Choose a destruction arrangement based on information sensitivity, custody, retention requirements and evidence. The location alone does not establish security.
The facts behind the comparison
For entities covered by the Australian Privacy Principles, OAIC guidance describes reasonable steps to destroy or de-identify personal information when no longer needed, subject to retention exceptions. Source: OAIC — Chapter 11: APP 11 Security of personal information.
What to compare
| Decision | On-site destruction | Off-site destruction |
|---|---|---|
| Custody | Confirm secure storage until the vehicle arrives. | Confirm sealed collection, transport custody and facility controls. |
| Witnessing | Ask what can be witnessed and documented. | Ask what records evidence receipt and destruction. |
| Service scope | Confirm accepted media and destruction method. | Confirm the same media and method requirements. |
| Exceptions | Agree handling of missed visits and unsuitable material. | Agree handling of delayed, rejected or incomplete loads. |
Before you decide
- Check the retention schedule before releasing any records.
- Specify paper and other media separately.
- Ask for the chain-of-custody process and incident reporting.
- Keep service evidence alongside the authorised destruction record.
What this comparison cannot tell you
A destruction certificate alone does not establish full privacy compliance. This comparison does not determine whether your business is an APP entity or override other record-retention requirements.
Related decisions
Explore the related comparison · Explore waste services
Discuss your waste setup with Bundle Waste.
Sources
- OAIC — Chapter 11: APP 11 Security of personal information. 11.29–11.34 and 11.49–11.50. Checked 18 September 2026.
Bundle Waste