WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Melbourne organisations frequently operate under two privacy frameworks simultaneously, and a surprising number do not realise it. Commonwealth law applies to most businesses above the turnover threshold. Victorian law applies to public sector information and, separately, to health information held anywhere in the state.

A private clinic in Carlton, a university handling student records, a technology supplier to a department, an aged care provider contracting to the state: each sits across more than one regime with principles that overlap without being identical.

Nathan ISO Consulting implements privacy information management systems for Victorian organisations, either standalone under the 2025 revision or alongside an existing ISO 27001 certification.

The standard became certifiable on its own in October 2025

Until the 2025 revision, ISO 27701 functioned only as an add-on to ISO 27001 and could not be certified independently. That changed. An organisation whose exposure is personal information rather than systems and intellectual property can now certify against the privacy standard directly, without first building and funding a full information security programme. Most privacy content aimed at the Melbourne market has not caught up with this, and continues to describe the superseded position.

Looking for an ISO 27701 Privacy Consultant in Melbourne?

Why ISO 27701 Matters for Melbourne Businesses

The Victorian health sector is the clearest case. Melbourne holds a concentration of hospitals, research institutes, private clinics and health technology suppliers, and health information here attracts obligations under state law in addition to the Commonwealth Privacy Act. Providers assuming federal law is the whole picture are working with an incomplete obligation set, which becomes apparent at the worst possible moment.

Superannuation supplies the second driver. Funds administering member savings hold detailed financial and identity information, and prudential expectations around data handling flow contractually to administrators and technology suppliers. In a city with this concentration of funds, a broad range of businesses inherit privacy obligations from customers rather than from statute.

Education adds a third. Victorian universities and colleges hold student records, international student information and research data, and the obligations attaching to each differ. Certification gives an institution or a supplier a structure that covers all of it rather than a set of separate arrangements that nobody can reconcile.

Legal and Regulatory Compliance in Victoria

ObligationWhat It Involves
Privacy Act 1988 and the 13 Australian Privacy PrinciplesFederal rules governing how personal information may be gathered, applied, shared, kept accurate, protected and made available to the person concerned
Notifiable Data Breaches schemeA requirement to evaluate whether serious harm is likely and, where it is, inform affected people and the regulator without undue delay. No fixed hour count applies here
Privacy and Data Protection Act 2014 (Vic)Victorian Information Privacy Principles applying to public sector information, with obligations reaching contracted service providers
Health Records Act 2001 (Vic)Health Privacy Principles applying to health information held by public and private sector organisations across Victoria
Victorian Protective Data Security StandardsSecurity obligations for Victorian public sector information, relevant where you handle it under contract
Statutory tort for serious invasions of privacyOperative since June 2025. Individuals may now sue directly where an invasion was deliberate or reckless, shifting exposure away from regulator action alone
Automated decision-making disclosurePrivacy policies must disclose significant automated decisioning, with the grace period ending 10 December 2026
Cross-border disclosure under APP 8Accountability for personal information disclosed overseas, including offshore administration and cloud arrangements

Which regimes apply depends on the information you hold and who you hold it for, not on your sector alone. We establish that during scoping because it determines the whole control set.

Melbourne Economic Zones and Sectors We Serve

Melbourne PrecinctBusiness ActivityPrivacy Exposure
Parkville biomedical precinctHospitals, research institutes, universitiesHealth information under state and federal law, research participant data
Clayton and Monash precinctMedical technology, clinical research, educationClinical trial data, student records, offshore research collaboration
Melbourne CBD and DocklandsSuperannuation funds, insurers, professional servicesMember and policyholder data, identity documents, claims information
Cremorne and RichmondSaaS platforms, martech, digital servicesProcessor obligations, tracking data, cross-border transfers
Southbank and St Kilda RoadGovernment offices, education providers, consultanciesVictorian public sector information handled under contract
Box Hill and BurwoodHealth services, education, community servicesPatient and student records, vulnerable client information
Carlton and inner northPrivate clinics, allied health, not-for-profitsHealth information in smaller practices with limited privacy resourcing
Dandenong and outer south eastCommunity health, aged care, disability servicesSensitive client information across multi-provider service arrangements
Regional VictoriaHealth services, councils, education providersState and federal obligations with fewer specialist privacy staff

Standalone or Combined, and How to Decide

The standalone route is new, which does not make it right for every organisation. Two questions usually settle it within a single conversation.

What Have Customers Actually Named?

Pull the last three supplier assessments or contract schedules you completed and read which certificate is specified. Melbourne health and education buyers increasingly name privacy directly. Financial services buyers more often name security. That answers the question more reliably than an internal debate about which feels more thorough.

Does Security Exposure Exist Independently of Personal Data?

