Harvey Norman
Retail & Ecommerce
No relevant claims found in policy. Overall: Good with minor gaps.
10 dimensions · 68 claims · assessed 18 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
6.83/106.83/10
Transparency
Good with minor gaps
Transparency & Clarity
7/10Policy provides clear scope, plain language commitment, definitions, specific contact details, and version tracking. However, lacks table of contents and comprehensive introductory summary.
Purpose Limitation & Use
7/10Clear primary and secondary purposes stated, marketing consent mechanisms, and commitment not to use for other purposes without consent. Some purposes could be more specific.
Policy Maintenance & Accountability
6/10Named privacy officer with contact details, version tracking, and complaint handling timeframes. However, lacks specific review frequency commitments and comprehensive governance framework details.
Data Protection
Good with minor gaps
7.22/107.22/10
Data Protection
Good with minor gaps
Data Collection Disclosure
8/10Comprehensive enumeration of specific data types collected, clear collection methods, sensitive data handling with consent requirements, and detailed notification requirements at collection time.
Third-Party Sharing & Disclosure
8/10Detailed disclosure of recipient categories with some named parties (Harvey Norman Holdings), specific purposes, contractual obligations requiring APP compliance, and clear consent mechanisms.
Data Security
5/10Basic security measures mentioned (locks, firewalls, passwords, access controls) but lacks specific technical details, certifications, or breach notification procedures. Generic security commitments.
Cross-Border Data Flows
7/10Clear disclosure of overseas transfers with specific countries named (US, UK), APP 8.1 compliance commitments, and reasonable steps to ensure recipient compliance with APPs.
Your Rights
Significant gaps
4/104/10
Your Rights
Significant gaps
Consumer Rights & Control
8/10Comprehensive rights framework with specific access/correction procedures, clear timeframes (48 hours acknowledgment, 10 days resolution), detailed opt-out mechanisms, and OAIC escalation pathway.
Automated Decision-Making
2/10Very limited disclosure - only mentions cookies for tailoring services and fraud checks. No specific ADM disclosure, opt-out rights, or human review mechanisms provided.
Children's Data
not assessedNo relevant claims found in policy.
No specific findings.
Sector Comparison
Retail & Ecommerce comparison