Savira - Making Compliance Easy

Legal Privacy Risk Scorecard

A 10-minute self-assessment for Australian law firms and legal practices.

Since 1 July 2026, law firms providing designated services under the AML/CTF Act have been reporting entities, which brings customer due diligence and record-keeping obligations alongside existing privacy duties. Firms also hold some of the most sensitive personal information in the economy, from family and criminal matters to health and financial records. This scorecard helps you identify gaps across governance, client onboarding, matter files, marketing and security.

0 of 30 answeredScore: 0/60

Governance and accountability

Questions 1 to 6 of 30

1A partner or senior staff member is formally responsible for privacy compliance.
2Privacy risk is reported to partners or the board at least annually.
3There is a documented privacy management plan or the firm has begun developing one.
4Staff receive privacy training at least once every 12 months, including on handling sensitive information.
5Privacy obligations are included in onboarding for new employees, paralegals and contractors.
6There is a documented data breach response procedure aligned to the Notifiable Data Breaches scheme.

This assessment provides general information only and does not constitute legal advice.

Want this fixed rather than just listed?

Savira handles the consent side of this for you - a banner that blocks tags until people agree, a record of every consent so you can prove it, and an evidence pack you can hand to anyone who asks. Free plan, about 15 minutes to set up.