Cyber-attacks and data breaches are rapidly increasing in sophistication, with immense ramifications for companies and their customers. Australian companies are under greater obligation than ever to manage their customers’ Personally Identifiable Information (PII).
The obligations related to Privacy protection under the Australian Privacy Act (Commonwealth) 1988 continue to evolve and be strengthened. Additionally organisations in some industries face greater data compliance obligations (e.g. SOCI, APRA, BIM, FOI, Public records act). Compliance with the current and anticipated standards is dependent on effective information lifecycle management across both structured and unstructured data.

Astral’s PII and Privacy service offering leverages Astral’s extensive EIM experience and focuses on performing a ISO31000-aligned risk assessment on how PII is being managed, and planning how the organisation can address the identified issues and build PII information lifecycle management capability.
Unstructured Data: PII and Privacy Data Governance Methodology
Astral’s PII and Privacy Data Governance service offering for unstructured data provides a proven methodology that has been developed from over 20 years of EIM engagements across a broad range of industries and different sized organisations.
Our approach typically includes three main streams of work:
- PII Analysis – Detailed analysis conducted via business engagement to determine how PII in unstructured data is managed on a day-to-day basis.
- PII Interrogation – A file interrogation tool is run across all target repositories storing unstructured data to identify PII according to the organisation-specific and industry standard business rules. Combined with the outcomes from Work stream 1, a Plan is developed that defines what activities are required to address the business risks identified.
- PII Remediation – Execution of the PII remediation initiatives as defined in the Plan.

Benefits
The benefits that this service offering can deliver include:
- Provide a clear PII risk assessment using your organisation’s risk management framework
- Prepare a pragmatic PII management and remediation plan that is aligned with business priorities and available resources
- Identify obsolete PII that can be deleted
- Enable legal hold capability across all relevant data
- Define an approach to ensure compliant PII management for unstructured data is sustainable across the organisation
Need more information?
Contact Astral to find out more about our PII and Privacy Data Governance offering. Let us help you ensure your data is governed, secure and compliant.

