Skip to content

Evidence request lists

Privacy Act 1988 (Australia)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach Response

AUPRV-7
Notifiable Data Breaches (NDB) Scheme, Incident Response

Per Privacy Act Part IIIC Notifiable Data Breaches scheme: breach notification. Requirements include (a) implement Notifiable Data Breaches (NDB) Scheme - if an eligible data breach occurs (unauthorised access or disclosure of personal information + likely to result in serious harm) notify OAIC + affected individuals as soon as practicable + (b) conduct breach assessment within 30 days of becoming aware of suspected breach + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + assessment process + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting OAIC reporting.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-7
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

Collection and Notice

AUPRV-2
APP 2-5 Anonymity, Solicited/Unsolicited Collection, Notification

Per APPs 2-5: anonymity + collection + notice. Requirements include (a) implement APP 2 - Anonymity and Pseudonymity - data subjects have option to deal with the entity not identifying themselves or using a pseudonym + (b) implement APP 3 - Collection of Solicited Personal Information only if reasonably necessary + lawful + (c) implement APP 4 - Dealing with Unsolicited Personal Information - destroy or de-identify if it would not have been lawful to collect + (d) implement APP 5 - Notification of the Collection of Personal Information at or before time of collection covering identity + purposes + recipients + access + correction + complaints + (e) maintain records of consent + notice + (f) integrate with broader privacy policy.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-2
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

Governance, Training, Enforcement

AUPRV-8
OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Per Privacy Act + OAIC + Privacy Reform Bill 2024-2025: governance + lifecycle + enforcement. Requirements include (a) cooperate with OAIC including responding to inquiries + facilitating audits + complying with determinations + (b) maintain Vendor and Outsourcing Management including supplier privacy due diligence + contractual flow-down + ongoing oversight + (c) deliver Training and Awareness programmes including role-based content + APPs + sensitive information + breach response + (d) operate Complaints Handling and Resolution mechanism enabling complaints to entity + OAIC + (e) maintain Enforcement and Penalties awareness including civil penalties (up to greater of AUD 50m + 30% adjusted turnover + 3x benefit gained for serious or repeated interferences with privacy under 2022 amendments) + (f) maintain governance + lifecycle.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-8
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

High-Risk Processing

AUPRV-6
Sensitive Information, PIA, Privacy by Design, Children

Per Privacy Act + OAIC guidance: heightened safeguards. Requirements include (a) implement Sensitive Information Handling per definition in Privacy Act including health + genetic + biometric + ethnicity + religion + political + sexual orientation + criminal record + trade union + with heightened consent + safeguards + (b) conduct Privacy Impact Assessment (PIA) for processing with significant privacy implications per OAIC guidance + (c) implement Privacy by Design and Default across systems + processes + products + procurement + (d) implement children's data protections per common law + statutory protections + (e) integrate with broader privacy programme + (f) maintain documented PIAs + safeguards.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-6
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

Individual Rights

AUPRV-5
APP 12-13 Access and Correction of Personal Information

Per APPs 12-13: access + correction. Requirements include (a) implement APP 12 - Access to Personal Information - upon request give access to personal information unless an exception applies + (b) implement APP 13 - Correction of Personal Information - upon request correct personal information that is inaccurate + out-of-date + incomplete + irrelevant + misleading + (c) maintain mechanism for receiving + verifying + responding to access + correction requests within statutory timelines + (d) handle refusals consistent with the Act + provide written notice of reasons + (e) maintain records of requests + responses + (f) integrate with complaint handling.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-5
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

Open Management and Accountability

AUPRV-1
APP 1 Open and Transparent Management + Privacy Management Framework

Per Australian Privacy Principle (APP) 1 + Accountability: open transparent management of personal information. Requirements include (a) implement APP 1 - manage personal information in an open and transparent way + (b) maintain a clearly expressed and up-to-date APP Privacy Policy describing how personal information is handled + (c) maintain Accountability and Privacy Management Framework with documented governance + roles + processes + (d) maintain Records of Processing including data flows + purposes + recipients + retention + (e) integrate with broader Australian Government Information Security Manual (ISM) + Notifiable Data Breaches scheme alignment + (f) maintain OAIC (Office of the Australian Information Commissioner) engagement.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-1
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

Quality and Security

AUPRV-4
APP 10-11 Quality, Security of Personal Information

Per APPs 10-11: quality + security. Requirements include (a) implement APP 10 - Quality of Personal Information - take reasonable steps to ensure personal information is accurate + up-to-date + complete + relevant + (b) implement APP 11 - Security of Personal Information - take reasonable steps to protect personal information from misuse + interference + loss + unauthorised access + modification + disclosure + and to destroy or de-identify when no longer needed + (c) implement encryption + access control + activity logging where appropriate + (d) conduct Regular Security Testing and Assessment + (e) integrate with broader information security baseline (ISO 27001 + ASD Essential Eight + ISM) + (f) maintain documented security measures.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-4
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial

Use and Disclosure

AUPRV-3
APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers

Per APPs 6-9: use + disclosure + marketing + cross-border + government identifiers. Requirements include (a) implement APP 6 - Use or Disclosure of Personal Information only for primary purpose collected unless data subject would reasonably expect or has consented + (b) implement APP 7 - Direct Marketing only where conditions met + opt-out mechanism + (c) implement APP 8 - Cross-Border Disclosure of Personal Information including reasonable steps that recipient does not breach APPs + (d) implement APP 9 - Adoption, Use, or Disclosure of Government Related Identifiers prohibited except in limited circumstances + (e) maintain records of use + disclosure + cross-border flows + (f) implement contractual + technical safeguards.

Artefacts an auditor will ask for
  • Privacy Act 1988 evidence for AUPRV-3
Where this commonly fails
  • NDB assessment process + PIA + vendor management partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Privacy Act 1988 (Australia) framework page.