Digital Marketing, Spam & Privacy
Privacy investigations: match conclusions to the dataset and period
Practical guidance on privacy investigations: match conclusions to the dataset and period, with a May 2026 explanation, business checklist and evidence questions.
What changed in May 2026
A follow-up OAIC investigation concluded that the subsequently examined products and services did not contain personal information during the relevant period. A prior finding did not prove the content of every successor dataset.
What businesses should do now
Verify the actual fields, sources, identifiability and time period for each dataset rather than transferring a conclusion from an earlier system, product or investigation.
- Map the live data flow, including temporary systems, pixels, vendors and onward disclosures.
- Confirm necessity, authority, notice, consent and purpose for each material use or disclosure.
- Reconcile intended privacy settings with live states across downstream systems.
- Apply access, configuration, monitoring, deletion and incident controls to non-production environments.
- Retest after changes to websites, vendors, migrations, permissions or data fields.
Evidence to retain
- Current data maps, system inventories and supplier responsibilities.
- Privacy assessments, notices, consent records and decision logs.
- Access reviews, configuration evidence, monitoring records and verified deletion.
- Incident chronology, assessment decisions, notifications and remediation evidence.
Turn the issue into a controlled decision
- Record the affected product, claim, customer journey, system, supplier or business process.
- Separate current requirements from proposals, priorities, allegations, warnings and matter-specific outcomes.
- Assign an owner, action date and evidence location for every material gap.
- Set review triggers for legal changes, new facts, supplier changes, incidents, complaints and campaign variations.
- Escalate when the available facts or evidence do not support the proposed decision.
Questions to ask
Focus on the decision and the evidence.
- 01
What personal information is actually collected, inferred, used, disclosed and retained?
- 02
Do privacy conclusions match the exact dataset, system, purpose and time period?
- 03
What evidence shows that the control works across suppliers and downstream systems?
Primary sources
Check the controlling material.
Recommended training
Watchdog PRO Certificate: Privacy Officer
Build practical privacy controls for digital marketing, tracking, consent and customer data.
- Map information, systems, purposes and data flows
- Review collection, use, disclosure and retention
- Conduct practical privacy impact assessments
Practical support
Apply the guidance to your facts.
Identify the exact product, claim, customer journey, supplier, legal entity or process involved. Preserve the information that supports the current position, record unresolved facts, assign an owner and confirm the point at which specialist review is required.
Tell us how this issue affects your organisation and receive a tailored recommendation for the most useful next step.
Important information
Check the current position.
This resource is general information, not legal advice. Laws, official guidance and proposals can change. Do not rely on a title or summary alone to decide whether a requirement applies to a particular entity, product or activity.
