Document details
- Description
- A plain-English summary of the privacy risks assessed and how they are managed.
- Version
- 1.0
- Effective
- On publication
- Last reviewed
- On publication
- Next review
- 12 months after publication
- Owner
- Privacy Officer
- Contact
- support@threadline.com.au
Threadline conducted a Privacy Impact Assessment (PIA) to understand how personal and health information moves through its service, identify privacy risks and determine how those risks are managed. This is a public summary. The full internal assessment, which contains detailed architecture and risk information, is kept confidential.
1. Scope
The assessment considered how personal and health information, including information about children, is collected, used, stored, shared, retained and deleted across the Threadline service, from account creation through to sharing an Assessment Package with a healthcare professional.
2. Information considered
Account and contact information; health and sensitive information provided to prepare an Assessment Package; information contributed by invited third parties such as teachers; payment and transaction information; and technical, security and usage information.
3. Information flows
Information is collected from families and invited contributors, organised into an Assessment Package, stored using approved service providers, shared with a healthcare professional at the family’s direction, and retained or deleted according to defined periods.
4. Methodology
The assessment mapped these information flows against the Australian Privacy Principles, identified privacy risks, and determined the controls needed to manage them.
5. Principal privacy risks identified
- Handling of children’s and other sensitive information
- Consent and authority to provide a child’s information
- Sharing with healthcare professionals and with service providers
- Overseas handling by some service providers
- Retention and secure deletion
- Unauthorised access or a data breach
6. Controls in place
In response to these risks, Threadline applies consent processes, access controls, encryption in transit and at rest, assessment of service providers, defined retention and deletion rules, security monitoring, and incident response and breach notification procedures. Children’s information is handled through an adult account with child-appropriate practices.
7. Residual risks
Some service providers may process information overseas, and the service relies on families and contributors to provide accurate information. These risks are managed through provider assessment, contractual protections and clear guidance to families, but cannot be fully eliminated.
8. Review
The responsible owner is the Threadline privacy function. This assessment is reviewed 12 months after publication, or sooner if the service or its information handling materially changes.