If the answer is no, standalone is narrower and cheaper to maintain. Clinics, allied health practices, member associations, training providers and community services usually fall here. If you also hold commercially sensitive material or run systems where availability matters, the combined route generally makes more sense because the governance is built once and serves both.

Not sure whether standalone or combined suits your organisation?

Our Approach to a Victorian Privacy Engagement

Building the System

Data mapping precedes everything. What arrives, from whom, on what basis, who handles it downstream, where it goes offshore and when it is supposed to be destroyed. For Victorian clients this stage also establishes which regimes apply to which holdings, because a provider may hold health information under state law, member data under federal law and public sector information under contract simultaneously. Role determination follows activity by activity, then the notices, applicability statement, individual rights handling, incident runbook calibrated to serious harm, assessment methodology and retention scheduling.

Getting You to Assessment

Standalone assessment capability is still expanding across accredited bodies, so we verify who genuinely holds scope before recommending anyone. Commercial process is ours, as is preparation: an audit tested against the standard and your principle-level obligations together, with a documented review. We attend both stages.

Keeping It Current Afterwards

Australian privacy law is mid-reform, and Victorian requirements are revised on their own cycle. We carry the recurring audit work, prepare you for surveillance, watch for developments that touch your scope, and revise the data map as services, suppliers and offshore arrangements change.

Deliverables

  • Personal information map. Every holding traced to its source, basis, handlers, location and disposal point, with the applicable regime identified for each.
  • Regime determination. Which of the Commonwealth, Victorian public sector and Victorian health frameworks apply to which parts of your operation.
  • Role determination. Controller or processor established activity by activity and reconciled to Australian statutory language.
  • Breach runbook. Calibrated to the serious harm threshold in Australian law rather than to a European notification clock.
  • Impact assessment methodology. Templates, thresholds and completed assessments for your highest-risk processing.
  • Automated decisioning register. Where systems make or substantially assist significant decisions, ahead of the December 2026 disclosure requirement.

Where Melbourne ISO 27701 Projects Go Wrong

  • Victorian health privacy obligations overlooked entirely, on the assumption that Commonwealth law covers the field
  • A policy drafted before the data map exists, describing processing that may or may not occur
  • Breach procedures imported from European templates, applying a fixed notification deadline that Australian law does not set
  • Role determination declared once for the organisation rather than established per activity
  • Retention schedules written but never operationalised, leaving records the organisation committed to destroying
  • Offshore administration and cloud arrangements omitted from cross-border disclosure controls

Preparing for an upcoming audit?

Who Certifies You, and Where We Fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Selection, quoting and scheduling of the accredited body are handled by us, matched to your scope, sector and how you prefer an audit to run. We are present for both assessment stages, and anything raised becomes ours to resolve rather than a task handed back to you. One check worth doing yourself first: confirm on the JAS-ANZ register that the body holds accreditation for the scope in question. Certificates from unaccredited providers are inexpensive, fast, and regularly refused by procurement.

Start With the Data Map

Send whatever mapping already exists, however incomplete. If none does, building it is the first work we do together, and it remains the most useful thing your organisation can hold whether or not certification follows.

Ready to start your ISO 27701 certification journey?

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

Independent certification became available with the 2025 edition. Anything indicating otherwise refers to the superseded version, which existed purely as an add-on. Health, education and community organisations across Victoria often find the independent route better suited to their exposure.

Generally yes. Victorian health privacy obligations apply to health information held by private as well as public sector organisations in the state, operating alongside the Commonwealth Privacy Act rather than instead of it.

Victorian public sector privacy principles and protective data security obligations reach contracted providers through agreement terms rather than by direct operation of the statute. Your contract wording determines the scope of what you have taken on.

They cover similar ground with different drafting, numbering and some substantive variation. An organisation subject to both cannot simply apply one set and assume coverage, which is why we map holdings to regimes rather than to the organisation as a whole.

Australian law sets no fixed period. You must assess whether serious harm is likely, then notify affected individuals and the regulator as soon as practicable once aware. The 72-hour rule belongs to European law and does not apply here.

Almost always both, varying by activity. Handling data on a client’s instruction places you in one role; deciding how to use your own staff or prospect information places you in the other. We record it activity by activity.

An inventory of where automated systems make or substantially assist decisions significantly affecting people, and updated privacy policy wording disclosing it. The inventory is the part most organisations have not started.

Meaningfully. The standard draws on European privacy concepts and the current edition tightens that alignment, making it a practical way for Victorian exporters and software businesses to run one privacy system across both jurisdictions.

Your certification body sets the window. Most of what you have written remains valid. The effort goes into structure: making the applicability statement function on its own and stripping out assumptions the old edition made about a parallel security certificate.

Roughly three and a half to six months standalone, and materially less where a security certificate already exists. Data mapping governs the schedule, and organisations across multiple privacy regimes should expect that phase to run longer.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance