Savira - Making Compliance Easy

Privacy Risk Scorecard

A 10-minute self-assessment for any Australian business.

This covers the obligations every organisation bound by the Australian Privacy Principles shares, without the sector-specific overlays. Penalties for serious or repeated interferences with privacy reach $50 million, a statutory tort for serious invasions of privacy is in force, and the small business exemption has been narrowing. If one of the six industry scorecards fits you better, take that one instead: the questions are sharper.

0 of 30 answeredScore: 0/60

Governance and accountability

Questions 1 to 6 of 30

1A named person is formally responsible for privacy compliance.
2Privacy risk is reported to owners, directors or the board at least annually.
3There is a documented privacy management plan, or work has begun on one.
4Staff receive privacy training at least once every 12 months.
5Privacy obligations are included in onboarding for new employees and contractors.
6There is a documented data breach response procedure aligned to the Notifiable Data Breaches scheme.

This assessment provides general information only and does not constitute legal advice.

Want this fixed rather than just listed?

Savira handles the consent side of this for you - a banner that blocks tags until people agree, a record of every consent so you can prove it, and an evidence pack you can hand to anyone who asks. Free plan, about 15 minutes to set up.