WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Queensland did something unusual in 2025. Rather than layering new obligations onto an existing structure, it collapsed two separate sets of privacy principles into one and attached a notification scheme with a fixed clock. Health agencies had worked to one framework and everybody else to another; both disappeared, replaced by a single set closely modelled on the Commonwealth principles.

For Brisbane organisations holding personal information on behalf of departments, hospital and health services or councils, the practical result is agreements with sharper wording and procurement conversations that a general assurance no longer settles.

Nathan ISO Consulting implements privacy information management systems for Queensland organisations, standalone under the 2025 revision of the standard or combined with an existing ISO 27001 certification.

Two Features Worth Understanding Before You Scope Anything

The first is consolidation. Queensland did not create a separate health privacy statute the way some states did; it folded health and non-health principles together, which means a Brisbane provider working across clinical and administrative information now applies one framework rather than reconciling two. The second is the clock. Where a suspected eligible breach involves agency information, assessment must be completed within 30 days and the Information Commissioner and affected individuals notified. That is a defined period, unlike the Commonwealth requirement to act as soon as practicable, and agencies pass the expectation to providers through contract.

Looking for an ISO 27701 Privacy Consultant in Brisbane?

Why ISO 27701 Matters for Queensland Organisations

The supplier position is the clearest driver. A Brisbane business processing personal information for a Queensland agency now sits behind an obligation with a deadline attached. Agencies working to a fixed assessment window need providers who can detect, escalate and supply information quickly, and they are writing that into agreements rather than assuming it.

The consolidation itself creates a second driver, in an unexpected direction. Because the framework is now unified, nobody can plead uncertainty about which principles apply to health information. That clarity cuts both ways: it simplifies implementation and removes a defence that previously existed.

The third is the change in the standard. Since October 2025, ISO 27701 has been certifiable on its own. An organisation whose exposure is personal information rather than broad information security no longer has to fund a full security programme to hold a certificate its customers will accept.

Legal and Regulatory Compliance in Queensland

ObligationWhat It Involves
Privacy Act 1988 and the 13 Australian Privacy PrinciplesFederal rules covering collection, use, disclosure, accuracy, protection and access for private organisations above the turnover threshold
Notifiable Data Breaches scheme (Cth)Judging whether serious harm is likely and notifying affected individuals and the federal regulator, with no fixed period specified
Information Privacy Act 2009 (Qld), as amendedQueensland Privacy Principles applying to agencies, health services and councils, reaching providers through agreement terms
Mandatory Notification of Data Breach schemeAssessment of a suspected eligible breach within 30 days, notification to the Information Commissioner and affected individuals, and a published breach policy
Human Rights Act 2019 (Qld)Public entities must act compatibly with human rights, privacy among them, and consider them properly in decisions
Statutory tort for serious invasions of privacyOperative since June 2025, allowing individuals to sue directly for deliberate or reckless serious invasions
Automated decision-making disclosurePrivacy policies must disclose significant automated decisioning, with the grace period ending 10 December 2026
Cross-border disclosure under APP 8Accountability for information disclosed overseas, including offshore processing and hosted platforms

Queensland obligations reach providers contractually rather than by direct operation of the Act, so the agreement wording determines what you have taken on. We read it during scoping.

Where Brisbane and Regional Queensland Work Sits

LocationActivityPrivacy Exposure
Brisbane CBDDepartments, superannuation administration, professional servicesAgency contract obligations, member and client records
Herston and WoolloongabbaHospitals, health services, pathology, medical researchClinical information under the consolidated Queensland principles
South Brisbane and West EndHealth technology, education, community servicesPatient and student records, vulnerable client information
Fortitude Valley and NewsteadSoftware platforms, digital services, marketing technologyProcessor obligations, tracking data, cross-border transfers
Milton and ToowongResources services, engineering, corporate functionsWorkforce records, contractor data, offshore processing
Springfield and IpswichEducation, technology services, government-adjacent providersAgency obligations arriving through contract
Gold Coast and Sunshine CoastHealth providers, education, allied health practicesClinical information in practices with limited privacy resourcing
Regional councilsLocal government across QueenslandBreach scheme obligations commencing a year behind other agencies
Regional health servicesHospital and health services outside the south eastConsolidated principles applied with fewer specialist staff

Standalone or Combined

Independent certification arrived with the 2025 revision, which does not make it right for everyone. Two questions generally settle it.

What Are Your Agreements Naming?

Read the last few contracts or assessment packs and check which certificate appears by name. Queensland health and education buyers increasingly specify privacy directly. Resources and financial services buyers more often specify security. That indicator beats an internal view about which sounds more thorough.

Does Exposure Exist Beyond Personal Data?

Where it does not, standalone is narrower to construct and lighter to sustain. Allied health practices, education providers, community organisations and member bodies typically sit here. Where you also hold commercially sensitive material or run systems where availability matters, combining makes more sense because governance is built once.

