PropoDoc provides self-help document templates and tools. It is not a law firm and does not provide legal advice. Learn more.
Skip to main content
Example
guide|spreadsheet|form

Privacy Impact Assessment Example

Example document for Privacy Impact Assessment. Use this as a reference when creating your own.

Professional Review Recommended

This document may have legal or financial implications. We recommend having a qualified professional review the final version before use.

Document: Privacy Impact Assessment

Example Document

Last updated 7/30/2026

Privacy Impact Assessment

1. Project Details

Project Name: Online Customer Booking System Project Manager: Sarah Jenkins Date of Assessment: 12 October 2023 Project Description: We are moving from a paper diary to an online booking system for plumbing jobs. Customers will be able to book appointments and enter their details via our website. Staff will access the schedule on tablets.

2. Information Flow

What personal information are you collecting? Full name, residential address, phone number, email address, description of plumbing issue.

How are you collecting it? Through a web form on our new website booking page.

Where will the information be stored? In a cloud based database hosted by the software provider.

Who will have access to it? Office admin staff and all plumbing technicians who use the tablets.

Do you plan to share the information with anyone else? No, not directly. The software provider stores the data, but we do not sell it to marketing lists.

3. Privacy Risk Assessment

Are you collecting information that is considered sensitive? No. The description of the plumbing issue might be personal, but it is not health information under the Act.

Do you have consent to collect and use this information? Yes. The web form includes a tick box for customers to agree to our terms and privacy policy before they submit.

Could this project cause harm to individuals if the data was lost or stolen? Yes. High risk. Customers home addresses and phone numbers could be used for scams or burglary.

4. Compliance with Australian Privacy Principles

APP 1 (Open and Transparent): We updated our website Privacy Policy last month. It clearly explains we collect data for bookings. We will add a link to the policy next to the Submit button on the form.

APP 6 (Use or Disclosure): We are using the data only to organise the plumbing jobs. This is the primary purpose. We will not use the email addresses for marketing unless they opt into our newsletter separately.

APP 11 (Security of Personal Information): The software provider uses two factor authentication and encrypts the data. We will ensure staff tablets have passcodes. We will change the admin password monthly.

5. Risk Mitigation Plan

Risk IdentifiedLikelihoodImpactMitigation StrategyResponsible Person
Staff leave tablet in van unsecuredMediumHighPolicy requiring staff to lock tablets in the glove box when not in use.Sarah Jenkins
Database hacked by outsiderLowHighEnsure provider has ISO 27001 certification. Use strong passwords.IT Contractor
Customer enters wrong addressHighLowConfirmation email sent to customer immediately to verify details.Office Admin

6. Approval

I confirm that this assessment has been completed accurately and that risks have been identified and mitigated.

Signature: S. Jenkins Name: Sarah Jenkins Role: Business Manager Date: 12 October 2023

Notes

Key Decisions:

  1. We identified that the biggest risk was physical theft of the tablets, so we added a specific policy about locking them away.
  2. We checked the software provider's security credentials (ISO 27001) to satisfy APP 11.
  3. We separated the marketing consent from the booking consent to ensure we comply with the Spam Act 2003.

About this Example

Part of the Privacy Impact Assessment document collection

Document Type

Privacy Impact Assessment

A tool to help businesses identify and reduce privacy risks when handling personal information. It ensures you meet Australian legal standards.

Complexity

moderate

Risk Level

medium