subscribe, registration, signup, software, applications, tablet, device, subscribe button, login, account, business, coffee, smart, security, credential, information, user, password, subscribe, registration, software, software, login, login, login, login, login, account
Photo by Mohamed_hassan on Pixabay

Stack Planning

Marketing stack security and permissions

Map permissions, customer data, connected applications and recovery across marketing systems so each critical control has an owner.

Map marketing systems that can publish content, spend money or expose customer information. Record who controls each system and how the business would regain access. Review tool-to-tool connections and each tool’s own settings.

Map the important systems and access routes

Start with marketing platforms and the underlying website, social and advertising accounts. For each, record the business owner, administrators, information handled, connected applications and recovery contact. Also list service accounts and API credentials: a staff user list will not show every route into a system.

Record what each route permits: drafting content, publishing it, inviting users and exporting customer records are different privileges. Flag an unknown owner or unexplained connection for investigation.

Control question / Record to keep

Who can change access or settings?
Effective administrators and the reason for their access
What information can leave?
Exports, connected applications and destinations
Who can regain control?
Approved recovery route and authorised deputy
What happens when access ends?
Handover, removal owner and completion record

Limit and review powerful access

Where the service permits, use individual accounts. Give people the rights their work requires, and protect privileged sign-ins with multi-factor authentication where available. Check effective access through groups, direct assignments and underlying native accounts; set a review point for temporary access.

A recurring administrator review should decide whether each privilege is still needed. An agency exit needs a separate cut-off and handover, because work and connections may depend on the departing agency.

Managing Privileged Access and Review Cycles

  1. Use individual accounts where possibleEnsure each user has a dedicated account with role-based permissions.
  2. Apply multi-factor authentication (MFA) to privileged sign-insRequired for high-risk access points such as admin dashboards.
  3. Review effective access through groups, direct assignments, and native accountsAudit access rights regularly to prevent privilege creep.
  4. Set review dates for temporary accessAutomate reminders or use internal tracking systems.
  5. Conduct administrator reviews to reassess ongoing need for privilegesRemove unnecessary access during regular audits.

Check the data arrangement

For a detailed vendor data-storage assessment, see the supporting article. At stack level, assign an owner to each connected service and its relevant controls.

APP 11 applies to personal information an entity holds. The Office of the Australian Information Commissioner explains this covers a record in the entity’s possession or control, not only one physically held by the entity. When assessing a connected service, account for records the organisation can control as well as those it can directly access.

For an APP entity disclosing personal information to an overseas recipient, APP 8.1 generally requires reasonable steps before disclosure to ensure the recipient does not breach the APPs (other than APP 1) in relation to that information. The entity is also accountable under section 16C for overseas recipients’ acts or practices that would breach the APPs, although exceptions apply.

An overseas disclosure must also meet APP 6.1: the information may be disclosed only for its primary collection purpose unless the individual consents or an exception applies. Make the purpose and any applicable exception part of the data-route decision, rather than treating hosting location as the only privacy consideration.

Applicable Privacy and Security Requirements by Data Flow Scenario

  • Data stored in AustraliaAPP 11: Reasonable steps to secure personal information. No cross-border disclosure required.
  • Data shared with overseas recipientAPP 8.1: Must take reasonable steps to ensure the recipient complies with APPs. Accountability under section 16C applies.
  • Disclosure for purpose other than primary collectionAPP 6.1: Only permitted if individual consents or an exception applies.

Make privacy duties visible across connected systems

For an organisation covered by the Australian Privacy Principles, APP 11 requires active measures to secure personal information it holds. Reasonable steps depend on the circumstances and include technical and organisational measures against misuse, interference, loss and unauthorised access, modification or disclosure.

Turn that obligation into stack-wide control assignments: identify who owns relevant technical measures and who makes organisational decisions about information handled by connected systems. Keep responsibilities visible where information passes between tools, so a change to one service does not leave a security task without an owner.

APP 11 also requires reasonable steps to destroy or de-identify personal information when it is no longer needed for a permitted purpose. This does not apply where the information is part of a Commonwealth record or must be retained under an Australian law or court or tribunal order. Build retention decisions into controls for connected copies, not just the main system.

Prepare for interrupted access and missing data

For each critical system, identify an authorised route that does not depend solely on one person’s device or mailbox. Protect emergency access, record its use and confirm the proposed route exists in the actual service.

Regaining an account does not restore deleted records or settings. Establish what can be restored, by whom and from which point, then arrange an appropriate restoration check. Keep the owner, access decision, data boundary, recovery route and unresolved gaps together so a change in one system can be assessed across the stack.

Preparing for Interrupted Access and Data Loss

  1. Identify authorised emergency recovery routes independent of single usersAvoid reliance on one person’s device or email.
  2. Confirm recovery routes exist in actual servicesTest access paths before incidents occur.
  3. Document what can be restored and from which backup pointInclude settings, records, and configurations.
  4. Assign responsibility for restoration checksEnsure clear ownership of recovery processes.
  5. Maintain records of recovery actions and unresolved gapsSupport audit readiness and continuous improvement.

In this guide

  1. Reviewing administrative access across marketing toolsReview effective administrator rights across marketing tools, groups, native accounts and connected apps, then verify each approved change.
  2. Checking how a vendor stores customer dataCheck where a marketing vendor stores customer information and copies, who can access them, how recovery works and what happens at exit.
  3. Planning account recovery for business-critical marketing systemsDocument authorised recovery routes for critical marketing accounts, protect emergency access and check how normal control is restored.
  4. Removing access when an agency engagement endsCoordinate an agency handover, remove direct and indirect access, verify business control and record remaining data obligations.

More from Stack Planning