Arrange confidential document destruction only after confirming what may be destroyed and what must be retained. Compare providers on the documented security process, chain of custody and full cost rather than treating a certificate or shred size as automatic legal compliance.
Check retention before disposal
Assign responsibility for approving destruction. Identify the document categories, relevant retention rules and any legal hold, investigation or contractual requirement. Keep the approved schedule with the disposal record.
For covered entities, OAIC guidance on APP 11 explains reasonable steps to destroy or de-identify information no longer needed, including retention exceptions. It does not mean every document held by every business must be shredded immediately.
Choose a process appropriate to the information
Compare on-site and off-site options by asking where documents are stored, who can access them, how transfers are recorded and when destruction occurs. Ask how the provider manages staff access, subcontractors and incidents.
Request the basis of any certification claim and confirm its scope and current status. Have your privacy or security lead determine the required destruction standard rather than assuming one advertised shred level fits every record.
Specify the service being quoted
List console or bin count, location, collection access, estimated volume and whether this is a recurring service or archive clear-out. Ask about material exclusions such as folders or other objects mixed with paper.
Separate rental, collection, destruction, minimum visit, additional containers and one-off removal costs. Confirm GST and whether the certificate or reporting carries a separate charge.
Verify the completed service
Request a record identifying the collection, document quantity or container identifiers, destruction date and process. Reconcile it with the authorised batch and invoice. A certificate helps document the activity but does not replace checking the actual security arrangement.
Keep electronic media separate
Identify drives, phones or other data-bearing equipment in an archive clear-out. Do not put them into a paper console unless the provider explicitly accepts and separately processes them. Ask the security lead to approve the appropriate sanitisation or destruction method for each medium.
Related guides
Sources
Checked 18 September 2026. Apply each source within its stated scope; site-specific approvals and quotes still need confirmation.
- Office of the Australian Information Commissioner — Chapter 11: APP 11 Security of personal information. Destroying or de-identifying personal information, retention exceptions.
Bundle Waste