Savira - Making Compliance Easy

Retail and Ecommerce Privacy Risk Scorecard

A 10-minute self-assessment for Australian online stores and retailers.

Retailers collect personal information at almost every touchpoint, and online most of it is collected automatically before anyone agrees to anything. Consent standards have tightened, the OAIC has taken action against major retailers over in-store data collection, and a statutory tort for serious invasions of privacy is in force. This scorecard covers governance, your website and tracking, customer data and marketing, in-store collection, and security. If you sell online only, answer Unsure for the in-store section and read your result on the other four.

0 of 36 answeredScore: 0/72

Governance and accountability

Questions 1 to 6 of 36

1A senior staff member is formally responsible for privacy compliance.
2Privacy risk is reported to owners, directors or the board at least annually.
3There is a documented privacy management plan.
4Staff receive privacy training at least once every 12 months, including casual and seasonal staff.
5Privacy obligations are included in onboarding for new store and head office employees.
6There is a documented data breach response procedure aligned to the Notifiable Data Breaches scheme.

This assessment provides general information only and does not constitute legal advice.

Want this fixed rather than just listed?

Savira handles the consent side of this for you - a banner that blocks tags until people agree, a record of every consent so you can prove it, and an evidence pack you can hand to anyone who asks. Free plan, about 15 minutes to set up.