WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Until recently Western Australia was the only mainland state whose public sector operated without privacy legislation. That ended in July 2026, when the substantive provisions of the Privacy and Responsible Information Sharing Act commenced, bringing WA agencies under a set of Information Privacy Principles for the first time and extending obligations to the businesses that provide services to them.

A second date is still ahead. The notifiable information breach scheme under the same Act commences in January 2027, which means agencies will shortly be required to report serious breaches to the Information Commissioner and to affected individuals. Suppliers who hold or process agency information are being asked, now, how they would support that.

Nathan ISO Consulting implements information security management systems under ISO/IEC 27001:2022 for Western Australian organisations across resources technology, government supply, health, engineering services and software.

Why this matters more here than elsewhere

Public sector organisations in other states have had privacy obligations for two decades and have built the habits that go with them. Western Australia has not, which means an entire supplier market is encountering agency information handling requirements for the first time, at speed, with a breach reporting obligation arriving shortly behind. Organisations that already hold a certified information security management system are adapting. Those without one are building from a standing start while a contract clock runs.

Why ISO 27001 matters for Perth businesses

Government supply is the immediate driver, and it is unusually concentrated in this market because Western Australia delivers a large share of services through contracted providers. Health, community services, corrective services, education support and infrastructure delivery all involve private organisations handling information about individuals on behalf of the state. Those arrangements are now being rewritten to reflect the new regime.

Resources technology supplies the second. Perth hosts remote operations centres directing equipment across the Pilbara, the Goldfields and the Mid West, along with the software, engineering and analytics businesses that support them. Operators impose security requirements on vendors through prequalification systems, and those requirements have tightened as operational and corporate networks have converged.

The third is exposure that does not respect the boundary between corporate and operational. A Perth business supporting both a head office network and a site control system is often treating them as one problem when the risk profiles are entirely different, and an assessor will ask which one the certificate actually covers.

Legal and regulatory compliance in Western Australia

ObligationWho it captures in WAWhat it requires
Privacy Act 1988 and APP 11Private organisations above the turnover thresholdReasonable steps to protect personal information from misuse, interference, loss and unauthorised access
Notifiable Data Breaches scheme (Cth)Entities within the federal privacy regimeAssessment of likely serious harm and notification of affected individuals and the federal regulator
Privacy and Responsible Information Sharing Act 2024 (WA)WA public entities and their contracted service providersInformation Privacy Principles governing collection, use, storage and disclosure of personal information
Notifiable information breach scheme (WA)WA public entities, commencing January 2027Reporting of serious information breaches to the Information Commissioner and affected individuals
Responsible information sharing frameworkWA public entities sharing information for permitted purposesStructured decision-making and transparency around information sharing, including Aboriginal data governance provisions
Security of Critical Infrastructure Act 2018Ports, energy and water assets, data centres, health operatorsAn all-hazards critical infrastructure risk management programme covering cyber
Operator vendor requirementsSuppliers to resources operatorsSecurity obligations imposed contractually through prequalification and vendor management systems

WA obligations reach suppliers through their agreements with public entities rather than by direct operation of the Act. The contract determines what you have taken on, and we read it during scoping.

Perth and regional WA coverage

LocationActivitySecurity driver
Perth CBD and West PerthResources head offices, remote operations centres, professional servicesOperator vendor requirements and convergence of corporate and site systems
Subiaco and Osborne ParkTechnology, engineering consultancies, health servicesCustomer security assessments and agency contract obligations
Government precinctsDepartments, agencies and contracted service providersNew Information Privacy Principles and the approaching breach scheme
Murdoch and QEII precinctHospitals, medical research, health technologyPatient information handled under state and federal frameworks
Fremantle and North QuayTerminal operators, freight technology, marine servicesCritical infrastructure obligations and customer assurance
Henderson and Australian Marine ComplexDefence, shipbuilding, marine engineeringControlled information handling and defence supply chain requirements
KwinanaRefining, chemicals, bulk handlingOperational technology exposure alongside corporate systems
Pilbara operationsIron ore, LNG, port and rail infrastructure directed from PerthRemote access, vendor connections and site system security
Goldfields and Mid WestMining operations, assay laboratories, regional servicesRemote connectivity and operator vendor obligations

How a Western Australian engagement runs

Phase one — build

Boundaries come first, and they usually hinge on which agency or operator engagements have to fall inside them, because that is the line a procurement reviewer reads. Asset cataloguing follows, then risk work conducted with your leadership present, an applicability statement written out of your own findings rather than adapted from a precedent, and the control build itself spanning access, supplier arrangements, development practice, logging, incident handling and technology recovery. Where WA agency duties bite, the control set is cross-referenced so a single body of evidence serves both readers.

