Privacy Act 1988 (Australia)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach Response
Per Privacy Act Part IIIC Notifiable Data Breaches scheme: breach notification. Requirements include (a) implement Notifiable Data Breaches (NDB) Scheme - if an eligible data breach occurs (unauthorised access or disclosure of personal information + likely to result in serious harm) notify OAIC + affected individuals as soon as practicable + (b) conduct breach assessment within 30 days of becoming aware of suspected breach + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + assessment process + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting OAIC reporting.
- Privacy Act 1988 evidence for AUPRV-7
- NDB assessment process + PIA + vendor management partial
Collection and Notice
Per APPs 2-5: anonymity + collection + notice. Requirements include (a) implement APP 2 - Anonymity and Pseudonymity - data subjects have option to deal with the entity not identifying themselves or using a pseudonym + (b) implement APP 3 - Collection of Solicited Personal Information only if reasonably necessary + lawful + (c) implement APP 4 - Dealing with Unsolicited Personal Information - destroy or de-identify if it would not have been lawful to collect + (d) implement APP 5 - Notification of the Collection of Personal Information at or before time of collection covering identity + purposes + recipients + access + correction + complaints + (e) maintain records of consent + notice + (f) integrate with broader privacy policy.
- Privacy Act 1988 evidence for AUPRV-2
- NDB assessment process + PIA + vendor management partial
Governance, Training, Enforcement
Per Privacy Act + OAIC + Privacy Reform Bill 2024-2025: governance + lifecycle + enforcement. Requirements include (a) cooperate with OAIC including responding to inquiries + facilitating audits + complying with determinations + (b) maintain Vendor and Outsourcing Management including supplier privacy due diligence + contractual flow-down + ongoing oversight + (c) deliver Training and Awareness programmes including role-based content + APPs + sensitive information + breach response + (d) operate Complaints Handling and Resolution mechanism enabling complaints to entity + OAIC + (e) maintain Enforcement and Penalties awareness including civil penalties (up to greater of AUD 50m + 30% adjusted turnover + 3x benefit gained for serious or repeated interferences with privacy under 2022 amendments) + (f) maintain governance + lifecycle.
- Privacy Act 1988 evidence for AUPRV-8
- NDB assessment process + PIA + vendor management partial
High-Risk Processing
Per Privacy Act + OAIC guidance: heightened safeguards. Requirements include (a) implement Sensitive Information Handling per definition in Privacy Act including health + genetic + biometric + ethnicity + religion + political + sexual orientation + criminal record + trade union + with heightened consent + safeguards + (b) conduct Privacy Impact Assessment (PIA) for processing with significant privacy implications per OAIC guidance + (c) implement Privacy by Design and Default across systems + processes + products + procurement + (d) implement children's data protections per common law + statutory protections + (e) integrate with broader privacy programme + (f) maintain documented PIAs + safeguards.
- Privacy Act 1988 evidence for AUPRV-6
- NDB assessment process + PIA + vendor management partial
Individual Rights
Per APPs 12-13: access + correction. Requirements include (a) implement APP 12 - Access to Personal Information - upon request give access to personal information unless an exception applies + (b) implement APP 13 - Correction of Personal Information - upon request correct personal information that is inaccurate + out-of-date + incomplete + irrelevant + misleading + (c) maintain mechanism for receiving + verifying + responding to access + correction requests within statutory timelines + (d) handle refusals consistent with the Act + provide written notice of reasons + (e) maintain records of requests + responses + (f) integrate with complaint handling.
- Privacy Act 1988 evidence for AUPRV-5
- NDB assessment process + PIA + vendor management partial
Open Management and Accountability
Per Australian Privacy Principle (APP) 1 + Accountability: open transparent management of personal information. Requirements include (a) implement APP 1 - manage personal information in an open and transparent way + (b) maintain a clearly expressed and up-to-date APP Privacy Policy describing how personal information is handled + (c) maintain Accountability and Privacy Management Framework with documented governance + roles + processes + (d) maintain Records of Processing including data flows + purposes + recipients + retention + (e) integrate with broader Australian Government Information Security Manual (ISM) + Notifiable Data Breaches scheme alignment + (f) maintain OAIC (Office of the Australian Information Commissioner) engagement.
- Privacy Act 1988 evidence for AUPRV-1
- NDB assessment process + PIA + vendor management partial
Quality and Security
Per APPs 10-11: quality + security. Requirements include (a) implement APP 10 - Quality of Personal Information - take reasonable steps to ensure personal information is accurate + up-to-date + complete + relevant + (b) implement APP 11 - Security of Personal Information - take reasonable steps to protect personal information from misuse + interference + loss + unauthorised access + modification + disclosure + and to destroy or de-identify when no longer needed + (c) implement encryption + access control + activity logging where appropriate + (d) conduct Regular Security Testing and Assessment + (e) integrate with broader information security baseline (ISO 27001 + ASD Essential Eight + ISM) + (f) maintain documented security measures.
- Privacy Act 1988 evidence for AUPRV-4
- NDB assessment process + PIA + vendor management partial
Use and Disclosure
Per APPs 6-9: use + disclosure + marketing + cross-border + government identifiers. Requirements include (a) implement APP 6 - Use or Disclosure of Personal Information only for primary purpose collected unless data subject would reasonably expect or has consented + (b) implement APP 7 - Direct Marketing only where conditions met + opt-out mechanism + (c) implement APP 8 - Cross-Border Disclosure of Personal Information including reasonable steps that recipient does not breach APPs + (d) implement APP 9 - Adoption, Use, or Disclosure of Government Related Identifiers prohibited except in limited circumstances + (e) maintain records of use + disclosure + cross-border flows + (f) implement contractual + technical safeguards.
- Privacy Act 1988 evidence for AUPRV-3
- NDB assessment process + PIA + vendor management partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Privacy Act 1988 (Australia) framework page.