Deleting a name is not automatically de-identification. Australian privacy law focuses on whether a person is no longer reasonably identifiable and requires reasonable steps to destroy or de-identify certain personal information when it is no longer needed.
De-identification Is Not the Same as Deleting a Name
The OAIC describes de-identification as removing or altering information that identifies an individual or is reasonably likely to identify them. Simply deleting a name while leaving a unique combination of address, purchase history, device identifiers or rare characteristics may not be enough.
The practical test is whether the person remains reasonably identifiable in the circumstances.
APP 11 Creates a Real Destruction/De-identification Obligation
APP 11.2 requires an organisation to take reasonable steps to destroy personal information or ensure it is de-identified when it no longer needs the information for any purpose for which it may be used or disclosed under the Privacy Act, subject to the statutory exceptions.
Where physical deletion is technically impossible, the OAIC's guidance explains that putting the information beyond use or de-identifying it can be relevant approaches.
But There Is Not a General Australian Right to Demand De-identification on Request
This is a crucial distinction. The Privacy Act gives individuals access and correction rights and, in certain situations, the ability to complain about handling of their information. APP 11.2 is primarily an obligation on organisations when information is no longer needed; it is not a universal consumer election saying "convert my entire history into anonymous data."
When De-identification Can Fail
A dataset can remain personal information if it can reasonably be linked back to an identifiable person using information held by the organisation or another party, or if rare combinations of characteristics make re-identification reasonably likely.
The OAIC recommends testing de-identification processes and considering re-identification risk, rather than assuming that a simple pseudonym or hashed identifier is anonymous.
How to Make a Useful Request
- Identify the personal information you believe is no longer needed.
- Ask why the organisation continues to retain it.
- Ask how long retention is intended to last.
- Ask whether the information will be destroyed or de-identified under APP 11 when no longer needed.
- If you are seeking deletion or correction, state that separately as an access/privacy request.
Do Not Assume "Anonymous Analytics" Is Automatically Outside Privacy Law
A business may legitimately retain aggregated or genuinely de-identified analytics after deleting direct identifiers. But if a record remains reasonably linkable to a person, the Privacy Act may still apply.
This distinction becomes especially important for loyalty data, device identifiers, health information and longitudinal behavioural datasets.
What This Means Practically
- De-identification breaks or reduces the identity link; it is not just deleting a name.
- APP 11.2 can require destruction or de-identification when personal information is no longer needed.
- There is no universal statutory right to demand de-identification of any dataset on request.
- Ask about retention, purpose and re-identification risk.
- Preserve the organisation's response if you believe it is retaining information without a valid need.
Related Kibbo Tools
Sources
- OAIC — APP 11 Security of personal information, current guidance. oaic.gov.au
- OAIC — Consolidated APP Guidelines, Chapter 11 (October 2025). oaic.gov.au
- OAIC — Privacy guidance on age-assurance technologies, March 2026, including de-identification principles. oaic.gov.au
- OAIC — What is personal information?. oaic.gov.au