Melbourne organisations frequently operate under two privacy frameworks simultaneously, and a surprising number do not realise it. Commonwealth law applies to most businesses above the turnover threshold. Victorian law applies to public sector information and, separately, to health information held anywhere in the state.
A private clinic in Carlton, a university handling student records, a technology supplier to a department, an aged care provider contracting to the state: each sits across more than one regime with principles that overlap without being identical.
Nathan ISO Consulting implements privacy information management systems for Victorian organisations, either standalone under the 2025 revision or alongside an existing ISO 27001 certification.
The standard became certifiable on its own in October 2025
Until the 2025 revision, ISO 27701 functioned only as an add-on to ISO 27001 and could not be certified independently. That changed. An organisation whose exposure is personal information rather than systems and intellectual property can now certify against the privacy standard directly, without first building and funding a full information security programme. Most privacy content aimed at the Melbourne market has not caught up with this, and continues to describe the superseded position.
Looking for an ISO 27701 Privacy Consultant in Melbourne?
Why ISO 27701 Matters for Melbourne Businesses
The Victorian health sector is the clearest case. Melbourne holds a concentration of hospitals, research institutes, private clinics and health technology suppliers, and health information here attracts obligations under state law in addition to the Commonwealth Privacy Act. Providers assuming federal law is the whole picture are working with an incomplete obligation set, which becomes apparent at the worst possible moment.
Superannuation supplies the second driver. Funds administering member savings hold detailed financial and identity information, and prudential expectations around data handling flow contractually to administrators and technology suppliers. In a city with this concentration of funds, a broad range of businesses inherit privacy obligations from customers rather than from statute.
Education adds a third. Victorian universities and colleges hold student records, international student information and research data, and the obligations attaching to each differ. Certification gives an institution or a supplier a structure that covers all of it rather than a set of separate arrangements that nobody can reconcile.
Legal and Regulatory Compliance in Victoria
| Obligation | What It Involves |
|---|---|
| Privacy Act 1988 and the 13 Australian Privacy Principles | Federal rules governing how personal information may be gathered, applied, shared, kept accurate, protected and made available to the person concerned |
| Notifiable Data Breaches scheme | A requirement to evaluate whether serious harm is likely and, where it is, inform affected people and the regulator without undue delay. No fixed hour count applies here |
| Privacy and Data Protection Act 2014 (Vic) | Victorian Information Privacy Principles applying to public sector information, with obligations reaching contracted service providers |
| Health Records Act 2001 (Vic) | Health Privacy Principles applying to health information held by public and private sector organisations across Victoria |
| Victorian Protective Data Security Standards | Security obligations for Victorian public sector information, relevant where you handle it under contract |
| Statutory tort for serious invasions of privacy | Operative since June 2025. Individuals may now sue directly where an invasion was deliberate or reckless, shifting exposure away from regulator action alone |
| Automated decision-making disclosure | Privacy policies must disclose significant automated decisioning, with the grace period ending 10 December 2026 |
| Cross-border disclosure under APP 8 | Accountability for personal information disclosed overseas, including offshore administration and cloud arrangements |
Which regimes apply depends on the information you hold and who you hold it for, not on your sector alone. We establish that during scoping because it determines the whole control set.
Melbourne Economic Zones and Sectors We Serve
| Melbourne Precinct | Business Activity | Privacy Exposure |
|---|---|---|
| Parkville biomedical precinct | Hospitals, research institutes, universities | Health information under state and federal law, research participant data |
| Clayton and Monash precinct | Medical technology, clinical research, education | Clinical trial data, student records, offshore research collaboration |
| Melbourne CBD and Docklands | Superannuation funds, insurers, professional services | Member and policyholder data, identity documents, claims information |
| Cremorne and Richmond | SaaS platforms, martech, digital services | Processor obligations, tracking data, cross-border transfers |
| Southbank and St Kilda Road | Government offices, education providers, consultancies | Victorian public sector information handled under contract |
| Box Hill and Burwood | Health services, education, community services | Patient and student records, vulnerable client information |
| Carlton and inner north | Private clinics, allied health, not-for-profits | Health information in smaller practices with limited privacy resourcing |
| Dandenong and outer south east | Community health, aged care, disability services | Sensitive client information across multi-provider service arrangements |
| Regional Victoria | Health services, councils, education providers | State and federal obligations with fewer specialist privacy staff |
Standalone or Combined, and How to Decide
The standalone route is new, which does not make it right for every organisation. Two questions usually settle it within a single conversation.
