What "Reasonable Security Safeguards" Means When the Act Doesn't Define It
Section 8(5) requires reasonable security safeguards without saying what that means technically. Here is how to reason about a term the Act deliberately leaves open.
What the Act says, and what it doesn't
Section 8(5) requires every Data Fiduciary to protect personal data in its possession or under its control, including data processed on its behalf by a Data Processor, by taking reasonable security safeguards to prevent a personal data breach. Notably, the Act does not enumerate specific technical measures, such as encryption standards, access control models, or logging requirements, the way some sectoral frameworks or overseas statutes sometimes do.
This is best understood as a deliberate legislative choice rather than an oversight. Technical security practice evolves quickly, and locking specific standards into primary legislation risks the law becoming outdated or, conversely, forcing organisations into specific technical choices that may not fit their actual risk profile.
Where the detail is expected to come from
The practical content of reasonable security safeguards is expected to be filled in over time through the Rules, through guidance the Board may issue in connection with actual cases, and through general industry practice and standards that a reasonable organisation in a given sector would be expected to follow. Existing information security frameworks and standards already in wide use, such as ISO 27001-aligned practices, encryption of data at rest and in transit, role-based access controls, and documented incident response procedures, are reasonable reference points even though the Act does not name them directly.
Because the standard is open-textured, what counts as reasonable for a large financial institution processing millions of records is unlikely to be judged by the same yardstick as what counts as reasonable for a small business handling a modest customer list; the standard is inherently proportionate to the nature and volume of data and the resources of the fiduciary, even though the Act does not spell this proportionality test out explicitly.
How this plays out if a breach occurs
In practice, the reasonableness of an organisation's safeguards is most likely to be tested retrospectively, after a breach has already occurred and the Board is considering whether Section 8(5) was complied with. Documented evidence of the safeguards actually in place at the time of the incident, security policies, access logs, past audit results, and evidence of prompt remedial action, is likely to matter a great deal in that assessment.
This creates a practical incentive to treat documentation of security measures as seriously as the measures themselves; an organisation with good practices it cannot evidence is in a materially weaker position than one with equally good practices it can demonstrate clearly.
Where to go next
The Readiness Assessment includes a security-safeguards module that can help benchmark current practices against what a reasonable regulator is likely to expect, and the /rules page should be checked periodically for any further technical detail the Rules eventually add.