Phase two — certify

Assessors vary in how they handle resources and public sector clients, and it shows in audit style more than in fee. We cut the field to real candidates, set out where they differ, and settle terms and dates. Readiness means an internal audit run to external standards, every finding closed, and a review properly minuted. Both stages attended.

Phase three — sustain

Recurring audit work, surveillance readiness and periodic risk reassessment stay with us. WA privacy guidance is still issuing as the regime beds in, and the breach scheme arrives in January 2027, so we track what affects your obligations. Where a new agency or operator engagement exceeds certified scope, the extension happens before signature.

Documents and evidence you receive

  • Scope statement. Wording covering the agency and operator relationships behind the project, phrased so a procurement reviewer accepts it without further explanation.
  • Information asset register. What you hold, where it sits, who can reach it, and the consequence if it were lost or exposed.
  • Risk assessment and treatment plan. Threat and vulnerability analysis with criteria endorsed by leadership and every treatment carrying a named owner.
  • Statement of Applicability. All 93 Annex A controls addressed with justification traceable to your own assessment work.
  • WA obligation cross-reference. Where agency information is involved, your controls mapped to the Information Privacy Principles and breach reporting expectations.
  • Assurance records. Full internal audit with findings closed and verified, plus review minutes covering each required input.

Where Perth ISO 27001 projects go wrong

  • WA agency privacy obligations treated as future work, when the principles are already operating and the breach scheme is months away.
  • A single scope covering corporate and operational technology as though they carried the same risk profile.
  • Scope defined around the organisation rather than the services the customer actually buys, which fails the first procurement review.
  • Control justifications assembled from a template, which assessors working this market recognise immediately.
  • Remote vendor connections into site systems left unassessed because they sit outside the corporate network.
  • Access reviews never carried out, still the most frequently raised finding we encounter.

Who certifies you, and where we fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Which accredited body you engage, on what terms and to what timetable, is work we take off you, matched against scope, sector and the audit approach that fits how you operate. Both assessment stages are attended by our people, and resolving whatever gets raised belongs to us rather than arriving as a list once the assessor leaves. Check one thing yourself first: that the JAS-ANZ register lists the body as accredited for your particular scope. Certificates from unaccredited providers cost little and take days, and procurement teams reject them regularly enough that the check pays for itself.

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

Western Australia's Privacy and Responsible Information Sharing Act brought the state public sector under privacy obligations for the first time, with substantive provisions commencing July 2026. It reaches contracted service providers to public entities, so it affects you through your agency agreements.

The notifiable information breach scheme under the same Act commences in January 2027, requiring agencies to report serious information breaches to the Information Commissioner and affected individuals. Suppliers are being asked now how they would support that obligation.

Correct. Western Australia was the last mainland state without one, which is why the supplier market here is encountering agency information handling requirements for the first time rather than adjusting to an amendment of something familiar.

They are separate frameworks, so no. Certification delivers most of the capability the Act assumes, and our mapping lets you evidence that coverage without keeping one file for the agency and another for the assessor.

Ninety-three, arranged in four themes rather than the fourteen domains used before the 2022 revision. Any Perth provider quoting a figure in the hundred-and-teens is working from material several years out of date.

It depends on what you are certifying and what your customers are asking about. Corporate and site systems carry different risk profiles, and a certificate covering one while implying both will be questioned. We settle that boundary during scoping.

Four to seven months for most organisations. Policy work moves quickly; changing access, logging and vendor connection arrangements does not, and that engineering effort governs the schedule.

Requirements are set through vendor prequalification systems and vary by operator and scope. Security certification appears commonly where systems connect to operator networks. Send us the vendor pack and we will tell you what is genuinely required.

For WA government, resources and health buyers, ISO 27001 carries further and produces an ongoing certificate rather than a report covering one period. SOC 2 matters mainly when selling into United States enterprises.

Yes, across the Pilbara, Goldfields, South West, Mid West and Great Southern. Security work is largely location-independent, so travel is reserved for assessing physical controls, site systems and the audit itself.

Send us the agreement

Forward whatever set this off, whether that is an agency schedule, a vendor prequalification pack or a client questionnaire. Reading the clause as written settles scope in minutes where a conversation about it would take an hour and still leave doubt.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance