Your readiness 0 of 24 controls evidenced
0%
01 · Legal · Privacy · Business owners
Governance & data mapping 0/4 Map the personal data, systems, purposes, recipients and retention points for material processing activities. Evidence: Processing inventory with named ownersAct §§ 4, 8 Identify the Data Fiduciary and Data Processor for each processing relationship. Evidence: Role map and approved contract positionAct § 2(i), § 2(k), § 8(1) Record consent or the applicable certain legitimate use for every purpose. Evidence: Purpose-and-ground registerAct §§ 4, 6–7 Define retention triggers and lawful overrides instead of retaining data indefinitely. Evidence: Approved retention scheduleAct § 8(7)–(8)
02 · Legal · Product · Design
Notice & consent 0/4 Provide a clear, standalone notice that itemises personal data and each specified purpose. Evidence: Versioned notice and screen capturesAct § 5 · Rule 3 Use an affirmative action for consent that is free, specific, informed, unconditional and unambiguous. Evidence: Consent journey and acceptance criteriaAct § 6(1) Make withdrawal as easy as giving consent and propagate it to downstream processors. Evidence: Tested withdrawal workflowAct § 6(4)–(7) Make notices and consent requests accessible in English or an Eighth Schedule language chosen by the individual. Evidence: Language coverage recordAct §§ 5–6
03 · Security · Engineering · Incident response
Security & breach response 0/4 Implement documented technical and organisational safeguards appropriate to the processing risk. Evidence: Control register and test evidenceAct § 8(5) · Rule 6 Flow security, cooperation, deletion and breach duties into processor contracts. Evidence: Signed DPA and processor scheduleAct § 8(2) · Rule 6 Maintain a playbook for notifying affected Data Principals and the Board without delay. Evidence: Approved and exercised response planAct § 8(6) · Rule 7 Prepare the fuller Board submission required within seventy-two hours unless an extension is allowed. Evidence: Notification template and decision logRule 7(2)(b)
04 · Privacy operations · Support · Engineering
Data Principal rights 0/4 Publish an accessible channel and identifiers for submitting rights requests. Evidence: Published instructions and request formAct §§ 11–14 · Rule 14 Verify the requester proportionately without collecting unnecessary additional data. Evidence: Identity-verification procedureRule 14 Route correction and erasure requests across production systems and processors. Evidence: End-to-end workflow testAct § 12 Provide grievance redressal with ownership, tracking and escalation to the Board. Evidence: SLA, escalation path and case logAct § 13
05 · Product · Trust & safety · Legal
Children & protected users 0/4 Identify journeys likely to involve children and apply an appropriate age-assurance approach. Evidence: Child-user journey assessmentAct § 9 · Rules 10–12 Obtain verifiable parental consent before processing a child's personal data unless a valid exemption applies. Evidence: Consent verification recordAct § 9(1) · Rule 10 Prevent detrimental processing, tracking, behavioural monitoring and targeted advertising directed at children. Evidence: Product controls and advertising rulesAct § 9(2)–(3) Verify lawful guardianship when a guardian acts for a person with disability. Evidence: Guardian verification procedureRule 11
06 · Leadership · Audit · Procurement
Assurance & readiness 0/4 Maintain an inventory of processors, sub-processors, locations and contract owners. Evidence: Current vendor and data-flow registerAct § 8(2) Exercise consent withdrawal, rights, erasure and breach workflows before commencement. Evidence: Test results and remediation logAct §§ 6, 8, 11–14 Train teams with operational responsibilities and retain completion evidence. Evidence: Role-based training registerReasonable accountability practice Assign responsibility for monitoring later Gazette notifications, amendments and Board directions. Evidence: Regulatory watch owner and cadenceAct §§ 18–26, 40