Layer 1
Privacy Impact Assessments (PIA)


What is a Privacy Impact Assessment


Privacy is often confused with confidentiality or secrecy. However, privacy considerations are much broader than just ensuring information is not disclosed without authority. Privacy impacts can occur any time ‘Personal Information’ is collected, stored, processed, or disclosed. (Personal Information means any information about an identified individual, or an individual who is reasonably identifiable.)

The Australian Privacy Principles (APP) apply across the life cycle of Personal Information as it is collected by an organisation, held, processed, and eventually disposed of. Each point in the information life cycle can pose challenges and risks. Privacy risks can arise at any point in the life cycle of the Personal Information and can result from internal or external sources. Our privacy services are designed to pragmatically bolster your ability to prevent, and respond to, privacy risks and legal obligations effectively and efficiently.

A PIA report should describe and de-mystify the initiative, identify and analyse the privacy implications, and make clear recommendations, in plain English, for minimising privacy risks while maximising data utility ensuring your business objectives are met. We report conformity to the APPs on a three point scale outlined below:



Privacy risk management activities are conform to APPs and applicable privacy laws.



Activities are partially compliant to APPs or applicable privacy laws with some non-conformity identified.


Activities are wholly or materially not compliant with the APPs or applicable laws.

A Privacy Impact Assessment can also be scoped to include exposure and impacts arising under foreign privacy regimes such as the EU General Data Protection Regulation (GDPR) and to cover international data transfer risks through a Transfer Impact Assessment (TIA).

The engagement workflow will follow a defined process outlined below:


Get a no obligation consultation

At Albrecht Burrows, we understand the complexity and urgency of cyber and privacy risks facing businesses today. Get a no obligation consultation with our experts to better understand how your business can increase your resilience to cyber and privacy threats and regulatory risks. Our team of experienced multidisciplinary professionals will work closely with you to create personalised risk management solutions tailored to your business' unique needs needs and budget. Don't wait until it's too late – schedule your no-obligation consultation today and take proactive steps towards protecting your business from cyber threats and privacy breaches.


AB is an outstanding firm that delivers practical and innovative solutions for our business. Their experienced lawyers take a strategic and proactive approach while always trying to minimise costs - plus they explain scenarios in plain English so we know exactly what the outcomes might be."

Murray Liston
Managing Director, Civic MJD


Meet the Team


Our cyber and privacy services are delivered by our team of highly qualified professionals with decades of experience across all areas of cyber security and law, as well as law enforcement, artificial intelligence, privacy and data protection, risk management, business resilience, disaster recovery, crisis management, insurance and more.

James A. Cole
Partner | Head of Cyber & Privacy

My passion is helping our clients to implement holistic and commercial technology, privacy, and governance strategies that are aligned to their business objectives and risk appetite. I enjoy holistically applying my expertise across technology, business, and law enabling me to get to the heart of the issues and achieve positive, long-term results for clients.


Mark Anderson
Legal Consultant, Lawyer (NZ)

Managing risk with both technical precision and pragmatism is critical in the modern environment. Properly understanding your business needs and then delivering that advice together with integrity, trust and loyalty are fundamental to ensuring your most optimal outcomes.


Case Study

Case Study
Mapping Privacy Compliance across a Government Agency


Data breach emergencies

If you have experienced a data breach, whether unintential employee errors, employee data theft, or you’ve been the victim of a cyber-attack, the first 48 hours is crucial. So don’t waste any time, just get in touch.

Reach out, day or night.

If you don’t reach us straight away, we will get in touch ASAP!

Email us on [email protected]

Breach emergency Line: 02 8318 5980

woman holding silver iPhone 6



Smart Commercial Lawyers


Delivering emotionally intelligent legal solutions

ablaw.com.au | [email protected]

Reception 02 8014 2511