Kmart Australia
Retail & Ecommerce
Very weak provisions with no age verification, parental consent mechanisms, or child-specific protections. Only mentions collecting age/date of birth and student ID numbers without any special safeguards for minors. Overall: Good with minor gaps.
10 dimensions · 67 claims · assessed 11 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
7.83/107.83/10
Transparency
Good with minor gaps
Transparency & Clarity
8/10Policy provides comprehensive scope statement, clear definitions, specific privacy officer contact details, current version date, and strong introductory section with data handling principles. Missing plain language commitment and section overview.
Purpose Limitation & Use
8/10Extensive list of primary purposes clearly stated, secondary uses explicitly disclosed including data analysis and marketing, opt-out mechanisms provided. Some broad catch-all clauses present but overall very comprehensive.
Policy Maintenance & Accountability
7/10Clear policy update notification process, current version availability commitment, specific privacy officer contact details, and complaint handling process with OAIC escalation. Missing specific review frequency and detailed governance framework.
Data Protection
Good with minor gaps
7.78/107.78/10
Data Protection
Good with minor gaps
Data Collection Disclosure
9/10Exceptionally detailed enumeration of personal information types collected, comprehensive disclosure of collection methods including automated technologies, clear sensitive data handling, and specific third-party data sources. Exceeds minimum requirements with granular specificity.
Third-Party Sharing & Disclosure
9/10Comprehensive disclosure with named third parties (Flybuys, OnePass, Google), specific advertising networks, detailed purposes for sharing, contractual obligations for overseas recipients, and clear opt-out mechanisms. Exceeds minimum requirements.
Data Security
4/10Generic security commitment with basic measures mentioned (secured servers, controlled facilities). Lacks specific encryption details, certifications, breach notification procedures, or audit practices beyond general statements.
Cross-Border Data Flows
8/10Specific destination countries named (US, UK, European countries, Asia Pacific including China, India, Bangladesh, Singapore, Vietnam, Hong Kong), contractual obligations for overseas recipients clearly stated with purpose limitation and confidentiality requirements.
Your Rights
Room for improvement
5.2/105.2/10
Your Rights
Room for improvement
Consumer Rights & Control
6/10Access and correction rights clearly stated with specific contact mechanisms, marketing opt-out provided, complaint process described with OAIC escalation. However, response timeframes are vague ('reasonable time') and no deletion rights mentioned.
Automated Decision-Making
6/10Good disclosure of profiling activities, automated advertising decisions, and facial recognition processing with opt-out mechanisms provided. However, lacks human review rights and detailed algorithmic transparency about decision logic.
Children's Data
2/10Very weak provisions with no age verification, parental consent mechanisms, or child-specific protections. Only mentions collecting age/date of birth and student ID numbers without any special safeguards for minors.
Sector Comparison
Retail & Ecommerce comparison