Cyber Insurance Subjectivity Tracker

Controls / Privacy Act (Australia)

Personal information held is protected by reasonable steps against misuse, interference, loss and unauthorised access

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: take reasonable steps to protect the personal information you hold.

In Australia

Only when the Privacy Act 1988 applies to the business.

ClauseThe held text, and the evidence an assessor asks for
APP 11
Australian Privacy Principles
Security of personal information

Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.

evidence an assessor asks for Information security controls for personal information; Destruction/de-identification of redundant PI

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 90 by the default rule: a Privacy Act line. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule