Skip to main content

Common agency privacy risks

Read about common agency privacy risks, who to involve and potential mitigations.

Privacy risks

Staff are not adequately trained to handle personal information

The agency does not understand where personal information is stored and processed

Privacy risks are not associated with new products, services or processes

Privacy risks are not associated with material changes to existing products, services or processes

Personal information is retained longer than is necessary for the business purpose

More personal information is collected than is required for the business purpose

Third party providers do not handle personal information appropriately

Personal information is used or disclosed in an unauthorised manner

Privacy-related enquiries are not appropriately handled

Personal information is inadequately secured

Privacy processes do not operate as intended

Privacy-related incidents are not responded to appropriately

The agency does not learn from patterns of privacy-related incidents

Utility links and page information

Was this page helpful?
Thanks, do you want to tell us more?

Do not enter personal information. All fields are optional.

Last updated