A NSW Government website

Step 4 of 10

Privacy & data

Answering “No” to the lead question below skips the rest of this section. Each Yes/Unsure is a trigger for review.

B1Does the solution involve the collection, use, storage, processing, analysis, generation or disclosure of personal, health or other sensitive information?
B2Will a third-party vendor, reseller, subcontractor, cloud, AI or support provider have access to personal, health or government information?
B3Will the solution involve information sharing with another agency, public sector body, private entity, supplier or subcontractor?
B4Will personal, health or government information be stored, processed, accessed, supported or disclosed outside NSW or Australia, including by offshore personnel?
B5Will the solution involve data matching, analytics, linkage, profiling, automated recommendations, AI-enabled processing or automated decision-making?
B6Will the solution create new information, records, classifications, profiles, scores, recommendations, summaries, audit logs or other derived information?
B7Could the solution affect a person's ability to access government information, understand how information is used, or exercise privacy, access or correction rights?
B8Is it unclear who will hold the information, in what form, where it will be stored, and how agency access will be provided during and after the engagement?
B9Is it unclear whether contract arrangements address data return, deletion, retention, audit rights, access to logs, incident notification and data-breach responsibilities?
B10Will production data be used in non-production environments such as development, testing, training, support, demonstrations or AI model training?
B11Will any supplier, administrator or project team member be able to directly change, correct, migrate, extract or manipulate production data?

Proof of concept reconstructed from the MICTA/ICTA Risk Guidance prototype. Not an official NSW Government tool.