
Workspace Security
Coworking privacy and information security
Assess confidential work in a coworking space across calls, printing, networks, storage and guest access.
A coworking space can support confidential work when the business checks what others might hear, see, collect or access. Start with the work your team handles, then assess the space and its rules against those risks. A private office door alone does not settle questions about calls, shared printers, Wi-Fi or visitors.
Map the work before assessing the space
List the activities people will carry out on site: client meetings, personnel matters, customer records and contract work. For each, ask who may see or hear the information, where it will be stored and whether the activity needs to happen in the coworking space.
Set a practical boundary for the team: which work is suitable at a shared desk, which needs a private room or approved service, and which must happen elsewhere. Check any client, professional or contractual requirements that apply.
Cybersecurity Risks in Remote and Shared Work Environments
- Percentage of small businesses affected by cyberattacks in 202358%
- Common cause of data breaches in remote workUnsecured Wi-Fi connections
- Proportion of employees who reuse passwords across work and personal accounts43%
Check where sharing creates exposure
| Exposure point | Decision to make |
|---|---|
| Conversations | Which discussions need a private room, and what is the fallback if none is suitable? |
| Screens and devices | Can others see the work, and do devices lock when unattended? |
| Printing and scanning | Who can release a job, collect output or receive a scan? |
| Network | Which connection is approved for work, and who manages it? |
| Materials | Where are paper files and devices kept during the day and overnight? |
| Visitors | Where may guests go, who hosts them and when does access end? |
Discuss these points with the operator and your own IT or information owner. The operator can explain the building and shared services; your business decides what its people may use there.
Record answers that depend on a particular membership, room or configuration. Feature names such as “private Wi-Fi” and “lockable office” do not establish the controls behind them.
Use controls that address each exposure
For confidential calls, consider whether the space is suitable for conversations that others must not hear. The managing calls in coworking spaces article covers this in detail.
For shared printers and scanners, check whether they are suitable for the information your team handles. The reviewing shared printing article has detailed guidance.
For networks, check that your organisation’s requirements can be met in the space. The reviewing coworking networks article sets out detailed guidance.
Match storage access to the material. Ask who holds keys or codes and who can enter after hours.
For digital files, use an approved service with access limited to those who need it. Check backup and recovery arrangements; cloud storage does not necessarily include the backup your business needs.
Apply a privacy and retention test
For personal information, first ask whether your business holds a record containing it. The OAIC explains that an entity holds information when it has possession or control of the record; this is not limited to records physically on its premises.
That distinction matters in a coworking arrangement: assess your business’s possession or control of records, rather than treating their physical location as the only test. APP 11 applies to personal information an APP entity holds, and requires active measures to protect it.
Consider the full range of harm when reviewing a proposed work activity: misuse, interference or loss, as well as unauthorised access, modification or disclosure. This gives the team a more complete test than asking only whether another person can see the information.
The OAIC says APP entities must actively consider whether they are permitted to retain personal information. When it is no longer needed for a purpose for which it may be used or disclosed under the APPs, reasonable steps must be taken to destroy or de-identify it.
There are exceptions to that destruction or de-identification requirement: it does not apply where the information is part of a Commonwealth record, or where an Australian law or a court or tribunal order requires retention.
Include those conditions when deciding whether information can be removed from a work location or service.
Agree how incidents will be handled
Write down whom staff should contact about a lost credential, missing document, misdirected print job or unexpected visitor. The operator may control a door or printer while your organisation controls the information. Agree how both sides will share what is needed to respond.
Before using the space for sensitive work, walk through a typical day: take a call, print or avoid printing a document, store materials and admit a visitor. Record gaps and set a safer process for tasks the space cannot support.
In this guide
- Handling confidential calls in shared offices: a procedureDecide where to take confidential calls in a shared office, secure the meeting setup and plan a fallback when privacy is inadequate.
- Reviewing shared printer and network risksTrace shared print jobs and scans, then check the coworking network boundary and approved connection for sensitive work.
- Choosing storage for sensitive business materialsChoose physical and digital storage for sensitive materials in coworking by checking access, recovery and end-of-use handling.
- Defining guest access to private team areasSet guest routes, hosts, permissions and expiry for visits to private team areas in a coworking space.



