Until recently Western Australia was the only mainland state whose public sector operated without privacy legislation. That ended in July 2026, when the substantive provisions of the Privacy and Responsible Information Sharing Act commenced, bringing WA agencies under a set of Information Privacy Principles for the first time and extending obligations to the businesses that provide services to them.
A second date is still ahead. The notifiable information breach scheme under the same Act commences in January 2027, which means agencies will shortly be required to report serious breaches to the Information Commissioner and to affected individuals. Suppliers who hold or process agency information are being asked, now, how they would support that.
Nathan ISO Consulting implements information security management systems under ISO/IEC 27001:2022 for Western Australian organisations across resources technology, government supply, health, engineering services and software.
Why this matters more here than elsewhere
Public sector organisations in other states have had privacy obligations for two decades and have built the habits that go with them. Western Australia has not, which means an entire supplier market is encountering agency information handling requirements for the first time, at speed, with a breach reporting obligation arriving shortly behind. Organisations that already hold a certified information security management system are adapting. Those without one are building from a standing start while a contract clock runs.
Why ISO 27001 matters for Perth businesses
Government supply is the immediate driver, and it is unusually concentrated in this market because Western Australia delivers a large share of services through contracted providers. Health, community services, corrective services, education support and infrastructure delivery all involve private organisations handling information about individuals on behalf of the state. Those arrangements are now being rewritten to reflect the new regime.
Resources technology supplies the second. Perth hosts remote operations centres directing equipment across the Pilbara, the Goldfields and the Mid West, along with the software, engineering and analytics businesses that support them. Operators impose security requirements on vendors through prequalification systems, and those requirements have tightened as operational and corporate networks have converged.
The third is exposure that does not respect the boundary between corporate and operational. A Perth business supporting both a head office network and a site control system is often treating them as one problem when the risk profiles are entirely different, and an assessor will ask which one the certificate actually covers.
Legal and regulatory compliance in Western Australia
| Obligation | Who it captures in WA | What it requires |
|---|---|---|
| Privacy Act 1988 and APP 11 | Private organisations above the turnover threshold | Reasonable steps to protect personal information from misuse, interference, loss and unauthorised access |
| Notifiable Data Breaches scheme (Cth) | Entities within the federal privacy regime | Assessment of likely serious harm and notification of affected individuals and the federal regulator |
| Privacy and Responsible Information Sharing Act 2024 (WA) | WA public entities and their contracted service providers | Information Privacy Principles governing collection, use, storage and disclosure of personal information |
| Notifiable information breach scheme (WA) | WA public entities, commencing January 2027 | Reporting of serious information breaches to the Information Commissioner and affected individuals |
| Responsible information sharing framework | WA public entities sharing information for permitted purposes | Structured decision-making and transparency around information sharing, including Aboriginal data governance provisions |
| Security of Critical Infrastructure Act 2018 | Ports, energy and water assets, data centres, health operators | An all-hazards critical infrastructure risk management programme covering cyber |
| Operator vendor requirements | Suppliers to resources operators | Security obligations imposed contractually through prequalification and vendor management systems |
WA obligations reach suppliers through their agreements with public entities rather than by direct operation of the Act. The contract determines what you have taken on, and we read it during scoping.
