Privacy Advisory
Handle personal information with confidence — and prove it.
Privacy risk in Australia has expanded. Individuals can now bring civil claims for serious invasions of privacy under the statutory tort, separate from and in addition to regulator action. The Privacy Act is also introducing transparency requirements for automated decision-making that uses personal information, and the Notifiable Data Breach scheme keeps its unforgiving arithmetic — 30 days to assess a suspected eligible breach.
Avocado's privacy specialists work alongside the security, risk and delivery consultants who implement what the advice requires — assessing privacy risk against the Australian Privacy Principles, building governance and controls your teams can actually operate, and quantifying privacy exposure in business terms so your board funds privacy as risk management, not paperwork.
You'll recognise the situation
You don't have a clear map of what personal information you hold, where it flows, or the lawful purpose for each use.
Individuals can now bring civil claims directly for serious invasions of privacy under the statutory tort, and you need to know your actual exposure.
You're not sure you could assess a suspected eligible data breach within the 30-day Notifiable Data Breach obligation.
You need to get ahead of automated decision-making transparency requirements before they commence, not scramble once they do.
Assess the risk, build the controls
Risk Assessment
Know what personal information you hold, where it flows, and what could go wrong, before it does.
Governance and Controls
Build the privacy framework, policies, processes and evidence your obligations (and your customers) expect.
How each capability works
Risk Assessment
Privacy risk assessments often stop at legal exposure. Ours don't, because privacy failures are usually system failures: data kept past its purpose, flows nobody mapped, access nobody reviewed. We assess privacy risk with people who understand the systems the data lives in and we can quantify the exposure using FAIR, so 'privacy risk' arrives at your board as a number with a mitigation cost beside it, not an adjective.
- Personal information mapping — what you hold, where it lives, where it flows, and the lawful purpose for each use.
- Privacy impact assessments for new systems, projects and data uses, embedded into design rather than bolted on after go-live.
- Privacy risk assessment against the Australian Privacy Principles, with exposure quantified in financial terms using FAIR.
- Automated decision-making readiness — identifying where personal information feeds automated decisions, ahead of incoming transparency obligations.
- Notifiable Data Breach readiness — whether you could actually assess a suspected eligible breach within the 30-day obligation.
- Third-party and cross-border privacy risk — what your suppliers and offshore flows do with the personal information you're accountable for.
Governance and Controls
A privacy policy is not a privacy program. We build governance that operates: clear accountability for privacy decisions, processes that fire when systems change, and controls with evidence trails — so when a regulator, customer or court asks how you protect personal information, the answer is a record, not a promise. Note: breach response work here is process design and exercising only.
- Privacy governance framework — accountability, roles and escalation for privacy decisions, integrated with your cyber governance.
- Privacy policy, collection notices and procedure development aligned to the Australian Privacy Principles.
- Consent design — collection, purpose and consent models that are honest, usable and evidenced.
- Data minimisation and retention controls — keeping only what you need, for as long as you need it, with defensible disposal.
- Data breach response process design and exercising for privacy incidents, built so your teams can execute the 30-day assessment obligation.
- Privacy by design integration into your project, procurement and change processes, and privacy training delivered with our Cyber Security Training service.
Map, assess, govern, evidence
Map
Map what personal information you hold, where it lives, where it flows, and the lawful purpose for each use.
Assess
Assess privacy risk against the Australian Privacy Principles.
Govern
Build the governance framework, policies, consent models and controls your teams can actually operate.
Evidence
Embed evidence trails into consent, retention, access and de-identification controls, so the answer to a regulator or customer is a record, not a promise.
Book a discovery with our cyber team
Tell us what personal information you handle and what's changing — we'll tell you where your privacy risk actually sits.
Grounded in how systems are built
Assessment is run against the Australian Privacy Principles, with exposure able to be quantified in dollar terms using FAIR — the same approach used across our Governance, Risk and Compliance service. Certified privacy and data protection practitioners hold CDPSE alongside CISM, CRISC and CISA, so privacy advice is grounded in how systems are actually built and secured, not treated as a standalone legal exercise.
What you walk away with
Not sure where your privacy risk sits? Talk to us about a privacy health check. Contact us for a tailored quote.
Common questions
What is the statutory tort for privacy?
It's a civil cause of action that lets individuals bring claims directly for serious invasions of privacy, separate from and in addition to regulator action under the Privacy Act.
What are the automated decision-making transparency requirements?
New Privacy Act obligations requiring organisations to be transparent about personal information used in automated decision-making, relevant to any AI or automated system that processes personal information to make or inform a decision.
How much time do we have to assess a data breach?
30 days to assess whether a suspected breach is an eligible data breach under the Notifiable Data Breach scheme — this is an assessment deadline, not a notification deadline, but it's treated as a hard ceiling.
Does Avocado provide breach response?
Privacy breach response work here is process design and exercising only — building and testing your capability to respond before an incident happens. Avocado does not provide live incident engagement.
How can privacy risk be quantified?
Using FAIR (Factor Analysis of Information Risk), so privacy exposure arrives at the board as a dollar figure with a mitigation cost attached, rather than a qualitative rating.
Where teams go next
Make privacy a promise you can keep
Talk to our privacy specialists about assessing your exposure and building governance your customers and regulators can trust.