Security of Personal Information
How Merion protects personal information from misuse, interference, loss, and unauthorised access — obligations under Australian Privacy Principle 11.
APP 11 — What it requires
Australian Privacy Principle 11 requires entities to take reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. It also requires that personal information be destroyed or de-identified when it is no longer needed for any purpose for which it may lawfully be used or disclosed.
APP 11 sets a floor of "reasonable steps" — the standard is not perfection, but a proportionate, layered set of controls appropriate to the sensitivity of the information and the scale of operations. Merion's approach is to meet that floor through both technical and organisational safeguards, rather than relying on any single measure.
Technical controls
- Encryption at rest: debtor PII — including name, phone number, email address, and postal address — is encrypted using AES-256-GCM at the field level, before being written to disk. AES-256-GCM provides authenticated encryption: any tampering with ciphertext is detected on decryption.
- Encryption in transit: all data transmitted between Merion's systems and user devices is encrypted using TLS 1.2 or higher. TLS 1.3 is used where supported by both parties. HSTS is enforced with a one-year max-age to prevent downgrade attacks.
- Authentication: Merion uses OIDC/PKCE-based single sign-on for staff and creditor access. Debtor access uses a passwordless flow (account reference + magic link + OTP), removing password credential risk entirely.
- Multi-tenant isolation: the application enforces tenant isolation at every data access point — creditors see only their own cases, and debtors see only their own account. There is no cross-tenant data leakage by design.
- Audit logs: access to personal information is recorded in append-only audit logs. These logs cannot be altered after the fact and are retained for the purposes of security review and regulatory response.
Organisational controls
- Role-based access: staff access to personal information is granted on a least-privilege basis — individuals have access only to what their role requires. Access rights are reviewed periodically.
- Staff training: Merion staff receive training on their obligations under the APPs and on Merion's internal privacy and data security procedures.
- Vendor due diligence: before engaging any technology sub-processor that will handle personal information, Merion reviews the vendor's security posture and requires a data processing agreement. See Vendor & Sub-Processor Due Diligence for detail.
Destruction and de-identification
APP 11.2 requires that personal information be destroyed or de-identified when it is no longer needed for any purpose for which it may lawfully be used or disclosed. When a case is closed and the applicable retention period has elapsed, Merion destroys or de-identifies the relevant personal information in accordance with its data retention schedule. Destruction events are recorded in the audit log.
See Data Retention Schedule for specific retention periods by data category.
Further information
For technical detail on encryption and key management, see Encryption & Key Management. For Merion's obligations in the event of a data breach, see Notifiable Data Breaches.
Ready to talk to Merion?
Whether you have accounts to recover or a question about a notice, the first conversation is always obligation-free.