// privacy & security readiness

Initial readiness check — Amendment 13 & information security

A few practical questions that help surface areas worth reviewing. “I don’t know” is valuable because uncertainty itself often identifies where ownership or documentation is missing.

This is an initial self-check only. It is not legal advice, a legal opinion, a security audit, or confirmation of compliance.
1. Does the organisation hold personal information about customers, employees or users?
2. Do you know which systems hold the personal information?
3. Is there a clear list of people and roles with access?
4. Are permissions removed when people change roles or leave?
5. Is MFA enabled on key systems?
6. Are logs retained on key systems?
7. Does someone review unusual activity rather than only collect logs?
8. Is there a documented security-incident process?
9. Is it clear who makes decisions during an incident?
10. Has the incident-response process been exercised?
11. Is there a list of external suppliers that can access information?
12. Do you know where the organisation’s main personal-information stores are?
13. Has a risk assessment or security review been completed recently?
14. Has the organisation checked whether it is required to appoint a DPO?
15. Are security and privacy controls documented and reviewed?
Last step — where should we send the conversation?

Submitting the questionnaire sends ITgalya your contact details together with the assessment context so we can follow up from the result you just generated.

Do not enter passwords, credentials, API keys, logs, incident evidence or other sensitive material.