• Skip to main content
  • Skip to footer

InfoGovANZ

Information Governance in the AI age

  • Become a Member
  • Member Login
  • Member Account
    • My Account
    • My Courses
    • Webinar Recordings
  •  
  • Home
  • About Us
    • Our Goals
    • Founder & Executive Director
      • Dr Susan Bennett
    • Advisory Board
      • Dr Peter Chapman
      • Matthew Golab
      • Andrew King
    • International Council
      • Dr Susan Bennett
      • Sarah Auva’a
      • Denise Backhouse
      • Barclay T Blair
      • Brynmor Bowen
      • Dr Pietro Brambilla
      • Dr Peter Chapman
      • Dr Ronke Ekwensi
      • Carol Feuerriegel
      • Matthew Golab
      • Mazen Kassis
      • Richard Kessler
      • Andrew King
      • Ilana Lutman
      • Lynne Saunder
      • Tarun Samtani
      • Dr Nichole Sterling
      • Dr Pieter Van Der Walt
      • Patrick E. Zeller
  • AI Governance
    • AI Governance Courses
    • AI Governance for Professionals
    • AI Governance for Directors
    • AI Resources
  • Events & Workshops
    • Upcoming Events
    • AI Governance Training
    • Bespoke Workshops
    • Webinar Recordings
  • Member Resource Hub
    • Latest News
    • Artificial Intelligence (AI)
    • Cyber & Info Security
    • Data – Sharing & Identity
    • eDiscovery
    • Environmental, Social and Governance (ESG)
    • FOI – Access to Information
    • Information Governance
    • Privacy
    • Records Management
    • IGANZ Industry Reports
    • The Governance of Things Monthly Publication
    • Webinar Recordings
  • Join Now
  • My account
    • Courses
    • Webinar Recordings

OAIC guidance on retention and deletion of PI

July 31, 2022 by InfoGovANZ

In July, OAIC published guidance on the retention and deletion of personal information (PI) collected during the COVID-19 pandemic. Organisations should take stock of the personal information they hold and assess whether it is necessary to continue to collect and retain PI.

Australian Privacy Principles 11.1 and 11.2 require that reasonable steps be taken to protect personal information and personal information be destroyed or de-identified once it is no longer needed.

If information is stored electronically, such as in cloud-based storage, servers, USBs or with a third-party provider, you should ensure that the digital records are permanently destroyed, including in any back-up system or offsite storage.

It is also important to consider whether employees require any training to ensure that personal information is securely destroyed.

In November, OAIC published the COVIDSafe privacy report in accordance with s 94ZB of the Privacy Act, which examined compliance and risk throughout the ‘information lifecycle’ of COVID app data collected during the pandemic. Read the COVIDSafe Report May–November 2022 here.

Filed Under: Privacy - Australia and NZ

Footer

Information Governance ANZ Pty Ltd

Level 26, 1 Bligh St, Sydney 2000
Ph: +61 2 8226 8546
E: infogovanz@infogovanz.com

ACN: 611 611 360

Linkedin Information Governance ANZ Twitter Information Governance ANZ

Become a Member
Corporate Partnership Opportunities

Contact

Copyright © 2026 Information Governance ANZ Pty Ltd · Privacy Policy · Terms of Use