Skip to main content

Assess project privacy risk

A project privacy risk assessment (PIA) considers the risks associated with a specific process, product or service.

Project privacy risk

Assessing the privacy risks associated with a project is an important activity within any privacy programme.

Considering new projects through the information life cycle, which describes how personal information travels through an agency, can be useful for identifying, organising and communicating the potential privacy risks associated with a project.

Information life cycle

The information life cycle consists of:

  • collection
  • storage and security
  • use
  • access and correction
  • disclosure
  • retention
  • disposal.

An agency may also utilise the Information Privacy Principles (IPP) as a framework for identifying project privacy risks.

Office of the Privacy Commissioner — Privacy Principles

Assessment tools

Privacy Threshold Assessments and Privacy Impact Assessments are tools for assessing the privacy impact of a project.

Privacy Threshold Assessment (PTA)

Privacy Impact Assessment (PIA)

Privacy Impact Assessment toolkit

Reviewing a Privacy Impact Assessment (PIA)

PIAs may be presented in a range of styles and include different content depending on the agency completing the PIA and the project that is being assessed.

When reviewing a PIA, consider the following questions:

General

Collection

Storage and security

Use

Access and correction

Disclosure

Retention and disposal

Utility links and page information

Was this page helpful?
Thanks, do you want to tell us more?

Do not enter personal information. All fields are optional.

Last updated