Woolworths
Retail & Ecommerce
Complete absence of any automated decision-making disclosures across all key areas including ADM use, types of decisions, opt-out rights, human review availability, and logic transparency. No relevant claims were found in the privacy policy content. Overall: Major deficiencies.
10 dimensions · 34 claims · assessed 15 Apr 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Room for improvement
5/105/10
Transparency
Room for improvement
Transparency & Clarity
6/10The claims show adequate transparency with general purpose statements and contact information provided, but lack specific mechanisms for key transparency requirements like update notifications, version history, and language accessibility. The disclosures are somewhat vague with generic language rather than detailed specific processes.
Purpose Limitation & Use
4/10The claims provide basic purpose statements but lack specificity and comprehensiveness required for APP 6 compliance. While primary purposes are mentioned, the language is vague ('great shopping experience'), secondary use disclosures are minimal, and there's no mention of consent mechanisms or marketing opt-out options.
Policy Maintenance & Accountability
4/10The claims provide basic contact information and generic statements about user control, but lack specific commitments on key accountability measures like review frequency, change notification procedures, governance frameworks, or compliance monitoring timeframes required for higher scores.
Data Protection
Major deficiencies
3/103/10
Data Protection
Major deficiencies
Data Collection Disclosure
4/10The disclosures are minimal and generic, using broad categories like 'personal information' and 'cameras and technology' without specifying actual data types collected. While collection methods are mentioned, the lack of granular detail and specific data enumeration results in inadequate disclosure quality.
Third-Party Sharing & Disclosure
3/10The claims provide only minimal, generic disclosures about third-party sharing with vague recipients like 'other companies' and broad purposes like 'help deliver our services', lacking specific named parties, detailed purposes, or information about contractual protections.
Data Security
2/10The claims contain only generic, boilerplate language about security design principles and user responsibility without any specific technical measures, encryption details, certifications, or breach notification commitments required for meaningful APP 11 compliance.
No specific findings.
Cross-Border Data Flows
2/10While New Zealand is specifically named as an operational location, there are no actual disclosures about cross-border data transfers, adequacy mechanisms, or safeguards as required by APP 8. This is merely a business operations reference without privacy-specific content.
Your Rights
Major deficiencies
1.6/101.6/10
Your Rights
Major deficiencies
Consumer Rights & Control
4/10The policy provides basic consumer rights disclosures including access, correction, and complaint mechanisms, but lacks specificity in key areas such as response timeframes, detailed processes, deletion rights, and clear escalation procedures to OAIC.
Automated Decision-Making
0/10Complete absence of any automated decision-making disclosures across all key areas including ADM use, types of decisions, opt-out rights, human review availability, and logic transparency. No relevant claims were found in the privacy policy content.
Children's Data
not assessedNo relevant claims found in policy.
No specific findings.
Sector Comparison
Retail & Ecommerce comparison