Privacy Impact Assessment Disclosure Log

In accordance with OAIC recommendations, DHA publishes a summary of all Privacy Impact Assessments (PIAs) undertaken from 1 July 2018 on its PIA disclosure log.

A privacy impact assessment (PIA) is a systematic tool used to assess the privacy impacts of a project or procurement activity and sets out recommendations for managing, minimising or eliminating that impact. In accordance with the Office of the Australian Information Commissioner's recommendations, DHA publishes a summary of its PIAs in this disclosure log. This contributes to the transparency of the project's development and intent, and demonstrates to stakeholders and the community that the project has undergone critical privacy analysis.

Date Requested Project Name and Summary Outcome Status Date Completed
14/1/2019 Additional fields added to DHA's Client Management profiles Recording contractor security clearances.
No requirement for PIA - project to proceed.
No additional personal information collected / transferred. This relates to information that DHA already holds (security clearance of DHA contractors). The only change relates to how that information is displayed to improve allocation of on-base maintenance / repairs to contractors that hold the appropriate security clearance.
Completed 21/1/2019
14/12/2018 Defence member platform: Maintenance certificates System improvements to automate the process for the recovery of tenant charges and invoicing.

No requirement for PIA - project to proceed. There is no change to the information that is sent to Defence.
Completed 21/1/2019
23/10/2018 Monthly workforce dashboard Employee information will be aggregated to report on top line/overall totals

Consideration of the type of the information to be reported on is needed.

Full PIA required.
In Progress
19/9/2018 Data for assets to be moved into internal workflow system No requirement for full PIA - project can proceed.
There is no change identified to the type of personal information collected. The only change relates to where the information is stored. Transfer will be conducted internally.
Completed 7/11/2018
24/8/2018 Third party investigation where personal information held by DHA will be disclosed Proceed with the procurement of the third party investigator provided:
1. information and any subsequent report is transferred via secure file transfer
2. no cloud based / overseas storage by investigator, and
3. written notice provided to the investigator at the conclusion of the investigation that all personal information must be destroyed or permanently de-identified
Received 4/10/2018