Reviewing customer data access: List all locations holding customer or order records with owners and review dates.; Check if permissions allow access to identifiable data, including exports and copies.; Under Australian privacy law, APP 11 requires reasonable steps to protect personal information.
Image: Ecommerce Insight Desk

Data Quality

Part of Ecommerce analytics operations

Reviewing access to customer-level analytics

Review who can view or export identifiable store data, check effective permissions and record a decision for each grant.

Review access by tracing who can reach identifiable customer or order records, why they need them and where copies can be made. Check effective permissions, remove grants without a current purpose and review exports separately. A summary dashboard is only one route to the data.

Inventory records and copies

List customer profiles, order-level reports, analytics properties, warehouse tables, scheduled exports and shared files used for analysis. For each location, record its owner, users and service accounts, purpose, export ability and next review date.

Distinguish an aggregate report from a row-level file that identifies, or could reasonably identify, a customer when combined with other available information.

Australian privacy obligations depend on the organisation and its circumstances. For an entity covered by the Privacy Act, APP 11 requires reasonable steps to protect personal information it holds from misuse, interference, loss and unauthorised access, modification or disclosure. An access review can support that work, but a permission setting alone does not establish compliance.

Key Data Protection Requirements under APP 11

  • Personal Information Protection RequirementReasonable steps to prevent misuse, interference, loss, and unauthorised access/modification/disclosure
  • Scope Applies ToOrganisations covered by the Privacy Act 1988 (Cth), including small businesses handling personal information
  • Compliance SupportAccess reviews help demonstrate due diligence but are not standalone compliance measures

Check what permissions allow

Shopify store permissions apply at the store level. Within a store, permissions cannot be restricted to individual orders, products or customers. The stated exceptions are app and channel permissions, which can be granted for specific apps or channels, and a B2B permission that limits access to assigned company locations. Check whether the role gives access to customer or order records, and whether those exceptions apply.

For Google Analytics, review assigned access and any data restrictions in the product's access management settings. Do not assume a report view alone limits access to the underlying data; verify what the user can access and whether they can make or access copies.

Decide each grant

Finding / Decision to record

Purpose and permission still match
Retain with an owner and next review date.
A narrower role or aggregate meets the need
Change access and check the resulting view.
No current purpose
Revoke access and check inherited, shared and export routes.
Purpose or ownership is unclear
Pause any expansion and assign a review owner.

Include contractors, integration accounts and scheduled jobs. Removing source access does not remove a copy already held elsewhere. Record the decision, approver, date and any copies requiring action. Check effective access after a change instead of assuming a role edit closed every route.

Repeat the review after staff or supplier changes, a new integration or a new customer-level export, as well as on an agreed cycle.

More from Data Quality

Measurement Planning

Maintaining a dictionary of store metrics

Maintain metric formulas, owners and effective dates so report users can reproduce store figures and recognise definition changes.