Are you ready? 2 min read
If enacted, the Government's proposed Privacy Act reforms will require significant changes across data governance, data practices, IT systems, marketing, customer journeys and incident response.
Boards should already be testing the scale of the compliance task, management’s understanding of the organisation's data flows and assets (including the data and practices that will be brought within the regulatory net), the adequacy of implementation funding and resourcing, and the financial, legal and regulatory exposure if the organisation gets it wrong.
We've outlined the five questions directors should be asking management now about these proposed reforms.
1. Where are our biggest compliance gaps and what will it cost to close them? How would our existing privacy risk profile fare under the new regime?
- Who is accountable for closing the compliance gaps?
- Which proposed reforms require the most significant change to our current practices?
- What are the expected implementation costs, ongoing costs and business impacts?
- Which business units are most affected?
- Do we engage in any data practices that customers, regulators or courts could regard as unexpected, unreasonable or unfair?
- Are our insurance and risk transfer arrangements still adequate?
2. How will we manage regulatory uncertainty, what is our implementation timeline, and do we have the resources to deliver it?
- How will management navigate regulatory uncertainty while awaiting passage of the reforms and related OAIC guidance? What, if any, interim measures will we adopt?
- How will we manage our digital and AI transformation programs already underway to ensure privacy improvements are built into design rather than retrofitted?
- Are we sufficiently resourced across privacy, legal, cyber and technology to implement the changes?
3. Do we know what personal information we hold, where it sits and how we use it?
- Have we completed an inventory of data flows and assets that would withstand regulatory scrutiny?
- What personal information currently sits outside established governance processes?
- Does our data inventory adequately capture personal information used in analytics, AI, marketing and customer insight activities, particularly given the expanded definition of personal information?
4. Are our third-party (including intragroup), outsourcing and technology arrangements fit for the new regime?
- Do we clearly understand our controller or processor status in each key arrangement?
- Which vendor arrangements create our most significant privacy exposure?
- What contractual and oversight changes will we need to make?
5. Could we meet the new data breach reporting and mitigation requirements if a major breach occurred tomorrow?
- If not, what changes would we need to make?


