Prevent data breaches,
before they happen

A proactive, technology-driven approach to preventing exposure of sensitive or personal information — while enhancing your overall compliance with privacy legislation. We can even scan your network for at-risk data and report back in plain English.

Privacy management, evolved.

A digitised, fully automated approach to compliance with the Australian Privacy Principles. A modern technology system that integrates with your existing infrastructure and transitions you to best practice. Build a system that gives you a complete picture over your data privacy footprint at all stages of your customer lifecycle.

Effortless compliance with APP 1

The OAIC and other regulators are increasingly looking for organisations that embrace transparent, auditable privacy management. We create or enhance the documentation to reflect your integrated systems and actual data flows.

Easily manage retention and deletion

Excessive data that shouldn't have been retained or collected creates significant cyber risk. We solve it with technologically auditable processes that automatically flag out-of-date data for deletion — reducing holdings to Privacy Act levels.

Knowing your data,
before someone else does.

The case for treating privacy as a system rather than a policy. How the Privacy Act 1988 (Cth) and the Australian Privacy Principles actually land in a modern technology environment, and the two obligations that do most of the work in determining whether a technology business is meeting data protection best practice.

Privacy management, evolved

Most Australian organisations treat privacy as a documentation exercise. A policy is published on the website, a register is maintained somewhere on a shared drive, a breach response plan is drafted and filed, and the work is treated as done. That posture is increasingly out of step with what the Privacy Act 1988 (Cth) actually requires, and even further out of step with what the OAIC and the courts are signalling they expect from an organisation that holds personal information at any meaningful scale.

What regulators are looking for

The shift is from privacy-as-paperwork to privacy-as-system. Regulators are looking for organisations whose privacy practices are transparent, auditable and integrated with the technology that actually holds the data. That is a higher bar than a policy document, and it requires a different toolkit; the controls need to live in the systems themselves rather than in a binder on a compliance shelf.

We have built our preparedness practice around that reality. Rather than charging hundreds of hours to manually catalogue data flows that will be out of date the moment the work is finished, we recommend and help implement modern technology that does the cataloguing on an ongoing basis. The legal work then becomes what it should be: advising on whether the integrated system you have built actually satisfies the Australian Privacy Principles, drafting the documentation that explains it to a regulator, and tuning the controls where the law and the technology have a gap.

The breach-response dividend

This approach has another advantage. The same systems that prove your APP compliance also dramatically reduce the cost and risk of responding to a cyber incident. If you already know whose information is stored where, you can identify affected individuals within hours rather than weeks. That is exactly the position you want to be in when the Notifiable Data Breaches scheme's thirty-day assessment clock starts running under the Privacy Act 1988 (Cth).

The Australian Privacy Principles in practice

The Australian Privacy Principles are the operative obligations under the Privacy Act 1988 (Cth). There are thirteen of them, covering everything from the open and transparent management of personal information through to cross-border disclosures. Two of them, APP 1 and APP 11, do most of the work in determining whether a modern technology business is actually meeting its obligations.

APP 1: open and transparent management

APP 1 requires open and transparent management of personal information. In practical terms, that means your organisation needs to have a clearly articulated privacy practice, documented procedures, and the ability to explain to regulators, to customers, and to the individuals whose information you hold, how personal information moves through your systems.

The OAIC is increasingly looking for organisations that embrace transparent, auditable privacy management rather than treating APP 1 as a "publish a privacy policy on the website" exercise. Where we get involved, we either create or enhance the documentation so that it reflects your integrated technology systems and the actual data flows within your organisation, not an idealised version that bears no resemblance to what your engineers built.

APP 11: retention, destruction, de-identification

APP 11 is the retention and security principle. It requires organisations to take reasonable steps to protect personal information from misuse, interference and loss, and to destroy or de-identify personal information that is no longer needed for any purpose for which it can be used or disclosed.

APP 11.2 in particular is often the principle organisations struggle with: excess data, retained beyond its purpose, sitting in places nobody is actively monitoring. That excess data is also the data most likely to surface in a breach.

Where the two obligations meet

The interaction between the two is where most organisations come unstuck. You cannot deliver on APP 1's transparency obligation if you do not actually know where personal information is stored, and you cannot deliver on APP 11's retention obligation if you cannot see the data well enough to identify what should be deleted. Both obligations point to the same underlying requirement: a system that gives you a real-time, auditable view of what personal information you hold, where it sits, and what is happening to it. Without that, you are managing privacy by hope.

