Privacy Analyser

Understand the privacy impact.
Keep the whole assessment connected.

Move from a Privacy Threshold Assessment (PTA) to a full Privacy Impact Assessment (PIA) where needed. Keep business answers, privacy risks, evidence and professional judgement in one privacy record.

See the privacy workflow A dedicated workspace for privacy teams

Begin with the right questions

Collect the answers.
Make the next step clear.

Work through the OPC Brief Privacy Analysis risk areas, AIS supplementary triggers and your organisation’s own questions. Send a Word or Excel questionnaire to the business and preview returned answers before importing them.

  • Avoid retyping the business questionnaire
  • Record a threshold determination and whether a PIA is required
  • Override the AIS determination with a recorded professional reason
The determination uses AIS’s own labelled policy. The assessor retains oversight.
Product screen from the AIS User Guide. Example assessment data.
Privacy Analyser: threshold assessment and determination
Privacy Analyser: threshold assessment and determination

Product screen from the AIS User Guide. Example assessment data.

Where the assessment happens

From privacy risks
to evidence-backed findings.

The full PIA brings the scope, information flows, consultation and evaluation together. Principles carry the actual validation work.

01

Privacy risks

Record inherent, current and target positions. Review and select AI-drafted risks before adding them.

02

Principles & evidence

Document the validation plan and assessment notes for each applicable principle. Keep working notes private from exports.

03

Findings & actions

Raise findings and recommendations from the principle. Connect the risks, owner, due date and evidence.

The Privacy Act 2020 is the built-in baseline. Additional instruments, including the Biometric Processing Privacy Code 2025 where in scope, can be assessed alongside it.

Explore instruments
RESPONSE ASSURANCE EXPERIMENTAL

What the business says.
What the documents support.

Compare questionnaire answers with source documents such as contracts, data processing agreements and architecture documents. Review supported answers, inconsistencies and issues the questionnaire did not ask about.

  • Follow issues back to a source clause and page
  • See where documents do not cover the questionnaire
  • Review suggested follow-up questions before sending them
  • Import follow-up answers separately from the original questionnaire

This experimental capability does not automatically change answers, create formal findings or move the determination. A document can be excluded from AI comparison while remaining available for human review.

Experimental capability. Suggestions require professional review.
Response Assurance: source documents and evidence-backed follow-up questions
Response Assurance: source documents and evidence-backed follow-up questions

Experimental capability. Suggestions require professional review.

Finish with a record you can revisit

Review once in context.
Produce the documents you need.

PTA & PIA reports

Generate separate Word reports from the same privacy record. Use configurable report templates, plus Word and Excel questionnaires.

Review & integrity

Reviewers comment on risks, principles and findings. Integrity checks highlight gaps and contradictions. Closure exceptions follow your configured policy.

Reassess after go-live

Carry forward scope and descriptions, then assess ratings and compliance afresh. Optionally carry findings forward for explicit follow-up.

Privacy findings enter the Findings Registry when the assessment closes. Privacy and security retain their own assessment records and access permissions.

See it with your team

Bring your assessment.
We’ll show you the workflow.

A 30-minute walkthrough tailored to your frameworks, your team and the work you need to deliver.