Perth and regional WA coverage
| Location | Activity | Security driver |
|---|---|---|
| Perth CBD and West Perth | Resources head offices, remote operations centres, professional services | Operator vendor requirements and convergence of corporate and site systems |
| Subiaco and Osborne Park | Technology, engineering consultancies, health services | Customer security assessments and agency contract obligations |
| Government precincts | Departments, agencies and contracted service providers | New Information Privacy Principles and the approaching breach scheme |
| Murdoch and QEII precinct | Hospitals, medical research, health technology | Patient information handled under state and federal frameworks |
| Fremantle and North Quay | Terminal operators, freight technology, marine services | Critical infrastructure obligations and customer assurance |
| Henderson and Australian Marine Complex | Defence, shipbuilding, marine engineering | Controlled information handling and defence supply chain requirements |
| Kwinana | Refining, chemicals, bulk handling | Operational technology exposure alongside corporate systems |
| Pilbara operations | Iron ore, LNG, port and rail infrastructure directed from Perth | Remote access, vendor connections and site system security |
| Goldfields and Mid West | Mining operations, assay laboratories, regional services | Remote connectivity and operator vendor obligations |
How a Western Australian engagement runs
Boundaries come first, and they usually hinge on which agency or operator engagements have to fall inside them, because that is the line a procurement reviewer reads. Asset cataloguing follows, then risk work conducted with your leadership present, an applicability statement written out of your own findings rather than adapted from a precedent, and the control build itself spanning access, supplier arrangements, development practice, logging, incident handling and technology recovery. Where WA agency duties bite, the control set is cross-referenced so a single body of evidence serves both readers.
Assessors vary in how they handle resources and public sector clients, and it shows in audit style more than in fee. We cut the field to real candidates, set out where they differ, and settle terms and dates. Readiness means an internal audit run to external standards, every finding closed, and a review properly minuted. Both stages attended.
Recurring audit work, surveillance readiness and periodic risk reassessment stay with us. WA privacy guidance is still issuing as the regime beds in, and the breach scheme arrives in January 2027, so we track what affects your obligations. Where a new agency or operator engagement exceeds certified scope, the extension happens before signature.
Documents and evidence you receive
Where Perth ISO 27001 projects go wrong
Who certifies you, and where we fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Which accredited body you engage, on what terms and to what timetable, is work we take off you, matched against scope, sector and the audit approach that fits how you operate. Both assessment stages are attended by our people, and resolving whatever gets raised belongs to us rather than arriving as a list once the assessor leaves. Check one thing yourself first: that the JAS-ANZ register lists the body as accredited for your particular scope. Certificates from unaccredited providers cost little and take days, and procurement teams reject them regularly enough that the check pays for itself.
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Western Australia's Privacy and Responsible Information Sharing Act brought the state public sector under privacy obligations for the first time, with substantive provisions commencing July 2026. It reaches contracted service providers to public entities, so it affects you through your agency agreements.
The notifiable information breach scheme under the same Act commences in January 2027, requiring agencies to report serious information breaches to the Information Commissioner and affected individuals. Suppliers are being asked now how they would support that obligation.
Correct. Western Australia was the last mainland state without one, which is why the supplier market here is encountering agency information handling requirements for the first time rather than adjusting to an amendment of something familiar.
They are separate frameworks, so no. Certification delivers most of the capability the Act assumes, and our mapping lets you evidence that coverage without keeping one file for the agency and another for the assessor.
Ninety-three, arranged in four themes rather than the fourteen domains used before the 2022 revision. Any Perth provider quoting a figure in the hundred-and-teens is working from material several years out of date.
It depends on what you are certifying and what your customers are asking about. Corporate and site systems carry different risk profiles, and a certificate covering one while implying both will be questioned. We settle that boundary during scoping.
Four to seven months for most organisations. Policy work moves quickly; changing access, logging and vendor connection arrangements does not, and that engineering effort governs the schedule.
Requirements are set through vendor prequalification systems and vary by operator and scope. Security certification appears commonly where systems connect to operator networks. Send us the vendor pack and we will tell you what is genuinely required.
For WA government, resources and health buyers, ISO 27001 carries further and produces an ongoing certificate rather than a report covering one period. SOC 2 matters mainly when selling into United States enterprises.
Yes, across the Pilbara, Goldfields, South West, Mid West and Great Southern. Security work is largely location-independent, so travel is reserved for assessing physical controls, site systems and the audit itself.
Send us the agreement
Forward whatever set this off, whether that is an agency schedule, a vendor prequalification pack or a client questionnaire. Reading the clause as written settles scope in minutes where a conversation about it would take an hour and still leave doubt.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving