Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

7 steps to prepare your organisation for changes to Australia’s privacy legislation

Michael Fagan, former chief transformation officer at Village Roadshow, examines the proposed changes to the Privacy Act and how CIOs in Australia can prepare for them.

Australian privacy legislation is about to undergo a major overhaul with more than 100 proposals under consideration, you can see the detail here.  While the exact details of changes to the law remain unknown, there is much that organisations can do to prepare.

  1. Take inventory of what data you do hold

Do you know what information you currently hold?  Where it is held?  Why it was collected and what the future usage of that data will be?  Have you clearly identified owners of that data? Hint, it’s not someone in your IT department (or shouldn’t be – this is usually a red flag for CEOs).  What are some use cases that might need that data?  If you don’t know where your data is then you will struggle to be compliant.

  1.  Be open and transparent about what data you collect and how you use it

Australian Privacy Principle #1 (APP 1) requires organisations to have a clearly defined and contemporary policy describing how they manage personal information.  Is yours readable? Have you run it through ChatGPT and determined the Flesch-Kincaid readability score? It should be readable by a 14-year-old, Year 8 student.  The good news is that you can ask any of the large language models (LLMs) like ChatGPT to rewrite paragraphs or sections for improved comprehension or make it more concise.

  1.  Delete old data

I lived in Hong Kong 2008-2013 and one of my most pleasurable weekends was a trip to see an incredible band at the MGM hotel in Macau.  Twelve years later, in September 2023, some of my details were compromised in the MGM Resorts hack in the USA.  Luckily it was just my name and a now-defunct email address – but it had been expired for at least 10 of those years.  I cannot remember ever receiving a single piece of marketing from MGM, but they kept my old data on file – and may have been getting “return to sender” messages for years.

How much old data are you keeping? Deleting obsolete information provides several benefits.   Firstly, it tests your ability to destroy data.  This is not a trivial matter – backups, archives, deeply linked data present challenges. It also gives executives a clear picture of how much customer data you really have.  I helped an organisation clean up their Customer Data Platform (CDP) last year and removed more than a million records, about 15% less than they thought they had.

Another benefit is that it saves money.  Not on disk space which can nearly be considered free at this stage, but many CDPs and other SaaS applications have a charging model based on the amount of data (customer records) that you hold.  That company I helped had a significant reduction in their CDP licensing cost post clean-up.

  1. Develop and manage a consent framework for new data, and de-identify where you can

Rely more on first-party data that you collect yourself.  Inform customers when you collect that data, and what you will use it for.  Inform them of this collection, prior to gathering it.  If you have new uses for the data, seek further consent or de-identify the data. 

For the latter, one such technique involves encryption of identifiers which allows different datasets to be linked together for analysis, but still obscure the original data. Another technique is homomorphic encryption, where a data owner encrypts a dataset, sends to the cloud (or another server) for processing, the server processes the data without decrypting, and sends the encrypted results back to the owner – who is the only party able to decrypt the results.

  1.  Drive partner accountability

Who are you sharing data with, and what do they do with it?  Are they always using your customers data in a way that is consistent with the promises you made?  Review your contracts and agreements in your partner ecosystem and hold them accountable.  “It is a condition of doing business with us that you have a mutually acceptable attitude to privacy (and modern slavery, and ethical sourcing, and ….).

  1. Ensure your breach notification plan exists, and is up to date

Have you conducted a boardroom wargame, simulating a data breach?  Have you repeated it in the last 12 months?

  1. Educate your teams, and support people who raise issues

‘Jidoka’ is a principle in Lean that was started by Toyota.  A key principle of Jidoka is that anyone can raise an issue, and in reality, stop the production line.  In many organisations I have worked in, stopping all production would be career suicide, however in Toyota this first step in the process is for the manager to find the employee who initiated the stop, and say “Thank you”.  This drives a culture of Quality first.  Only by thanking and rewarding those who raise privacy concerns can we drive a Privacy-first culture.

These are not the only steps you need to take to prepare for improved legislation, but they are a good starting point.

Data Governance, Data Privacy, Legal


Read More from This Article: 7 steps to prepare your organisation for changes to Australia’s privacy legislation
Source: News

Category: NewsApril 3, 2024
Tags: art

Post navigation

PreviousPrevious post:An IT leader’s mission to retrofit the tech foundation at EonNextNext post:エンタープライズアーキテクチャにまつわる6つの大罪

Related posts

Barb Wixom and MIT CISR on managing data like a product
May 30, 2025
Avery Dennison takes culture-first approach to AI transformation
May 30, 2025
The agentic AI assist Stanford University cancer care staff needed
May 30, 2025
Los desafíos de la era de la ‘IA en todas partes’, a fondo en Data & AI Summit 2025
May 30, 2025
“AI 비서가 팀 단위로 지원하는 효과”···퍼플렉시티, AI 프로젝트 10분 완성 도구 ‘랩스’ 출시
May 30, 2025
“ROI는 어디에?” AI 도입을 재고하게 만드는 실패 사례
May 30, 2025
Recent Posts
  • Barb Wixom and MIT CISR on managing data like a product
  • Avery Dennison takes culture-first approach to AI transformation
  • The agentic AI assist Stanford University cancer care staff needed
  • Los desafíos de la era de la ‘IA en todas partes’, a fondo en Data & AI Summit 2025
  • “AI 비서가 팀 단위로 지원하는 효과”···퍼플렉시티, AI 프로젝트 10분 완성 도구 ‘랩스’ 출시
Recent Comments
    Archives
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.