Skip to content
Cyber Strategy and Governance

Privacy Advisory

Handle personal information with confidence — and prove it.

Privacy Advisory
Map → Assess → Govern
Overview

Privacy risk in Australia has expanded. Individuals can now bring civil claims for serious invasions of privacy under the statutory tort, separate from and in addition to regulator action. The Privacy Act is also introducing transparency requirements for automated decision-making that uses personal information, and the Notifiable Data Breach scheme keeps its unforgiving arithmetic — 30 days to assess a suspected eligible breach.

Avocado's privacy specialists work alongside the security, risk and delivery consultants who implement what the advice requires — assessing privacy risk against the Australian Privacy Principles, building governance and controls your teams can actually operate, and quantifying privacy exposure in business terms so your board funds privacy as risk management, not paperwork.

Who is this for?

You'll recognise the situation

You don't have a clear map of what personal information you hold, where it flows, or the lawful purpose for each use.

Individuals can now bring civil claims directly for serious invasions of privacy under the statutory tort, and you need to know your actual exposure.

You're not sure you could assess a suspected eligible data breach within the 30-day Notifiable Data Breach obligation.

You need to get ahead of automated decision-making transparency requirements before they commence, not scramble once they do.

What's included

Assess the risk, build the controls

Risk Assessment

Know what personal information you hold, where it flows, and what could go wrong, before it does.

Governance and Controls

Build the privacy framework, policies, processes and evidence your obligations (and your customers) expect.

In detail

How each capability works

01

Risk Assessment

Privacy risk assessments often stop at legal exposure. Ours don't, because privacy failures are usually system failures: data kept past its purpose, flows nobody mapped, access nobody reviewed. We assess privacy risk with people who understand the systems the data lives in and we can quantify the exposure using FAIR, so 'privacy risk' arrives at your board as a number with a mitigation cost beside it, not an adjective.

Our approach
  • Personal information mapping — what you hold, where it lives, where it flows, and the lawful purpose for each use.
  • Privacy impact assessments for new systems, projects and data uses, embedded into design rather than bolted on after go-live.
  • Privacy risk assessment against the Australian Privacy Principles, with exposure quantified in financial terms using FAIR.
  • Automated decision-making readiness — identifying where personal information feeds automated decisions, ahead of incoming transparency obligations.
  • Notifiable Data Breach readiness — whether you could actually assess a suspected eligible breach within the 30-day obligation.
  • Third-party and cross-border privacy risk — what your suppliers and offshore flows do with the personal information you're accountable for.
02

Governance and Controls

A privacy policy is not a privacy program. We build governance that operates: clear accountability for privacy decisions, processes that fire when systems change, and controls with evidence trails — so when a regulator, customer or court asks how you protect personal information, the answer is a record, not a promise. Note: breach response work here is process design and exercising only.

Our approach
  • Privacy governance framework — accountability, roles and escalation for privacy decisions, integrated with your cyber governance.
  • Privacy policy, collection notices and procedure development aligned to the Australian Privacy Principles.
  • Consent design — collection, purpose and consent models that are honest, usable and evidenced.
  • Data minimisation and retention controls — keeping only what you need, for as long as you need it, with defensible disposal.
  • Data breach response process design and exercising for privacy incidents, built so your teams can execute the 30-day assessment obligation.
  • Privacy by design integration into your project, procurement and change processes, and privacy training delivered with our Cyber Security Training service.
How do we deliver it?

Map, assess, govern, evidence

01

Map

Map what personal information you hold, where it lives, where it flows, and the lawful purpose for each use.

02

Assess

Assess privacy risk against the Australian Privacy Principles.

03

Govern

Build the governance framework, policies, consent models and controls your teams can actually operate.

04

Evidence

Embed evidence trails into consent, retention, access and de-identification controls, so the answer to a regulator or customer is a record, not a promise.

Book a discovery

Book a discovery with our cyber team

Tell us what personal information you handle and what's changing — we'll tell you where your privacy risk actually sits.

What tools and technology do we use?

Grounded in how systems are built

Assessment is run against the Australian Privacy Principles, with exposure able to be quantified in dollar terms using FAIR — the same approach used across our Governance, Risk and Compliance service. Certified privacy and data protection practitioners hold CDPSE alongside CISM, CRISC and CISA, so privacy advice is grounded in how systems are actually built and secured, not treated as a standalone legal exercise.

What outcomes can you expect?

What you walk away with

Know your true privacy exposure, including the statutory tort risk individuals can now bring directly.
Catch privacy problems at design time, when they cost the least to fix.
Meet the automated decision-making transparency deadline with an inventory, not a scramble.
Answer "how do you protect personal information" with evidence, not assurances.
Proof · Case study

Remediating security and privacy risks

Read the case study
How is this engagement structured?

Not sure where your privacy risk sits? Talk to us about a privacy health check. Contact us for a tailored quote.

FAQ

Common questions

What is the statutory tort for privacy?

It's a civil cause of action that lets individuals bring claims directly for serious invasions of privacy, separate from and in addition to regulator action under the Privacy Act.

What are the automated decision-making transparency requirements?

New Privacy Act obligations requiring organisations to be transparent about personal information used in automated decision-making, relevant to any AI or automated system that processes personal information to make or inform a decision.

How much time do we have to assess a data breach?

30 days to assess whether a suspected breach is an eligible data breach under the Notifiable Data Breach scheme — this is an assessment deadline, not a notification deadline, but it's treated as a hard ceiling.

Does Avocado provide breach response?

Privacy breach response work here is process design and exercising only — building and testing your capability to respond before an incident happens. Avocado does not provide live incident engagement.

How can privacy risk be quantified?

Using FAIR (Factor Analysis of Information Risk), so privacy exposure arrives at the board as a dollar figure with a mitigation cost attached, rather than a qualitative rating.

Deliver with certainty

Make privacy a promise you can keep

Talk to our privacy specialists about assessing your exposure and building governance your customers and regulators can trust.