Skip to content
Private Preview
Join Waitlist →

Compliance Presets

One-click configuration for Privacy Act, PCI-DSS, and ASD Essential Eight alignment

4 min readAuthor: Redactorr Support Team · [email protected]Last reviewed: March 2026

Compliance Presets: One-Click Privacy Act Alignment

Navigating Australian privacy regulations and industry-specific compliance requirements is demanding. Each framework has its own data categories, handling requirements, and obligations.

Compliance Presets turn that complexity into a one-click configuration.

What Are Compliance Presets?

Pre-configured detection patterns tailored to specific regulatory frameworks:

Privacy Act Preset (General Privacy): Detects personal information as defined under the Australian Privacy Act 1988 — names, contact details, government identifiers (TFN, Medicare, ABN), financial information, health information, and other data that could reasonably identify an individual. Aligned with Australian Privacy Principle 11 (security of personal information).

Healthcare Preset (AU): Detects sensitive health information under the Privacy Act 1988, including medical record numbers, patient identifiers, AHPRA registration numbers, Medicare numbers, health fund member IDs, and referral details. Relevant to healthcare providers, hospitals, allied health practitioners, and aged care operators.

PCI-DSS Preset (Payment Cards): Detects Primary Account Numbers (PANs), CVV codes, card expiration dates, cardholder names, and BSBs. Required for any organisation handling payment card data, regardless of jurisdiction.

ASD Essential Eight Preset (Cybersecurity): Detects credentials, API keys, configuration secrets, database connection strings, and access tokens — the categories most commonly involved in the Australian Signals Directorate's Essential Eight breach scenarios.

How They Work

When you enable a preset:

Detection patterns activated — the relevant patterns are automatically enabled for your document

Sensitivity tuned — detection thresholds are adjusted for the compliance context (high precision, low missed detections)

Redaction format applied — default redaction formats match the framework requirements

1 / 3

Real-World Use Cases

Healthcare providers: Enable the Healthcare preset before sharing redacted patient records for research, audit, or specialist referral.

Legal and accounting firms: Use the Privacy Act preset when handling client documents containing personal information, particularly for compliance with APP 11 obligations.

E-commerce and finance: Apply the PCI-DSS preset to sanitise payment logs before sharing with developers or auditors.

IT and security teams: Use the ASD Essential Eight preset to scrub configuration files and log exports before sharing externally.

Presets Are Not Certifications

Important: Redactorr's presets help you meet compliance obligations by detecting and redacting regulated data types. However:

  • Redactorr is not itself certified under the Privacy Act, PCI-DSS, or any other standard
  • Using Redactorr does not automatically make your organisation compliant
  • Compliance requires policies, training, audits, and organisational controls beyond data redaction alone

Think of presets as guardrails, not guarantees.

Customising Presets

Presets are starting points. You can customise them:

  • Add organisation-specific identifiers (e.g., patient ID formats, internal matter numbers)
  • Adjust redaction formats (e.g., show last 4 digits of card numbers)
  • Whitelist known safe values (e.g., your publicly listed ABN)

Combining Presets

You can enable multiple presets simultaneously. For example:

Healthcare + Payments: A hospital billing department may need both the Healthcare preset (patient information) and PCI-DSS (payment cards) active at the same time.

Privacy Act + ASD Essential Eight: An IT team handling personal data exports with embedded credentials needs both active.

Overlapping patterns are automatically deduplicated, and the strictest redaction rule wins.