What “Reasonable Steps” Means in Practice
APP 11 does not prescribe controls. It requires steps that are reasonable in the circumstances — which means the standard is set retrospectively, by a regulator, with the benefit of knowing what went wrong.
That has a practical consequence most organisations underweight. Where an exposure was externally visible, freely checkable and inexpensive to identify, it becomes very difficult to characterise the absence of a check as reasonable. The cheaper the step, the harder it is to justify not having taken it.
The Year the Mechanics of Your Website Became a Privacy Control
In June 2026 the Privacy Commissioner determined that Medmate and Monash IVF breached privacy law through tracking pixels, establishing that health providers must obtain consent before collecting sensitive information this way. In the same month an OAIC sweep found multiple Australian health service websites covertly transmitting sensitive health information to social media platforms.
The reasoning is not confined to health. Where a URL path discloses a sensitive attribute — a treatment, a practice area, a hardship application, an eligibility check — transmitting that path to a third-party advertising platform alongside a persistent identifier is a collection of sensitive information, and APP 3 sets a materially higher bar for that than for personal information generally.
There is a second exposure almost nobody is naming. If your site transmits to destinations your privacy policy does not disclose, the policy itself is inaccurate. Consent is contestable; whether your policy names the recipients your site actually contacts is a matter of fact, establishable by anyone with a browser.
What a BlackFlag Advisory Privacy Assessment Covers
- Third-party transmission inventory — every destination your public pages contact, including vendors loaded indirectly by tag managers, observed in a browser rather than read from a configuration
- Consent sequencing — whether scripts fire before the visitor answers your consent mechanism, which renders that mechanism decorative regardless of its wording
- Sensitive path analysis — which of your URLs disclose a health, disability, legal or financial circumstance simply by being requested
- Privacy policy reconciliation against observed practice, including APP 8 overseas recipient disclosure
- External exposure of systems holding personal information — internet-facing interfaces, forgotten hosts and unpatched web properties
- Credential exposure where corporate identities appear in published breach and infostealer corpora, which speaks directly to unauthorised access risk under APP 11
- APP-by-APP mapping of every finding, with the evidence attached and dated
Who This Is For
Health service providers
The June 2026 determinations are directly on point, and the concurrent OAIC sweep tells you the regulator is already looking.
Legal practices
Family, criminal, immigration and employment practice-area pages disclose a great deal about the person browsing them.
Financial services and insurers
Hardship, claims and product-specific pages disclose circumstance, and a persistent identifier turns that into an inference about an identifiable person.
Aged care, disability and education providers
Service enquiry, wellbeing and support paths disclose health and disability information by the act of being requested.
Any APP entity preparing for 10 December 2026
From that date, privacy policies must disclose substantially automated decisions that significantly affect individuals. Meeting it requires an accurate inventory first.
How the Engagement Runs
Five steps. The only one that requires your time is the first and the last.
1. Scope
We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.
2. Passive collection
We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.
3. Analysis and triage
Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.
4. Regulatory mapping
Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.
5. Delivery and walkthrough
A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.
Frequently Asked Questions
The questions we are asked most often by privacy officers, general counsel and practice managers.
What does APP 11 require?
APP 11.1 requires an APP entity to take such steps as are reasonable in the circumstances to protect personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure. What is reasonable is assessed against the entity’s circumstances, the sensitivity of the information, and the practicability of the steps available.
What did the June 2026 tracking pixel determinations decide?
In June 2026 the Privacy Commissioner made determinations finding that Medmate and Monash IVF breached privacy law through the use of tracking pixels, establishing that health providers must obtain consent before collecting sensitive information this way. A concurrent OAIC sweep found multiple Australian health service websites covertly transmitting sensitive health information to social media platforms.
Can an inaccurate privacy policy itself be a breach?
APP 1.3 requires a clearly expressed and up-to-date privacy policy, and APP 1.4 sets out what it must contain — including whether personal information is likely to be disclosed to overseas recipients and, where practicable, the countries concerned. Where a website transmits to destinations the policy does not disclose, the policy is inaccurate on its face. That is establishable in a single browser session.
Do you access our systems or databases?
No. The assessment observes only what your organisation discloses publicly — what your web properties transmit, what your domains and certificates reveal, and whether corporate credentials appear in published breach corpora. No systems, networks or accounts are accessed, probed or tested.
Packages are set out on the assessment packages page. If you are a health provider, a professional services firm, or any organisation whose service pages disclose a sensitive circumstance, book a short call.