
Data Quality
Part of Ecommerce analytics operations
Reviewing access to customer-level analytics
Review who can view or export identifiable store data, check effective permissions and record a decision for each grant.
Review access by tracing who can reach identifiable customer or order records, why they need them and where copies can be made. Check effective permissions, remove grants without a current purpose and review exports separately. A summary dashboard is only one route to the data.
Inventory records and copies
List customer profiles, order-level reports, analytics properties, warehouse tables, scheduled exports and shared files used for analysis. For each location, record its owner, users and service accounts, purpose, export ability and next review date.
Distinguish an aggregate report from a row-level file that identifies, or could reasonably identify, a customer when combined with other available information.
Australian privacy obligations depend on the organisation and its circumstances. For an entity covered by the Privacy Act, APP 11 requires reasonable steps to protect personal information it holds from misuse, interference, loss and unauthorised access, modification or disclosure. An access review can support that work, but a permission setting alone does not establish compliance.
Key Data Protection Requirements under APP 11
- Personal Information Protection RequirementReasonable steps to prevent misuse, interference, loss, and unauthorised access/modification/disclosure
- Scope Applies ToOrganisations covered by the Privacy Act 1988 (Cth), including small businesses handling personal information
- Compliance SupportAccess reviews help demonstrate due diligence but are not standalone compliance measures
Check what permissions allow
Shopify store permissions apply at the store level. Within a store, permissions cannot be restricted to individual orders, products or customers. The stated exceptions are app and channel permissions, which can be granted for specific apps or channels, and a B2B permission that limits access to assigned company locations. Check whether the role gives access to customer or order records, and whether those exceptions apply.
For Google Analytics, review assigned access and any data restrictions in the product's access management settings. Do not assume a report view alone limits access to the underlying data; verify what the user can access and whether they can make or access copies.
Decide each grant
Finding / Decision to record
- Purpose and permission still match
- Retain with an owner and next review date.
- A narrower role or aggregate meets the need
- Change access and check the resulting view.
- No current purpose
- Revoke access and check inherited, shared and export routes.
- Purpose or ownership is unclear
- Pause any expansion and assign a review owner.
Include contractors, integration accounts and scheduled jobs. Removing source access does not remove a copy already held elsewhere. Record the decision, approver, date and any copies requiring action. Check effective access after a change instead of assuming a role edit closed every route.
Repeat the review after staff or supplier changes, a new integration or a new customer-level export, as well as on an agreed cycle.