Not sure whether standalone or combined suits your organisation?

How We Run a Queensland Project

Stage One – Designing and Building

Data mapping comes first: what arrives, from where, on what basis, who handles it downstream, where it travels offshore and when it should be destroyed. For Queensland clients this stage also determines which framework governs which holdings, since an organisation may hold agency information under state principles and its own customer information under federal law at the same time. Role determination follows per activity, then notices, the applicability statement, rights handling, an incident runbook satisfying both the federal serious harm test and the Queensland assessment window, and retention scheduling.

Stage Two – Reaching Assessment

Standalone scope is not held by every accredited body yet. We verify who genuinely carries it before recommending anyone, settle terms and dates, and prepare through an audit measured against the standard and your principle obligations in one exercise. Both stages attended.

Stage Three – Maintaining It

Queensland guidance continues issuing after the reforms and federal privacy law remains under review. Recurring audit work, surveillance readiness and monitoring of developments affecting your scope stay with us, as does revising the data map as services, suppliers and offshore arrangements change.

What Is Handed Over

  • Personal information map. Each holding traced to source, basis, handlers, location and disposal point, with the governing framework recorded beside it.
  • Framework determination. Which holdings fall under Queensland principles, which under federal principles, and which under both simultaneously.
  • Role determination. Controller or processor settled per activity and reconciled to the language Australian and Queensland law actually use.
  • Incident runbook. Built to satisfy the federal serious harm assessment and, for agency information, the Queensland assessment window and notification path.
  • Assessment approach. Templates, trigger thresholds and worked assessments across the processing carrying most risk.
  • Automated decisioning register. Where systems make or materially shape significant decisions, prepared ahead of the December 2026 disclosure requirement.

Where Brisbane ISO 27701 Projects Go Wrong

  • An incident runbook written only to the federal model, incapable of supporting a fixed assessment window where agency information is involved
  • Policy drafted before the data map exists, describing handling that may or may not actually occur
  • Framework determination made once for the organisation rather than per holding, so agency and commercial information get treated identically
  • Retention schedules written and never operationalised, leaving records the organisation undertook to destroy
  • Overseas processing and hosted platforms left out of the controls governing disclosure beyond Australia
  • Automated decisioning unmapped as the December 2026 obligation approaches, with nothing to disclose from

Preparing for an upcoming audit?

Who Certifies You, and Where We Fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

We handle which accredited body you engage, what it costs and when it happens, choosing on the basis of your scope, your sector and the audit style that suits your operation. Our people sit through Stage 1 and Stage 2 alongside yours, and closing out whatever gets raised is our work rather than a list left behind. Do verify one thing independently beforehand: that the JAS-ANZ register shows the body accredited for your specific scope. Unaccredited certificates are quick and cheap to obtain and are turned away by procurement teams often enough to make that check worthwhile.

Send Us the Data Map

Whatever mapping exists, however partial, is the right starting point. Where none exists, building it is our first task together and it holds value for the organisation regardless of whether certification follows.

Ready to start your ISO 27701 certification journey?

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

Independent certification became available with the 2025 edition. Material saying otherwise describes the earlier version, which operated only as an extension. For Queensland health, education and community organisations the standalone route often matches the actual exposure better.

A single set introduced in 2025, replacing the separate principles that previously applied to health and non-health agencies. They follow the Commonwealth model closely, with differences in numbering and coverage that matter when mapping obligations across both.

Within 30 days of suspecting an eligible breach, which is a defined period rather than the federal approach of acting as soon as practicable. Providers supporting agency systems are routinely expected to make that timeframe achievable.

No. Unlike some states, Queensland consolidated health and non-health principles into one set rather than maintaining a distinct health statute. Health agencies and their suppliers now work to the same framework as other agencies.

Queensland local government received additional time and came within the scheme from 1 July 2026, a year after other agencies. Suppliers to councils should expect matching contract requirements to have followed.

Being compliant is a legal condition; certification evidences a managed route toward it. Our mapping runs the control set against both federal and Queensland principles so each obligation can be traced to where it is satisfied.

Typically both, differing by activity. Processing agency information on instruction places you in one position; deciding how your own workforce or client data is used places you in the other. We assess it activity by activity.

A list of where automated systems make or materially shape decisions with significant consequences for individuals, and privacy policy wording disclosing it. Building that list is the part most Queensland organisations have yet to start.

Move on the schedule your assessor sets. Substantive material largely holds. The effort is structural: rebuilding the applicability statement to stand alone and stripping assumptions the earlier edition made about an accompanying security certificate.

Roughly three and a half to six months standalone, shorter where a security certificate exists. Data mapping controls the schedule, and organisations holding both agency and commercial information should allow longer for it.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance