Back to Trust & Security

Privacy Impact Assessment - Public Summary

Version 1.0Effective On publication

Document details

Description
A plain-English summary of the privacy risks assessed and how they are managed.
Version
1.0
Effective
On publication
Last reviewed
On publication
Next review
12 months after publication
Owner
Privacy Officer

Threadline conducted a Privacy Impact Assessment (PIA) to understand how personal and health information moves through its service, identify privacy risks and determine how those risks are managed. This is a public summary. The full internal assessment, which contains detailed architecture and risk information, is kept confidential.

1. Scope

The assessment considered how personal and health information, including information about children, is collected, used, stored, shared, retained and deleted across the Threadline service, from account creation through to sharing an Assessment Package with a healthcare professional.

2. Information considered

Account and contact information; health and sensitive information provided to prepare an Assessment Package; information contributed by invited third parties such as teachers; payment and transaction information; and technical, security and usage information.

3. Information flows

Information is collected from families and invited contributors, organised into an Assessment Package, stored using approved service providers, shared with a healthcare professional at the family’s direction, and retained or deleted according to defined periods.

4. Methodology

The assessment mapped these information flows against the Australian Privacy Principles, identified privacy risks, and determined the controls needed to manage them.

5. Principal privacy risks identified

  • Handling of children’s and other sensitive information
  • Consent and authority to provide a child’s information
  • Sharing with healthcare professionals and with service providers
  • Overseas handling by some service providers
  • Retention and secure deletion
  • Unauthorised access or a data breach

6. Controls in place

In response to these risks, Threadline applies consent processes, access controls, encryption in transit and at rest, assessment of service providers, defined retention and deletion rules, security monitoring, and incident response and breach notification procedures. Children’s information is handled through an adult account with child-appropriate practices.

7. Residual risks

Some service providers may process information overseas, and the service relies on families and contributors to provide accurate information. These risks are managed through provider assessment, contractual protections and clear guidance to families, but cannot be fully eliminated.

8. Review

The responsible owner is the Threadline privacy function. This assessment is reviewed 12 months after publication, or sooner if the service or its information handling materially changes.