(1) This Procedure is effective from 31 January 2023. (2) This Procedure provides instruction on when and how to conduct a Privacy Impact Assessment. (3) This Procedure applies to Projects in which Personal Information will be collected, accessed, used, disclosed, aggregated, stored, deleted or destroyed. (4) This Procedure is pursuant to the Privacy policy. (5) A Privacy Screening Form must be completed by a Project Manager before a new Project, or a proposed change to an existing Project, is commenced, and must be entered into TRIM. Examples of Projects to which this Procedure applies include: (6) If the Privacy Screening Form indicates that the Project will involve or affect Personal Information held by or intended to be held by the University, it must be forwarded to the Privacy Officer. (7) The Privacy Officer will review the Privacy Screening Form and will determine if the Project requires a Privacy Impact Assessment (PIA). (8) The University General Counsel may authorise referral of the PIA to an external provider. The Project Manager will liaise directly with the external provider and the finalised PIA will be provided by the external provider to the Project Manager. (9) Project areas will bear the costs of the external provider and these costs should be included in the Project budget. (10) The PIA will be undertaken in the form approved by the Privacy Officer. The Privacy Officer will make available on the Office of General Counsel staff webpage the Privacy Screening Form. (11) Each PIA must consider: (12) The staff member preparing the PIA must consult with Deakin Cybersecurity, Deakin Privacy and the Information and Records unit in preparing the PIA, however responsibility for competing the PIA rests with that staff member. (13) A Faculty, Institute or Portfolio may decide to accept the risks identified in the PIA, in which case a risk owner must be identified. The risk owner will manage the risk in accordance with the Risk Management policy. (14) The completed PIA must be signed by the Project Manager and the Project Sponsor and the fully executed PIA entered into TRIM by the Project Manager, with a copy provided to the Privacy Officer. (15) A PIA is a living document and may be updated throughout the life of the Project to reflect changes in the scope of the Project, use of additional technologies or management of additional Personal Information. (16) The Privacy Officer may authorise the conduct of a retrospective PIA if a PIA was not undertaken prior to the implementation of a Project. (17) For the purpose of this Procedure:Privacy Impact Assessment procedure
Section 1 - Preamble
Section 2 - Purpose
Section 3 - Scope
Top of PageSection 4 - Policy
Section 5 - Procedure
Section 6 - Definitions
View Current
This is the current version of this document. To view historic versions, click the link in the document's navigation bar.