DFSI-2016-07 Privacy Governance Framework
The Privacy Governance Framework assists NSW public sector agencies in managing privacy concerns and the comply with NSW Legislation.
Issued: 5 May 2016 by Department of Finance, Services and Innovation
This AR is archived. No replacements were suggested by the author.
Key information
- Status
- Archived
- Type
- Department of Finance, Services and Innovation Circular
- Identifier
- DFSI-2016-07
- Compliance
- Mandatory
Who needs to know and/or comply with this?
- Departments
- Executive agencies related to Departments
- Advisory Entities (including Boards and Committees)
- Separate agencies
- Statutory Authorities/Bodies
- Councils under the Local Government Act
- Universities
About
The Privacy Governance Framework assists NSW public sector agencies in managing privacy concerns and the comply with NSW Legislation.
Key Points
- The NSW Privacy Commissioner has launched the Privacy Governance Framework as a new resource for NSW public sector agencies to support their responsibilities under the NSW privacy legislation.
- The Privacy Governance Framework is an online tool designed for ‘whole of organisation’ engagement with the management of personal information.
Purpose
The purpose of the Privacy Governance Framework is to help NSW public sector agencies to understand:
-
privacy risks and opportunities, and to address their roles and responsibilities in relation to privacy management under the Privacy and Personal Information Protection Act 1998 (PPIP Act)
- that an effective privacy governance framework begins with leadership by the agency head, and
- that privacy is best managed proactively and at the outset in the development of policy, programs and services.
The Privacy Governance Framework provides a ‘privacy by design’ approach to assist NSW public sector agencies respond to the challenges of privacy matters raised by their customers.
Directions
The Privacy Governance Framework requires agencies subject to the PPIP Act to consider the following elements to embed good privacy practices into agency processes:
- setting leadership and governance
- planning and strategy
- program and service delivery
- complaint incident management
- evaluation and reporting.