Savira -- Making Compliance Easy

Legal Privacy Risk Scorecard 2026

A 10-minute self-assessment for Australian law firms and legal practices.

Since 1 July 2026, law firms providing designated services under the AML/CTF Act have been reporting entities, which brings customer due diligence and record-keeping obligations alongside existing privacy duties. Firms also hold some of the most sensitive personal information in the economy, from family and criminal matters to health and financial records. This scorecard helps you identify gaps across governance, client onboarding, matter files, marketing and security.

0 of 30 answeredScore: 0/60

Governance and accountability

Questions 1 to 6 of 30

1A partner or senior staff member is formally responsible for privacy compliance.
2Privacy risk is reported to partners or the board at least annually.
3There is a documented privacy management plan or the firm has begun developing one.
4Staff receive privacy training at least once every 12 months, including on handling sensitive information.
5Privacy obligations are included in onboarding for new employees, paralegals and contractors.
6There is a documented data breach response procedure aligned to the Notifiable Data Breaches scheme.

This assessment provides general information only and does not constitute legal advice.

Ready to connect?

Start collecting compliant consent through your website in minutes. No developers required.