NRMA Insurance
Banking & Finance
Children mentioned only as potential data subjects with general third-party consent requirements. No age verification, parental consent mechanisms, specific protections, or age thresholds defined. Overall: Room for improvement.
10 dimensions · 74 claims · assessed 19 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
6.83/106.83/10
Transparency
Good with minor gaps
Transparency & Clarity
7/10Policy provides clear scope statement, specific contact information, current date, and section headings. However, lacks comprehensive definitions section and table of contents for better navigation.
Purpose Limitation & Use
7/10Clear stated purposes for collection and use, marketing opt-out mechanisms provided, and service provider purpose limitations. Some secondary uses disclosed but includes broad catch-all provisions.
Policy Maintenance & Accountability
6/10Policy update notification commitment and current date provided with multiple contact methods. However, no specific review frequency schedule or named privacy officer mentioned.
Data Protection
Good with minor gaps
7.22/107.22/10
Data Protection
Good with minor gaps
Data Collection Disclosure
8/10Comprehensive enumeration of specific data types collected including telematics data, clear collection methods, third-party sources, and sensitive information handling with consent mechanisms.
Third-Party Sharing & Disclosure
8/10Detailed disclosure of third-party categories and some named entities, clear purposes for sharing, contractual obligations for service providers, and overseas disclosure with specific countries listed.
Data Security
5/10Basic security measures disclosed including firewalls, encryption, and secure processes for electronic data. However, lacks specific certifications, breach notification commitments, or detailed audit practices.
Cross-Border Data Flows
7/10Comprehensive list of 24 specific countries for overseas transfers with contractual safeguards requiring compliance with Australian privacy laws. Clear notification provided in policy.
Your Rights
Major deficiencies
3.4/103.4/10
Your Rights
Major deficiencies
Consumer Rights & Control
6/10Access and correction rights clearly stated with contact mechanisms, marketing opt-out available, and complaint escalation to OAIC provided. However, no deletion rights mentioned and response timeframes not specified.
Automated Decision-Making
2/10Very limited disclosure with only implied automated processing for pricing and underwriting decisions. No explicit ADM disclosure, opt-out rights, human review options, or transparency about logic provided.
Children's Data
1/10Children mentioned only as potential data subjects with general third-party consent requirements. No age verification, parental consent mechanisms, specific protections, or age thresholds defined.
Sector Comparison
Banking & Finance comparison