Australian Taxation Office
Government & Utilities
No relevant claims found in policy. Overall: Good with minor gaps.
10 dimensions · 78 claims · assessed 18 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
7.67/107.67/10
Transparency
Good with minor gaps
Transparency & Clarity
8/10Comprehensive scope statement covering multiple user types, specific contact methods including dedicated privacy hotline, clear last updated date, and policy availability in multiple formats. Strong introductory section explaining policy purpose and transparency commitment.
Purpose Limitation & Use
7/10Clear primary purposes for tax and superannuation administration, explicit secondary uses for audit, data matching, and research. Specific purposes for call recordings and biometric data, though limited explicit consent requirements for secondary uses beyond biometrics.
Policy Maintenance & Accountability
8/10Regular review commitment with website publication, designated Privacy Officer and Champion under APP Code 2017, privacy impact assessment register, comprehensive compliance framework, and dedicated privacy hotline. Strong governance structure with specific security measures.
Data Protection
Excellent transparency
8.22/108.22/10
Data Protection
Excellent transparency
Data Collection Disclosure
9/10Exceptionally detailed enumeration of personal information types collected, comprehensive collection methods including direct, third-party, cookies, and web browsing data. Clear legal basis statements, specific biometric data handling with consent mechanisms, and detailed Google Analytics collection practices.
Third-Party Sharing & Disclosure
8/10Specific named categories of recipients with clear purposes, detailed disclosure to law enforcement and prescribed taskforces, comprehensive overseas disclosure under tax treaties with named countries. Strong contractual obligations for contractors and clear voice biometric restrictions.
Data Security
7/10Industry best practice security measures including audits and penetration testing, clear staff access controls, specific biometric data geographic restrictions, contractor security obligations, and detailed authentication logging. However, lacks specific encryption or certification details.
Cross-Border Data Flows
9/10Comprehensive disclosure with specific named countries under tax treaties and TIEAs, clear purposes for international tax cooperation, specific Google Analytics data location in USA with anonymization, and explicit restrictions on voice biometric transfers.
Your Rights
Room for improvement
5.6/105.6/10
Your Rights
Room for improvement
Consumer Rights & Control
9/10Comprehensive access and correction rights with specific 30-day timeframes, no-charge commitments, multiple complaint mechanisms with 3-day response commitment, clear OAIC escalation path, and specific deletion rights for voiceprints with opt-out mechanisms.
Automated Decision-Making
5/10General disclosure of data matching, biometric identification, and compliance analysis systems with some transparency about purposes. However, lacks specific details about decision logic, human review rights, or comprehensive opt-out mechanisms beyond biometrics.
Children's Data
not assessedNo relevant claims found in policy.
No specific findings.
Sector Comparison
Government & Utilities comparison