pre-defined customer notification channels. 24-hour internal escalation, 30-day OAIC NDB clock embedded in the runbook.
Data minimisation + retention enforcement
APP 3 + APP 11.2 + APP 11.3
Collect only what is necessary for the function (APP 3). Retain only as long as necessary (APP 11.2). Auto-delete or anonymise at retention expiry. Customer-initiated deletion within 30 days. Backups respect retention windows (no perpetual backup of deleted records).
Secure development lifecycle (SDLC)
APP 11.1 reasonable steps + Essential 8 ML 1-3
Threat modelling on every feature. Static + dynamic application security testing in CI. Dependency vulnerability scanning. Penetration testing at least annually + after major releases. Bug bounty programme. Security champions in every product team.
Where to verify the source
Authoritative Privacy by Design + APP 11 sources.
These are the regulator + standards-body sources behind the principles + controls above. Use them as the playbook for your own privacy programme:
OAIC Privacy Management Framework — oaic.gov.au privacy-management-framework
The OAIC's practical 4-step playbook for embedding privacy throughout an APP entity. The regulator's expected baseline for "reasonable steps" under APP 11. Use as your privacy programme's structural reference.
OAIC Guide to Securing Personal Information — oaic.gov.au guide-to-securing-personal-information
OAIC's authoritative guidance on what "reasonable steps" means under APP 11. Maps to ISO/IEC 27001 Annex A controls. Adjusts the standard based on entity size + sensitivity of information.
ACSC Essential 8 — cyber.gov.au essential-eight
Australian Cyber Security Centre's 8 mitigation strategies. Maturity Level 1 is a reasonable baseline for SMBs handling routine personal information. Maturity Level 2-3 for businesses handling sensitive information.
ISO/IEC 27701 — Privacy Information Management System
International standard for Privacy Information Management Systems (PIMS). Extends ISO/IEC 27001. Provides a certifiable framework for demonstrating compliance with privacy regulations including the Australian Privacy Act.
Privacy by Design — The 7 Foundational Principles (Cavoukian)
Original Privacy by Design framework by Ann Cavoukian (Information and Privacy Commissioner of Ontario). The conceptual foundation behind the controls in this page. Now codified in ISO/IEC 27701.
All 22+ industries served
Industry-specific Privacy by Design priorities.
Every industry has a different threat surface. Healthcare prioritises encryption + audit logs on health information. Mining prioritises biometric-template protection. Real estate prioritises tenancy-database access controls. Use this matrix to prioritise your own controls.
Construction
PbD focus — Subcontractor TFN + super-fund-membership data triggers TFN handler obligations (always-covered regardless of turnover). White card / induction database under APP 6 — secondary use limits.
Healthcare
PbD focus — Health information requires explicit consent under APP 3.3 + APP 6.2(c). My Health Record interactions, AHPRA registration data, Medicare claims all carry overlapping consent regimes.
Hospitality
PbD focus — Loyalty programme data + booking-system PII + employee TFNs all in scope when above threshold. POS data with card-on-file triggers PCI-DSS overlap (separate from Privacy Act but related).
Retail
PbD focus — E-commerce capture of address + payment + browsing history all in scope above threshold. APP 5 collection notice required at point of capture; APP 1 privacy policy must be findable on the site.
Professional Services / Consulting
PbD focus — Client-confidential information sits under both Privacy Act + common-law confidentiality. APP 11 reasonable-security standards extend to engagement files at rest + in transit.
Digital / Tech / SaaS
PbD focus — Cookie / analytics / session data all PII in scope. APP 8 cross-border transfer requires either same-or-substantially-similar protection by the foreign recipient OR explicit consent.
Finance / Mortgage Brokers
PbD focus — Credit information has stricter rules than general personal information — separate consent regime under Pt IIIA. APP 12 access requests carry credit-specific response time limits.
Legal
PbD focus — Client legal-privilege information sits above Privacy Act protection but APP rules still apply to handling. Conflict-check databases under APP 11 reasonable-security standards.
Childcare / Early Learning
PbD focus — Parent ID + child medical records + emergency contacts under APP 3.3 explicit-consent regime. Photo/video consent forms require granular specificity per APP 5 collection notices.
Education / RTOs
PbD focus — Student record systems carry both APP and federal Education and Training Reform Act obligations. Disability-support records are sensitive information under APP 3.3.
Manufacturing
PbD focus — Supplier portal capture + customer-relationship data + employee biometric (timeclock) data all in scope. APP 1 privacy policy + APP 5 collection notice required at customer onboarding.
