priivacy
27 May 2026 โ 27 May 2026
Australian Privacy Principles
Across 1 scan, this assessment analysed 70 files and identified 68 containing personally identifiable information (97.1% exposure rate), with 1,074 total PII instances detected. Of these, 22 critical and 1 high-risk files require immediate attention. Person Name is the most frequently detected PII type (356 instances).
Files Scanned
70
Files with PII
68
97.1% exposure rate
Overall Risk Level
MEDIUM
Score: 44/100
Total PII Found
1,074
17 distinct PII types
22 Critical Risk Files
These files contain highly sensitive PII with high identifiability, posing significant breach risk.
Action: Review and remediate as priority
135 Restricted Sensitivity Findings
Restricted-sensitivity PII (e.g. TFN, SSN, credit card, passport) was detected and requires enhanced protection.
Action: Apply encryption and access controls immediately
| PII Type | Sensitivity | Instances | Files |
|---|---|---|---|
| Person Name | INTERNAL | 356 | 41 |
| Organisation Name | INTERNAL | 316 | 46 |
| Credit Card Number | RESTRICTED | 100 | 1 |
| Email Address | INTERNAL | 100 | 1 |
| Location / Address | INTERNAL | 70 | 34 |
| Nationality | INTERNAL | 35 | 19 |
| Date of Birth | CONFIDENTIAL | 33 | 20 |
| Passport Number | RESTRICTED | 28 | 17 |
| Date of Expiry | CONFIDENTIAL | 16 | 16 |
| Australian Address | INTERNAL | 4 | 1 |
| Phone Number (AU) | INTERNAL | 4 | 1 |
| Patient ID / MRN | RESTRICTED | 3 | 2 |
| Racial / Ethnic Origin | RESTRICTED | 3 | 1 |
| Driver's Licence | CONFIDENTIAL | 2 | 2 |
| Gender / Sex | CONFIDENTIAL | 2 | 2 |
| Australian Business Number (ABN) | INTERNAL | 1 | 1 |
| International Bank Account Number | RESTRICTED | 1 | 1 |
PII types ranked by risk, with retention age breakdown
| # | PII Type | Total | Current (0-7 years) | 7-10 Years | 10+ Years | Retention Risk | Risk | Score |
|---|---|---|---|---|---|---|---|---|
| 1 | Credit Card Number | 100 | 100 | - | - | - | 10/10 | 110 |
| 2 | International Bank Account Number | 1 | 1 | - | - | - | 10/10 | 100 |
| 3 | Passport Number | 28 | 28 | - | - | - | 10/10 | 100 |
| 4 | Patient ID / MRN | 3 | 3 | - | - | - | 10/10 | 100 |
| 5 | Racial / Ethnic Origin | 3 | 3 | - | - | - | 10/10 | 100 |
| 6 | Driver's Licence | 2 | 2 | - | - | - | 7/10 | 70 |
| 7 | Date of Birth | 33 | 33 | - | - | - | 7/10 | 70 |
| 8 | Date of Expiry | 16 | 16 | - | - | - | 7/10 | 70 |
| 9 | Gender / Sex | 2 | 2 | - | - | - | 7/10 | 70 |
| 10 | Email Address | 100 | 100 | - | - | - | 4/10 | 50 |
| 11 | Organisation Name | 316 | 316 | - | - | - | 4/10 | 50 |
| 12 | Person Name | 356 | 356 | - | - | - | 4/10 | 50 |
| 13 | Australian Business Number (ABN) | 1 | 1 | - | - | - | 4/10 | 40 |
| 14 | Australian Address | 4 | 4 | - | - | - | 4/10 | 40 |
| 15 | Phone Number (AU) | 4 | 4 | - | - | - | 4/10 | 40 |
| 16 | Location / Address | 70 | 70 | - | - | - | 4/10 | 40 |
| 17 | Nationality | 35 | 35 | - | - | - | 4/10 | 40 |
Priority Score: Risk Weight (1-10) x 10 + Retention Risk % x 0.5 + Volume Bonus (100+ items=+10, 1K+=+20, 10K+=+30).Amber rows indicate 30%+ items exceed 7-year retention.Red values indicate 10+ year old data requiring immediate review.
Pending
1,074
Remediated
0
Reviewed
0
False Positive
0
The Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) regulate the handling of personal information by Australian Government agencies and private sector organisations. APP 11 requires entities to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
1,074 PII instances detected across 68 files, requiring review under Australian Privacy Principles.
22 files classified as CRITICAL risk โ immediate action recommended.
135 restricted-sensitivity findings detected (e.g. TFN, SSN, financial data).
1,074 findings are pending remediation.
priivacy ยท Report generated 27 May 2026