

Last month, the Office of the Australian Information Commissioner (OAIC) released a self-assessment tool for organisations operating in Australia. The assessment is designed to take 15-20 minutes to complete and it scores your overall privacy maturity.
Generally speaking, we like the tool! It’s easy to follow, easy to understand, and it highlights some of the key foundational elements of privacy maturity – including items that are often overlooked, like timely destruction of personal information.
But, there are some limitations too. We dig into how this tool works, and its pros and cons in this post.
The tool is available as a downloadable in either PDF or Excel format. We used the PDF version for our review (but the Excel version is definitely better and doesn’t have some of the issues outlined above).
Essentially, the tool is a 28-page document with the following layout:
Note we’ve used the PDF page count functionality for our description above (though the paging may well be updated).
The Questionnaire covers the following foundational elements of organisational privacy:
The tool lays out 14 foundational privacy practices in clear, plain language. We like the fact that it’s easy to follow and it offers practical guidance at every step. The scoring system makes it clear where your organisation should direct its efforts to improve privacy maturity, and makes it easier to identify gaps and blind spots.
Here’s a list of practical applications we see for the tool:
While being a helpful tool for organisations looking for a starting point for promoting a culture of privacy and promoting privacy maturity, the tool does have some limitations – which are to be expected given its title as Privacy Foundations Self-Assessment Tool.
Importantly, it does not assess compliance under Australia’s Privacy Act, or other legal obligations. Nor does it necessarily identify organisational privacy risk levels (though it can be a helpful input into privacy risk consideration, based on identified maturity levels).
There are other tools that are helpful if you’re more focused on legal compliance at this stage. We suggest the OAIC’s interactive privacy management plan tool.
There are some areas which it might help to look at in more detail, for example:
However, we also understand that the tool can’t cover everything and the above are some of the more detailed issues which would be part of the next review.
It can also be hard to measure privacy maturity across an organisation – with different parts of the organisation likely to have different privacy responsibilities, practices and associated risks. A useful next step might be guidance on how to use the tool across a more complex agency or organisation, which might include multiple assessments being aggregated into an overarching privacy maturity view.
It is interesting that the tool refers to the use of opt-outs for marketing – although this is allowed under the Privacy Act, best practice suggests that opt-in is the preferred option and a change in the definition of ‘consent’ in the future may further support this approach.
Ultimately, using this tool requires an initial 15-20 minute investment. From there, it will either identify some gaps in your privacy practices or, in cases where your privacy maturity is currently on the lower side, it will offer a basic framework for improving privacy.
It is a great starting point for organisations yet to begin their privacy maturity uplift journey and provides a great insight into the areas the OAIC regarded as foundational.
It is also really encouraging to see this sort of practical tool released by the OAIC. We are confident that it will be widely used and appreciated by Australian entities covered by the Privacy Act.
If you’d like an outside opinion on your organisation’s privacy practices or your next steps for improving your privacy maturity, reach out. Our team of privacy professionals regularly offers outsourced privacy services ranging from privacy management to tailored training and awareness programs.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.