Galexia

  Projects

VIC-TAC - Victorian Transport Accident Commission (TAC)


[ Galexia Dots ]

Related Galexia services and solutions

Related news about Galexia Privacy Impact Assessments in Victoria



The TAC is a Victorian Government-owned organisation set up to pay for treatment and benefits for people injured in transport accidents, promote road safety and improve Victoria's trauma system.

<https://www.tac.vic.gov.au>



[ Galexia Dots ]

VIC-TAC - Privacy Advice and 2-stage PIA of PageUp services to TAC (2018)

Galexia undertook a privacy review, developed initial issues guidance and then a subsequent independent Privacy Impact Assessment (PIA) considering the June 2018 PageUp data breach issue and provided broader advice on the potential use of additional PageUp services.

Whilst the PageUp data breach issue did not have a direct impact on TAC data, it was important to undertake an independent strategic review.



[ Galexia Dots ]

VIC-TAC - PIA for MyTAC enhancement - Supported Needs Identification (2018)

Galexia provided an Independent Privacy Impact Assessment (PIA) for TAC on the design and proposed implementation of the Needs Identification Questionnaire via the MyTAC App and web portal.

This PIA examined issues around the cloud hosting services (Microsoft Azure), system design and the user interface.

Galexia’s advice examined compliance with Victorian privacy and health privacy legislation.



[ Galexia Dots ]

VIC-TAC - 2nd PIA for proposed cloud-based Data, Analytics and Reporting (DAR) Platform and Development of a Data Release Privacy Checklist (Phase 2 - Expanded Data Set) (2018)

Galexia was engaged to develop an independent Privacy Impact Assessment (PIA) - examining the privacy consideration of the complete data analytics program, examining privacy issues on the use of cloud hosting services (Microsoft Azure), system design (including the ‘Data Vault Model’), and the risk profile of the underlying information assets - building on the Data, Analytics and Reporting (DAR)Working Model PIA (July 2018).

This PIA was the second for the program and is intended to provide recommendations and identify the risks for the DAR Program as it progresses into the design phase. Subsequent assessments will then provide assurance that the design and built solution have taken into consideration the independent PIA recommendations.

Using the prior developed DAR PIAs (Phase 1 Working Model and then Phase 2 Expanded Data Set) as a baseline, Galexia developed a Data Release Privacy Checklist for the TAC Data, Analytics and Reporting (DAR) Program.



[ Galexia Dots ]

VIC-TAC - Initial PIA for proposed cloud-based Data, Analytics and Reporting (DAR) Program (Phase 1 - Working Model) (2018)

Galexia has completed a Privacy Impact Assessment (PIA) for the Transport Accident Commission (TAC) on Phase 1 of their proposed Data Analytics and Reporting (DAR) Program. Phase 1 includes the development of a limited working model, based upon a slice of data.

The PIA considers privacy issues surrounding the proposed implementation of a new Data Analytics and Reporting (DAR) system based on cloud infrastructure. Galexia’s advice examines compliance with Victorian privacy and health privacy legislation.

The purpose of the PIA is to assist identifying and managing privacy issues that are raised by the design and proposed implementation of the DAR Program.

This initial PIA was limited to consideration of the first phase of the DAR Project, consisting of:

  • 1. Establishing a Working Model for the DAR Project utilising a limited data set;
  • 2. Working with sub-contractors and cloud service providers to develop the underlying infrastructure required for the DAR Program; and
  • 3. Evaluating the Working Model before proceeding with the further development and implementation of the DAR Project across a broader set of data



[ Galexia Dots ]

VIC-TAC - PIA for Point of Sale (PoS) online service (2017)


Find out more about TAC’s cloud based digital payment solution using Lantern Pay >

Galexia completed a Privacy Impact Assessment (PIA) for the Transport Accident Commission (TAC) on the proposal to develop and implement a Point of Sale (POS) application using Lantern Pay <http://www.lanternpay.com> (in association with Westpac). The application will be hosted, in part, on a cloud-computing platform.

The purpose of the PIA was to assist in identifying and managing privacy issues raised by the design and proposed implementation of the Point of Sale (POS) application - the Lantern Pay service.

The PIA considered compliance with privacy legislation, user acceptance and public perception issues. The PIA made a broad range of recommendations for mediating privacy risks, including changes to the design, practical privacy compliance steps, further research and privacy governance arrangements.



[ Galexia Dots ]

VIC-TAC - PIA for Phase 1 of proposed Online Client Service (2017)


Find out more about using myTAC >

Galexia was successful in a competitive tender to undertake a PIA examining privacy issues arising from the design and implementation of a new Online Client Service (including an online portal for self-managing clients and a mobile app).

Galexia’s advice covered compliance with Victorian privacy and health privacy legislation, and advice on best practice in moving existing processes to a cloud based service. The PIA was completed in April 2017 and included:

  • Galexia PIA Matrix (Victoria)
  • ‘Urgent Issues’ guidance in the first 2 weeks of the engagement - ensuring a no surprises approach and working closely with multi-disciplinary and agile teams.
  • 3 staged briefing notes and vendor and internal team updates incorporated into an agile delivery process.
  • Draft and Final PIAs
  • Follow-up briefing to executive and privacy teams



[ Galexia Dots ]