Queensland did something unusual in 2025. Rather than layering new obligations onto an existing structure, it collapsed two separate sets of privacy principles into one and attached a notification scheme with a fixed clock. Health agencies had worked to one framework and everybody else to another; both disappeared, replaced by a single set closely modelled on the Commonwealth principles.
For Brisbane organisations holding personal information on behalf of departments, hospital and health services or councils, the practical result is agreements with sharper wording and procurement conversations that a general assurance no longer settles.
Nathan ISO Consulting implements privacy information management systems for Queensland organisations, standalone under the 2025 revision of the standard or combined with an existing ISO 27001 certification.
Two Features Worth Understanding Before You Scope Anything
The first is consolidation. Queensland did not create a separate health privacy statute the way some states did; it folded health and non-health principles together, which means a Brisbane provider working across clinical and administrative information now applies one framework rather than reconciling two. The second is the clock. Where a suspected eligible breach involves agency information, assessment must be completed within 30 days and the Information Commissioner and affected individuals notified. That is a defined period, unlike the Commonwealth requirement to act as soon as practicable, and agencies pass the expectation to providers through contract.
Looking for an ISO 27701 Privacy Consultant in Brisbane?
Why ISO 27701 Matters for Queensland Organisations
The supplier position is the clearest driver. A Brisbane business processing personal information for a Queensland agency now sits behind an obligation with a deadline attached. Agencies working to a fixed assessment window need providers who can detect, escalate and supply information quickly, and they are writing that into agreements rather than assuming it.
The consolidation itself creates a second driver, in an unexpected direction. Because the framework is now unified, nobody can plead uncertainty about which principles apply to health information. That clarity cuts both ways: it simplifies implementation and removes a defence that previously existed.
The third is the change in the standard. Since October 2025, ISO 27701 has been certifiable on its own. An organisation whose exposure is personal information rather than broad information security no longer has to fund a full security programme to hold a certificate its customers will accept.
Legal and Regulatory Compliance in Queensland
| Obligation | What It Involves |
|---|---|
| Privacy Act 1988 and the 13 Australian Privacy Principles | Federal rules covering collection, use, disclosure, accuracy, protection and access for private organisations above the turnover threshold |
| Notifiable Data Breaches scheme (Cth) | Judging whether serious harm is likely and notifying affected individuals and the federal regulator, with no fixed period specified |
| Information Privacy Act 2009 (Qld), as amended | Queensland Privacy Principles applying to agencies, health services and councils, reaching providers through agreement terms |
| Mandatory Notification of Data Breach scheme | Assessment of a suspected eligible breach within 30 days, notification to the Information Commissioner and affected individuals, and a published breach policy |
| Human Rights Act 2019 (Qld) | Public entities must act compatibly with human rights, privacy among them, and consider them properly in decisions |
| Statutory tort for serious invasions of privacy | Operative since June 2025, allowing individuals to sue directly for deliberate or reckless serious invasions |
| Automated decision-making disclosure | Privacy policies must disclose significant automated decisioning, with the grace period ending 10 December 2026 |
| Cross-border disclosure under APP 8 | Accountability for information disclosed overseas, including offshore processing and hosted platforms |
Queensland obligations reach providers contractually rather than by direct operation of the Act, so the agreement wording determines what you have taken on. We read it during scoping.
Where Brisbane and Regional Queensland Work Sits
| Location | Activity | Privacy Exposure |
|---|---|---|
| Brisbane CBD | Departments, superannuation administration, professional services | Agency contract obligations, member and client records |
| Herston and Woolloongabba | Hospitals, health services, pathology, medical research | Clinical information under the consolidated Queensland principles |
| South Brisbane and West End | Health technology, education, community services | Patient and student records, vulnerable client information |
| Fortitude Valley and Newstead | Software platforms, digital services, marketing technology | Processor obligations, tracking data, cross-border transfers |
| Milton and Toowong | Resources services, engineering, corporate functions | Workforce records, contractor data, offshore processing |
| Springfield and Ipswich | Education, technology services, government-adjacent providers | Agency obligations arriving through contract |
| Gold Coast and Sunshine Coast | Health providers, education, allied health practices | Clinical information in practices with limited privacy resourcing |
| Regional councils | Local government across Queensland | Breach scheme obligations commencing a year behind other agencies |
| Regional health services | Hospital and health services outside the south east | Consolidated principles applied with fewer specialist staff |
Standalone or Combined
Independent certification arrived with the 2025 revision, which does not make it right for everyone. Two questions generally settle it.
