Bunnings Australia
Retail & Ecommerce
No specific children's data protections identified despite collecting age and date of birth information. No age verification, parental consent mechanisms, or child-specific safeguards mentioned. Very weak coverage of children's privacy requirements. Overall: Good with minor gaps.
10 dimensions · 64 claims · assessed 19 Apr 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
7.5/107.5/10
Transparency
Good with minor gaps
Transparency & Clarity
8/10Comprehensive scope statement covering all business entities, clear definitions section with legal references, specific contact details for privacy officer, structured sections with clear headings, and current version dating. Strong transparency commitment with good navigation structure.
Purpose Limitation & Use
7/10Detailed primary purposes across eight categories with specific examples, clear secondary use disclosure including cross-brand data sharing, comprehensive marketing uses with opt-out available. However, lacks explicit purpose limitation commitment and relies more on opt-out model than consent for secondary uses.
Policy Maintenance & Accountability
7/10Clear update notification process, current version dating, designated privacy officer with comprehensive contact details, structured complaint handling with timeframes, and security framework outlined. Good governance structure but lacks specific review frequency commitments.
Data Protection
Good with minor gaps
7.56/107.56/10
Data Protection
Good with minor gaps
Data Collection Disclosure
9/10Exceptionally detailed enumeration of specific data types across seven categories, comprehensive collection methods (direct, automated, third-party), explicit sensitive data handling (facial recognition), and clear disclosure of collection necessity with consequences. Goes beyond basic categories to provide granular specifics.
Third-Party Sharing & Disclosure
8/10Extensive list of third-party categories with specific purposes, named parties including Flybuys, OnePass, and Related Companies, specific countries for overseas transfers with contractual safeguards. Clear disclosure of law enforcement sharing and advertising network partnerships with opt-out mechanisms.
Data Security
5/10Lists several security measures including encryption, access controls, and firewalls, but lacks specific details about implementation, certifications, or breach notification procedures. Generic security statements without technical specifics or audit practices mentioned.
Cross-Border Data Flows
7/10Specific countries and regions named for data transfers, clear contractual safeguards requiring overseas parties to protect information and comply with applicable law. Good notification of transfer destinations but could be more specific about adequacy mechanisms.
Your Rights
Significant gaps
4.6/104.6/10
Your Rights
Significant gaps
Consumer Rights & Control
8/10Clear access and correction rights with identity verification requirements, comprehensive complaint mechanism with 30-day response timeframe, specific OAIC escalation process with contact details, and multiple opt-out methods for marketing. Strong coverage of key consumer rights with clear mechanisms.
Automated Decision-Making
3/10Discloses profiling activities and data analysis for personalisation but lacks explicit automated decision-making disclosure, no specific opt-out rights for automated decisions, and no transparency about decision logic or human review rights. Minimal coverage of this important area.
Children's Data
1/10No specific children's data protections identified despite collecting age and date of birth information. No age verification, parental consent mechanisms, or child-specific safeguards mentioned. Very weak coverage of children's privacy requirements.
Sector Comparison
Retail & Ecommerce comparison