That underlying requirement is the reason we package our preparedness work into two deliberate services: a Customer Data Platform implementation for the forward flow, and a recurring at-risk data scan for the historical residue.

How we set up
a Customer Data Platform.

A Customer Data Platform is the technology category most likely to deliver the real-time view of personal information that APP 1 and APP 11 effectively require. The build follows a deliberate sequence — unify the flow, store it safely, make subject access programmatic, choose the right vendor, and report up to the executive in language they'll actually use.

  1. Stage 01 Collection Forms, apps, integrations

    Unify your data sources

    Insert the CDP between every source of personal information collection and every consuming system. Every flow goes through one controlled gate rather than sprawling silo-to-silo.

  2. Stage 02 Storage Dedicated warehouse

    Store it safely

    The CDP itself typically doesn't hold the data. It points at a dedicated data warehouse you've chosen, with the security controls you've selected. The sensitive payload lives where you can defend it.

  3. Stage 03 Subject access Programmatic deletion

    Programmatic SAR & deletion

    Wipe the master record in the warehouse and the downstream systems get the deletion through the CDP. Subject-access requests stop being a multi-department email scramble.

  4. Stage 04 Vendor Market-leading platforms

    Vendor-agnostic integration

    We're familiar with the market-leading CDP products but we don't hold a fixed view that one is universally better. We marry the right tool to your data sources, warehouse and existing stack — we don't sell a particular vendor.

  5. Stage 05 Reporting OAIC + board + IR

    Report to the executive

    The CDP itself becomes your APP 1 documentation — a live, auditable view of where personal information lives and what's happening to it. That's the artefact the OAIC, your board and your incident-response team all need.

Scanning for the data nobody manages.

A Customer Data Platform governs personal information from the moment a source is wired into it. It does nothing for the personal information that accumulated before then: spreadsheets on file shares, exports from retired systems, backups of databases that were decommissioned three reorganisations ago, attachments in support tickets, copies someone made for a project and never cleaned up. That residue is the data most likely to surface in a breach, because it sits in places nobody actively defends. The at-risk data scan is the deliberate counterpart to a CDP rollout; a process we've developed to find that information and bring it back inside a controlled posture under APP 11.2.

Methodology: two phases of the scan

APP 11.2 is the retention principle, requiring destruction or de-identification of personal information once it is no longer needed for the purpose it was collected. The scan exists to raise an organisation's compliance with that obligation. We use the same class of automated discovery tools an external intruder would reach for; what differs is authorisation, scope, and what happens with the findings.

What each phase delivers

  1. Phase one maps the silos (data warehouses, file shares, collaboration tools, ticketing systems, mailboxes) with the assistance of your IT team where appropriate. The output is a holistic view of where personal information lives, and a clear basis to either add controls or reduce the volume held in any one location.
  2. Phase two identifies the loose information sitting outside those silos. The output is an inventory and a recommended action against each finding.

Every breach we've responded to has involved data nobody on the executive knew was retained. The scan exists so that statement stops being true of your organisation.

Reporting to the executive

The report is deliberately plain. At the conclusion of the scan we deliver an executive-grade document setting out what we found, what we recommend deleting, what we recommend consolidating, and what we recommend protecting further. It is written to be read in one sitting; no jargon, no twenty-page appendices. The recommendations draw on our position as privacy lawyers and technologists rather than one or the other: where a finding has a regulatory dimension we say so, and where it is purely operational we say that too.

Improving your security posture

A scan is rarely a one-off project. We typically recommend running one before a CDP rollout, so the project starts from a known baseline; again six to twelve months in, once the platform has bedded down; then on a periodic basis aligned to your audit cycle. Each pass measurably reduces the volume of personal information held outside your defended silos, which is the metric that most directly tracks to a smaller blast radius if an incident does occur. A CDP for the forward flow paired with a recurring scan for the historical residue is, in our view, the practical floor for an Australian organisation that takes the Privacy Act 1988 (Cth) seriously.

Prevent breaches
before they happen.

Leave us a short message about your organisation, the systems you run, and the data you hold. We'll come back with our view of the next steps — scan first, CDP first, or a staged approach that suits your priorities.

Get started quickly

Need urgent action? We pull together an action plan using our digital-first approach to scoping and estimates. No Gantt charts — just quick answers.

Free, fast pricing

Once we've agreed to help, we deliver an online Statement of Work with fixed estimates. Don't sign anything until you've seen ours.

Ask us anything

Drop a videoconference or booking link into the form and we'll answer questions before we engage. Meet you on your tooling of choice.