Pull the last three supplier assessments or contract schedules you completed and read which certificate is specified. Melbourne health and education buyers increasingly name privacy directly. Financial services buyers more often name security. That answers the question more reliably than an internal debate about which feels more thorough.
If the answer is no, standalone is narrower and cheaper to maintain. Clinics, allied health practices, member associations, training providers and community services usually fall here. If you also hold commercially sensitive material or run systems where availability matters, the combined route generally makes more sense because the governance is built once and serves both.
Not sure whether standalone or combined suits your organisation?
Our Approach to a Victorian Privacy Engagement
Data mapping precedes everything. What arrives, from whom, on what basis, who handles it downstream, where it goes offshore and when it is supposed to be destroyed. For Victorian clients this stage also establishes which regimes apply to which holdings, because a provider may hold health information under state law, member data under federal law and public sector information under contract simultaneously. Role determination follows activity by activity, then the notices, applicability statement, individual rights handling, incident runbook calibrated to serious harm, assessment methodology and retention scheduling.
Standalone assessment capability is still expanding across accredited bodies, so we verify who genuinely holds scope before recommending anyone. Commercial process is ours, as is preparation: an audit tested against the standard and your principle-level obligations together, with a documented review. We attend both stages.
Australian privacy law is mid-reform, and Victorian requirements are revised on their own cycle. We carry the recurring audit work, prepare you for surveillance, watch for developments that touch your scope, and revise the data map as services, suppliers and offshore arrangements change.
Deliverables
Where Melbourne ISO 27701 Projects Go Wrong
Preparing for an upcoming audit?
Who Certifies You, and Where We Fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Selection, quoting and scheduling of the accredited body are handled by us, matched to your scope, sector and how you prefer an audit to run. We are present for both assessment stages, and anything raised becomes ours to resolve rather than a task handed back to you. One check worth doing yourself first: confirm on the JAS-ANZ register that the body holds accreditation for the scope in question. Certificates from unaccredited providers are inexpensive, fast, and regularly refused by procurement.
Start With the Data Map
Send whatever mapping already exists, however incomplete. If none does, building it is the first work we do together, and it remains the most useful thing your organisation can hold whether or not certification follows.
Ready to start your ISO 27701 certification journey?
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Independent certification became available with the 2025 edition. Anything indicating otherwise refers to the superseded version, which existed purely as an add-on. Health, education and community organisations across Victoria often find the independent route better suited to their exposure.
Generally yes. Victorian health privacy obligations apply to health information held by private as well as public sector organisations in the state, operating alongside the Commonwealth Privacy Act rather than instead of it.
Victorian public sector privacy principles and protective data security obligations reach contracted providers through agreement terms rather than by direct operation of the statute. Your contract wording determines the scope of what you have taken on.
They cover similar ground with different drafting, numbering and some substantive variation. An organisation subject to both cannot simply apply one set and assume coverage, which is why we map holdings to regimes rather than to the organisation as a whole.
Australian law sets no fixed period. You must assess whether serious harm is likely, then notify affected individuals and the regulator as soon as practicable once aware. The 72-hour rule belongs to European law and does not apply here.
Almost always both, varying by activity. Handling data on a client’s instruction places you in one role; deciding how to use your own staff or prospect information places you in the other. We record it activity by activity.
An inventory of where automated systems make or substantially assist decisions significantly affecting people, and updated privacy policy wording disclosing it. The inventory is the part most organisations have not started.
Meaningfully. The standard draws on European privacy concepts and the current edition tightens that alignment, making it a practical way for Victorian exporters and software businesses to run one privacy system across both jurisdictions.
Your certification body sets the window. Most of what you have written remains valid. The effort goes into structure: making the applicability statement function on its own and stripping out assumptions the old edition made about a parallel security certificate.
Roughly three and a half to six months standalone, and materially less where a security certificate already exists. Data mapping governs the schedule, and organisations across multiple privacy regimes should expect that phase to run longer.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving