Skip to main content

Assess agency privacy risk

An agency privacy risk assessment provides a snapshot of its current privacy risks and how it will manage them as an organisation.

A privacy risk assessment will allow an agency to:

  • identify privacy risks
  • identify potential mitigations
  • prioritise resources to areas of greatest risk
  • identify opportunities for improvement.

Privacy risk assessments are most effective when aligned or integrated with an agency’s overall risk management approach. Privacy risk assessments should be prepared in consultation with the appropriate business units.

Completing a privacy risk assessment

Follow these 4 steps when completing a privacy risk assessment.

1. Gather information

Establish privacy context

Complete a data inventory

Undertake a third party inventory

2. Assess the risk

Identify the risk

Rate the risk

3. Manage the risk

Determine risk response

Understand common agency privacy risks

4. Monitor, review and update

Review often

Communicate and consult

In this section

Common agency privacy risks

Read about common agency privacy risks, who to involve and potential mitigations.

Utility links and page information

Was this page helpful?
Thanks, do you want to tell us more?

Do not enter personal information. All fields are optional.

Last updated