Transport / Logistics
PbD focus — Telematics / GPS / ELD data is personal information about the driver. APP 5 collection notice required at driver onboarding; secondary use restricted under APP 6.
Mining / Resources
PbD focus — Biometric site-access data is sensitive information under APP 3.3 — explicit consent required. FIFO worker family-contact data carries higher-than-baseline privacy risk.
Agriculture / Primary Production
PbD focus — Seasonal worker data + WHM (working holiday maker) records carry overlap with immigration data-handling regime. Drone footage capturing neighbouring properties may breach others’ privacy.
Fitness / Health Clubs
PbD focus — Member health screening + biometric access (gym entry fingerprints) + personal training records all sensitive information under APP 3.3 explicit-consent regime.
Not-for-Profit
PbD focus — Donor data + beneficiary case files + volunteer working-with-children-check records all sensitive. APP 1 privacy policy must address donor + beneficiary + volunteer separately.
Events / Conferences
PbD focus — Attendee dietary + accessibility data is sensitive information under APP 3.3. Photo / video capture at events requires APP 5 collection notice + opt-out signage.
Creative / Photography / Production
PbD focus — Model release + image rights consent under APP 5 + APP 6 secondary-use rules. Capture of minors requires parental consent + sensitive-information regime under APP 3.3.
Marketing / Advertising Agencies
PbD focus — Email-marketing under Spam Act 2003 + APP 7 (direct marketing) overlap. Lead-generation forms must satisfy APP 5 collection notice + APP 1 privacy policy linkage.
HR / Recruitment
PbD focus — Resume + background-check + reference data all PII. Background checks involving police records are sensitive information under APP 3.3 — explicit consent required.
Insurance Brokers / Underwriters
PbD focus — Medical reports + claim histories + financial-position data all sensitive information. APP 8 cross-border data flow common in re-insurance — disclosure regime applies.
Real Estate / Property Management
PbD focus — Tenancy applications carry the heaviest collection notice requirements per APP 5 + tenancy-database-specific rules. Bond data + utility account references all in scope.
FAQs
Privacy by Design — answered.
What is Privacy by Design (PbD)?
Privacy by Design is the engineering discipline of building privacy into the system from day one — not bolting it on after a breach. The framework was developed by Ann Cavoukian (former Privacy Commissioner of Ontario) and is now codified in ISO/IEC 27701 and referenced in the OAIC Privacy Management Framework. Seven foundational principles (proactive not reactive, privacy as default, embedded into design, full functionality, end-to-end security, visibility and transparency, user-centric).
Does APP 11 require specific security controls?
APP 11.1 requires "reasonable steps" — the standard varies with the kind and sensitivity of information, the size of the entity, and the practicality of the steps. The OAIC interprets this through the Guide to Securing Personal Information, which maps to control sets like ISO/IEC 27001, the Essential 8, and SOC 2. Reasonable steps for an SMB handling routine personal information are very different from reasonable steps for a hospital handling health information.
How does APP 8 work with overseas SaaS providers?
When you disclose personal information overseas, APP 8 makes you accountable for any APP breach by the overseas recipient — unless the recipient is bound by laws or a binding scheme that provide substantially-similar protection AND a complaint mechanism is available, OR the individual gave express consent after being told consent removes the safeguard. Most platforms contract overseas processors to APP-equivalent contractual terms — that satisfies the substantially-similar test.
What is the OAIC Privacy Management Framework?
The OAIC Privacy Management Framework is a 4-step practical playbook for embedding privacy in an APP entity: (1) embed a culture of privacy that enables compliance, (2) establish robust internal practices, procedures, and systems, (3) evaluate the privacy practices, procedures, and systems to ensure continued effectiveness, (4) enhance your response to privacy issues. It is the regulator's expected baseline for "reasonable steps" under APP 11.
Do I need ISO/IEC 27701 certification?
No — certification is not legally required. But ISO/IEC 27701 (Privacy Information Management System) provides a structured way to demonstrate "reasonable steps" under APP 11. Larger SMBs and any business that handles health, credit, or large volumes of personal information often pursue 27701 certification because it scales the privacy programme and signals trust to customers + B2B buyers.
How does XIntelliSync apply Privacy by Design?
Privacy controls are first-class citizens in the platform: encryption-at-rest is the default storage layer; MFA is enforced on every admin account; audit logs run on every customer-data query; APP 5 collection notices auto-render on every customer-facing form; APP 8 cross-border records are kept for every overseas processor; deletion is real (not a status flag). XGVS Layer 9 is the runtime enforcement layer — if a feature would breach APP 11 reasonable security or APP 8 cross-border safeguards, the action halts before it executes.
Continue reading