Properly managing the offboarding process is crucial toensure a smooth transition and protect your business from risks. This factsheet provides essential steps small businesses should follow when offboarding employees to maintain security, ensure compliance, and protect business interests.
Security Risks: Prevent unauthorised access to company systems, data, or assets by revoking access promptly.
Business Continuity: Ensure a smooth transition of duties and protect important client and business relationships.
Compliance: Meet legal obligations related to any non-compete clauses.
Notify Key Departments: Alert HR, IT, and finance to coordinate payroll, benefits, and access removal.
Revoke Access and Change Passwords: Immediately revoke access to company systems, networks, and confidential data. Change passwords to all business accounts the employee had access to, including email, project management tools, and cloud storage.
Recover Company Assets: Collect laptops, phones, access cards, and other company property. For devices that are no longer usable, follow proper disposal or recycling protocols.
Dispose of Devices and Accounts: If devices are being retired, ensure proper data wiping or destruction to prevent sensitive information from being accessed. If the employee had access to cloud accounts or online services, ensure these accounts are closed or transferred to active team members.
Use Document Shredding Services: Safely dispose of any sensitive printed documents. Consider using professional document shredding services to ensure that no confidential information can be retrieved from discarded paperwork.
Manage Knowledge Transfer: Ensure a thorough handover of ongoing projects, client relationships, and critical documentation.
Review Non-Compete Agreements: If applicable, ensure departing employees understand and comply with any non-compete or confidentiality clauses.
Exit Communication: Clearly communicate the employee’s departure internally and to relevant external stakeholders.
Data Privacy: Securely remove the departing employee’s access to sensitive client, colleague, or business data.
Proper Disposal of Documents: Use document shredding services for secure destruction of physical records, preventing any unauthorised access.
Record-Keeping Obligations: Small businesses must keep accurate employee records (onboarding documentation, payslips, time sheets, leave records) for 7 years, as mandated by the Fair Work Act. Failure to do so can result in fines. However, it is best practice to archive ex-employee records so that they are not routinely accessible.
Privacy Act: If your business handles personal information, ensure you comply with the Privacy Act 1988.
Password Management: Use password managers to revoke access to all business accounts quickly and change shared passwords as necessary.
Cloud Backup and Data Disposal: Backup all necessary files before offboarding. For devices no longer in use, ensure proper data wiping and disposal protocols to protect sensitive information.
Human Resources Software: HR tools exist that can assist you to manage access, payroll, and exit documentation, ensuring compliance with legal obligations.
Identity Care Australia & New Zealand Ltd (IDCARE) provides identity and cyber security incident response services (the Services) in accordance with the following disclaimer of service:
Mon - Fri: 8am - 5pm AEST
QLD: 07 3555 5900
ACT & NSW: 02 8999 3356
VIC: 03 7018 2366
NT, SA & WA : 08 7078 7741
Mon - Fri: 10am - 7pm NZST
AKL: 09 884 4440
IDCARE as a registered charity does not ask individuals to donate or pay for our front line services. We are not a charity that can receive tax deductible donations.
We rely on organisations that care enough about you to care about us to keep our charitable service going. Proudly these organisations are displayed above and on our Subscriber Organisations page.
If you are asked for payment from someone claiming to be from IDCARE, please report this to us using our Report Phishing email.
IDCARE has access to the Department of Home Affairs Free Interpreting Service, delivered by the Translating and Interpreting Service (TIS National). Access to the Free Interpreting Service is provided to assist you to communicate with non-English speaking people who hold a Medicare card. Please note that the service does not extend to New Zealand citizens or residents who do not hold an Australian Medicare card, or to tourists, overseas students or people on temporary work visas.
New Zealand Relay provides services to help Deaf, hearing impaired, speech impaired, Deafblind and standard phone users communicate with their peers.
A TTY user connects to New Zealand Relay via a toll-free number and types their conversation to a Relay Assistant (RA) who then reads out the typed message to a standard phone user (hearing person).
The RA relays the hearing person's spoken words by typing them back to the Textphone (TTY) User.
The National Relay Service (NRS) is an Australian government initiative that allows people who are deaf, hard of hearing and/or have a speech impairment to make and receive phone calls.
The NRS is available 24 hours a day, every day and relays more than a million calls each year throughout Australia.
ABN 84 164 038 966
IDCARE acknowledges and Respects the traditional custodians of the land on which we operate across Australia and New Zealand.
This website may contain names, images and voices of deceased Aboriginal, Torres Strait Islander and Māori peoples.