Privacy Advisory & Compliance

16 - Privacy

Privacy Advisory
& Compliance

Practical privacy support for Australian organisations. Privacy is not only a legal issue - it affects how personal information is collected, stored, used, shared, protected and deleted across systems, suppliers, staff processes and customer services. RTCS helps identify privacy risks, improve data handling practices and prepare clear documentation that supports compliance, assurance and good governance.

  • Privacy compliance reviews and APP gap assessments
  • Privacy Impact Assessments for new platforms, projects and AI tools
  • Privacy policy, collection notice and consent review
  • Notifiable Data Breaches readiness and breach response planning
  • Personal information handling, retention and disposal review
  • Third-party and supplier privacy assessments
  • AI and Copilot privacy risk review
  • Privacy governance, reporting and remediation roadmap
  • Plain-English deliverables for executives and risk teams
Discuss This Service
Focus Areas
Data handling - APPs - PIAs - breach readiness - supplier privacy - AI privacy - governance
Frameworks
Privacy Act 1988 - Australian Privacy Principles - NDB Scheme - OAIC guidance - WA PRIS Act - GDPR (where relevant)
Engagement Types
Compliance review - APP gap - PIA - breach readiness - supplier review - AI privacy review
Outputs
Risk-rated findings - privacy risk register - policy updates - PIA report - remediation roadmap
Privacy Act APPs WA PRIS Act NDB Scheme ISO 27001
APP
Privacy Principle Gap Review
PIA
Privacy Impact Assessments
NDB
Data Breach Readiness
AU
Onshore Delivery
01 / Context

Privacy is about how information is actually handled.

Privacy advisory and compliance helps organisations manage personal information in line with legal, regulatory and business expectations - reviewing practices, preparing policies, assessing data flows, supporting Privacy Impact Assessments, improving breach readiness and reviewing supplier privacy risk. The goal is responsible handling of personal information and fewer privacy incidents.

02 / Common Gaps

Most organisations hold more personal information than they realise.

G1

Privacy policies don't match actual practices

G2

Personal information collected without a clear purpose

G3

Unclear data retention practices

G4

Weak access controls over personal information

G5

Suppliers handling data without proper review

G6

Limited breach response planning

G7

Poor visibility of where personal information is stored

G8

New systems or AI tools introduced without privacy review

G9

Staff unsure how personal information should be handled

03 / Compliance Review

A practical view of how personal information is actually managed.

RTCS assesses how your organisation manages personal information across systems, processes, suppliers and documentation. We're Perth-based, so for WA public-sector and government-funded organisations we also cover the Privacy and Responsible Information Sharing (PRIS) Act alongside the Commonwealth Privacy Act and APPs.

Personal information collection Use & disclosure Privacy policies & notices Consent & notification Access & correction Data storage & security Retention & disposal Supplier & third-party handling Breach response processes Governance & accountability
04 / Privacy Impact Assessments

Privacy Impact Assessments

When to Run a PIA

New platforms, data projects, AI tools, customer systems, analytics, system integrations and supplier changes - any time personal information is going to be collected, processed or shared in a new way.

What a PIA Covers

Data flow review, personal information mapping, privacy risk identification, control review, supplier privacy considerations, recommendation development and privacy risk treatment planning.

05 / Data Breach Readiness

Be ready for the moment notification matters.

A privacy breach can create legal, operational, reputational and customer-trust issues. RTCS helps organisations prepare for privacy incidents by reviewing breach response processes, escalation paths, evidence handling and notification considerations.

Data breach response procedure Notifiable Data Breaches readiness Breach assessment workflow Internal escalation Communication templates Evidence requirements Post-incident review

For the operational incident-handling side, pair with Incident Response Readiness. For executive-level crisis decisions, see Crisis Management.

06 / Supplier & AI Privacy

Supplier & AI Privacy

Supplier & Third-Party Privacy

Suppliers and SaaS platforms often process personal information on your behalf. RTCS reviews supplier privacy risk - data processing arrangements, offshore disclosure, access to personal information, retention and deletion practices, breach notification obligations and contractual control gaps. Pair with Supply Chain Risk.

AI & Privacy Risk

AI tools create privacy risk when personal information is entered, processed, stored or reused without clear controls. RTCS reviews AI use cases - public AI tools, Microsoft Copilot, SaaS AI features, internal chatbots and data analysis tools - across handling, minimisation, staff guidance, vendor review and retention. Pair with AI Security & Consulting.

Understand to Support

A practical, staged engagement that produces privacy documentation and processes your organisation will actually use.

01
Understand

Review your organisation, systems, personal information handling, suppliers and compliance drivers.

02
Assess

Assess privacy practices, documentation, risks, controls and evidence.

03
Prioritise

Identify the most important gaps and provide practical remediation actions.

04
Improve

Help update documents, strengthen processes and improve privacy governance.

05
Support

Where required, support privacy reporting, breach preparation and ongoing improvement.

07 / Who It's For & What You Receive

Who It's For & What You Receive

Who This Service Is For

  • Handle customer, employee or sensitive information
  • Need to review privacy compliance
  • Need a Privacy Impact Assessment
  • Need to update privacy policies or notices
  • Need data breach readiness support
  • Need to assess supplier privacy risk
  • Introducing AI, analytics or new data platforms
  • Need privacy evidence for audits, tenders or assurance
  • Want practical privacy guidance without complexity

Typical Deliverables

  • Privacy compliance review
  • APP gap assessment
  • Privacy Impact Assessment
  • Privacy risk register
  • Privacy policy review
  • Collection notice review
  • Data breach response procedure
  • Supplier privacy review
  • AI privacy risk review
  • Remediation roadmap
  • Executive summary
  • Practical action plan
08 / Related Services

Where privacy connects to the rest of the program.

Incident Response Readiness

Operational data breach response playbooks, escalation and the technical side of NDB events.

Governance, Risk & Compliance

Privacy obligations mapped alongside ISO 27001, Essential Eight and broader compliance.

Supply Chain Risk

Supplier and SaaS risk including offshore disclosure, contractual gaps and assurance evidence.

AI Security & Consulting

AI acceptable use, data leakage assessments and Copilot governance review.

Identity & Access Management

Access controls over the systems that hold personal information.

Crisis Management

Executive crisis decisions and BCP for serious privacy events.

Cloud Security

Cloud configuration and exposure review for the platforms holding personal information.

vCISO & Security Advisory

Executive-level oversight of privacy and security risk as part of the broader program.

Privacy compliance should be clear, practical and connected to how your organisation actually handles information. Talk to us about privacy advisory support, APP gap assessment, Privacy Impact Assessment, supplier privacy review or data breach readiness.

Common Questions

What is privacy compliance?

Privacy compliance is the process of managing personal information in line with privacy obligations, business requirements and customer expectations.

What are the Australian Privacy Principles?

The Australian Privacy Principles are the main privacy principles under the Commonwealth Privacy Act for many Australian organisations and government agencies. In Western Australia, the Privacy and Responsible Information Sharing (PRIS) Act introduces a separate set of WA Information Privacy Principles for WA public-sector and government-funded organisations.

Do you cover the WA Privacy and Responsible Information Sharing (PRIS) Act?

Yes. RTCS is Perth-based and can support WA public-sector and government-funded organisations preparing for the PRIS Act, including gap reviews against the WA Information Privacy Principles, data handling reviews, breach notification readiness and supplier and information-sharing arrangements.

What is a Privacy Impact Assessment?

A Privacy Impact Assessment identifies privacy risks in a project, system or process and recommends ways to reduce those risks before implementation.

Can you review our privacy policy?

Yes. RTCS can review privacy policies, collection notices and related documentation to identify gaps and improvement areas.

Can you help with data breach readiness?

Yes. RTCS can help develop breach response procedures, escalation steps, assessment workflows and notification planning.

Can you review supplier privacy risk?

Yes. RTCS can review suppliers and SaaS platforms that collect, store, process or access personal information.

Can you review AI privacy risk?

Yes. RTCS can assess privacy risks linked to AI tools, AI-enabled SaaS platforms, internal AI systems and staff use of public AI tools.