Digital Marketing, Spam & Privacy
Privacy controls in practice: an evidence checklist
Practical guidance on privacy controls in practice: an evidence checklist, with a July 2026 explanation, business checklist and evidence questions.
What changed in July 2026
The OAIC closed preliminary inquiries without commencing an investigation or making concluded breach findings. The report highlights the value of implemented supplier assurance, access controls, training, incident response and retention processes.
What businesses should do now
Keep risk-specific evidence that privacy and security controls operate in practice, especially for overseas providers, privileged access, social-engineering risk and incident decisions.
- Map the live data flow, including temporary systems, pixels, vendors and onward disclosures.
- Confirm necessity, authority, notice, consent and purpose for each material use or disclosure.
- Reconcile intended privacy settings with live states across downstream systems.
- Apply access, configuration, monitoring, deletion and incident controls to non-production environments.
- Retest after changes to websites, vendors, migrations, permissions or data fields.
Evidence to retain
- Current data maps, system inventories and supplier responsibilities.
- Privacy assessments, notices, consent records and decision logs.
- Access reviews, configuration evidence, monitoring records and verified deletion.
- Incident chronology, assessment decisions, notifications and remediation evidence.
Turn the issue into a controlled decision
- Record the affected product, claim, customer journey, system, supplier or business process.
- Separate current requirements from proposals, priorities, allegations, warnings and matter-specific outcomes.
- Assign an owner, action date and evidence location for every material gap.
- Set review triggers for legal changes, new facts, supplier changes, incidents, complaints and campaign variations.
- Escalate when the available facts or evidence do not support the proposed decision.
Questions to ask
Focus on the decision and the evidence.
- 01
What personal information is actually collected, inferred, used, disclosed and retained?
- 02
Do privacy conclusions match the exact dataset, system, purpose and time period?
- 03
What evidence shows that the control works across suppliers and downstream systems?
Primary sources
Check the controlling material.
Recommended training
Watchdog PRO Certificate: Privacy Officer
Build practical privacy controls for digital marketing, tracking, consent and customer data.
- Map information, systems, purposes and data flows
- Review collection, use, disclosure and retention
- Conduct practical privacy impact assessments
Practical support
Apply the guidance to your facts.
Identify the exact product, claim, customer journey, supplier, legal entity or process involved. Preserve the information that supports the current position, record unresolved facts, assign an owner and confirm the point at which specialist review is required.
Tell us how this issue affects your organisation and receive a tailored recommendation for the most useful next step.
Important information
Check the current position.
This resource is general information, not legal advice. Laws, official guidance and proposals can change. Do not rely on a title or summary alone to decide whether a requirement applies to a particular entity, product or activity.