Read the last few contracts or assessment packs and check which certificate appears by name. Queensland health and education buyers increasingly specify privacy directly. Resources and financial services buyers more often specify security. That indicator beats an internal view about which sounds more thorough.
Where it does not, standalone is narrower to construct and lighter to sustain. Allied health practices, education providers, community organisations and member bodies typically sit here. Where you also hold commercially sensitive material or run systems where availability matters, combining makes more sense because governance is built once.
Not sure whether standalone or combined suits your organisation?
How We Run a Queensland Project
Data mapping comes first: what arrives, from where, on what basis, who handles it downstream, where it travels offshore and when it should be destroyed. For Queensland clients this stage also determines which framework governs which holdings, since an organisation may hold agency information under state principles and its own customer information under federal law at the same time. Role determination follows per activity, then notices, the applicability statement, rights handling, an incident runbook satisfying both the federal serious harm test and the Queensland assessment window, and retention scheduling.
Standalone scope is not held by every accredited body yet. We verify who genuinely carries it before recommending anyone, settle terms and dates, and prepare through an audit measured against the standard and your principle obligations in one exercise. Both stages attended.
Queensland guidance continues issuing after the reforms and federal privacy law remains under review. Recurring audit work, surveillance readiness and monitoring of developments affecting your scope stay with us, as does revising the data map as services, suppliers and offshore arrangements change.
What Is Handed Over
Where Brisbane ISO 27701 Projects Go Wrong
Preparing for an upcoming audit?
Who Certifies You, and Where We Fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
We handle which accredited body you engage, what it costs and when it happens, choosing on the basis of your scope, your sector and the audit style that suits your operation. Our people sit through Stage 1 and Stage 2 alongside yours, and closing out whatever gets raised is our work rather than a list left behind. Do verify one thing independently beforehand: that the JAS-ANZ register shows the body accredited for your specific scope. Unaccredited certificates are quick and cheap to obtain and are turned away by procurement teams often enough to make that check worthwhile.
Send Us the Data Map
Whatever mapping exists, however partial, is the right starting point. Where none exists, building it is our first task together and it holds value for the organisation regardless of whether certification follows.
Ready to start your ISO 27701 certification journey?
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Independent certification became available with the 2025 edition. Material saying otherwise describes the earlier version, which operated only as an extension. For Queensland health, education and community organisations the standalone route often matches the actual exposure better.
A single set introduced in 2025, replacing the separate principles that previously applied to health and non-health agencies. They follow the Commonwealth model closely, with differences in numbering and coverage that matter when mapping obligations across both.
Within 30 days of suspecting an eligible breach, which is a defined period rather than the federal approach of acting as soon as practicable. Providers supporting agency systems are routinely expected to make that timeframe achievable.
No. Unlike some states, Queensland consolidated health and non-health principles into one set rather than maintaining a distinct health statute. Health agencies and their suppliers now work to the same framework as other agencies.
Queensland local government received additional time and came within the scheme from 1 July 2026, a year after other agencies. Suppliers to councils should expect matching contract requirements to have followed.
Being compliant is a legal condition; certification evidences a managed route toward it. Our mapping runs the control set against both federal and Queensland principles so each obligation can be traced to where it is satisfied.
Typically both, differing by activity. Processing agency information on instruction places you in one position; deciding how your own workforce or client data is used places you in the other. We assess it activity by activity.
A list of where automated systems make or materially shape decisions with significant consequences for individuals, and privacy policy wording disclosing it. Building that list is the part most Queensland organisations have yet to start.
Move on the schedule your assessor sets. Substantive material largely holds. The effort is structural: rebuilding the applicability statement to stand alone and stripping assumptions the earlier edition made about an accompanying security certificate.
Roughly three and a half to six months standalone, shorter where a security certificate exists. Data mapping controls the schedule, and organisations holding both agency and commercial information should allow longer for it.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving